By Aaron TurnerOver the last 25 years, I’ve traveled to over 60 countries around the world conducting information security research and working as a consultant to government and private-sector organizations. I wish I could say that I had all of the answers when it comes to traveling safely with technology, but every new trip proves that assumption wrong. Governments and organized criminals are exploiting technology to their benefit, and most travelers don’t notice the breadth of information stolen in those attacks nor the persistent access which the attackers have been able to achieve recently.
Unfortunately, if you are an iOS user, there is nothing you can do about these roots of trust without jailbreaking your device and making changes to the trusted root store. Google has provided an option in Android version 7 and later to allow a user to toggle the trust settings for each certificate authority (go to Settings > Security & location > Encryption & credentials > Trusted credentials to view the toggle options). My recommended list of minimal certificate trusts includes Amazon, Baltimore, Comodo, Digicert, Entrust, Geotrust, Globalsign, GoDaddy, Identrust, Network Solutions, OpenTrust, SecureTrust, Thawte, Verisign and Visa certificate authorities. This generally provides a decent user experience without the blatant government-operated roots of trust risks. International travelers should be watching for any strange alerts about network or trust settings that appear and take action if they believe that a new root certificate has been injected into the trust store as most network operators have permissions to manipulate the roots of trust on devices which are connected to their cellular networks. Again, on Android, find the newly-installed root and make sure to toggle the trust relationship off. So, the first recommendation for the wary international tech traveler – leave your iPhone at home and use a Pixel or Android One device with all software updates installed and the trust settings reduced as recommended. Why so much focus on credentials? We have seen in multiple cases over the years in which hostile governments have opportunistically captured user credentials and then used them at a later time when they are needed. This happens especially often in EU regulatory proceedings where companies are being investigated for trade or business practice violations of EU business laws.
If You Can’t Afford to Lose It, Don’t Bring It
I’ll start with some general guidance on the current state of affairs: don’t take any data or credentials with you that you aren’t prepared to lose. This is similar guidance that I give to friends who want to go visit Mexico City, Sao Paulo or Buenos Aires with me. I tell them to only carry with them that which they are prepared to willingly hand over to anyone who asks for it. Whether that’s a wallet, a watch, a ring, cash, or credit cards. I’ve followed this policy for two decades now; I’ve been robbed multiple times but never harmed. A key point that many people do not understand while they are traveling internationally is that there is no guarantee that governments or organized criminals will not use readily-available exploits to gain access to data and credentials opportunistically or through targeted attacks. How can these governments and organized criminals gain such easy access to data and credentials? The root cause is essentially the poor state of the world’s cryptographic infrastructure. Let’s start with a focus on smartphones and some tips about protecting your digital privacy on mobile devices while traveling.Pro Tips on Protecting Your Digital Privacy Abroad
On iOS and Android devices, over 30 countries have applied to participate in Apple’s and Google’s trusted root certificate authority programs. This is all legal: those countries use their laws and international legal precedents to apply to have their roots of trust pre-installed at the Google and Apple factories as part of the ‘lawful intercept’ programs in each jurisdiction where smartphones are sold. This means that the governing authorities can intercept and manipulate any TLS-protected network connection without the user’s consent or knowledge. Most concerning of the countries participating in Apple’s and Google’s trusted root programs are Turkey, Iran, and Venezuela. But there is evidence that even supposedly privacy-respecting countries will use their ‘lawful intercept’ capabilities to exploit the situation for industrial espionage and regulatory enforcement actions.
Unfortunately, if you are an iOS user, there is nothing you can do about these roots of trust without jailbreaking your device and making changes to the trusted root store. Google has provided an option in Android version 7 and later to allow a user to toggle the trust settings for each certificate authority (go to Settings > Security & location > Encryption & credentials > Trusted credentials to view the toggle options). My recommended list of minimal certificate trusts includes Amazon, Baltimore, Comodo, Digicert, Entrust, Geotrust, Globalsign, GoDaddy, Identrust, Network Solutions, OpenTrust, SecureTrust, Thawte, Verisign and Visa certificate authorities. This generally provides a decent user experience without the blatant government-operated roots of trust risks. International travelers should be watching for any strange alerts about network or trust settings that appear and take action if they believe that a new root certificate has been injected into the trust store as most network operators have permissions to manipulate the roots of trust on devices which are connected to their cellular networks. Again, on Android, find the newly-installed root and make sure to toggle the trust relationship off. So, the first recommendation for the wary international tech traveler – leave your iPhone at home and use a Pixel or Android One device with all software updates installed and the trust settings reduced as recommended. What to Know About Credentials
The next major mobile risk area that can be managed by tech travelers has to do with the credentials that are associated with our digital identities. Unfortunately, even on a properly-configured Android device, it is extremely likely that mobile applications will leak credentials to a hostile network operator. The best recommendation is to practice some mobile application and digital identity hygiene before leaving on your trip. Here’s how:- Uninstall any unnecessary mobile application from your devices and make sure that any application that is installed is fully updated to the latest version.
- On any application which you decide to keep, make sure the username and password for that application are unique and not recycled from other accounts (using a password manager like LastPass will help with this).
- Once you’ve returned home, reset all username and password pairs for any applications which were installed on any device while traveling.
