Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

201–210 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#201
post #47

This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling, then restore when you get back. Log into the minimal number of apps after you've entered the destination country, and optionally delete/logout of said apps prior to return travel if the return border crossing is also a concern. Admittedly if you u…

Can't they order you to sign into iCloud or equivalent and then just sync whatever they want, photos, texts, emails, apps (and then order you to sign into those apps like Facebook, Whatsapp, Gmail)? Bottom line is they can get you AND everything you have access to. And it you try to circumvent it by i.e. temporarily encrypting everything for 24hr boom you just committed a felony. This is my understanding at least.

You know what's strange? I just can't remember my password to this account.

Real talk, if you play games they will find a way to fuck you up, and even if it is not strictly legal, even if you with some kind of relief later (not likely a nice settlement), you will still have to deal with getting fucked pretty bad at the time. Not a great outcome.

Re: 1Password Travel Mode: Protect your data when crossing borders

#202
post #194

Earlier quoted context omitted.

Should the slope become that slippery we'll have a much better reason to stand outside a legislator's office with pointy sticks than "I was mildly inconvenienced by the TSA."

If what is already happening across the country is not a good enough reason already, I doubt anything will be.

Yep. Quite simply, the 0.1% of the US population here on HN does not care about privacy nor protesting nor writing to their local or state government.

HN needs to stop living in a bubble. Only 1/3 of the US even bothered voting in the Trump v Clinton presidential election. I'll let you think about that for a moment. Now think about border searches. Has your phone been searched? Neither has mine. I'll go back to my company catered lunch now.

Re: 1Password Travel Mode: Protect your data when crossing borders

#203

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

> always answer "no" to "may I search your laptop?" in my case, that would mean deportation due to not being american. i either get deported and lose all the traveling plans or i get searched.

Correct. We'd have to comply.

US citizens, however, can choose to deny them and go through any hassle that CBP may want to put them through, but they cannot deny them entry.

Re: 1Password Travel Mode: Protect your data when crossing borders

#204

This feature really should ask you to commit to your duration of travel beforehand. It's no use if you can be compelled to readd the data.

Yes, THIS. THIS. Lying to a federal agent brings a world of hurt (obligatory disclaimer: I am a law professor but I am not YOUR lawyer...). Right now any customs agent with a brain can just ask "do you have that travel mode turned on? Ok, turn it off," and most courts will allow them to force compliance with that order. It would be really useful to be able to honestly say "I can't."

It's true, if they really want to make someone give up the info, they can arguably detain that person until the timer expires. But that move is much more costly to the government, as well as subject to all kinds of interesting potential legal challenges. So a timer makes the data strictly more secure, even if not perfectly secure.

Re: 1Password Travel Mode: Protect your data when crossing borders

#205

It's a clever idea, but how long before border authorities simply order travelers to log on to 1Password and turn off travel mode, or be denied entry? I'm guessing not very.

This is a good point in my opinion.

My thought on this whole situation is to simply not take my phone or laptop. I don't live nor work in the US, however, so I don't have the issues being faced by people in this thread.

Re: 1Password Travel Mode: Protect your data when crossing borders

#206

Earlier quoted context omitted.

Demanding web logins rather than local logins for anything is a step beyond the fuzzy legal authority currently given to the TSA.

web login is likely the same as app login credentials. I don't use 1password, but that's the generate case with LastPass (at least last time i used its mobile app). So, if they take the actual password, as opposed to having you log in for them, then they can easily go to 1password's web interface. I'm not sure if there is a legal barrier to taking that step, but there is no real barrier there if the credentials are t…

There is an additional key/identifier that you don’t have to carry with you that would prevent them from logging in even if you had to give them your vault password.

Re: 1Password Travel Mode: Protect your data when crossing borders

#207

This feature really should ask you to commit to your duration of travel beforehand. It's no use if you can be compelled to readd the data.

That doesn't solve the problem, because you could be detained until the data is accessible again.

It's beyond disturbing that we have reached the point where we are discussing this as a potential feature, and not a plot element of a dystopian scifi.

Re: 1Password Travel Mode: Protect your data when crossing borders

#208
post #200

Earlier quoted context omitted.

Or why we have passwords at all. Sites like Medium have moved to a passwordless model, where you're sent a login link to access your account rather than forcing you to remember or retrieve a password. https://blog.medium.com/signing-in-to-medium-by-email-aacc21...

... so a link sent over a protocol that is considered "insecure" by any sane security expert allows account access? Not to mention you still have to "secure" a password to your e-mail account. I'm sorry, what in the world is Medium thinking? This is a step backwards from a user/password model.

They cover this in the article: "reset my password" emails are already the norm, so it's not any riskier than your existing online banking or social media accounts.
Post reply on HN