Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

441–450 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#441
post #42
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

"Are you hiding any drugs from us?" "Oh yeah, I've got lots in my apartment in $ANOTHER_COUNTRY" Why should the actual answer be any different with data than it would be with the drugs?

Have you set things up so the drugs will be available to you once you have gone through security?

Re: 1Password Travel Mode: Protect your data when crossing borders

#442
post #249
post #215

Earlier quoted context omitted.

> they do nothing but raise suspicions Oh god, no. Technical measures - of course - do work. So does erasing data from phones, laptops, hard drives, etc. Do not let the security theater scare you into obedience.

Again, this is not valid advice for non-citizens. If you're a citizen, sure, feel free to go through with an empty or password-protected device. Maybe you'll be detained for a while, inconvenienced, given a stern talking to, etc. If you're not a citizen? You can be denied for literally anything the agent feels like. They feel you're suspicious because you claim (falsely or not) you don't have a facebook account? You'…

What you are describing is not the result of yourself protecting your privacy but the result of being found to be suspicious.

Not appearing suspicious is an important part of protecting your privacy. While it's true that acting stupid or careless can bring you in trouble this is not sufficient to deny the utility of privacy enhancing behavior.

Re: 1Password Travel Mode: Protect your data when crossing borders

#443

I've had this idea for so many years now: your gmail account has - let's call it - a master password and a throwaway password. Say you need to print something from a public PC, you just use that password that works only once, even if somebody key-logs it, you're safe.

2FA is basically an ever changing 2nd password used 1 time. I use it everywhere it is supported. More info: https://www.google.com/landing/2step/

Additionally Google will give you a set of (longer) `recovery codes' that can be used as one-time second factor passcodes.

Re: 1Password Travel Mode: Protect your data when crossing borders

#444
post #211

Earlier quoted context omitted.

Bingo. Why would anyone want to go through that on their vacation? Unless you enjoy that sort of thing, go somewhere pleasant instead. (And if you enjoy that sort of thing, there are far easier ways...) I say this as a US citizen who will be sad if it comes to pass, but this bullshit won't stop unless the rest of the world refuses to put up with it. Your average US citizen doesn't travel internationally (only about 1…

Put up with what? I go through Houston Customs almost every month and they rarely search anyone. It's like a river of people walking right out the airport doors after a cursory glance at the customs declaration. I have never once seen a person with an open laptop in the search areas. That doesn't mean it doesn't happen but good grief, what's the actual percentage? I am willing to bet a minuscule percentage gets their…

The US will not provide foreigners with a visa unless they submit to be fingerprinted like a criminal:

https://travel.state.gov/content/visas/en/general/border-bio...

I'm not a criminal, and I will not be fingerprinted.

Re: 1Password Travel Mode: Protect your data when crossing borders

#445
post #427
post #407

Earlier quoted context omitted.

Customs read these articles just like us. What if they ask you if travel mode is turned on? Will you lie?

I was thinking this (and no I wouldn't lie to customs), but the second half of the article details how to let a remote administrator enforce these policies, ie blame your employer for wanting to secure their data from unauthorised access. Of course the real answer is to avoid the business hostile USA (or at least the border)

The definition of "border" is surprisingly vast too -- if you're within 100 miles of any "external boundary". Two thirds (!) of Americans live within this "border" area.

https://www.aclu.org/other/constitution-100-mile-border-zone

Re: 1Password Travel Mode: Protect your data when crossing borders

#447

Earlier quoted context omitted.

well, with some experience, border guards will learn to spot a non-ntfs partition, that windows dutyfully reports as unformated/blablah space, so that will eventually be caught, dont rely on this to actually protect you, its more of a sleigh of hand that may be easily spotted by the right guard.

Time to write one's own filesystem driver, that either hides this info or shows the disk as fully partitioned but empty NTFS partition, and when something tries to write onto it, throws a failure (so you can have e.g. 10 MB at the very front of the partition free, and the rest looks empty, but actually contains your Linux system) Another hack would be one's own BIOS, that lies to Windows saying "This disk is 100 GB",…

What about dumping the partition table before simply removing the partition that matters? Just restore the partition table later. You could even grow the remaining partition without growing the actual filesystem, and hack something so that the FS layer reports the whole size. Or have both GPT and MBR that differ, offering two different views of the disk. If you're using lvm or btrfs you could also make a snapshot before removing all data then revert to the snapshot, and/or apply clever subvolume tricks like btrfs-convert does to keep the ext filesystem around [0].

[0]: https://btrfs.wiki.kernel.org/index.php/Conversion_from_Ext3

Re: 1Password Travel Mode: Protect your data when crossing borders

#448

Earlier quoted context omitted.

This sounds like the reprisals citizens of the totalitarian states in the Warsaw Pact had to endure. Heads up for pushing against it. Out of curiosity, do you know if there are any people trying to challenge these rulings/treatment they receive in court?

At least in those - and I'm sure this still happens - you could bribe the officials. Actually is that possible in the US or do the border officials still have a stick up their arse? I mean if you work for a big multinational IT company, surely they can provide a few hundred bucks to bribe someone to skip security. Bribing the police is normal in a lot of countries.

Yeah. My father described the experience of crossing borders between East Germany/Poland/Belarus/Ukraine in the 80s early 90s as the exact same theatre -

" -sir, we have to strip your car to search it for contraband.

-Ok, how long it's going to take?

- About 24-48 hours, but it might take longer if we see anything suspicious

- ok, what do I do in the meantime?

- you can sit on the bench there

- for 48 hours?

- that's correct

- I happen to have this nice bottle of vodka, would you like it as a thank you for your hard service?

- hmmmm I have to check with my superior [ comes back 5 minutes later] - that's fine, we don't need to check your car today, have a safe journey"

Nowadays I'm being told that this practice has been eradicated almost everywhere, but it basically relied on border control agents making your life as miserable as physically possible in hope that you will pay up. If you decided not to, they would eventually let you go, but you're wasting only your own time, they had infinite amount of it and perfect justification for everything they did.

Re: 1Password Travel Mode: Protect your data when crossing borders

#449
post #368
post #352

"May I search your laptop?" "Certainly." "But... this is practically empty." "Yes sir. I FedEx'd my SSD to the destination." I have a small SSD in the primary disk in my T420s, it has just enough to get me through the flight. I keep the primary in the UltraBay with a simple adapter, takes one reboot and no tools to put it back in place. Done. Happy searching! I can't log into anything even if I wanted to because I ph…

It's a practical approach, and my comment here isn't necessarily aimed at you, chx (since I don't know your citizenship status), but I would add this entreaty to American citizens like me: If you ever get asked that question at the US border, please don't acquiesce to that request. They have the right to ask, and they even have the power to search it regardless of your permission, but despite an alarming drift toward…

I am a dual Canadian-Hungarian citizen, residing in Vancouver, BC, Canada. I work remotely for a USA client. Avoiding the USA is hard / impossible.

Re: 1Password Travel Mode: Protect your data when crossing borders

#450
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

The point of travel mode isn't to dodge border control policies or questioning; the point is to prevent the exposure of credentials when travelling, even if the exposure is to a border agency. If a border agent asks you directly, "Did you remove information from this device to prevent us or others from seeing it when entering or within this country?" the only truthful answer is "Yes", but travel mode has still achiev…

At some point, you're going to have to have a separate device for international travel. Then they'd have to ask: "Do you have another device back home that you didn't bring because it contains sensitive information?"
Post reply on HN