Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

171–180 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#171

Earlier quoted context omitted.

That's basically the definition of spoliation of evidence, if things were to ever escalate to civil or criminal proceedings.

This qualifies already. 18 U.S. Code § 1519 defines it as "Whoever knowingly...conceals...with the intent to impede...the proper administration of any matter within the jurisdiction of any department or agency of the United States" So technically, entering travel mode for the purpose of hiding your stuff from border agents could be interpreted as a violation of that statute, regardless of whether there was an active…

There would be no backlash unless the person was well-known, all they would have to do is show an unflattering picture of the victim and accuse them of 'possessing hacking tools' and 'hiding information from law enforcement.' Both would be true, the latter being actually true and the former applying to anyone using a terminal with black background and green text.

Re: 1Password Travel Mode: Protect your data when crossing borders

#172

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

The solution to this problem is to not visit US.

Re: 1Password Travel Mode: Protect your data when crossing borders

#173

Earlier quoted context omitted.

Can't they order you to sign into iCloud or equivalent and then just sync whatever they want, photos, texts, emails, apps (and then order you to sign into those apps like Facebook, Whatsapp, Gmail)? Bottom line is they can get you AND everything you have access to. And it you try to circumvent it by i.e. temporarily encrypting everything for 24hr boom you just committed a felony. This is my understanding at least.

IANAL and I don't have an answer to this, but I would be deeply alarmed if this were the case. I can understand them making the case that anything on your personal is searchable (though I disagree that this should be allowed). By asking you to sign in and sync, they're not just requesting access to information on your person -- that's an enormous expansion of their search powers.

Isn't it established that they'll ask for social media credentials which sync old data automatically?

Re: 1Password Travel Mode: Protect your data when crossing borders

#174
post #135

Earlier quoted context omitted.

I don't understand your logic. Facts matter. Either you have the data on your laptop or you don't. If it's been removed, you don't. Yes, they can ask you if you've deleted things, or if you have things elsewhere, but that's not generally what they ask or look for, or the issue at hand.

The data is still on the device. Only the password "vaults" have been wiped, obscuring the presence of the data and removing its access. Look, you can twist the words however you want. At the end of the day, if a CBP agent or Federal prosecutor clues to the fact that you're using this functionality, their interpretation is almost certainly going to be "'late2part is hiding something !", and they will bring their (con…

I would say this is more like a local git repository than what you said. When you add passwords to a vault, then it gets saved to your local copy and then synced to the server. When changes are made elsewhere, it downloads the changes and syncs your local repository.

Now "travel mode" simply removes the local git repository. The data still exists in the cloud, but you have to actively go out and log in to their service to retrieve it. Are you "hiding something" because you deleted a local copy of something from your device? There isn't something on your device that is somehow hidden. It's not there.

Re: 1Password Travel Mode: Protect your data when crossing borders

#175

Earlier quoted context omitted.

Yup. The correct solution is to stop traveling to the US. Stop sending your employees to the US as well. If the rest of the world starts insisting that US companies always come to them because of how US border agents act, that shit will bubble up to the lobbyists real fast.

And to the UK: https://www.theguardian.com/politics/2017/may/14/campaign-gr...

It's amazing how disparate the experience is in Europe. The first time I flew to CDG a year ago I honestly thought I somehow skipped customs accidentally. Heathrow, on the other hand, feels like a dystopian experience straight out of Minority Report. 20 questions and having your photo taken at every turn for simply connecting through the UK.

Re: 1Password Travel Mode: Protect your data when crossing borders

#176
post #164

Earlier quoted context omitted.

I opted out for years and made fun of TSA agents during the pat down. It turns out you're not allowed to requests pat downs from specific agents. Who knew? ;) But now I don't even opt out. Instead I tell them that I can't raise my arms above my head. They direct me around the scanner (sometimes the metal detector too), swab my hands, and call it done. I often skip 10-15 people in the process. If they ask why, I tell…

Does that count as lying to federal government agents? (Title 18, United States Code, Section 1001)

Not if its true. We don't know if it is or not, unless you know this person in real life.

Re: 1Password Travel Mode: Protect your data when crossing borders

#178
post #136
post #116

Earlier quoted context omitted.

Do you honestly think customs agents care whether you'll get fired or not? US immigrations will permanently sever families that have been together for years or even decades with utter disregard for the emotional trauma they're inflicting. Your job matters exactly fuck-all to a CPB agent.

That border agent is a real person, who is "only doing their job". So are you. It works both ways. If enough people say no, then after a hellish but hopefully short adjustment period, the policy will change.

> the policy will change.

The policy might change to include cells at the borders where people are detained until they hand over login details or voluntarily decide not to enter.

Re: 1Password Travel Mode: Protect your data when crossing borders

#179
post #68

Earlier quoted context omitted.

You're deleting the data because you don't want to travel with that data . You're not hiding it. You literally just don't want to have access to it while you're traveling. In that sense it's no different than, say, leaving a hard drive with all your data behind (plugged into an internet-enabled computer that you can SSH in to and transfer your files back to yourself after you've crossed the border).

Read rosser's comment above. If push came to shove, your clever wordplay would amount to getting into a rules-lawyering contest with Federal prosecutors, and I promise you that is a contest you would lose.

I don't think it's rules lawyering to say that literally not having the data is different than hiding it. There's nothing illegal about choosing to not bring stuff with you when you travel. And as long as the CBP's authority is limited to searching your devices and not forcing you to log into websites, then simply not carrying the data on your device seems perfectly reasonable.

Furthermore, I don't think there's anything productive at all about making the argument that federal prosecutors will get you no matter what you do. That's just shutting down the discussion entirely.

Re: 1Password Travel Mode: Protect your data when crossing borders

#180
post #135

Earlier quoted context omitted.

I don't understand your logic. Facts matter. Either you have the data on your laptop or you don't. If it's been removed, you don't. Yes, they can ask you if you've deleted things, or if you have things elsewhere, but that's not generally what they ask or look for, or the issue at hand.

The data is still on the device. Only the password "vaults" have been wiped, obscuring the presence of the data and removing its access. Look, you can twist the words however you want. At the end of the day, if a CBP agent or Federal prosecutor clues to the fact that you're using this functionality, their interpretation is almost certainly going to be "'late2part is hiding something !", and they will bring their (con…

[deleted]
Post reply on HN