Blog

Cybersecurity on Vacation: Relax Without Giving Your Passwords a Holiday

A practical summer checklist for backups, public Wi-Fi, VPNs, device security, and keeping vacation photos safe without turning the trip into an IT project.

Dmytro
cybersecurity travel backups

Cybersecurity on Vacation: Relax Without Giving Your Passwords a Holiday

Summer is the season for beaches, mountain roads, delayed flights, and discovering that the hotel Wi-Fi password is hotel2026. Your laptop, phone, and online accounts do not know that you are on vacation, though. They remain fully available for work, photography, banking, and anyone who can persuade you to connect to the wrong network.

The good news is that travel cybersecurity does not need to become a second job. Most of the useful preparation can be finished before departure, preferably before the taxi is waiting outside.

Before leaving, make a backup you can actually restore

“Backups run every night” is reassuring. “We restored a file from yesterday’s backup and it opened correctly” is evidence.

Before travelling, confirm that important documents, photos, server configurations, password-manager data, and recovery codes exist somewhere other than the device in your bag. Check the last successful backup date, review any error notifications, and restore a small selection of files to a temporary location. A green checkmark is nice; a successful restore is nicer.

Keep more than one copy, with at least one copy separated from the original device and account. A permanently connected backup can be damaged by the same ransomware, software error, or accidental deletion as the source. CISA likewise recommends frequent backups and warns against leaving an external backup drive connected when it is not in use.

For affordable off-device storage, an ITLDC HD VDS provides large HDD capacity intended for backups and data storage. Encrypt sensitive data before uploading it, protect the server with SSH keys and a firewall, and monitor whether backup jobs complete. Renting storage does not automatically create a backup any more than buying a suitcase automatically packs your socks.

Update and lock everything before the airport

Install operating-system, browser, password-manager, VPN, and application updates while you still have a trusted connection. Enable full-device encryption, a strong screen lock, and automatic locking after a short idle period. Turn on device-location and remote-wipe features where appropriate, and make sure you know how to use them before the phone disappears into a taxi seat.

Use unique passwords and enable multifactor authentication for email, cloud storage, banking, social media, and your hosting control panel. An authenticator app or security key is generally preferable to relying only on SMS. Keep recovery codes somewhere secure and separate from the device they recover. A screenshot named recovery-codes.png on the same phone is more of a hostage note than a recovery plan.

Take only the data and devices you need. Less stored locally means less exposed if a device is lost, searched, borrowed, or stolen. Physical security still counts: do not leave a laptop unattended at a café, airport gate, rental car, or hotel lobby while you investigate the buffet.

Public Wi-Fi is not automatically evil, but it is not your network

Modern HTTPS encrypts most web traffic, so using airport or hotel Wi-Fi is not the open-air password broadcast it was twenty years ago. The US Federal Trade Commission notes that widespread website encryption has made public Wi-Fi generally safer.

That does not make every hotspot trustworthy. Attackers can create networks with convincing names, redirect users to fake login pages, exploit outdated devices, or target traffic from applications that are misconfigured or use weak encryption. Real incidents involving credential theft and hostile hotspots exist, but the risk should be described accurately: encryption has improved, while phishing, fake portals, metadata exposure, and software mistakes have not taken a holiday.

Confirm the exact network name with airport, railway, hotel, or café staff. Disable automatic connection to open networks and forget the hotspot after use. Prefer cellular data or your own hotspot for banking and other sensitive tasks when practical. If the browser warns that a site’s certificate is invalid, stop. Do not click through because the departure board says “final call.”

Never install a root certificate, device-management profile, “security update,” or unknown application merely to obtain Wi-Fi access. A trusted root certificate can allow its operator to impersonate secure sites to your device. A legitimate captive portal may ask you to accept terms, enter a room number, or provide a voucher, but it should not require the keys to your entire TLS kingdom.

Also give captive portals the minimum personal information required. Free Wi-Fi does not need your date of birth, home address, employer, passport biography, and first pet’s philosophical beliefs. If the form feels excessive, use another connection.

