Guide

Quick Travel Security Checklist

On the road you connect to unfamiliar networks more often, leave devices unattended, and charge them through ports you don't control — the risk of a data leak spikes at exactly those moments. Here's a short checklist you can finish in 15–20 minutes before your flight, and that keeps working for the whole trip.

Before you fly (5 minutes)

  • Update the operating system and every app on your phone and laptop — the latest patches close the vulnerabilities most commonly used to intercept data on public networks.
  • Turn on a PIN or biometric screen lock on every device you're bringing, including a tablet or smartwatch.
  • Check that two-factor authentication is enabled for email, banking apps, and messengers — it stops sign-in even with a password that was intercepted somewhere.
  • If you use different passwords across services, sync your password manager ahead of time, while you still have your home network — not airport Wi-Fi.
  • If you plan to encrypt traffic on your phone and laptop while traveling, install and set up the app in advance: downloading and signing in to HamikVPN at home is far faster than doing it in the boarding line.

Hotel and cafe Wi-Fi

A password-free network at a hotel, cafe, or airport doesn't guarantee your traffic is invisible to other devices on the same network. The gap between standards matters here: Wi-Fi with WPA3 support and Enhanced Open (OWE) mode creates individual encryption for each device, even on an open network with no password — while the older WPA2 standard offers no such protection for open hotspots. There's usually no way to know in advance which standard a given network uses, so it's worth following the general rules recommended by, among others, the US cybersecurity agency CISA:

  • turn off auto-connect to open networks and remove the network from your saved list after you leave;
  • disable file and folder sharing on your phone and laptop for the duration of the trip;
  • confirm the exact network name with staff — a fake access point with a similar name ("Hotel_Free_WiFi" instead of "Hotel-WiFi") remains an easy way to intercept someone else's traffic;
  • where possible, use an encrypted connection on top of whatever network you join — this reduces the risk of interception regardless of the security standard a given hotspot uses (more in our breakdown of public Wi-Fi risks).

Charging and USB ports

Public charging stations at airports and train stations carry a separate risk known as "juice jacking": a compromised or modified USB port could theoretically be used to try to access data on your device. Following guidance from the US Federal Communications Commission (FCC), it's safer to charge your phone through your own power adapter plugged into an outlet, a portable power bank, or a cable that physically carries no data. If there's no outlet and you have to use a public USB port, choose "charge only" rather than "transfer data" in the prompt that appears on screen.

While you're on the move

  • Keep Bluetooth and NFC off when you're not actively using them.
  • Turn on the find-my-device feature ("Find My Device" on Android, Find My on iOS) — in case of theft or loss on the trip.
  • Don't sign in to personal accounts on hotel business-center computers; if you have to, make sure to sign out afterward and never agree to save the password in the browser.

After you get home

Change the passwords for any service you accessed over networks you weren't sure about, and review the list of active sessions in your email and messaging apps — most services show which devices and cities were recently used to sign in. It's worth revisiting that list periodically even outside of travel — for example, alongside a basic phone checkup.

Frequently asked question

Do I really need to turn off Wi-Fi and Bluetooth on a plane?

Requirements vary by airline and crew instructions: generally, turning on airplane mode is enough, and Wi-Fi and Bluetooth can be re-enabled separately if the flight explicitly allows it. Outside of a plane, turning them off isn't about rules — it shrinks your attack surface, since a device with no active wireless connections is harder to find and connect to without the owner's knowledge.

Want to secure your connection today?
3 days free, no card required
Try it free

Frequently Asked Questions

Do I really need to turn off Wi-Fi and Bluetooth on a plane?
Requirements vary by airline and crew instructions: generally, turning on airplane mode is enough, and Wi-Fi and Bluetooth can be re-enabled separately if the flight explicitly allows it. Outside of a plane, turning them off isn't about rules — it shrinks your attack surface, since a device with no active wireless connections is harder to find and connect to without the owner's knowledge.
What should I do if border officials ask me to unlock my phone for inspection?
Rules differ from country to country and can be legally mandatory in a given jurisdiction. Practical preparation doesn't depend on the exact rules: back up important data before you travel, use separate cloud accounts for work and personal data where possible, and sign out of apps you won't need on the trip. The Electronic Frontier Foundation publishes a detailed practical breakdown of this topic (Digital Privacy at the Border) — worth reading in advance if your route crosses borders where such checks are more common.
How do I quickly regain access to my accounts if my phone is stolen or lost while traveling?
If your phone is the only way to get one-time two-factor codes, losing it locks you out of every linked account at once. Save the backup recovery codes that email, banking, and messaging services issue when you turn on 2FA ahead of time, and keep them separate from the phone. Right after losing the device: turn on remote lock and wipe through a find-my-device service, contact your carrier to block the SIM card, and change passwords for your main services from another device. More detail in our breakdown of two-factor authentication.
Is it safe to sign in to personal accounts from a hotel business-center computer if there's no other option?
The risk is higher than on your own device: a public computer may have a keylogger installed, and your history and saved data are visible to the next guest. If there's truly no other way — open a private browser window, never save the password when the browser prompts you, and manually sign out afterward instead of just closing the window. After you get home, change the password for any account you accessed this way, even if you didn't notice anything suspicious.