Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

281–290 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#281
post #197

Earlier quoted context omitted.

Potato/potahto, really. Good luck getting a visa next time if you've ever been "denied entry". Really, for non-Americans the best advice is just don't go in the first place. Second best advice is just comply with border security personnel. Any tricks like leaving the battery empty, bringing a burner, not bringing a laptop and getting a loaner when you get there etc, they do nothing but raise suspicions.

> Any tricks like leaving the battery empty, bringing a burner, not bringing a laptop and getting a loaner when you get there etc, they do nothing but raise suspicions. as i said on another comment, even not having social media is suspicious. which is insane, because it means you cannot have privacy if you want to go to another country.

And I happen to not have social media, for real. Whoops. I need to go through U.S. Customs at least once a year. :(

Re: 1Password Travel Mode: Protect your data when crossing borders

#283

Earlier quoted context omitted.

That's a great solution if you're a US citizen and want to enjoy showing off to a border guard before being guaranteed entry, but for migrants (who are most affected by this), this kind of 'gotcha' logic would likely be considered insubordinate grandstanding, and get them denied entry.

> this kind of 'gotcha' logic would likely be considered insubordinate grandstanding I'm not sure what you mean. I don't think it's unreasonable for anyone, migrants included, to tell CBP "I don't feel safe traveling with sensitive data, so I don't have any of that data on my computer". What's the 'gotcha' here? CBP isn't the only reason to want to have Travel Mode, there's also the increased risk of having your lapt…

In your original post, I took

> Only if you know them. ... You can't log into the website without that account key.

To mean that you'd openly have access to information in front of the guard, and then let them know that you can't access it at this time because of your elaborate scheme (e.g. tell them that it exists, but that they can't have it).

That's quite different to just not travelling with the data (or evidence of it existing) at all.

> CBP isn't the only reason to want to have Travel Mode

No, but it's the only 'reason' that's likely to use serious, life-altering coercion to make you to disable it, if they detect that it exists. It may be better to have no data that suggests capabilities, than openly posses partially disabled capabilities.

There's no way for a border agent to tell if you're refusing to disable travel mode because you won't or you can't (and little reason for them to care).

Re: 1Password Travel Mode: Protect your data when crossing borders

#284
post #116

Earlier quoted context omitted.

Do you honestly think customs agents care whether you'll get fired or not? US immigrations will permanently sever families that have been together for years or even decades with utter disregard for the emotional trauma they're inflicting. Your job matters exactly fuck-all to a CPB agent.

It completely depends if you are white or not. If you are white, and speak politely, the agent will care deeply about your concerns, including potential firing as an example. If you are not white, and especially if you appear black, Latino or Arab, then your comment will definitely hold true.

You are absolutely the worst kind of person.

Re: 1Password Travel Mode: Protect your data when crossing borders

#285
post #254

Earlier quoted context omitted.

> If CBP ever starts requiring that you call a third party to retrieve confidential information What would they do, do you think, if said third party was a foreign citizen—of a country with no deportation treaty with the US—and upon getting the person you have in hand to call them (presumably under duress), they just said "I don't negotiate with hostile governments" and hung up?

>of a country with no deportation treaty with the US I'm not sure what this means, afaik there's no such thing as a "deportation treaty" (perhaps you're thinking of extradition?). If you aren't a citizen, you can be deported, no treaty necessary. Furthermore, if you're at the border you're not even being deported, you're just being denied entry - you get to not pass customs at all and sleep in the airport lounge unti…

Yes, that's the one I was going for, extradition treaty—I was referring to the fact that CBP can't just lean on the other country to send them the person they actually want to interview (i.e. extradite them for a crime they've been implicated in by the testimony of the person they just interviewed), so they really are stuck with just getting the detained person to call them up and negotiate.

If US CBP catches a low-level gang member from the UK, they can use their testimony to get an extradition order for higher-ranking gang members—so CBP are incentivized to detain low-level gang members and grill them to see what they know, even if they haven't done anything. But if it's e.g. a low-level Russian or Chinese or Iranian gang member, then the "extradite" part of the "use testimony as evidence to extradite higher-level members" plan doesn't work, so there's relatively little point to grilling such people.

