Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

241–250 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#241

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

The solution to this problem is to not visit US.

Then Europe is going to do the same, and the solution will be to not visit Europe, and so. Eventually we won't be able to leave our country without giving up our privacy.

The real solution is that people from the country protest when such an abusive policy is introduced.

Re: 1Password Travel Mode: Protect your data when crossing borders

#242
If you travel for work, wouldn't it be better to just let your employer hold the password? When border security asks for data you truly cannot provide it.

I think the only way to get around this shit is to have another person hold at least part of the key. Border security can't force you to lie to your employer on the phone, so they're not getting access.

Re: 1Password Travel Mode: Protect your data when crossing borders

#243
post #238

Or: just delete the app before you get to customs and redownload after you pass customs. Simple, elegant, and fool proof.

If CBP knows you're a 1P user (which they hypothetically could since the NSA has read 1P's emails to you, a foreign user of that service), but you don't have the app installed when you attempt to enter, what makes you think they'll respond differently than they currently do to people whom they know have Facebook accounts, but delete the app from their device before attempting to enter the country, rather than allow t…

"I forgot my password"

Re: 1Password Travel Mode: Protect your data when crossing borders

#245
post #238

Or: just delete the app before you get to customs and redownload after you pass customs. Simple, elegant, and fool proof.

If CBP knows you're a 1P user (which they hypothetically could since the NSA has read 1P's emails to you, a foreign user of that service), but you don't have the app installed when you attempt to enter, what makes you think they'll respond differently than they currently do to people whom they know have Facebook accounts, but delete the app from their device before attempting to enter the country, rather than allow t…

You're absolutely correct that there's nothing stopping your proposed scenario from happening. That being said, it's extremely unlikely they'll do that because in order to do so, they would have to:

1) Intercept your emails 2) Store the fact that you're a 1P user 3) Match up your email address to you, as a person at the border 4) Stop you at the border for questioning 5) Force you to unlock your phone 6) Recognize that your phone does not have the 1P app installed 7) Force you to install the app + unlock it

For certain people, they may do that. But for the vast majority of people, they will not.

1P does not enjoy the popularity that Facebook is at. In the western world, one can reasonably expect any random given person to have a Facebook profile. The same cannot be said for 1P.

Re: 1Password Travel Mode: Protect your data when crossing borders

#246
post #66

One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time. That way if you need to use unsafe PC from a hostel, you can log in with that password.

Someone posted something like this 1-2 years ago here. They used a Yubikey (?) with TOTP to give one-time read-only (?) access to their email while traveling. They posted the project on github, I believe it was a Show HN but I cannot seem to work out the search-fu to find it. EDIT: Ok, TOTP was wrong in my recollection. They use pregenerated one-time passwords: https://news.ycombinator.com/item?id=12255833

Yeah, it is a little different if it is pre-generated. And if you face a situation where you need access your email from an unsafe computer, it is probably because you can´t use your smartphone.

So, two steps authentication is not a great option. And from my experience traveling, this kind of situation happens a lot.

Edit: Apparently LastPass has this option: https://helpdesk.lastpass.com/your-lastpass-icon/loggin-in/o...

Re: 1Password Travel Mode: Protect your data when crossing borders

#247

Earlier quoted context omitted.

> change our elected officials In America, who you vote in has very little effect on public policy, and by very little I mean a near zero/statically insignificant amount (unless you're part of the top 10% of income earners): http://fightthefuture.org/videos/does-voting-make-a-differen...

Eeyore / South Park style cyncism actively forments apathy. Self-fulfiling prophesy. Counterpoint: My friends and associates do amazing things. Marriage equality, marijuana legalization, DREAM Act, etc, etc. I (a yeoman) also do what I can. Maybe think of politics, society, culture like thermodynamics: Organization requires continuous effort, to mitigate entropy.

Keep in mind Marriage Equality in America came via the supreme court, not legislation (unlike New Zealand, Canada, et. al.)

I'm not saying people shouldn't be active. Groups like The Anti-Corruption Act (https://www.youtube.com/watch?v=lhe286ky-9A) are doing a lot, not to mention the group that pushed Maine's ranked voting amendment.

But the vote itself is not very useful. There are other forms of activism that are more worthwhile; those that seek to slowly and fundamentally change the system. Focusing on the left right paradigm will ultimately lead people to being angry at two parties that are essentially the same.

Re: 1Password Travel Mode: Protect your data when crossing borders

#248
post #233

Earlier quoted context omitted.

> Furthermore, I don't think there's anything productive at all about making the argument that federal prosecutors will get you no matter what you do. That's just shutting down the discussion entirely. Well, it is true that if the government wants to come after you- as in, you specifically- then it is basically true that they will get you no matter what you do. But that's not the point I was making in my previous pos…

> The point I was trying to make was that this 1Password feature will not help you, legally, if CBP realizes you're using it and they want to make a fuss. Maybe if you rolled your own PW manager and decided not to sync the incriminating data, you'd have a case. But this feature is literally advertised as "protect your data from unwarranted searches [clearly implying, searches by the government] when you travel". The…

> If I choose not to bring my phone with me to the border, and an agent remarks on the suspiciousness of that fact, if I were to reply, "I didn't bring it because I didn't want to travel with it," did you commit a crime?

Probably not.

> We are hinging on the subtle difference between deletion and non action.

I agree, and my argument is that "activating Travel Mode" is clearly the former, regardless of its technical implementation, because it requires positive action.

Re: 1Password Travel Mode: Protect your data when crossing borders

#249
post #215
post #197

Earlier quoted context omitted.

Potato/potahto, really. Good luck getting a visa next time if you've ever been "denied entry". Really, for non-Americans the best advice is just don't go in the first place. Second best advice is just comply with border security personnel. Any tricks like leaving the battery empty, bringing a burner, not bringing a laptop and getting a loaner when you get there etc, they do nothing but raise suspicions.

> they do nothing but raise suspicions Oh god, no. Technical measures - of course - do work. So does erasing data from phones, laptops, hard drives, etc. Do not let the security theater scare you into obedience.

Again, this is not valid advice for non-citizens. If you're a citizen, sure, feel free to go through with an empty or password-protected device. Maybe you'll be detained for a while, inconvenienced, given a stern talking to, etc.

If you're not a citizen? You can be denied for literally anything the agent feels like. They feel you're suspicious because you claim (falsely or not) you don't have a facebook account? You're not coming in. Visa denied.

Re: 1Password Travel Mode: Protect your data when crossing borders

#250
post #238

Earlier quoted context omitted.

If CBP knows you're a 1P user (which they hypothetically could since the NSA has read 1P's emails to you, a foreign user of that service), but you don't have the app installed when you attempt to enter, what makes you think they'll respond differently than they currently do to people whom they know have Facebook accounts, but delete the app from their device before attempting to enter the country, rather than allow t…

"I forgot my password"

That will get you a cell in the UK, true or not.

In the US, it will probably get you denied entry, possibly permanently, for "lying to a customs officer" (if a non-citizen), or the device possibly being confiscated if you're a citizen, (and a note in a file somewhere that says you've probably lied to a federal agent — particularly if they happen to catch any security camera footage of you stupidly using your device shortly after exiting the international arrivals area).

Post reply on HN