Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

191–200 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#191

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

Ill tell the TSA no if you buy me a new laptop/phone when it happens.

Re: 1Password Travel Mode: Protect your data when crossing borders

#192

Earlier quoted context omitted.

Can't they order you to sign into iCloud or equivalent and then just sync whatever they want, photos, texts, emails, apps (and then order you to sign into those apps like Facebook, Whatsapp, Gmail)? Bottom line is they can get you AND everything you have access to. And it you try to circumvent it by i.e. temporarily encrypting everything for 24hr boom you just committed a felony. This is my understanding at least.

IANAL and I don't have an answer to this, but I would be deeply alarmed if this were the case. I can understand them making the case that anything on your personal is searchable (though I disagree that this should be allowed). By asking you to sign in and sync, they're not just requesting access to information on your person -- that's an enormous expansion of their search powers.

I mean, aren't they forcing you to give Facebook passwords now?

https://www.cnet.com/news/us-border-agents-facebook-twitter-...

Re: 1Password Travel Mode: Protect your data when crossing borders

#193

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

I can tell you most of the corporate policy says comply with all law enforcement requests when asked while traveling and report it to corporate security/legal.

Re: 1Password Travel Mode: Protect your data when crossing borders

#194
post #178

Earlier quoted context omitted.

> the policy will change. The policy might change to include cells at the borders where people are detained until they hand over login details or voluntarily decide not to enter.

Should the slope become that slippery we'll have a much better reason to stand outside a legislator's office with pointy sticks than "I was mildly inconvenienced by the TSA."

If what is already happening across the country is not a good enough reason already, I doubt anything will be.

Re: 1Password Travel Mode: Protect your data when crossing borders

#195

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

Many US workers are not citizens. Your solution would mean losing both their job and home if they were stopped on their way back into the US.

A better solution is to not allow people to travel with anything that would be catastrophic if lost. My former employer would give employees loaner devices for travel to certain countries.

Re: 1Password Travel Mode: Protect your data when crossing borders

#196
post #83

Earlier quoted context omitted.

> Can the border patrol ask you to sign into any online service? If you're a non-citizen attempting to enter the US under a visa waiver program, from certain countries, yes, they can.

a border officer searched for me on fucking facebook when i was going into the us in march. she said "i just want to know who you are and why you are coming". i don't have a facebook account. she said this was really suspicious. oh and she also found suspicious that i had two us entry stamps within a week of each other and didn't accept my explanation that i had gone through the us to go to england with my wife (even…

Actually they ask for social media accounts when applying for a visa waiver now, e.g. ESTA.

I bet they'll mark you as suspicious if you travel without any electronics too, because that has become uncommon.

Re: 1Password Travel Mode: Protect your data when crossing borders

#197

Earlier quoted context omitted.

> always answer "no" to "may I search your laptop?" in my case, that would mean deportation due to not being american. i either get deported and lose all the traveling plans or i get searched.

I think in this case the correct technical term is "denied entry". You haven't passed immigration to the country. Deportation is the expulsion of someone who's actually in the country, past the border, and resident or visiting.

Potato/potahto, really. Good luck getting a visa next time if you've ever been "denied entry".

Really, for non-Americans the best advice is just don't go in the first place. Second best advice is just comply with border security personnel.

Any tricks like leaving the battery empty, bringing a burner, not bringing a laptop and getting a loaner when you get there etc, they do nothing but raise suspicions.

Re: 1Password Travel Mode: Protect your data when crossing borders

#198

It's a clever idea, but how long before border authorities simply order travelers to log on to 1Password and turn off travel mode, or be denied entry? I'm guessing not very.

A solution, and what I first thought this did from the headline is to lock you out of your account for, say 4 hours

Re: 1Password Travel Mode: Protect your data when crossing borders

#199

Earlier quoted context omitted.

And I could argue that my intent was to protect myself from identity theft, should my device be stolen. It's a reasonable explanation for having deleted the data. I'd also argue that I could've purchased a completely new device immediately prior to travel and brought that along, with the intention of being able to say that the device had never contained information that I was trying to hide. I think that part of the…

> [proving intent is] essentially impossible if you have a device that never contained sensitive data in any form. I'd like to see a short story based on this premise: man is arrested and tried for crossing the border with a brand new phone, having left his usual phone at home. The prosecution argues that since he presumably usually keeps sensitive information on his phone, not copying that data to the phone he was c…

I think it's a race already, between the story being written and it actually happening to someone.

Re: 1Password Travel Mode: Protect your data when crossing borders

#200
post #66

One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time. That way if you need to use unsafe PC from a hostel, you can log in with that password.

Or why we have passwords at all. Sites like Medium have moved to a passwordless model, where you're sent a login link to access your account rather than forcing you to remember or retrieve a password. https://blog.medium.com/signing-in-to-medium-by-email-aacc21...

... so a link sent over a protocol that is considered "insecure" by any sane security expert allows account access? Not to mention you still have to "secure" a password to your e-mail account.

I'm sorry, what in the world is Medium thinking? This is a step backwards from a user/password model.

Post reply on HN