Re: 1Password Travel Mode: Protect your data when crossing borders

#286

Earlier quoted context omitted.

> [proving intent is] essentially impossible if you have a device that never contained sensitive data in any form. I'd like to see a short story based on this premise: man is arrested and tried for crossing the border with a brand new phone, having left his usual phone at home. The prosecution argues that since he presumably usually keeps sensitive information on his phone, not copying that data to the phone he was c…

> he presumably usually keeps sensitive information Wouldn't they have to argue that he was a person of interest for some time now. That they have records of him traveling two and from countries of interest. That he is on a watch list? For the average Joe. I don't think this would get very far. My response would be. "What sensitive information are you looking for?"

I was proposing a short fictional piece based on this premise -- not sure if you meant to respond to that specifically. In any case, it's speculative fiction: we put the story in a not-too-distant dystopian future where the laws and norms have changed just enough to make this plausible. I think it's more fun too if the protagonist actually doesn't have anything to hide, and is not suspected of any criminal activity before, during, or after his attempted border crossing.

Re: 1Password Travel Mode: Protect your data when crossing borders

#287

Is travelling with confidential data really necessary? Wouldn't it make more sense for me to have a 'empty' notebook and store my data out of harm's way (but accessible via a VPN).

I've come to the conclusion that this is the only reasonable technical solution. Don't travel with sensitive data, and openly explain that you don't do so. The frustrating part is the UX, and the fuss when you land. I've found that this works: - Burner android (burner account explicitly for travel) for music, podcasts, light browsing, etc. - Cheap ThinkPad for headscratching / hacking (work over SSH, keys on a Yubike…

Any recommendations for a "burner android" phone?

Re: 1Password Travel Mode: Protect your data when crossing borders

#288
post #284

Earlier quoted context omitted.

It completely depends if you are white or not. If you are white, and speak politely, the agent will care deeply about your concerns, including potential firing as an example. If you are not white, and especially if you appear black, Latino or Arab, then your comment will definitely hold true.

You are absolutely the worst kind of person.

[deleted]

Re: 1Password Travel Mode: Protect your data when crossing borders

#289
post #230

Earlier quoted context omitted.

They cover this in the article: "reset my password" emails are already the norm, so it's not any riskier than your existing online banking or social media accounts.

Resetting via link alone is yet another bad thing, because as you pointed out it leads to the exact situation you just described. Password resetting should involve some type of challenge/response, and accounts should be secured with 2FA on top of all that. Medium still isn't winning any security points here.

> Medium still isn't winning any security points here.

Sure they are. Removing a credential—in this case, passwords—is strictly more secure. It's the same rationale as to why 2FA with just a TOTP app is more secure than TOTP app + SMS backup. And the emailed links are analogous to password reset links so there's no erosion of security there, provided they're properly secured (one time use, time bounded, etc.).

Also, realistically, if they used passwords, many of their users would probably re-use the same email,password pair at other sites. If any of those other sites use bad password hashing hygiene AND get hacked, then the users' account security is busted.

Re: 1Password Travel Mode: Protect your data when crossing borders

#290
post #107

Earlier quoted context omitted.

Answer no, and it's just as valid as if you had a hand-written notebook full of work-related records that you left in your office back home before traveling. There aren't any reasonable justifications for requiring you to bring all information you physically have access to you with you when traveling, regardless of the format it's stored in. Not bringing something with you is inherently different from hiding it.

> There aren't any reasonable justifications for requiring you to bring all information you physically have access to you with you when traveling... regardless of the format it's stored in. I think many of us would equally argue there isn't any 'reasonable justification' for forcing phone unlocks on random strangers in airports, but that still happens. I think you are asking for a reasoned distinction from people inc…

Exactly. People are already forced to log into social media accounts and such. So it appears anything you're able to access online is considered fair game.
Post reply on HN