Travel Digital Security: Borders, Hotel Wi-Fi and Private Calls
Travelling puts your phone, data and conversations at risk. Border device searches, hotel Wi-Fi, roaming and calls, and what a careful traveller carries.
Travel is when your digital life is most exposed. You carry every device you own through airports and across borders, connect to networks you know nothing about, and make calls from rooms you have never seen before. For executives, public figures and anyone whose conversations have value, a single trip can undo years of careful habits.
None of this means you should stop travelling or leave your phone at home. It means planning, the same way you plan a route or a meeting. This guide covers the main risks and the practical steps that reduce them, and how VOIDEX fits into a travel kit.
At the border
Many countries give their border agencies broad powers to inspect electronic devices. In the United States, for example, Customs and Border Protection publishes its policy on the border search of electronic devices, which allows officers to inspect phones and laptops of travellers entering the country. Rules differ between countries, and they change, so check the current position for each destination.
What this means in practice is that anything on the device when you arrive may be seen. A few principles help:
- Carry less. The safest data at a border is data that is not on the device. Before a trip, ask what you actually need.
- Consider a travel device. Many organisations issue a clean phone or laptop for high-risk trips, with only the apps and accounts needed for that journey.
- Power down before you cross. A fully powered off device with a strong passcode is harder to access than one that is simply locked.
- Use a long passcode, not just a face or fingerprint. Biometrics are convenient but can be applied to you without your cooperation.
- Know your own obligations. Laws differ, and a traveller's rights at a border are not the same as a citizen's rights at home. Legal advice before a sensitive trip is worth having.
End-to-end encrypted messaging does not protect what is visible on an unlocked phone. It does ensure that what travels across networks and sits on a company's servers cannot be read there. That is why the number and history of conversations on the device you carry matters as much as the app you use.
Hotel Wi-Fi and public networks
Hotel networks are shared by strangers, often run by third parties, and rarely designed with security in mind. In 2014, researchers at Kaspersky described a campaign they named DarkHotel, in which attackers used hotel networks to target senior executives staying at luxury hotels. The details of that campaign are years old; the lesson is not.
Sensible habits on any shared network:
- Assume the network is watched. Treat hotel, airport, café and conference Wi-Fi as untrusted.
- Prefer your own connection. A mobile hotspot from your own phone is usually better than a shared network.
- Rely on end-to-end encryption, not the network. If an app encrypts from your device to the other person's device, a hostile network sees only ciphertext.
- Install updates before you leave, not on hotel Wi-Fi mid-trip, and decline unexpected update prompts that appear when you join a new network.
- Avoid public charging points, or use your own charger and cable plugged into a wall socket.
Roaming, SIMs and the phone network
The ordinary phone network was not built for privacy. Standard calls and text messages pass through carriers in every country you visit, and roaming adds more parties to that chain. In late 2024, US officials confirmed that state-backed hackers known as Salt Typhoon had been inside American telecommunications networks. The US Cybersecurity and Infrastructure Security Agency then advised highly targeted individuals to use end-to-end encrypted communications rather than relying on ordinary calls and texts. We covered the background in Salt Typhoon and the telecom hacks.
For travellers this translates into a simple rule: carrier calls and text messages are for logistics, not for anything confidential. Sensitive conversations belong in an end-to-end encrypted app.
Local SIM cards are useful for data and cost, but remember that a new number is also a new identity to protect. Keep the number that secures your important accounts private and, where possible, off your travel device.
Calls from unfamiliar rooms
A hotel room, a rented villa or a meeting room abroad is not a private space by default. Before a sensitive call, think about who is in earshot, whether the conversation needs to happen now, and whether the other person is also somewhere private. Encryption protects the line. It does not protect a conversation overheard through a door.
Photos and location
Travel is when people post the most, and when location leaks do the most harm. Photos taken on phones often carry GPS coordinates, the device model and the time of capture. A picture from a hotel balcony can show where you are staying before you have checked out. Post after you leave, not while you are there, and use platforms that strip location data. See photo metadata and GPS for the full picture.
What a careful traveller carries
A practical kit for a trip where privacy matters:
- A phone with only what the trip needs, fully updated, with a strong passcode.
- An end-to-end encrypted messenger for all sensitive conversations and calls.
- Your own charger and cable, and a small power bank.
- Two-factor authentication on an authenticator app or security key, not text messages, so a lost or swapped SIM does not lock you out or let someone in.
- Recovery codes stored at home or in a trusted password manager, not on the travel device.
- A plan for loss. Know in advance how you will sign devices out and what you will do if a phone is taken.
VOIDEX on the road
VOIDEX is an invite-only, end-to-end encrypted platform owned by CNOTA. It is free, carries no ads, and uses no third-party trackers or ad pixels.
VOIDEX Messenger is built for exactly the moments travel makes risky. Direct messages use a hybrid post-quantum key agreement combining X25519 with ML-KEM-768, then a double ratchet with post-quantum re-keying, so every message has its own key. Keys are created on your devices; VOIDEX's servers store only public keys and ciphertext. On a hostile hotel network, what passes through is ciphertext.
Voice and video calls run over WebRTC with DTLS-SRTP. The call setup is sealed under the conversation key, so the server cannot swap the encryption fingerprint, and calls are relayed through VOIDEX's own TURN relay rather than a third party's. For a traveller, that is a private line that does not depend on the local phone network.
Several controls suit carrying less:
- Disappearing messages, so conversations that do not need to persist do not sit on the device you take through a border.
- Delete for everyone, for a message that should never have been sent.
- Per-chat screenshot control, set in each conversation.
- A recovery code only you hold. Each member has a VOIDEX recovery code that opens their message history on a new device. VOIDEX never holds it. That allows a clean travel device to be set up and wiped without losing your history, as long as the code is kept safe somewhere else. A lost code cannot be restored by anyone. Members can also switch the encrypted history copy off. More in own your keys.
When you post publicly in VOIDEX Space, images are re-encoded and video capture metadata such as GPS, device model and creation time is removed before the post goes public. A file that cannot be cleaned is refused, never published raw. And when you need to look something up abroad, VOIDEX Pulse sends searches to the web through VOIDEX, so sites and search engines never see who is asking.
Honest limits
No app can protect data on a device that is unlocked and handed over, or a conversation overheard in the room. Border rules are set by governments, not by software. Public posts in VOIDEX Space and public channels are not end-to-end encrypted, because they are meant to be seen, and VOIDEX labels them. The goal is fewer things to lose and a private channel for what matters.
Travel light
The best travel security is mostly subtraction: less data on the device, fewer accounts signed in, fewer conversations on the ordinary phone network. Add one private channel for everything sensitive, and a plan for the day something goes missing.
VOIDEX is invite-only. Request access before your next trip, or read how VOIDEX encrypts calls and messages.
Sources
- US Customs and Border Protection, Border Search of Electronic Devices: https://www.cbp.gov/travel/cbp-search-authority/border-search-electronic-devices
- Kaspersky Securelist, The Darkhotel APT (November 2014): https://securelist.com/the-darkhotel-apt/66779/
- CISA, Mobile Communications Best Practice Guidance (December 2024): https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



