TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

1Password Travel Mode: Protect your data when crossing borders

1004 pointsby nthitzalmost 8 years ago

59 comments

chxalmost 8 years ago
&quot;May I search your laptop?&quot; &quot;Certainly.&quot; &quot;But... this is practically empty.&quot; &quot;Yes sir. I FedEx&#x27;d my SSD to the destination.&quot;<p>I have a small SSD in the primary disk in my T420s, it has just enough to get me through the flight. I keep the primary in the UltraBay with a simple adapter, takes one reboot and no tools to put it back in place. Done. Happy searching! I can&#x27;t log into anything even if I wanted to because I physically do not have my password store <a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a> with me. (<a href="https:&#x2F;&#x2F;github.com&#x2F;chx&#x2F;ykgodot" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;chx&#x2F;ykgodot</a> I wrote this trivial script to automate yubikey neo with pass)<p>Alternative: encode the entire primary disk <a href="https:&#x2F;&#x2F;github.com&#x2F;cornelinux&#x2F;yubikey-luks" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;cornelinux&#x2F;yubikey-luks</a> and FedEx the yubikey. Yanking the disk is better, though.
评论 #14407612 未加载
评论 #14410493 未加载
评论 #14407692 未加载
评论 #14409810 未加载
评论 #14408599 未加载
评论 #14407752 未加载
alexpwalmost 8 years ago
If you are refusing to enter the password, access to the device, or to disable travel mode, then good luck to you. IANAL, but the border agent doesn&#x27;t care if the data is technically in the cloud, rather than on the device, because it restores when you unlock it.<p>In addition to removing the data from the device, cheers, don&#x27;t you also need to be able to honestly say you can not provide access to it?<p>Ways to honestly answer, &quot;not possible&quot;, and mean it:<p>- schedule a time period where no password is accepted. - enable whitelist&#x2F;blacklist zones via geolocation. - set a new password that you give to a trusted friend&#x2F;coworker&#x2F;spouse that you must contact to retrieve.<p>Some combination of the above for ease-of-use, and ploys like emailing yourself the new password after a period of time for redundancy&#x2F;safety.
评论 #14407527 未加载
评论 #14407252 未加载
评论 #14407217 未加载
评论 #14407481 未加载
评论 #14411834 未加载
评论 #14408182 未加载
gruezalmost 8 years ago
Counter: the border agent asks &quot;are you hiding any information from us?&quot;. answer yes, and they get you to disable travel mode. answer no, and you just committed a felony.
评论 #14404655 未加载
评论 #14404754 未加载
评论 #14407982 未加载
评论 #14404725 未加载
评论 #14404672 未加载
评论 #14406896 未加载
评论 #14404551 未加载
评论 #14405090 未加载
评论 #14404630 未加载
评论 #14404589 未加载
评论 #14404638 未加载
评论 #14404584 未加载
评论 #14404525 未加载
评论 #14405403 未加载
评论 #14414531 未加载
评论 #14404880 未加载
评论 #14404738 未加载
评论 #14404874 未加载
评论 #14414543 未加载
评论 #14404682 未加载
edanmalmost 8 years ago
I&#x27;m struggling to understand all the comments here, but it feels like I&#x27;m living in an alternate universe. All of these questions like &quot;but do the customs agents search for hidden partitions&quot;, etc...<p>Who is it that is running into all these scenarios with border control? I&#x27;ve gone on international flights, including to the us, dozens of times, and have seen around me thousands upon thousands of travelers, and I&#x27;ve <i>never</i> seen anyone asked to open their laptop, no to mention being grilled on hidden partitions.<p>Not that I&#x27;m doubting this <i>ever</i> happens. But from these comments, someone would get the feeling that this is <i>routine</i>, rather than a 1-in-an-X occurence for a probably very high X.
评论 #14412291 未加载
mholtalmost 8 years ago
The implementation looks sound, and it&#x27;s easy to use. Props to Agile Bits for making this feature a priority.<p>So this is great! -- I think. My only concern is that if the authorities are already suspicious of you, and find no password vaults (or practically nothing in your password vault), they may just detain you until you reveal what you haven&#x27;t disclosed to them.<p>There&#x27;s clearly a technical solution to the problem of protecting data across borders but they do not work so well under duress. Is there any technical way to convince an adversary you are not hiding anything else or did not delete something?
