Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

71–80 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#71

Earlier quoted context omitted.

Being anxious is something you can work on. Business secrets are perfectly legal to carry across a border. Not wanting the TSA to look at your shit is something I can understand. I'd basically tell them to fuck off (in a more diplomatic sense) until it reached the point of being either blocked entirely from traveling or detainment. At that point you gotta ask yourself if the juice is worth the squeeze and turn back o…

Just out of curiosity, how's the treatment at the border in Canada?

10 years ago I was working in Canada; couple of friends and I (Australian, British and Québécois) decided to go and ski in Montana for a few days. We had a few beers on the way down and stopped just before customs to drop off open cans before we crossed the border. Being 11pm, we were the only people at the crossing. As we circled round they decided something wasn't right (probably justified although not in their jurisdiction) - 4 hours later we were allowed into the US having been fingerprinted and our car searched on a ramp for what I assume was explosives or drugs. 3 days later we returned to the border travelling the other direction - the CBSA officer looked at the cover of all three different nations' passports before saying "I'm sure there's a visa in there somewhere, have a nice day."

Re: 1Password Travel Mode: Protect your data when crossing borders

#72
post #47

This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling, then restore when you get back. Log into the minimal number of apps after you've entered the destination country, and optionally delete/logout of said apps prior to return travel if the return border crossing is also a concern. Admittedly if you u…

That may be a solution, but I'm never going to have the time to do that personally.

But are you concerned with border agents searching your phone? If you are then any time spent on this is time well spent. Although protecting your password manager is obviously of vital importance, there's a lot more to be concerned about sitting around on your phone if they can get in.

There's also the general concern -- although I don't know if it's ever been proven to have happened anywhere -- of border agents installing tracking software / malware. They often take the phone out of sight for a while. This is probably more of an issue with Android phones but again if you are a journalist or human rights activist or anyone with legitimate reasons to be concerned, I would absolutely want to wipe the phone as soon as possible after a border crossing if agents had forced me to hand it over for inspection.

Re: 1Password Travel Mode: Protect your data when crossing borders

#73
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

As a general comment to so many of the follow-ups to this post:

You really, really don't want to get into a rules-lawyering match with Federal fucking prosecutors over whether "clever technological solution" counts as "hiding" something or not. They have all of the guns in this situation, and you have a demonstrably inaccurate understanding of the relevant statute.

You WILL lose.

Re: 1Password Travel Mode: Protect your data when crossing borders

#74
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

Answer no, and it's just as valid as if you had a hand-written notebook full of work-related records that you left in your office back home before traveling. There aren't any reasonable justifications for requiring you to bring all information you physically have access to you with you when traveling, regardless of the format it's stored in. Not bringing something with you is inherently different from hiding it.

Lying to a federal employee is a felony; if you know you are answering untruthfully and the USG can prove it then you are probably going to prison.

Re: 1Password Travel Mode: Protect your data when crossing borders

#75
post #41

Earlier quoted context omitted.

Entering travel mode is literally deleting the data off your computer. It's not concealing anything. I think a federal prosecutor would have a hell of a time arguing that people aren't allowed to erase data from their computer before traveling.

In the law, intent matters. You're deleting the data with the intent to hide it from border agents. A federal prosecutor absolutely could argue that, if they wished.

And I could argue that my intent was to protect myself from identity theft, should my device be stolen. It's a reasonable explanation for having deleted the data.

I'd also argue that I could've purchased a completely new device immediately prior to travel and brought that along, with the intention of being able to say that the device had never contained information that I was trying to hide.

I think that part of the point is that they'd have to prove intent. It's easiest to prove if you refuse to unlock the device, harder to prove if you provide a destrutive password, harder still if you remove your passwords and keys before leaving, and essentially impossible if you have a device that never contained sensitive data in any form.

Re: 1Password Travel Mode: Protect your data when crossing borders

#76
post #61
post #37

Earlier quoted context omitted.

Literally removing your access to data isn't the same thing as hiding it. Having a TrueCrypt partition on your drive that you can still unlock if you know it's there is hiding it. Securely erasing that partition is not.

This is closer to the former than the latter. You aren't erasing the data that's protected under the vaults. You're just temporarily removing the vaults from local storage, disabling access and obscuring its presence. It's trivial to re-enable that access, so you are hiding , not destroying . Nice mental gymnastics, though. I'm genuinely curious whether the first Federal judge to see this argument laughs or issues a…

Can the border patrol ask you to sign into any online service? Because that's essentially what this is.

The data isn't on the computer they are searching, it's on a server thousands of miles away. The data was erased from the device. If they can force you to sign into that service, they could also force you to sign into your bank, github, etc.

Re: 1Password Travel Mode: Protect your data when crossing borders

#77
I have some ideas I think will improve our security in this direction. Apple seeks to make it technically impossible to extract iPhone data and I've been wondering how we can do the same with using someone's credentials to enter the systems we build.

One idea is to allow users to define how many concurrent sessions they can have so they can manage those slots and require something sign out before their credentials can sign in again.

The other is to allow users to configure a schedule when their credentials work so you can block most of the world and probably most of most days too.

Re: 1Password Travel Mode: Protect your data when crossing borders

#78
post #66

One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time. That way if you need to use unsafe PC from a hostel, you can log in with that password.

2FA

Re: 1Password Travel Mode: Protect your data when crossing borders

#79
post #61
post #37

Earlier quoted context omitted.

Literally removing your access to data isn't the same thing as hiding it. Having a TrueCrypt partition on your drive that you can still unlock if you know it's there is hiding it. Securely erasing that partition is not.

This is closer to the former than the latter. You aren't erasing the data that's protected under the vaults. You're just temporarily removing the vaults from local storage, disabling access and obscuring its presence. It's trivial to re-enable that access, so you are hiding , not destroying . Nice mental gymnastics, though. I'm genuinely curious whether the first Federal judge to see this argument laughs or issues a…

Seems like it's a tough argument though, I never have all my email on my phone, or all my dropbox files, etc. If I choose to not sync certain GMAP labels to IMAP, does that mean I am 'hiding' them?

Re: 1Password Travel Mode: Protect your data when crossing borders

#80
post #66

One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time. That way if you need to use unsafe PC from a hostel, you can log in with that password.

Backup codes are exactly that, though they're more in case you don't have access to your 2FA device.
Post reply on HN