Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

271–280 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#271

Could we have something like time-delay passwords? Like the time-delayed vaults they (allegedly) have in banks? Then you could say: "Even if I agreed to give you my password, you wouldn't be able to unlock my device with it for another 24 hours".

That’s just begging them to detain you for a day.

Time delays only work for the entity in power. The bank has your money, you’ll just have to wait to get it. But the border people have power, not you; they can make you wait if they want.

Re: 1Password Travel Mode: Protect your data when crossing borders

#274

This feature really should ask you to commit to your duration of travel beforehand. It's no use if you can be compelled to readd the data.

Setting GPS locations where the vault can be readded to your device and disallowing it everywhere else would be good.

GPS location can easily be spoofed, and your ID has an address on it.

Re: 1Password Travel Mode: Protect your data when crossing borders

#275

Earlier quoted context omitted.

Setting GPS locations where the vault can be readded to your device and disallowing it everywhere else would be good.

Came here to make the same suggestion, and strongly agree. I should not be able to re-add the vault if I am not in my house.

I thought about mentioning this too, as well as things like IP addresses and 2FA. The problem with GPS is proving that the location or request isn't spoofed. Ultimately, the phone is trusted when it supplies coordinates, so a determined adversary can easily circumvent it (for example, a SDR running a GPS spoofer). That's not to say it's a bad idea, as it certainly inproves security, but we are talking about state level targeting here.

The other options, like IP and 2FA are more likely to result in failure demand by non-expert users. It's really tricky to get the balance right, as it's hard to justify to yourself a full wipe when going to a relatively low but nonzero risk country.

Re: 1Password Travel Mode: Protect your data when crossing borders

#276

It's a clever idea, but how long before border authorities simply order travelers to log on to 1Password and turn off travel mode, or be denied entry? I'm guessing not very.

:-/ What we really need is plausible deniability - if they don't know you use 1password, they don't know to ask for it.

Is plausible deniability the right term here? Usually that's about the ability to deny having known about or authorised something after it's already been discovered.

I'm not really sure how you'd refer to the concept "they don't know I have it, so they don't know to ask". Security through ignorance?

Re: 1Password Travel Mode: Protect your data when crossing borders

#277

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

Hey, look, a citizen (or non-USian) commenting on immigration matters. Without any clue what this means for non-citizens who live in the US. If you're e.g. an H1B visa holder your friendly ICE officer might decide "no" is reason enough to eject you out of the country.

Just one of the new risks of travel. (Well, not new that they can send you back, but a new reason for the little tinpot dictators who revel in their power)

Re: 1Password Travel Mode: Protect your data when crossing borders

#278
post #233

Earlier quoted context omitted.

> The point I was trying to make was that this 1Password feature will not help you, legally, if CBP realizes you're using it and they want to make a fuss. Maybe if you rolled your own PW manager and decided not to sync the incriminating data, you'd have a case. But this feature is literally advertised as "protect your data from unwarranted searches [clearly implying, searches by the government] when you travel". The…

> If I choose not to bring my phone with me to the border, and an agent remarks on the suspiciousness of that fact, if I were to reply, "I didn't bring it because I didn't want to travel with it," did you commit a crime? Probably not. > We are hinging on the subtle difference between deletion and non action. I agree, and my argument is that "activating Travel Mode" is clearly the former, regardless of its technical i…

I don't see why the distinction matters. Deleting data because you don't want to travel with it should be no different than leaving your phone at home because you don't want to travel with it.

Re: 1Password Travel Mode: Protect your data when crossing borders

#279
post #116

The right solution to this problem is, when traveling, always answer "no" to "may I search your laptop?" It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes. Companies need to make clear to their employees (and the public) that s…

Do you honestly think customs agents care whether you'll get fired or not? US immigrations will permanently sever families that have been together for years or even decades with utter disregard for the emotional trauma they're inflicting. Your job matters exactly fuck-all to a CPB agent.

It completely depends if you are white or not. If you are white, and speak politely, the agent will care deeply about your concerns, including potential firing as an example. If you are not white, and especially if you appear black, Latino or Arab, then your comment will definitely hold true.

Re: 1Password Travel Mode: Protect your data when crossing borders

#280
post #135

Earlier quoted context omitted.

The data is still on the device. Only the password "vaults" have been wiped, obscuring the presence of the data and removing its access. Look, you can twist the words however you want. At the end of the day, if a CBP agent or Federal prosecutor clues to the fact that you're using this functionality, their interpretation is almost certainly going to be "'late2part is hiding something !", and they will bring their (con…

The vaults are the data. I'm not sure what data besides the vaults you're referring to that's still on the device. The fact that the data is still on a server somewhere is irrelevant for searching the device. However if they ask to login to your 1Password account that's a different matter.

Does "travel mode" remove all the cookies, local storage, and any other indications that you're a user of the site(s) in the removed vault?

Remember: if you're this far down the rabbit hole at immigration, the machine is out of your bag, open, and unlocked. They can take it, while in this state, and image it. If there is evidence that you've been even unintentionally untruthful with the CBP folks, you're screwed. Not only have you lied, but you may have handed over evidence of obstruction of justice/tampering with evidence.

Federal charges like that stack up quickly. If they want to fuck with you, they will.

Post reply on HN