评论 #14404402 未加载
评论 #14406375 未加载
评论 #14404151 未加载
jzlalmost 8 years ago
This is a nice feature, but ultimately if you are concerned with border agents requiring a phone search then you should just backup and install a fresh OS before traveling, then restore when you get back. Log into the minimal number of apps after you&#x27;ve entered the destination country, and optionally delete&#x2F;logout of said apps prior to return travel if the return border crossing is also a concern. Admittedly if you use a password manager you might need still want to make use of a feature such as the one in this article, or install the password manager app after entering the country, or just write down the passwords that you will need and hide them somewhere unfindable with your stuff.<p>On iOS about the only thing you would lose is your message history during the trip. It might be an annoyance if you wanted to play games that had non-cloud-based saved player state, but I can&#x27;t think of too many other issues with doing this.
评论 #14404657 未加载
评论 #14405349 未加载
评论 #14405952 未加载
MatthewWilkesalmost 8 years ago
This feature really should ask you to commit to your duration of travel beforehand. It&#x27;s no use if you can be compelled to readd the data.
评论 #14405758 未加载
评论 #14405939 未加载
评论 #14404796 未加载
评论 #14406313 未加载
IcyPicklealmost 8 years ago
I&#x27;m a little sad that this would require me to use the 1Password cloud-service. I would never want my 1Password vault to be on any server outside of my control. While I completely trust agilebit&#x27;s intentions, I feel that their cloud service adds a very major attack surface. Someone like the NSA would certainly be able to obtain copies of the encrypted vaults, which means that <i>everyone&#x27;s</i> vaults are just one bug&#x2F;backdoor in the cryptographic stack (remember Debian RNG bug?) away from being exposed.<p>Hence, I only use WiFi sync for 1Password. It would be nice if 1Password added a sync option through my own WebDAV server. I&#x27;d then be happy to pay for a 1Password cloud account just for the TravelMode feature, as long as the vault data itself wasn&#x27;t stored anywhere outside of my control. Having my own server would mean the the NSA (or whoever) would have to do a targeted attack on me personally, which is a whole different ballgame from everybody&#x27;s encrypted vaults sitting on agilebit&#x27;s servers.<p>In the meantime, if I had to cross the US border (as a non-citizien!), I would probably delete the whole 1Password app from my phone before crossing, and then restore the entire phone from backup afterwards.
Sophiraalmost 8 years ago
I think this is an incredibly worrisome move on 1Password&#x27;s part. Coming from the right motives, but ultimately it&#x27;ll end up being used against us.<p>Look at it from the perspective of the government. By bringing information from elsewhere into the US, you&#x27;re importing it. It just so happens that the import security is tight in airports. So you use 1Password to delay importing this data until you can reach it through an alternative import method which is much harder to regulate - the Internet.<p>What&#x27;s going to happen is that they&#x27;ll spend much more effort on tightening up the &quot;import security&quot; from the Internet. Things like SSL&#x2F;TLS MITMing and deep packet inspection will be used to enforce compliance.<p>Don&#x27;t get me wrong. The ability to be able to do this is incredibly important. If they had marketed this as anything other than a travel mode specifically, and let users work it out themselves, it&#x27;d probably be better. But as it is, they&#x27;ve created something which is basically publicly stating that it exists to break import security, and as a result it&#x27;s going to get a lot of attention from the wrong people. I worry that the existence of this mode this is going to be used by the government as an excuse to have a &quot;Great Firewall of America&quot;.
评论 #14409259 未加载
misnomealmost 8 years ago
Isn&#x27;t the counter simple; they ask for your logins to the 1Password vault? I guess this just adds an extra layer of obfuscation.<p>The most secure way I can think of is to either encrypt your drive (or wipe for travel and online restore once arriving) and physically mail the new password (or hand over to a trusted friend&#x2F;store location) to the destination. Then there is no way of restoring at the airport.<p>Of course, then they can just detain you indefinitely for not revealing the password you don&#x27;t know...
评论 #14404351 未加载
评论 #14404785 未加载
评论 #14404326 未加载
评论 #14404592 未加载
评论 #14404296 未加载
评论 #14404295 未加载
评论 #14404666 未加载
davidgawalmost 8 years ago
It&#x27;s a clever idea, but how long before border authorities simply order travelers to log on to 1Password and turn off travel mode, or be denied entry? I&#x27;m guessing not very.
评论 #14405568 未加载
评论 #14405765 未加载
评论 #14405679 未加载
petepetealmost 8 years ago
Is travelling with confidential data really necessary? Wouldn&#x27;t it make more sense for me to have a &#x27;empty&#x27; notebook and store my data out of harm&#x27;s way (but accessible via a VPN).
