Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

531–540 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#531
post #405

Earlier quoted context omitted.

Yes. If you are a US citizen. If you are not, this can mean waiting for the next pane back in handcuffs and being banned from entering the US for life.

Why go there in the first place? Doesn't sound very appealing.

I live in Canada working in medical/tech industry.

Every vendors main business is in the USA. 95% of our clients are not in Canada.

If I want to avoid the USA, I would have to change industries... Which isn't gonna happen hopefully anytime soon.

I have to goto states 3x times a year and hate the traveling aspect going through customs (I have a trip in a few weeks, already dreading it).. but once I pass through the border, it is rather nice.

Re: 1Password Travel Mode: Protect your data when crossing borders

#532
post #518

Earlier quoted context omitted.

Employees can handle imaging and restoring. You can send an employee in advance, who will have devices ready for you on arrival. So all that gets handled while you're in transit.

If you have any methods for hiring employees trustworthy enough to backup and reimage my most secure computing device with the most sensitive data, and somehow do so on notice given only via ESP, at several major world airports, please do let me know. I guess I could get a fourth phone, the one I use only for talking to my Airport Phone Guy, who would somehow be incorruptible enough to not hijack my bitcoin wallet or…

I don't know smartphones. But for machines with SSDs or HDDs, imaging and restoring software FDE volumes doesn't involve decryption. I don't know about hardware-based FDE, however. I use Linux VMs, and you can just copy LUKS-encrypted VDI files. If you're paranoid, you can backup and wipe the LUKS header, and send it separately.

Re: 1Password Travel Mode: Protect your data when crossing borders

#533
post #518

Earlier quoted context omitted.

If you have any methods for hiring employees trustworthy enough to backup and reimage my most secure computing device with the most sensitive data, and somehow do so on notice given only via ESP, at several major world airports, please do let me know. I guess I could get a fourth phone, the one I use only for talking to my Airport Phone Guy, who would somehow be incorruptible enough to not hijack my bitcoin wallet or…

I don't know smartphones. But for machines with SSDs or HDDs, imaging and restoring software FDE volumes doesn't involve decryption. I don't know about hardware-based FDE, however. I use Linux VMs, and you can just copy LUKS-encrypted VDI files. If you're paranoid, you can backup and wipe the LUKS header, and send it separately.

Thanks, but my phones and tablet are my primary systems and even just resyncing breadwallet alone takes a half hour or more. You have no idea what you are talking about.

Re: 1Password Travel Mode: Protect your data when crossing borders

#534

Earlier quoted context omitted.

If you are an American citizen, can they prevent you from entering the country? I understand they can delay you, but I don't think it can be indefinite.

^ This right here. They can deny foreigners, but I've always read that they cannot deny Americans in unless their citizenship gets revoked, I guess.

Not even that. Your right to enter the country, as a US citizen, is "Absolute, Unconditional, and Irrevocable."

Re: 1Password Travel Mode: Protect your data when crossing borders

#535
post #319

I don't understand. Is this really a thing? I'm from the UK and never heard such a thing. Is this common in US? What are they looking for? Do they just pick someone randomly, login to the laptop and check emails and stuff?

As I understand it, they generally don't just aimlessly scroll through your email/facebook in front of you, then give your device back (although they can, if they feel like it) - they get you to surrender your credentials, then save these in their database; the contents of the accounts will then be downloaded automatically. Same for devices - they have you unlock the device, then take it away, plug it into a PC/whate…

Thanks for the details? Is it a common procedure? Are they doing that to everyone coming to US?

Re: 1Password Travel Mode: Protect your data when crossing borders

#536
I am a U.S. citizen and I flew last year from America > Qatar > India and from India > Qatar > America on a business trip. I was carrying two laptops. Neither laptop was searched, but they were put in separate trays under the x-rays to make sure they didn't contain physical explosives or hinder the x-raying of the food and clothes in my backpack.

Re: 1Password Travel Mode: Protect your data when crossing borders

#537
post #357

Earlier quoted context omitted.

