Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

221–230 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#221
post #73

Earlier quoted context omitted.

As a general comment to so many of the follow-ups to this post: You really, really don't want to get into a rules-lawyering match with Federal fucking prosecutors over whether "clever technological solution" counts as "hiding" something or not. They have all of the guns in this situation, and you have a demonstrably inaccurate understanding of the relevant statute. You WILL lose.

This is especially true if you allow them to frame the action as "hiding". L First you must ask them to not use loaded terminology like "hiding" when dealing with information you own and don't feel like accessing. Don't answer "yes" or "no" to whether you're hiding something. If you use their words then they have a huge advantage.

I'm gonna bet that trying to "language-lawyer" how your CBP agent phrases their questions is a one-way ticket to a private interview, because that's not suspicious at all.

Re: 1Password Travel Mode: Protect your data when crossing borders

#222
post #47

This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling, then restore when you get back. Log into the minimal number of apps after you've entered the destination country, and optionally delete/logout of said apps prior to return travel if the return border crossing is also a concern. Admittedly if you u…

>This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling

This is just another version of the "why do you need privacy unless you have something to hide" argument.

Re: 1Password Travel Mode: Protect your data when crossing borders

#223

I'm a very happy 1Password customer. Repeating my #1 feature request here, dovetailing this thread, please forgive. Problem: My logins keep breaking as websites evolve, change their forms, etc. Suggestion: Online catalog of login config/scripts. a) Pre-populate with "official" scripts for top 50 websites. Also serve as examples to show everyone how its done. b) Permit users to submit new scripts. c) Version these scr…

[deleted]

Re: 1Password Travel Mode: Protect your data when crossing borders

#224

Earlier quoted context omitted.

Then you can just turn around and be deported. Non-citizens don't have many rights at the border. The big questions is for Americans, who also have fewer rights at the border (4th amendment for example). Can they force you to sign into external services at the airport if you're a citizen? Everyone should refuse to do this.

I'm not a lawyer, and I hate having to preface that. But Hell No they can't. They can ask. They can threaten. But once they know you're a US citizen, they either detain you or they let you go (on to customs).

They can confiscate your belongings though.

Re: 1Password Travel Mode: Protect your data when crossing borders

#225

Earlier quoted context omitted.

Yup. The correct solution is to stop traveling to the US. Stop sending your employees to the US as well. If the rest of the world starts insisting that US companies always come to them because of how US border agents act, that shit will bubble up to the lobbyists real fast.

It's just that easy.

No, it's not. That's similar to saying just stay away from bullies, or leave if you don't like your job/school/whatever. It is easy if you view the issue in isolation, but for a lot of people it is more complicated, such as how will you see your loved ones / do your job / travel freely? In this case, the ones most dependent on being able to travel have little choice if they can't take on almost unlimited (potentially, but still) risk to their livelyhood.

Re: 1Password Travel Mode: Protect your data when crossing borders

#226

Earlier quoted context omitted.

Can't they order you to sign into iCloud or equivalent and then just sync whatever they want, photos, texts, emails, apps (and then order you to sign into those apps like Facebook, Whatsapp, Gmail)? Bottom line is they can get you AND everything you have access to. And it you try to circumvent it by i.e. temporarily encrypting everything for 24hr boom you just committed a felony. This is my understanding at least.

You know what's strange? I just can't remember my password to this account. Real talk, if you play games they will find a way to fuck you up, and even if it is not strictly legal, even if you with some kind of relief later (not likely a nice settlement), you will still have to deal with getting fucked pretty bad at the time. Not a great outcome.

Yeah, no shit. "Oh, you can't remember your password? That's OK, we have a nice place here for you to sit until you do."

Re: 1Password Travel Mode: Protect your data when crossing borders

#227
post #194

Earlier quoted context omitted.

If what is already happening across the country is not a good enough reason already, I doubt anything will be.

Yep. Quite simply, the 0.1% of the US population here on HN does not care about privacy nor protesting nor writing to their local or state government. HN needs to stop living in a bubble. Only 1/3 of the US even bothered voting in the Trump v Clinton presidential election. I'll let you think about that for a moment. Now think about border searches. Has your phone been searched? Neither has mine. I'll go back to my co…

In our busy and overwhelming lives it is easy to procrastinate about civic responsibilities while still caring about living in a just and fair world.

My phone has not been searched, either, but the issue here is to stand up for your rights. If you have never been wronged by a person or organization in position of authority in US government then consider yourself lucky. I and most people I know living in the US have.

Re: 1Password Travel Mode: Protect your data when crossing borders

#228
post #136
post #116

Earlier quoted context omitted.

Do you honestly think customs agents care whether you'll get fired or not? US immigrations will permanently sever families that have been together for years or even decades with utter disregard for the emotional trauma they're inflicting. Your job matters exactly fuck-all to a CPB agent.

That border agent is a real person, who is "only doing their job". So are you. It works both ways. If enough people say no, then after a hellish but hopefully short adjustment period, the policy will change.

That job they're "just doing" is, as it's drilled into their minds, to act as a barrier against anything that even might be a threat in some form or fashion to their country. They have pretty broad authority toward that end.

You (the notional you) aren't even from here. If you say no, you've identified yourself as a potential threat, and can just sit in a room by yourself for as long as it takes to put you on the next flight back to wherever you came from, at your expense. And you probably won't be allowed to return.

If you're a citizen and say no, they might confiscate the device, and might make you wait around long enough to miss your connecting flight (and maybe even the next couple, if they're feeling particularly peevish), but that's about all they can do.

Re: 1Password Travel Mode: Protect your data when crossing borders

#229
post #164

Earlier quoted context omitted.

I opted out for years and made fun of TSA agents during the pat down. It turns out you're not allowed to requests pat downs from specific agents. Who knew? ;) But now I don't even opt out. Instead I tell them that I can't raise my arms above my head. They direct me around the scanner (sometimes the metal detector too), swab my hands, and call it done. I often skip 10-15 people in the process. If they ask why, I tell…

Does that count as lying to federal government agents? (Title 18, United States Code, Section 1001)

Who said I'm lying? I'm not going to disclose private medical issues to rent-a-cops.

Re: 1Password Travel Mode: Protect your data when crossing borders

#230
post #200

Earlier quoted context omitted.

... so a link sent over a protocol that is considered "insecure" by any sane security expert allows account access? Not to mention you still have to "secure" a password to your e-mail account. I'm sorry, what in the world is Medium thinking? This is a step backwards from a user/password model.

They cover this in the article: "reset my password" emails are already the norm, so it's not any riskier than your existing online banking or social media accounts.

Resetting via link alone is yet another bad thing, because as you pointed out it leads to the exact situation you just described. Password resetting should involve some type of challenge/response, and accounts should be secured with 2FA on top of all that.

Medium still isn't winning any security points here.

Post reply on HN