评论 #14406370 未加载
评论 #14404701 未加载
评论 #14404965 未加载
评论 #14407337 未加载
netgustoalmost 8 years ago
Wouldn&#x27;t an alternative &quot;destroy everything&quot; password be a good idea also ?<p>Would work like this : When forced to enter &#x2F; give the password to your vault, you enter&#x2F;give this one, and everything the vault contains is wiped out before the vault is unlocked.
评论 #14404573 未加载
评论 #14404425 未加载
评论 #14404491 未加载
评论 #14405582 未加载
评论 #14404993 未加载
评论 #14404432 未加载
评论 #14404468 未加载
vit05almost 8 years ago
One thing that I have always thought about is why Emails doesn&#x27;t have disposable passwords. For example, you make 1 new password that you can use just one time.<p>That way if you need to use unsafe PC from a hostel, you can log in with that password.
评论 #14404841 未加载
评论 #14404887 未加载
评论 #14404805 未加载
评论 #14404780 未加载
评论 #14404778 未加载
faragonalmost 8 years ago
TL;DR: Just avoid traveling to the USA.<p>P.S. I love the USA, don&#x27;t get me wrong. I hope some day the madness on the borders gets less paranoid.
评论 #14407347 未加载
teekertalmost 8 years ago
I use Linux. I&#x27;m convinced that if I put a small Windows partition up (or another Linux install) and make grub boot into it automatically (with little delay) no one would ever notice. Does any one know if they check for multiple partitions at all?<p>And Android can have multiple users, can you set up a new user and boot into that one automatically?
评论 #14407780 未加载
gtirlonialmost 8 years ago
Mandatory &quot;No Linux client&quot; comment :|<p>Does anyone have any insight if this is a pure business decision or there&#x27;s something holding them back technically?
评论 #14406723 未加载
codelittalmost 8 years ago
Excellent effort. I do wonder though, what is to prevent authorities from forcing you to just turn off travel mode? Is there a timer that you set? Deadman&#x27;s switch? Geolocating? (The last 2 are not good solutions, but you get the idea)<p>Edit: I missed this bit below:<p>&gt; even if you’re asked to unlock 1Password by someone at the border, there’s no way for them to tell that Travel Mode is even enabled.<p>However, it won&#x27;t take very long for authorities to wise up, know that 1password has a travel mode, and tell you to turn off Travel Mode, eh? Or am I missing something?
评论 #14404480 未加载
brokenmachinealmost 8 years ago
Although it&#x27;s a great option, what&#x27;s to stop them for asking for your 1Password account credentials?<p>I believe they already ask for your social media accounts, don&#x27;t they? That is ridiculous in itself. Why not ask for my bank logins while you&#x27;re at it?
评论 #14407936 未加载
simonCGNalmost 8 years ago
It is very sad that it had to come that far
YeGoblynQueennealmost 8 years ago
Could we have something like time-delay passwords? Like the time-delayed vaults they (allegedly) have in banks?<p>Then you could say: &quot;Even if I agreed to give you my password, you wouldn&#x27;t be able to unlock my device with it for another 24 hours&quot;.
评论 #14406465 未加载
评论 #14406412 未加载
评论 #14406476 未加载
kevindongalmost 8 years ago
Or: just delete the app before you get to customs and redownload after you pass customs. Simple, elegant, and fool proof.
评论 #14406128 未加载
seanhandleyalmost 8 years ago
They can only legally view the data you bring into the country on physical media in your possession as you pass through customs.<p>Though it&#x27;s not difficult to remove the app&#x2F;vault and then reinstate it after customs...
benologistalmost 8 years ago
I have some ideas I think will improve our security in this direction. Apple seeks to make it technically impossible to extract iPhone data and I&#x27;ve been wondering how we can do the same with using someone&#x27;s credentials to enter the systems we build.<p>One idea is to allow users to define how many concurrent sessions they can have so they can manage those slots and require something sign out before their credentials can sign in again.<p>The other is to allow users to configure a schedule when their credentials work so you can block most of the world and probably most of most days too.
jackjeffalmost 8 years ago
In a true democracy this would be a pointless feature.
评论 #14404906 未加载
评论 #14409049 未加载
评论 #14404909 未加载
tormehalmost 8 years ago
If you travel for work, wouldn&#x27;t it be better to just let your employer hold the password? When border security asks for data you truly cannot provide it.<p>I think the only way to get around this shit is to have another person hold at least part of the key. Border security can&#x27;t force you to lie to your employer on the phone, so they&#x27;re not getting access.
rukuu001almost 8 years ago
Crazy question: is it more effective to have your laptop couriered to you after you&#x27;ve arrived and cleared customs?