>don't you also need to be able to honestly say you can not provide access to it? It's been said further down, but they can't possibly have carte blanche to compel that you reveal all data you have access to anywhere, which is what this would require.

Of course they have that carte blanche, at least if you are not a citizen (and since you are travelling internationally, I'd assume that you're not a citizen on at least one of the legs). Normally, they can ask whatever the eff they like to decide whether to grant you entry or not. The logical conclusion here, is to decide, what is more important: Gaining entry, or keeping your data. In the first case you're just fuc…

> Normally, they can ask whatever the eff they like to decide whether to grant you entry or not.

Yep. There's this tendency to say "I beat their rules, so they have to let me go!" The CBP aren't fairies, they aren't bound to stay within some narrow precommitment. At least if you're not a US citizen, these things are almost totally discretionary. Not only can they bar you for not unlocking Facebook, they can bar your for genuinely not having Facebook if they decide you're lying. When even simple truth isn't a defense, clever tech tricks don't count for anything.

In my cynical moments, this outlook strikes me as a disease caused by excess programming - living in a world of contracts and invariants blinds people to how much of the world runs on "screw you, you know what I mean."

Re: 1Password Travel Mode: Protect your data when crossing borders

#538
post #400
post #123

Earlier quoted context omitted.

If the question is "are you hiding any information" then the obvious (and true) answer is no. If the question is "did you use travel mode for 1password" then that's a very different question. Unless you can point out a statute that requires you to travel with certain information on your device it's hard for me to see the problem. Your position seems to be that if you were carrying your checkbook (as an American) and…

I don't think searches of accounts are in any way excusable either, but for the purpose of rules-lawyering: You have deliberately chosen to make certain information not available during the search period and are planning to make it available again once the search is over. I can absolutely see how that counts as "hiding".

And crucially, "can see how" is all that matters here. If the argument isn't prima facie absurd, then you get to go to court with the government, where you won't win and will face horrible harms even if you somehow do. "But I'm technically right!" doesn't count here, only "but there's reason to dispute that".

Re: 1Password Travel Mode: Protect your data when crossing borders

#539
post #73

Earlier quoted context omitted.

As a general comment to so many of the follow-ups to this post: You really, really don't want to get into a rules-lawyering match with Federal fucking prosecutors over whether "clever technological solution" counts as "hiding" something or not. They have all of the guns in this situation, and you have a demonstrably inaccurate understanding of the relevant statute. You WILL lose.

More than that, everyone is getting up on the wording of the particular hypothetical question posed above. It could easily be replaced with "Did you remove any data from your device so that we wouldn't be able to see it?", or "Did you enable Travel Mode in 1Password?", or even "Please sign this form affirming that you have not hidden anything from us or employed anything from this list of loopholes thought up by chee…

> Your adversary here is a group of humans. Not a Bash script.

This is an awfully good summary. There are a thousand different questions that would invalidate this, and the idea that maybe-possibly-sort-of outwitting one question solves the problem is insane. Any reasonable plan has to be prepared for a question that can't be invaded - whether that means "yes, here's the data", or "yes, but I can't get the data", or "no comment, I want a lawyer".

Re: 1Password Travel Mode: Protect your data when crossing borders

#540

Earlier quoted context omitted.

Of course they have that carte blanche, at least if you are not a citizen (and since you are travelling internationally, I'd assume that you're not a citizen on at least one of the legs). Normally, they can ask whatever the eff they like to decide whether to grant you entry or not. The logical conclusion here, is to decide, what is more important: Gaining entry, or keeping your data. In the first case you're just fuc…

> Normally, they can ask whatever the eff they like to decide whether to grant you entry or not. Yep. There's this tendency to say "I beat their rules, so they have to let me go!" The CBP aren't fairies, they aren't bound to stay within some narrow precommitment. At least if you're not a US citizen, these things are almost totally discretionary. Not only can they bar you for not unlocking Facebook, they can bar your…

> The TSA aren't fairies, they aren't bound to stay within some narrow precommitment. At least if you're not a US citizen, these things are almost totally discretionary.

I think you are confusing TSA with CBP here.

Post reply on HN