6 ms·
Digital Security Tips to Prevent the Cops from Ruining Your Trip Abroad
- raybb 3y agoSummary: bring burner devices, tamper-evident bags, and keep your devices empty when crossing borders.
- amelius 3y agoHow do you post vacation photos to social media when you're not logged in?
- EvanAnderson 3y agoI read "post vacation photos while on vacation" as "signaling I'm not at home and a good target for burglary". I tend not to tell anybody that I've taken a trip until I've returned home.
- whoknew1122 3y agoPosting vacation photos to social media when you're actually on vacation is a bad idea. You're signaling to people you're not at your residence or job, which is bad security anyway. Save all the cute pictures to post when you get home.
- ActorNightly 3y agoOr even better: don't bring any devices with you, buy a phone at the airport when you land, buy a cheap laptop at an electronics store if you need one. Depending on the phone you plan to buy, you can also bring an hdmi adapter and a bluetooth portable keyboard and plug in your phone to your hotels tv if you need a full desktop. Then when you leave, make sure to wipe your devices, and leave them in country. For extra security, rent an EC2 instance (in the region you are traveling to), and use that with an SSH socks proxy or set up VPN software on it.
- intrasight 3y ago>takes your phone or laptop to another room, the safe bet is to consider that device compromised if it’s brought back later, and to immediately procure new devices in-region, if possible Isn't an easy solution to this is to have your "laptop" just have a generic OS install, but have your real machine a bootable USB or SD?
- chillycurve 3y agoDepending on your threat model, if the hardware is sufficiently compromised, no amount of software gymnastics will keep you safe.
- asynchronous 3y agoTo add an example a hardware keylogger would still capture keystrokes in your USB boot OS.
- intrasight 3y agoI read once that those traveling overseas should always copy and paste in passwords rather than typing - basically assuming that your machine has been compromised with a software or hardware keylogger.
- dtx1 3y agoNo that could be searches aswell. The correct solution is having all data online with passwords to it in your head and an empty device
- plugin-baby 3y agoThese suggestions seem inconvenient. I guess like a lot of security there’s a trade-off to be made between risk, impact & the cost of mitigation. If you travel frequently, need to work while in transit, you’re going somewhere with unreliable internet, or just don’t consider yourself a likely target then you’re not going to bother with most of this.
- AlbertCory 3y ago> The first digital security rule of traveling is to leave your usual personal devices at home. Go on your trip with “burner” travel devices instead. I thought it was just easier to do this for Israel. An Israeli company snail-mailed the phone to me before I left, and I mailed it back to them when I returned. You don't have to worry that the phone will work in that country. It might be different if I were traveling on business or crossing a lot of borders. I didn't do this, but I should have: > Just as you shouldn’t bring your usual devices, you also shouldn’t bring your usual accounts. Make sure you’re logged out of any personal or work accounts which contain sensitive information. If you need to access particular services, use travel accounts you’ve created for your trip. Make sure the passwords to your travel accounts are different from the passwords to your regular accounts, and check if your password manager has a travel mode which lets you access only particular account credentials while traveling.
- jrochkind1 3y agoIsrael is definitely not typical, and is known to deny people entry more often than most countries (at least most "allied with the West", "free" countries), and also known to specifically ask for access to email and social media at the border sometimes. So that does seem like one to especially log out of any personal accounts for. But then... if they realize they don't have access to your usual personal accounts, they may deny you entry for THAT, so.... https://www.eff.org/deeplinks/2012/06/defending-privacy-israeli-border-information-travelers-carrying-digital-devices https://www.eff.org/deeplinks/2012/06/defending-privacy-isra...
- AlbertCory 3y agoPossibly for some people. My phone wasn't even inspected. Physically at least /s
- Syzygies 3y ago"Travel" shouldn't be considered a special risk. I had my laptop stolen on a San Francisco BART train. It is possible to set up Apple devices so they're bricks in anyone else's hands. If you're not satisfied with your level of security for travel, why are you comfortable taking your device out of a locked safe?
- tayo42 3y agoSounds excessive. Probably the only country I would bring burner devices to would be China. Even that idk, I'd have to research and make sure I'm not just a victim of media fear mongering. Who's the target audience for this article? I've been to I think 16 countries, I think i only talked to a cop once, that was at a traffic check point.
- EvanAnderson 3y agoI'm a US citizen and surely not of any interest to the government. I'd like to travel abroad, but I have an admittedly irrational fear of being denied re-entry (or, at the very least, being subjected to considerable unpleasantness upon re-entry) that gives me great pause. (I keep justifying to my wife that we haven't been to all of the US yet but that argument will only go so far.) I absolutely would not travel with any of my daily-driver devices. I worry having a completely empty phone w/o a SIM or a visible history of use would cause me to be more heavily scrutinized. Same goes for a computer. I've heard there's an expectation for some returning travelers to divulge passwords for online accounts upon re-entry to the US (at the risk of "unpleasantness"). I worry because I don't have accounts on the common major social networks. For the accounts I do have (basically Facebook, LinkedIn, and a moribund Gmail account I have grudgingly) I wouldn't know the passwords (because I use a password manager and random passwords exclusively). I wouldn't have my password manager or 2FA seeds with me either. I know I'm a crazy person when it comes to other aspects of my life. Am I a crazy person when it comes to this? (It definitely doesn't help that I've watched various "reality TV" border/customs TV shows...)
