Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

301–310 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#301

Earlier quoted context omitted.

Yep. Quite simply, the 0.1% of the US population here on HN does not care about privacy nor protesting nor writing to their local or state government. HN needs to stop living in a bubble. Only 1/3 of the US even bothered voting in the Trump v Clinton presidential election. I'll let you think about that for a moment. Now think about border searches. Has your phone been searched? Neither has mine. I'll go back to my co…

Where did you get the 1/3 from? It's been 55% of eligble voters. Counting non-eligibles wouldn't really make sense in your argument Source: https://www.google.de/amp/s/amp.cnn.com/cnn/2016/11/11/polit...

Actually you should count all Adults not just "eligible" for a few reasons

1. No one once reaching the age of majority should have their voting rights taken, for any reason including criminality

2. The figures also do not include people of age who are ineligible to vote or have not registered. The "Have not registered" is a key part because many stated in the last 2 election cycles have been passing a number of laws to disenfranchises segments of the populations making it harder and harder to register

3. The concept of our nation is "Consent of the people", that is all people, not just those voting. the majority of PEOPLE reject the 2 candidates put forth buy the corrupted and unethical political parties then the government can not claim to have the consent of THE PEOPLE...

Many many many Americans feel complete disenfranchised by the political systems that gives them 2 Choices that are equally terrible and corrupt. Forcing a defensive vote that is mainly against the person you do not want to win instead of voting for a qualified person you actually want to be in office.

As a life long Libertarian, I have no interest in voting for either a Republican or Democrat

Re: 1Password Travel Mode: Protect your data when crossing borders

#303

Mandatory "No Linux client" comment :| Does anyone have any insight if this is a pure business decision or there's something holding them back technically?

They can't even ship version of their Windows client with the ability to create/edit/delete local vaults.

I think they are focusing on money before all else. They do still make a good product, but the direction they are moving towards eliminates their support for many threat levels that they had previously.

Now you have to have a cloud account and you have to store your stuff there because their supposed "cross-platform" client cannot work on their own vault format on Windows.

They might respond saying the version 4 of the windows client supports working with these vaults, but version 4 does not support OTPs so if you want to use the modern features without relying on their cloud storage...they don't care.

If you go to their forums and read the response from the community about windows not supporting creating or editing of local vaults you will see they are by and large dismissive. So I think it's really about money and resources.

Re: 1Password Travel Mode: Protect your data when crossing borders

#304

Wouldn't an alternative "destroy everything" password be a good idea also ? Would work like this : When forced to enter / give the password to your vault, you enter/give this one, and everything the vault contains is wiped out before the vault is unlocked.

Once again we drum up technical "solutions" to what ultimately is a policy issue. A better idea is to change our laws so that our constitutional rights are respected. If that's not possible then the next solution is to change our elected officials.

Blow up Sovereign Immunity ffs. If someone gets detained they have no recourse or compensation to mitigate it being used as a threat.

Re: 1Password Travel Mode: Protect your data when crossing borders

#305
post #116

Earlier quoted context omitted.

Do you honestly think customs agents care whether you'll get fired or not? US immigrations will permanently sever families that have been together for years or even decades with utter disregard for the emotional trauma they're inflicting. Your job matters exactly fuck-all to a CPB agent.

It completely depends if you are white or not. If you are white, and speak politely, the agent will care deeply about your concerns, including potential firing as an example. If you are not white, and especially if you appear black, Latino or Arab, then your comment will definitely hold true.

Recently delayed by the TSA to the point of missing my turn to board. Was subjected to additional searching. Upon finding nothing, I discovered the extra searching was what they do when you fail the hand swab test. I had not had the test administered. So they administered the test. I passed. They then searched my things again and I was questioned regarding the quantity of business cards I was carrying.

Oh also I'm white.

Re: 1Password Travel Mode: Protect your data when crossing borders

#306

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

> Companies need to make clear to their employees (and the public) that sharing passwords is a terminable policy violation.

Companies cannot tell their employees to not comply with lawful request of a federal officer, and some companies specifically underline that in a company policy.

Re: 1Password Travel Mode: Protect your data when crossing borders

#307
I'm a little sad that this would require me to use the 1Password cloud-service. I would never want my 1Password vault to be on any server outside of my control. While I completely trust agilebit's intentions, I feel that their cloud service adds a very major attack surface. Someone like the NSA would certainly be able to obtain copies of the encrypted vaults, which means that everyone's vaults are just one bug/backdoor in the cryptographic stack (remember Debian RNG bug?) away from being exposed.

Hence, I only use WiFi sync for 1Password. It would be nice if 1Password added a sync option through my own WebDAV server. I'd then be happy to pay for a 1Password cloud account just for the TravelMode feature, as long as the vault data itself wasn't stored anywhere outside of my control. Having my own server would mean the the NSA (or whoever) would have to do a targeted attack on me personally, which is a whole different ballgame from everybody's encrypted vaults sitting on agilebit's servers.

In the meantime, if I had to cross the US border (as a non-citizien!), I would probably delete the whole 1Password app from my phone before crossing, and then restore the entire phone from backup afterwards.

Re: 1Password Travel Mode: Protect your data when crossing borders

#308

Earlier quoted context omitted.

It completely depends if you are white or not. If you are white, and speak politely, the agent will care deeply about your concerns, including potential firing as an example. If you are not white, and especially if you appear black, Latino or Arab, then your comment will definitely hold true.

Recently delayed by the TSA to the point of missing my turn to board. Was subjected to additional searching. Upon finding nothing, I discovered the extra searching was what they do when you fail the hand swab test. I had not had the test administered. So they administered the test. I passed. They then searched my things again and I was questioned regarding the quantity of business cards I was carrying. Oh also I'm wh…

TSA is not the same agency as CBP. They don't receive the same training, encounter travelers in the same situations, enforce the same laws, or execute the same authority.

Re: 1Password Travel Mode: Protect your data when crossing borders

#309

This feature really should ask you to commit to your duration of travel beforehand. It's no use if you can be compelled to readd the data.

That doesn't solve the problem, because you could be detained until the data is accessible again.

No you can't be detained indefinitely (unless they have evidence to charge you with a crime). You could have your devices confiscated, and as a non-citizen, you could be denied entry.

Re: 1Password Travel Mode: Protect your data when crossing borders

#310

Earlier quoted context omitted.

That's basically the definition of spoliation of evidence, if things were to ever escalate to civil or criminal proceedings.

This qualifies already. 18 U.S. Code § 1519 defines it as "Whoever knowingly...conceals...with the intent to impede...the proper administration of any matter within the jurisdiction of any department or agency of the United States" So technically, entering travel mode for the purpose of hiding your stuff from border agents could be interpreted as a violation of that statute, regardless of whether there was an active…

The "matter within the jurisdiction" of border control is to inspect anything being brought across the border. You're not impeding that. You're simply not bringing something across the border. This is different from e.g. hiding drugs in your suitcase (or even data on a device): there you're impeding their ability to inspect those drugs.
Post reply on HN