评论 #14407516 未加载
评论 #14405811 未加载
评论 #14406083 未加载
评论 #14405813 未加载
marenkayalmost 8 years ago
I&#x27;m kind of wondering how this all works in general when getting to the US.<p>Considering my usual work contracts, complying with letting border control look into my fully encrypted work laptop would actually be a breach of my work contract.<p>How do you guys handle this?
评论 #14408615 未加载
nihoniumalmost 8 years ago
I don&#x27;t understand. Is this really a thing? I&#x27;m from the UK and never heard such a thing. Is this common in US? What are they looking for? Do they just pick someone randomly, login to the laptop and check emails and stuff?
评论 #14407037 未加载
alexc05almost 8 years ago
I thought the trick was to back up the phone on one side of the border, factory reset &#x2F; wipe, restore the phone on the other side of the border.<p>Obviously that doesn&#x27;t work for laptops - but for a phone it is in the realm of possible.
firebird84almost 8 years ago
Would it be equivalent if my (for example with LastPass) vault required a 2FA token to access, and I simply left the 2FA token at my house? I would in that case similarly be incapable of complying.
jstoikoalmost 8 years ago
I don&#x27;t get how this would prevent border agents from asking to unlock &#x2F; turn off travel mode.<p>Why not make this feature tied to a geo-location? Like the hotel or the conference centre I will be attending.
评论 #14404697 未加载
bisRepetitaalmost 8 years ago
One other way: change your password to a temporary one, give it to a trusted friend who changes it. You don&#x27;t know the password, you can tell the truth to the border agent.<p>Once you&#x27;re out of their hands, ask for it back and change it again.<p>Even if the friend is in the US, they cannot compell her&#x2F;him to release it easily, US laws apply.<p>There must be a way to also encrypt the new temporary password with 2 keys so that the trusted friend cannot access your encryped content without your own key.
评论 #14406705 未加载
throw2016almost 8 years ago
Its great that they have at least thought about this and developed something, but this just sidesteps the issue.<p>Only dissidents in despotic regimes need to resort to these kind of workarounds for lack of other options. Why should citizens of a democratic country have to workaround anything?<p>The solution to privacy, surveillance and overreach issues in democratic countries has to be political, and not technical.
webninjaalmost 8 years ago
I am a U.S. citizen and I flew last year from America &gt; Qatar &gt; India and from India &gt; Qatar &gt; America on a business trip. I was carrying two laptops. Neither laptop was searched, but they were put in separate trays under the x-rays to make sure they didn&#x27;t contain physical explosives or hinder the x-raying of the food and clothes in my backpack.
rafael859almost 8 years ago
Tangentially relevant, I made a pam authentication module for Linux a while ago, that addresses this issue. It allows for the creation of duress passwords. Here is the repository: <a href="https:&#x2F;&#x2F;github.com&#x2F;rafket&#x2F;pam_duress" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;rafket&#x2F;pam_duress</a>
评论 #14407440 未加载
stickfigurealmost 8 years ago
The right solution to this problem is, when traveling, always answer &quot;no&quot; to &quot;may I search your laptop?&quot;<p>It sucks, and it many mean a lot of hassle ranging from confiscated equipment to being held at the border to being refused entry, but this is just one of the new risks of travel. Border security only gets away with this because people say yes.<p>Companies need to make clear to their employees (and the public) that sharing passwords is a terminable policy violation. You should be able to say, honestly and credibly, &quot;I won&#x27;t unlock my laptop because I don&#x27;t want to get fired.&quot;
评论 #14405171 未加载
评论 #14406522 未加载
评论 #14405937 未加载
评论 #14405033 未加载
评论 #14405431 未加载
评论 #14406413 未加载
评论 #14405174 未加载
评论 #14406772 未加载
评论 #14405645 未加载
评论 #14405621 未加载
评论 #14407013 未加载
评论 #14407748 未加载
评论 #14404992 未加载
评论 #14406165 未加载
评论 #14407214 未加载
评论 #14405603 未加载
评论 #14405602 未加载
avaeralmost 8 years ago
When the features start rolling out, the market entrenches the status quo. Props to 1Password though; this is a symptom and they are not the cause.<p>I guess the reasonable next step, when all the outrage has fizzled, is pre-screening. Pay for the government to have all of your passwords all the time, and save yourself the hassle.