Add an always-on VPN

A well-configured VPN creates an encrypted path from your device to a server you control. This protects traffic crossing the local Wi-Fi from passive inspection and reduces how much the hotspot operator can learn about individual destinations. It also protects applications that route their traffic through the tunnel instead of relying on every app to handle an untrusted network perfectly.

It is an additional layer, not magic. A VPN does not make a phishing site honest, remove malware, fix a reused password, or protect data after it leaves the VPN server. HTTPS and application security still matter.

For personal use, one or two small NVMe VDS instances in different locations can run WireGuard or another maintained VPN solution. Two endpoints provide a fallback if one location has a routing problem or the hotel network dislikes a particular path. Keep the server patched, expose only necessary ports, and route all intended device traffic through the tunnel.

Where the device supports it, enable an always-on or on-demand connection and a kill-switch-style option that prevents traffic from quietly falling back to the local network. Some public Wi-Fi requires opening a captive portal before the VPN can connect, so complete that step carefully and let the tunnel reconnect immediately afterwards.

WireGuard was designed to be lightweight and efficient. An always-on tunnel still uses some CPU, radio time, and keepalive traffic, so it would be dishonest to promise zero battery cost. On a modern phone or tablet, the overhead is usually modest compared with the display, navigation, video, and poor mobile signal. In other words, the map app searching for a mountain road will probably concern your battery more than the encrypted tunnel.

Give vacation photos a home of their own

A holiday produces photos at an impressive rate. Phones are very good at turning sunsets, meals, boarding passes, and 47 almost identical pictures of a cat into a storage emergency.

Immich is an open-source, self-hosted photo and video management platform with mobile backup, albums, search, and a web interface. It works well for personal collections and can also support serious photography archives when the infrastructure is sized properly.

Current Immich documentation calls for at least 6 GB RAM and 2 CPU cores, with 8 GB RAM and 4 cores recommended. A suitably sized NVMe VDS is therefore a sensible starting point for the application and database. Remember that thumbnail generation and video transcoding add storage and compute work. As the library grows, a dedicated server can provide more storage, predictable resources, and room for expansion.

Immich itself is not the only backup. Its database contains metadata and file paths, while the original photos and videos live in the upload library. The project’s backup documentation recommends a 3-2-1 strategy and explicitly requires copies of both the database and uploaded media. Keep another copy on separate storage, such as an HD VDS, and test restoration. Otherwise, a beautifully organised single copy remains a single copy wearing a nicer interface.

Enable mobile uploads when connected through a suitable network, but do not delete the originals from the phone until the remote copy has completed and your independent backup has caught up. “Uploaded” and “safely backed up” are related concepts, not synonyms.

A few small habits that save large headaches

Avoid posting a public, real-time announcement that your home will be empty for two weeks. Share the photo dump after returning, or limit it to people you trust. Remove precise location metadata before publishing images when it could reveal a hotel, home, child, or daily routine.

Be suspicious of urgent travel messages. Fake airline refunds, hotel payment requests, QR codes, delivery notices, and “your account will be closed” emails work especially well when a tired traveller expects disruption. Open the airline, bank, or booking application directly instead of following a surprise link.

Carry a charged power bank and use your own charging cable. Turn off Bluetooth and file-sharing features when they are not needed. Keep important booking details available offline in case connectivity fails, but avoid placing an unencrypted document full of passport and card data on the lock screen.

Finally, tell a trusted person how to reach you and what to do if your main phone or account is lost. Incident response is much easier when someone at home can help revoke a session, locate a device, or retrieve a recovery code without first asking which beach umbrella contains the system administrator.

Then enjoy the vacation

The goal of travel security is not to spend the holiday staring suspiciously at every access point. Prepare before leaving: update devices, test backups, secure accounts, configure the VPN, and decide where new photos will go. During the trip, verify networks, reject strange certificates, share less information, and keep the encrypted tunnel running.

Then put the phone down occasionally. The backup can preserve the sunset, but it cannot watch it for you.

Have a safe and excellent vacation.

Sources and further reading

Need Help?

Our support team is available 24/7 to assist you with any questions or issues.

Contact Support