Live data from Hacker News

1Password Travel Mode: Protect your data when crossing borders

blog.agilebits.com

81–90 of 553 posts

Re: 1Password Travel Mode: Protect your data when crossing borders

#81
post #38

Earlier quoted context omitted.

This qualifies already. 18 U.S. Code § 1519 defines it as "Whoever knowingly...conceals...with the intent to impede...the proper administration of any matter within the jurisdiction of any department or agency of the United States" So technically, entering travel mode for the purpose of hiding your stuff from border agents could be interpreted as a violation of that statute, regardless of whether there was an active…

I think there is a line to be drawn somewhere, and I don't know where — but taking this further, if I erase my laptop before going to the US and then restore it from a backup online, isn't this the same thing as „knowingly concealing with the intent to impede”? And what if I don't take the laptop at all? Am I „concealing” anything? Theoretically — yes. There has to be a limit to how far one can take the application o…

If you aren't aware of a matter concerning your data you can't intend to impede that matter by choosing not to transport your data on your person.

Re: 1Password Travel Mode: Protect your data when crossing borders

#82
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

One option is to lock out the passwords for some amount of time, or to do geolocation.

Both can be defeated (they can detain you at the airport for a whole day, or they can spoof GPS) but neither of these mechanisms holds up to mass surveillance: you can't detain everyone who goes through the airport, or even all people with 1Password, for a day, nor can you spoof GPS at the security checkpoint because it'll probably leak to airplanes. You have to pick individual travellers and put them in a Faraday cage with a Stingray and an internet connection.

I'm not sure what the threat model really is, but it's possible that this will require enough time and resources to disincentivize asking for even more passwords when there's not a very specific suspicion, which might be good enough.

Re: 1Password Travel Mode: Protect your data when crossing borders

#83
post #61

Earlier quoted context omitted.

This is closer to the former than the latter. You aren't erasing the data that's protected under the vaults. You're just temporarily removing the vaults from local storage, disabling access and obscuring its presence. It's trivial to re-enable that access, so you are hiding , not destroying . Nice mental gymnastics, though. I'm genuinely curious whether the first Federal judge to see this argument laughs or issues a…

Can the border patrol ask you to sign into any online service? Because that's essentially what this is. The data isn't on the computer they are searching, it's on a server thousands of miles away. The data was erased from the device. If they can force you to sign into that service, they could also force you to sign into your bank, github, etc.

> Can the border patrol ask you to sign into any online service?

If you're a non-citizen attempting to enter the US under a visa waiver program, from certain countries, yes, they can.

Re: 1Password Travel Mode: Protect your data when crossing borders

#84

This feature really should ask you to commit to your duration of travel beforehand. It's no use if you can be compelled to readd the data.

That doesn't solve the problem, because you could be detained until the data is accessible again.

Re: 1Password Travel Mode: Protect your data when crossing borders

#85
post #66

One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time. That way if you need to use unsafe PC from a hostel, you can log in with that password.

You're basically describing two factor authentication, when you have not authorized the particular computing device in question to skip it.

Re: 1Password Travel Mode: Protect your data when crossing borders

#86
post #41

Earlier quoted context omitted.

Entering travel mode is literally deleting the data off your computer. It's not concealing anything. I think a federal prosecutor would have a hell of a time arguing that people aren't allowed to erase data from their computer before traveling.

In the law, intent matters. You're deleting the data with the intent to hide it from border agents. A federal prosecutor absolutely could argue that, if they wished.

Or literally anyone else in the country to which I'm travelling. Perhaps I feel I'm at an increased likelihood to either lose or have my phone stolen? Saving my passwords from a potential thief (who may or may not have tools to break into the device assuming I secured it) is a reasonable precaution.

Re: 1Password Travel Mode: Protect your data when crossing borders

#88
post #11
post #7

Isn't the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation. The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend/store location) to the destination. Then there is no way of restoring at the airport. Of course, th…

,,even if you’re asked to unlock 1Password by someone at the border, there’s no way for them to tell that Travel Mode is even enabled.'' It looks similar to hidden partition in TrueCrypt

Yes, it does. And you provide them to the password for the local vault. Since you activated travel mode, they'll be able to see your "travel safe" passwords, but no indication that there are other passwords that were recently removed from the vault, and no indication that you entered travel mode.

Re: 1Password Travel Mode: Protect your data when crossing borders

#89

Earlier quoted context omitted.

Answer no, and it's just as valid as if you had a hand-written notebook full of work-related records that you left in your office back home before traveling. There aren't any reasonable justifications for requiring you to bring all information you physically have access to you with you when traveling, regardless of the format it's stored in. Not bringing something with you is inherently different from hiding it.

Lying to a federal employee is a felony; if you know you are answering untruthfully and the USG can prove it then you are probably going to prison.

What lie has been told?

Re: 1Password Travel Mode: Protect your data when crossing borders

#90
post #31

Counter: the border agent asks "are you hiding any information from us?". answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.

If you're a citizen you don't have to answer any question until you've been accused of a crime and have a lawyer present. Also, the case law is iffy on whether a one-word answer of 'no' can be used in an obstruction charge. (read about 'exculpatory no doctrine').

I don't know, I think the border is a no-man's land. They can pretty much keep you in limbo as long as they want.

Edit: Yes, US citizens are allowed to ask for a lawyer (at the U.S. Border). But, the 4th Amendment is mostly out the window.

Post reply on HN