Cybersecurity for the Paranoid Business Traveller

speckx1 pts0 comments

Cybersecurity for the paranoid business traveller – Terence Eden’s Blog

Theme Switcher:

🌒 Dark

🌞 Light

📰 eInk

💻 xterm

🥴 Drunk

👻 Nude

♻️ Reset

Over the years, I've worked for organisations with various levels of risk tolerance for business travellers. Some have been (rightly) paranoid and others have been (wrongly) placid about the threats their employees face.

The fact is, individuals are often targeted for espionage, blackmail, or other state-sponsored attacks.

Here's a list of some of the different advice I've received, roughly sorted into levels of suitability. Start at the top and work your way down until you reach a suitable level.

USB sticks? No thanks!

At some point, you'll be given a gift of a decorative USB pen drive. It'll either be part of a goodie-bag or you'll be told it has all of this quarter's TPS reports on it.

You should thank them for their kind gift. On your way back to the hotel, drop the stick in a bin.

There's just too much which can go wrong with a USB stick. Maybe it has a virus. Maybe it is an exfiltration device. Maybe it has extreme pornography and the police will catch you with it. Just chuck it. If anyone asks, say you couldn't get it to work and can they please email you the information.

USB Power? Play it safe!

USB powers everything from your phone and laptop, to your headphone and eReader. But USB cables also carry data. Some devices can be silently hacked by plugging them in to a dodgy power port.

Is it likely that the USB socket on the airport bus has been set up to exfiltrate travellers' data? Probably not - but why take the risk?

The best thing you can do is to always charge from your own device. Get a travel charger or, ideally, a portable battery and only use that for charging.

For extra paranoia, you can buy USB condoms and charging-only cables - but they tend to be slower at charging.

Reduce Your App Attack Surface

Do you need all those apps on your phone? Will you cope without your banking apps, dating apps, streaming apps? Each one is a potential vector for abuse.

Is it legal for you to date your preferred romantic partner in your intended destination? You shouldn't have to hide yourself, but having an illegal app on your phone is a great way to get picked up by the police.

Go through your phone and uninstall anything which isn't important to the trip.

A VPN probably draws more attention than it is worth, but browse cautiously

This is slightly counter-intuitive. Every important site on the web uses HTTPS. The really important ones are on a special list which means your browser will only use a secure connection. The chances of your data being intercepted is minimal.

But using a VPN immediately makes your traffic look suspicious and, in some countries, may be illegal.

That said, while the contents of your communications will be private, their destination is easy to figure out. Don't browse pornography or any other site which is liable to get you in trouble. This may include news sites from outside the country.

What passwords do you need?

Hopefully you use a password manager - and hopefully all your passwords are unique. But do you really need to carry around all of them? You password manager almost certainly allows you to create a sub-account into which you can deposit anything you need for your trip.

Similarly, you don't need all your MFA codes with you. If you do need MFA please make sure it isn't coming through SMS.

They're not flirting with you.

Mate, you're a middle-aged sales rep who scored a trip to a conference in an exotic country. Do you really think that pretty young thing is enthralled by your tales of middle-management?

No.

At best, the photos will be used to blackmail you. At worst the police will claim that they're under the age of consent and that will be used to blackmail you.

Laptops and Liability

Your IT team has provided you with a laptop which is encrypted and biometrically secured, right? But do you need that specific laptop?

They should grab a cheap laptop. Fill it with only the documents you need. When you get back home, toss it.

I'm quite serious, a £200 Chromebook is a cheap price to pay to prevent your secrets getting stolen or your network being infiltrated.

What Else?

Possibly you think some of these are overkill. Perhaps you think I'm not being paranoid enough. What would you add to the list?

Share this post on…

try {<br>await navigator.share({url:u});<br>} catch {<br>// Show an alert if the share failed. Likely means no share support.<br>alert('Copied URl to clipboard');<br>})()" style=cursor:pointer;>

Voluntary Paywall

Enjoyed this post? Show your support and pay the author.

3 thoughts on “Cybersecurity for the paranoid business traveller”

Gabriel N

@Edent thanks for the article!

On the “What else” basket: is it too paranoid to get a used phone to travel to certain countries, just install the bare needs, and discard it when returning?

Reply | Reply to original comment on mastodon.social...

paranoid phone business laptop apps share

Related Articles