Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

501–510 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#501

Earlier quoted context omitted.

You forgot the end of the story: "I'm denying you the ability to enter the country. Next time you let me see everything instead of being a wise guy."

If you are an American citizen, can they prevent you from entering the country? I understand they can delay you, but I don't think it can be indefinite.

^ This right here.

They can deny foreigners, but I've always read that they cannot deny Americans in unless their citizenship gets revoked, I guess.

Re: 1Password Travel Mode: Protect your data when crossing borders

#502

Earlier quoted context omitted.

:-/ What we really need is plausible deniability - if they don't know you use 1password, they don't know to ask for it.

Is plausible deniability the right term here? Usually that's about the ability to deny having known about or authorised something after it's already been discovered. I'm not really sure how you'd refer to the concept "they don't know I have it, so they don't know to ask". Security through ignorance?

I guess it's a type of steganography then.

Re: 1Password Travel Mode: Protect your data when crossing borders

#503

Earlier quoted context omitted.

NSA can probably modify the firmware to create some sort of backdoor, if you actually look like that would be worthwhile?

Maybe the NSA can, maybe the NSA can't - but even if they could, I guarantee that customs/postal workers won't have access to it. Unless the NSA is specifically intercepting your particular SSD (in which case you have much bigger problems), standard enterprise-grade encryption will be good enough for shipping purposes.

This goes back to the level of protection you need/want, from whom, and whether you're a target of opportunity or a specific target.

Are you protecting against "drive-bys", the casually curious, motivated low-resource targeted attacks (e.g. disgruntled former employees, hated neighbors), "small" resource targeted attacks (<$50k?), high-resource attacks or state entities?

Re: 1Password Travel Mode: Protect your data when crossing borders

#504
post #328

If you are refusing to enter the password, access to the device, or to disable travel mode, then good luck to you. IANAL, but the border agent doesn't care if the data is technically in the cloud, rather than on the device, because it restores when you unlock it. In addition to removing the data from the device, cheers, don't you also need to be able to honestly say you can not provide access to it? Ways to honestly…

If you read the article, there is no "tell" that 1Password is in Travel Mode. The only impact is that most of your passwords are missing from the password vault, but the agent would have no way of knowing what's missing. It's not like it pops up a big "Travel Mode" banner.

Well, they might have sigint indicating that you have Gmail account, a Facebook account and a WhatsApp account, for example.

Re: 1Password Travel Mode: Protect your data when crossing borders

#505

Earlier quoted context omitted.

If you take the time to FedEx your SSD to avoid customs you certainly made sure the disk was encrypted...

NSA can probably modify the firmware to create some sort of backdoor, if you actually look like that would be worthwhile?

That would take a lot more work than just "searching through someone's private stuff on an airport" though;

I mean many "average" people get searched on airports, but i don't see why they would intercept an average guys Fedex shipped harddisk and do some voodoo on it. Unless of course you know you're being targeted for some specific reason.

Re: 1Password Travel Mode: Protect your data when crossing borders

#506
post #328

If you are refusing to enter the password, access to the device, or to disable travel mode, then good luck to you. IANAL, but the border agent doesn't care if the data is technically in the cloud, rather than on the device, because it restores when you unlock it. In addition to removing the data from the device, cheers, don't you also need to be able to honestly say you can not provide access to it? Ways to honestly…

>enable whitelist/blacklist zones via geolocation

This is exactly the approach I took with my password vault application (android only, far less well-known than 1password). I added a location-lock feature that allows the user to store a number of "safe locations" outside of which the vault simply will not decrypt, even if the correct password is entered.

The app also makes it very clear that location lock is enabled and that the user is outside of all "safe zones" and therefore will not unlock. The only way a border agent is getting access is to figure out the GPS coordinate encryption method and adding a new set into the sqlite db or physically driving to one of the safe locations and unlocking it there.

Re: 1Password Travel Mode: Protect your data when crossing borders

#507
post #485

Earlier quoted context omitted.

It's not really the same thing at all. Something you leave in your office is something you won't have access to at your destination - so it's logical that it wouldn't be subject to customs. Something online, regardless of physical storage location, is something you will have access to at your destination, so it should be subject to customs.

So if you travel without your phone, they still have the right to demand access to your email account? How does that make any sense?

I don't know whether or not they have the right - do they have the right to read some sealed-up documents in your briefcase? Whatever your answer to that question is, it should probably be the same answer to the e-mail question. All these trick arguments about "oh but the e-mail's not actually on my phone, it's in the cloud!" don't hold water for me; it's information you're bringing into the country. Either it's subject to search or it isn't.

Re: 1Password Travel Mode: Protect your data when crossing borders

#508
post #497

Earlier quoted context omitted.

You can get a 10 year prison sentence or so for bribery. In any country in the world, you can be prosecuted there, or in the US or Europe. You will probably also be fired.

> You will probably also be fired. Please elaborate on that.

Any large company has an ethics code. Bribing government employees is usually a rather big no-no in that code.

Re: 1Password Travel Mode: Protect your data when crossing borders

#509
post #494

I'm struggling to understand all the comments here, but it feels like I'm living in an alternate universe. All of these questions like "but do the customs agents search for hidden partitions", etc... Who is it that is running into all these scenarios with border control? I've gone on international flights, including to the us, dozens of times, and have seen around me thousands upon thousands of travelers, and I've ne…

According to a CBP press release from April, "in the first six months of FY17, CBP searched the electronic devices of 14,993 arriving international travelers, affecting 0.008 percent of the approximately 189.6 million travelers arriving to the United States."

The release goes on to show that this is nearly twice as frequent as the equivalent period last year.

Re: 1Password Travel Mode: Protect your data when crossing borders

#510
post #37

Earlier quoted context omitted.

Literally removing your access to data isn't the same thing as hiding it. Having a TrueCrypt partition on your drive that you can still unlock if you know it's there is hiding it. Securely erasing that partition is not.

Is there any difference between securely erasing a TrueCrypt partition vs forgetting the password?

Yeah, in the former the information is truly gone, but in the latter, you're trying to convince people that you forgot something you used to know, and they may not believe you.
Post reply on HN