评论 #14407667 未加载
betimslalmost 8 years ago
I&#x27;ve had this idea for so many years now: your gmail account has - let&#x27;s call it - a master password and a throwaway password. Say you need to print something from a public PC, you just use that password that works only once, even if somebody key-logs it, you&#x27;re safe.
评论 #14408614 未加载
ElDjialmost 8 years ago
Bin Laden has obviously succeeded removing freedom that american citizens were enjoying not so long ago.
speledingalmost 8 years ago
A travel mode like this for Dropbox would be even more useful. Being able to mark certain directories as confidential so they can easily be removed and re-synced would be much better than deleting and re-installing the entire app.
cyphunkalmost 8 years ago
because... seriously:<p>&gt; the border agent asks &quot;are you hiding any information from us?&quot;<p>Answer yes, always, because: I have client data I&#x27;m most certainly hiding from you on my computer because they&#x27;d in general be worried if it i didn&#x27;t, also I have passcodes to friends mail servers I manager for them I&#x27;m hiding from you, also I&#x27;m hiding from you all the emails I&#x27;ve sent to my parents, I&#x27;m also hiding from you all the pics of my gonads I sent to my lover. So yes, I&#x27;m hiding information from you. What country is this anyway? &lt;asks the person arriving to the US from Germany&gt;
SurrealSoulalmost 8 years ago
Shame it has to come to this
neillyonsalmost 8 years ago
I&#x27;m surprised this is even a thing. Do folks get asked for passwords at airports? What is the reason for this feature?<p>Hope this comment didn&#x27;t come across as negative. I&#x27;m a big 1password fan.
m3kw9almost 8 years ago
The video&#x2F;onboard tried too cute to make the Travel mode = off a confusing ambiguity by making just gray. If you don&#x27;t want to waste people&#x27;s time make things explicit.
beached_whalealmost 8 years ago
It would be interesting if service providers like Google, Microsoft, Apple, and Facebook started taking governments to court for unauthorised access to their systems.
评论 #14406419 未加载
评论 #14406421 未加载
kestalalmost 8 years ago
Do you really trust cloud password storage services?
ubikretailalmost 8 years ago
This might be troublesome in airports like Tel Aviv (personal experience). I&#x27;d rather encrypt and send my data through regular mail.
thepropalmost 8 years ago
I know many who buy an old laptop and ONLY use the Epic Privacy Browser or the TOR browser on it when traveling.
fapjacksalmost 8 years ago
LINUX SUPPORT PLEASE. Seriously, please.
mm4almost 8 years ago
maybe instead of developing all these bend over backwards solutions to deny these data rapists from getting any pleasure out of it, maybe change the law to make them stop doing it in the first place... they are acting on the rules set in the system so change them.
partycoderalmost 8 years ago
A more accurate reality: <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;538&#x2F;</a>
评论 #14404481 未加载
stefek99almost 8 years ago
Arms race in post-Snowdown era.<p>I would never imagine world in 2017 to look like this.<p>&quot;Black Mirror&quot;
edejongalmost 8 years ago
I don&#x27;t understand. Why would people not just change their passwords by someone they know, travel, plausibly deny kniwlege of the password, and call the relative to unlock once crossed the border?
评论 #14407066 未加载
tehwebguyalmost 8 years ago
Detect CBP IP address?<p>&gt; There are 0 passwords in your vault.
specialistalmost 8 years ago
I&#x27;m a very happy 1Password customer.<p>Repeating my #1 feature request here, dovetailing this thread, please forgive.<p>Problem: My logins keep breaking as websites evolve, change their forms, etc.<p>Suggestion: Online catalog of login config&#x2F;scripts.<p>a) Pre-populate with &quot;official&quot; scripts for top 50 websites. Also serve as examples to show everyone how its done.<p>b) Permit users to submit new scripts.<p>c) Version these scripts. Use some kind of repo.<p>d) Keep track of success rate, a la bugmenot, retailmenot, etc. Anonymize feedback, of course.
评论 #14405953 未加载
tiatiaalmost 8 years ago
Upload an encrypted image of your OS (Linux in my case) SSD on your server. Install an older legit version of windows (which was likely provided to you when you bought your computer).<p>Add some nasty gay porn and you are all set for the border.
mtgxalmost 8 years ago
I wish Android and iOS also had a more incognito&#x2F;hidden &quot;travel mode&quot; than the current account profiles.
chronic940almost 8 years ago
I said I wanted to avoid terrorist attacks, not be near them.
评论 #14407920 未加载
评论 #14407794 未加载
评论 #14407301 未加载