Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

51–60 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#51
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

You're not hiding anything, you're creating a legal barrier to someone accessing it. This is the privacy vs secrecy conversation.

Re: 1Password Travel Mode: Protect your data when crossing borders

#52
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

If you're a citizen you don't have to answer any question until you've been accused of a crime and have a lawyer present.

Also, the case law is iffy on whether a one-word answer of 'no' can be used in an obstruction charge. (read about 'exculpatory no doctrine').

Re: 1Password Travel Mode: Protect your data when crossing borders

#53

Wouldn't an alternative "destroy everything" password be a good idea also ? Would work like this : When forced to enter / give the password to your vault, you enter/give this one, and everything the vault contains is wiped out before the vault is unlocked.

Once again we drum up technical "solutions" to what ultimately is a policy issue. A better idea is to change our laws so that our constitutional rights are respected. If that's not possible then the next solution is to change our elected officials.

While it is a policy issue at its core, changing law and policy moves at a glacial pace, and it's not even a certainty that it'll get changed at all (the "nothing to hide" defense gets brought up a lot on these matters, and it's a pretty persuasive argument to those that can't recognize the fallacy). Technical solutions have the benefit of being much quicker to enact, albeit in a flawed way that is, if highly successful, a band-aid on a bullet wound.

Re: 1Password Travel Mode: Protect your data when crossing borders

#54
post #45

Earlier quoted context omitted.

At, say, the US/Canadian border? No, not accurate nor realistic at all.

Then again, you don't even need a $5 attitude readjustment tool when you can just shrug and say "Whatever. You are detained until you cough up what we want." - and are able to do just that...

They can't detain you indefinitely without articulating a good reason, even as a non-citizen. What they can do is deny you entry. For citizens, not even that.

Re: 1Password Travel Mode: Protect your data when crossing borders

#55
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

Answer no, and it's just as valid as if you had a hand-written notebook full of work-related records that you left in your office back home before traveling. There aren't any reasonable justifications for requiring you to bring all information you physically have access to you with you when traveling, regardless of the format it's stored in.

Not bringing something with you is inherently different from hiding it.

Re: 1Password Travel Mode: Protect your data when crossing borders

#56

Earlier quoted context omitted.

How is the web interface handled? Essentially, where do you turn this on and off? Wouldn't it become standard ptotocol to just demand web credentials for 1Password? This feature is only for subscription based 1Password accounts, so it would seem to me it would just be easiest to delete the app and re-download after crossing?

Demanding web logins rather than local logins for anything is a step beyond the fuzzy legal authority currently given to the TSA.

If you're a resident, they eventually have to let you in. But if you aren't, they can reject you for any reason. This isn't something you can solve with tech. Those of us who are citizens of the US need to vote for politicians who make privacy a priority, and be more politically active in general. I feel like you could even make the play that it's bad for business, because it's impeding business travel. You could even point to this very post as evidence that many companies consider it a Big Deal - the idea that they have to explicitly hide their company secrets in this way because border agents are out of control.

Re: 1Password Travel Mode: Protect your data when crossing borders

#57
post #47

This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling, then restore when you get back. Log into the minimal number of apps after you've entered the destination country, and optionally delete/logout of said apps prior to return travel if the return border crossing is also a concern. Admittedly if you u…

That may be a solution, but I'm never going to have the time to do that personally.

Re: 1Password Travel Mode: Protect your data when crossing borders

#59
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

Just travel with a dedicated traveling phone and have your main phone mailed to your destination.

Re: 1Password Travel Mode: Protect your data when crossing borders

#60
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

So are you required to have all the data that's ever been on your device at the time that you cross an international border? Are you required to copy passwords that were never in 1password onto your device before you travel?

EDIT: Another way to put this: Is there an expectation that a border agent could, for example, ask for the password to my bank account? If not, how would there be an expectation that if that used to be on my iPhone it should still be there when I travel?

Post reply on HN