Security Tips for Travel
Overview
Traveling comes with certain data security risks. Using devices like laptops, tablets, or smartphones in unfamiliar locations can expose them to threats. Connecting to public networks in hotels and airports often lacks robust security, making them easy to target.
Consider adding the following data security safeguards to your travel checklist: before, during, and after your trip. If you have any questions about securing your data on your trip, email security@berkeley.edu.
If Traveling Internationally:
For international travel, remember U.S. export controls and your destination country's import restrictions. Review encryption options to protect data while traveling.
- Contact the Export Control Office. Ask for guidance on export regulations, classification of controlled technical data, and assistance with export licenses for traveling researchers to avoid penalties and delays.
- Research encryption laws at your destination. Some foreign countries restrict the use of imported encryption software. If restrictions apply, use a loaner device instead, or contact IT Client Services: ITCS Support or your local IT department to decrypt your data before you leave.
- Inspect the content on your device. Even political cartoons could be an issue depending on the country.
- Register your trip and sign up for travel alerts Register your travel, get travel insurance, and sign up for alerts on political unrest, natural disasters, and other health warnings.
Before You Leave
- Leave data/devices at home. To safeguard your data and device, consider leaving your computer at home if you don’t need it. Instead, bring a loaner computer. Check with your department or technical support for borrowing options.
- Back up your data. Always back up your data when traveling with any device, whether it’s a loaner computer, your regular computer, tablet, or smartphone. This ensures you have a safe copy to recover from in case you lose your device or it becomes compromised.
- Install and configure encryption software (if applicable). Full disk encryption software is freely bundled with recent Microsoft Windows and macOS operating systems and is easy to use and setup. Some countries restrict imported encryption software, so be sure to check the encryption laws beforehand; you may need to contact ITCS to decrypt your data before you leave.
- Install and configure campus VPN software To protect your traffic on networks during your trip, install and configure VPN software to utilize full tunneling. Full tunnel VPN configuration will secure all internet traffic, whereas the alternate configuration, split tunneling, only protects internet traffic for UC Berkeley internet services.
- Prepare CalNet 2-Step Backup Passcodes. You can use passcodes for second-step verification. You can print them to take with you or use the Duo Mobile app on your phone to generate a passcode. This works anywhere, even without an internet connection or cellular service. Tip: Do this before you travel if you do not have cell service during your trip.
- Follow our "MSSND: How to Secure Devices": Update your operating system and apps to the latest versions. Install and update anti-malware software. Choose strong passphrases. For laptops, create and use a personal account without admin privileges (i.e., one that can’t install or write to your hard drive).
On the Road
- Do NOT leave your device unattended. Don’t leave it unattended, lend it to strangers, or check it in during flights. If you leave your computer, turn it off instead of hibernating or putting it to sleep.
- Do NOT plug in untrusted accessories. Avoid connecting untrusted items like flash drives, charging cables, or SD cards. If you need to buy an accessory abroad, choose one from a reputable source.
- Do NOT enter your credentials into public computers. If you need to use public computers during your trip, avoid entering your credentials on them.
- Connect only to known wifi networks. When connecting to a network, confirm the correct network name with staff at the business, then connect to it.
- Turn off your wifi when not in use. To avoid accidentally connecting to rogue Wi-Fi networks later, turn off Wi-Fi on your device when you are finished using the network.
- Use campus VPN Software. The VPN software offers access to UCB services, like library resources, while protecting your private information from eavesdroppers when using the network remotely. For optimal security, use the full-tunnel configuration mentioned above.
- Use a non-privileged account. Use a personal account without admin privileges, and elevate privileges only when necessary. This will provide additional protection against malware infections.
- Practice safe web browsing. Websites may collect data about you, or serve as gateways to steal your data. To protect yourself while browsing websites abroad,
- Only connect to HTTPS websites, which encrypt the data transmitted between your browser and the website,
- If your browser shows an error about the digital certificate used to encrypt the data, assume the site is fake, compromised, or that your web traffic is being intercepted. Stop connecting to the website.
- Do not click on suspicious links or prompts. Malicious websites try to trick you by exploiting your curiosity, impatience, or fear of malware. Always think carefully before clicking a link or agreeing to a prompt.
- Clear browsing session information. Some web applications don't log you out completely, even when you click the logout button or close the browser. Clear all the web browser session information to prevent others from accessing your account and data.
- Note the credentials you use during the trip. Whether you use them on your device or a public computer, they may be compromised. To be safe, note the credentials you used so you can change them on a trusted, secure device once you return.
After Your Trip
- Reset credentials you used during the trip. Reset your credentials used during the trip. Use a trusted computer, whether it’s your own or one provided by your IT support staff, to reset the credentials used during the trip. For example, go to the CalNet management website to reset your CalNet passphrase.
Import Restrictions on Encryption Software
Encryption software is a useful tool for strengthening data protection. However, many foreign countries do not permit encryption software to be imported or used without prior approval. For example, China requires international travelers to apply for a license to use encryption software before arrival. To learn more about background information and details of import restrictions on encryption software, follow the links below to external websites:
- Wikipedia article discussing restrictions on encryption software import
- Crypto Law Survey website with a list of countries and their respective encryption software import restrictions.
If you cannot use encryption software at your destination, we strongly recommend leaving your data and device at home and bringing a loaner device instead. If your information is sensitive and it is illegal to secure your devices/data and communication, contact the security office (security@berkeley.edu).