- asynchronous 3y agoProbably, but it is a reality that whatever illusion of protection from search and seizure US citizens benefit from is thrown out the window when you try and renter the country. That’s how federal agencies have caught many criminals without a search warrant.
- NickBusey 3y agoI don't know where you're getting your information, but there is absolutely not an expectation to divulge passwords for online accounts upon re-entry to the US.
- mikeweiss 3y agoAs a US citizen you cannot be denied entry into the united states. Your thought process around this does appear to be highly irrational and likely based on movies and television. This fear absolutely should not keep you from enjoying international travel.
- sbehere 3y agoI don't understand the point of traveling with clean burner devices and keeping your data encrypted in the cloud. Yes, it protects for threats where the devices are stolen or compromised when out of sight, but not for cases where government authorities are targeting you, as described in the article. What happens when govt. goons tell you to write down a list of your cloud accounts (email, storage etc.) and their corresponding security credentials and threaten you to not leave any out? Or, when you are asked to log in to your cloud accounts with the threat actors hovering around you? How many of us would refuse and/or roll the dice on not revealing certain accounts and risk them being discovered later (along with implications of not having revealed them earlier when specifically told to do so)? Wouldn't it be more rational and reasonable (for everyday folk, not journalists, activists, dissidents, etc.) to never travel with or keep on cloud storage any data that they would rather authorities never, ever see, if at all they have such data?I think the vast variety of business and personal data does not fall into this category. Note that, in principle, I am all for privacy and resisting govt. intrusions into private lives by crafting appropriate legal frameworks and strong technical mechanisms. In practice, as an average Joe, I don't know how much I should resist if/when I am personally targeted and threatened with dire consequences while traveling in a foreign country. It is easy to think that in such a situation, my priority would be to get out of that situation asap and folding completely may be seen as the fastest way to achieve that.
- whoknew1122 3y ago> What happens when govt. goons tell you to write down a list of your cloud accounts (email, storage etc.) and their corresponding security credentials and threaten you to not leave any out? That's why you uninstall all apps and delete your browsing history. They have no way to know how accounts you have, or where they are. Unless you leave those traces on your devices. If you're super paranoid about it, you can create a few cloud accounts and seed them with innocuous or otherwise fake data. That way you have something to provide, but it's nothing of interest.
- reaperman 3y ago> They have no way to know how accounts you have, or where they are. Hahahahahahaha. Data brokers are happy to sell them a list of all your accounts, cell-phone location history, your credit card purchases going back 10 years, and much more.
- neilv 3y agoCan we also tackle the general problem, by considering the snooping to be a diplomatic problem of the locale that does it? A lot of travel is discretionary, such as vacations. Academic and trade conferences can often choose where they're located. Business can often choose where they do business or expand. A public interest Web site could publish a trustworthy database of incidents and report card grades of different locales, covering more concerns than the US State Dept. does. Say, ExampleCon 2024 is announced to be in sunny Barlandia, and a bunch of members respond that they don't feel safe attending, because the database says that Barlandia Customs often clones the devices of visitors without apparent justifiable cause, and some alarming specific incidents. Some respond privately; some publicly announce not traveling to Barlandia, and why. When planning ExampleCon 2025, organizers consider the convention center in Footopia but have learned to check the database, and find that Footopia has a totalitarian attitude towards privacy&security, as well as elevated incidence of harassment of LGBTQ+ and certain ethnic/racial identities. They don't tell the membership that Footopia was considered, but when they announce the choice of Bazland, they also link its favorable status page on the database Web site. Meanwhile, the Blortcity government is taking note of this, and embarks on a intense campaign to make their status page numbers look great. A side effect -- besides their consequently growing tourism industry, and increasing tax base from new residents -- is that a lot of abusive/hostile behaviors are stopped for everyone living and visiting there.
- mattnewton 3y agoSerious question, are there locales with a consistently good track record on this? I have only seen news stories of when it goes wrong and it's difficult to calibrate %s for each region. Like the US is often good for rule of law, but there are a lot of notable counter examples. In this article, around the UK, it's difficult to get a sense of how often this sort of thing is happening especially relative to other western places. I suspect that virtually every country does this sort of thing regularly and the incentives to stop have got to be much more severe than tourism and conference hostings, there is just too long of a road from that to domestic voter outrage to actually endanger lawmakers jobs. We have to get people to care about it through arguing I think.
- NoZebra120vClip 3y ago
- JohnFen 3y agoI don't dare take my real smartphone or laptop with me when I fly domestically in the US. I certainly wouldn't take them with me when flying internationally, either.