Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

61–70 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#61
post #37
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

Literally removing your access to data isn't the same thing as hiding it. Having a TrueCrypt partition on your drive that you can still unlock if you know it's there is hiding it. Securely erasing that partition is not.

This is closer to the former than the latter. You aren't erasing the data that's protected under the vaults. You're just temporarily removing the vaults from local storage, disabling access and obscuring its presence. It's trivial to re-enable that access, so you are hiding, not destroying.

Nice mental gymnastics, though. I'm genuinely curious whether the first Federal judge to see this argument laughs or issues a contempt citation first.

Re: 1Password Travel Mode: Protect your data when crossing borders

#63
post #58

I don't get how this would prevent border agents from asking to unlock / turn off travel mode. Why not make this feature tied to a geo-location? Like the hotel or the conference centre I will be attending.

AFAIK you can only deactivate the travel mode on the web profile. Of course it would be much more effective when you use it in the team mode. So that someone else has to deactivate the mode for you.

Re: 1Password Travel Mode: Protect your data when crossing borders

#64

Is travelling with confidential data really necessary? Wouldn't it make more sense for me to have a 'empty' notebook and store my data out of harm's way (but accessible via a VPN).

I've come to the conclusion that this is the only reasonable technical solution.

Don't travel with sensitive data, and openly explain that you don't do so.

The frustrating part is the UX, and the fuss when you land.

I've found that this works:

- Burner android (burner account explicitly for travel) for music, podcasts, light browsing, etc.

- Cheap ThinkPad for headscratching / hacking (work over SSH, keys on a Yubikey, IP in your head. YubiKey as second factor for password manager as browser extension (uninstall before the border))

Re: 1Password Travel Mode: Protect your data when crossing borders

#65

Earlier quoted context omitted.

How is the web interface handled? Essentially, where do you turn this on and off? Wouldn't it become standard ptotocol to just demand web credentials for 1Password? This feature is only for subscription based 1Password accounts, so it would seem to me it would just be easiest to delete the app and re-download after crossing?

Demanding web logins rather than local logins for anything is a step beyond the fuzzy legal authority currently given to the TSA.

Not CBP though, which is the relevant institution for international border crossings.

Re: 1Password Travel Mode: Protect your data when crossing borders

#67
post #41

Earlier quoted context omitted.

Entering travel mode is literally deleting the data off your computer. It's not concealing anything. I think a federal prosecutor would have a hell of a time arguing that people aren't allowed to erase data from their computer before traveling.

In the law, intent matters. You're deleting the data with the intent to hide it from border agents. A federal prosecutor absolutely could argue that, if they wished.

I'd be entering travel mode with the intent of removing the ability to access the data from the device. I would be surprised if travel mode deleted my data.

Re: 1Password Travel Mode: Protect your data when crossing borders

#68
post #41

Earlier quoted context omitted.

Entering travel mode is literally deleting the data off your computer. It's not concealing anything. I think a federal prosecutor would have a hell of a time arguing that people aren't allowed to erase data from their computer before traveling.

In the law, intent matters. You're deleting the data with the intent to hide it from border agents. A federal prosecutor absolutely could argue that, if they wished.

You're deleting the data because you don't want to travel with that data. You're not hiding it. You literally just don't want to have access to it while you're traveling. In that sense it's no different than, say, leaving a hard drive with all your data behind (plugged into an internet-enabled computer that you can SSH in to and transfer your files back to yourself after you've crossed the border).

Re: 1Password Travel Mode: Protect your data when crossing borders

#69
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

Based on this wording, it sounds like a team admin might be able to enforce travel mode such that the user can't disable it.

>If you’re a team administrator, you have total control over which secrets your employees can travel with. You can turn Travel Mode on and off for your team members, so you can ensure that company information stays safe at all times.

In which case, you as a user literally can't access the information without communicating with an admin at your organization. If CBP ever starts requiring that you call a third party to retrieve confidential information, well... I hope we never get to that point.

Re: 1Password Travel Mode: Protect your data when crossing borders

#70
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

At first, I thought the same thing. But if they ask that question, then no, I'm not hiding it from the border agent. I'm disabling a feature while I travel so that nobody has the potential to get to it.

Edit: Besides, if I ever travel out of country with my work phone, if anyone wants access to it they'll need to call my work's legal office as I'm not allowed to let anyone access that phone without their permission.

Post reply on HN