Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

511–520 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#511
post #425

Earlier quoted context omitted.

Any idea why this happens to you? Your story suggests some targeting.

I was once on a list that got me secondary searching every single time I flew in the USA, for several years. This was back in the 1990s, when asking for your password wasn't a thing I've ever heard of them doing, but also when me bringing 128-bit encryption software (aka the US version of Netscape Navigator) to Japan, where I was a foreign student, was a serious crime akin to arms smuggling. Of course, I never found…

Myhrvold is a scumbag now, but back in the 90's he pulled off a heroic fuck you to NSA.

NSA didn't want to allow Microsoft to build RSA into Windows and export it. Even though the cat was out of the bag and foreign OEMs and vendors were already selling RSA. NSA wanted Microsoft to not give users more than 40 bits of encryption keys.

So Myhrvold, as President of Microsoft, flippantly offered to pad the keys generated by Windows with NSA's public RSA key. Win Win. Users can export more than 40 bits, and NSA gets a backdoor.

Microsoft won and was allowed to export software using RSA. No doubt that little stunt put Myhrvold on some Watchlist for Life.

It's too bad he became evil after he became a billionaire and started only caring about money and Yachts and hob knobbing with other 1% elites.

Re: 1Password Travel Mode: Protect your data when crossing borders

#512

Earlier quoted context omitted.

Is there any difference between securely erasing a TrueCrypt partition vs forgetting the password?

Yeah, in the former the information is truly gone, but in the latter, you're trying to convince people that you forgot something you used to know, and they may not believe you.

Don't most secure erase tools just write a stream (over several passes) of pseudo-random noise? If so, then it should be indistinguishable from a TrueCrypt partition.

Re: 1Password Travel Mode: Protect your data when crossing borders

#513
post #483

Earlier quoted context omitted.

So, if they're already in the business of demanding your passwords (otherwise this whole thing is irrelevant), why don't they just ask you to log into your 1Password account and see if you're in travel mode there?

They could, which is why I'd recommend not having your 1Password password with you. Disable travel mode once you return home.

It doesn't really matter. If you're an American citizen, you can just refuse and they have to let you enter. They might confiscate your device, but they can't turn you away from the border.

And if you're not a US citizen, "I'm not physically able to unlock the account right now" doesn't buy you anything. There's no obligation that says if you do all you can physically do to accommodate their wishes, that you get to enter. If they want access, you either grant access or you get back on a plane. The only thing not having your 1Password credentials with you does is remove the choice of which you want to do.

Re: 1Password Travel Mode: Protect your data when crossing borders

#514

Earlier quoted context omitted.

If you take the time to FedEx your SSD to avoid customs you certainly made sure the disk was encrypted...

NSA can probably modify the firmware to create some sort of backdoor, if you actually look like that would be worthwhile?

Probably?

Snowden leaks already show NSA has badbios-style firmware viruses targeting every manufacturer, every model, going back a decade. Imagine what they have today. Why not mass infect all hard drives at the factory? Targeting individuals or "thematic warrants" are still too clunk and doesn't scale.

All these folks who say "I'll out smart them, I'll encrypt my SSD and Fedex it" are "Not Even Wrong."

http://www.spiegel.de/media/media-35661.pdf

Re: 1Password Travel Mode: Protect your data when crossing borders

#515
post #509
post #494

I'm struggling to understand all the comments here, but it feels like I'm living in an alternate universe. All of these questions like "but do the customs agents search for hidden partitions", etc... Who is it that is running into all these scenarios with border control? I've gone on international flights, including to the us, dozens of times, and have seen around me thousands upon thousands of travelers, and I've ne…

According to a CBP press release from April, "in the first six months of FY17, CBP searched the electronic devices of 14,993 arriving international travelers, affecting 0.008 percent of the approximately 189.6 million travelers arriving to the United States." The release goes on to show that this is nearly twice as frequent as the equivalent period last year.

The press release in question:

https://www.cbp.gov/newsroom/national-media-release/cbp-rele...

Re: 1Password Travel Mode: Protect your data when crossing borders

#516
post #509

Earlier quoted context omitted.

According to a CBP press release from April, "in the first six months of FY17, CBP searched the electronic devices of 14,993 arriving international travelers, affecting 0.008 percent of the approximately 189.6 million travelers arriving to the United States." The release goes on to show that this is nearly twice as frequent as the equivalent period last year.

The press release in question: https://www.cbp.gov/newsroom/national-media-release/cbp-rele...

Thanks very much, I had been e-mailed a copy and didn't have the link handy.

Re: 1Password Travel Mode: Protect your data when crossing borders

#517
post #497

Earlier quoted context omitted.

> You will probably also be fired. Please elaborate on that.

Any large company has an ethics code. Bribing government employees is usually a rather big no-no in that code.

Any large company also makes allowances for differences in local laws and customs when applying their ethics code.

Re: 1Password Travel Mode: Protect your data when crossing borders

#518
post #470

Earlier quoted context omitted.

You misunderstand me; it is not the issue of the cost of the device, but the 2-4h on each side of imaging and restoring (for mobiles) or the 4-8h on each side for computers.

Employees can handle imaging and restoring. You can send an employee in advance, who will have devices ready for you on arrival. So all that gets handled while you're in transit.

If you have any methods for hiring employees trustworthy enough to backup and reimage my most secure computing device with the most sensitive data, and somehow do so on notice given only via ESP, at several major world airports, please do let me know.

I guess I could get a fourth phone, the one I use only for talking to my Airport Phone Guy, who would somehow be incorruptible enough to not hijack my bitcoin wallet or take copies of my camera roll (which, if used strategically, could alternately make or ruin entire careers or companies).

I'll be over here in the Real World.

Re: 1Password Travel Mode: Protect your data when crossing borders

#519
post #479
post #428

Earlier quoted context omitted.

For five years or so, I (a US citizen) politely but firmly refused to answer a single question put to me whilst re-entering the United States, as is my human right.

Not even "Was your trip business or pleasure?" Border guards have the power to prevent you from entering the country if they believe your business is unlawful, and asking those questions is one of the ways they decide. We can question whether border guards ought to exist, but, given that they do, refusing to answer their questions seems like a ticket to a back room for hours. You really never answered their questions…

The fifth amendment does not go away suddenly at the border (4A notwithstanding).

If exercising my human rights is "a ticket to a back room for hours", then something is fundamentally broken in our society. You should try it; without doing so you actually have no data about the practical perimeter of your basic rights. This stuff isn't printed in the newspaper.

Yes, I really never answered their questions, except the ones about citizenship and nationality and place of birth—which I answered by presenting my passport.

"Business or pleasure?" is a vague, leading question designed to get you to volunteer as much information as possible. Sometimes I replied "no" or "yes" to that one, with an occasional "On advice of my attorney I decline to answer questions from police except in writing and via counsel" thrown in to break up the monotony.

Never talk to the police.

Re: 1Password Travel Mode: Protect your data when crossing borders

#520
post #470

Earlier quoted context omitted.

You misunderstand me; it is not the issue of the cost of the device, but the 2-4h on each side of imaging and restoring (for mobiles) or the 4-8h on each side for computers.

Employees can handle imaging and restoring. You can send an employee in advance, who will have devices ready for you on arrival. So all that gets handled while you're in transit.

When you can't even trust your own Blood Boy [1] not to get stoned, eat twinkies, and write a tell-all expose about you, how are you supposed to hire an employee trustworthy enough to handle all of your most sensitive keys and information? (Let alone three of them, one for each company.)

[1] https://www.theverge.com/2017/5/22/15676696/hbo-silicon-vall...

Post reply on HN