# Welcome to Your Help Desk

Powered by the People and Ready to Assist!

*Ahora disponible en Español / Castellano en* [*https://ayuda.globalsupport.link/*](https://ayuda.globalsupport.link/)

The site provides **free** resources and links to anyone in need of digital and physical support.

In addition to the online resources, members of the [Help Desk](/ask-for-help) can answer questions and provide advice on digital and physical security via chat, messaging or email channels.&#x20;

***PLEASE NOTE: THE HELP DESK TEAM IS CURRENTLY PROVIDING ALL SUPPORT PRO-BONO AND WILL RESPOND AS BEST AS POSSIBLE TO REQUESTS***

**Reach out today to discuss with a member of the** [**Help Desk**](/ask-for-help) to see what is right for you or your organization or click through the resources available online:

* [Digital Security](/digital)
* [Physical Security](/physical)
* [Psychosocial Support](broken://pages/ywHw5zUwZQ8MXPfHNqWh)

This is an evolving resource that will be updated and improved with feedback from all of you!


# Digital Security

Focused on best practices for communication and data privacy and security

## **Leveling Up Your Digital Armor!** &#x20;

Shielding Your Digital Fortresses

**Purpose:**

This digital security training is to empower human rights activists, journalists, lawyers, and other participants with the knowledge and skills necessary to protect themselves and their organizations against cyber and physical threats. By equipping participants with practical cybersecurity strategies and tools, the training aims to enhance their digital resilience and mitigate the risks of data breaches, surveillance and other forms of cyber attacks.&#x20;

**Outcome:**

* Increased awareness: Participants develop heightened awareness of cybersecurity threats and vulnerabilities.
* Enhanced security practices: Participants acquire practical skills for securing devices, communications, and sensitive information.
* Readiness for incidents: Participants will be equipped to apply acquired skills and knowledge effectively in real-life incidents scenarios.&#x20;

**Process:**

During this digital security training, participants will engage in various modules aimed at equipping them with the knowledge and skills to defend against cyberattacks. The training will commence with strategies for securing mobile devices, followed by essential best practices for maintaining cybersecurity. Additionally, they will explore methods for communicating securely with privacy and anonymity. The training will also include a threat modeling exercise, where participants will apply their knowledge and skills to different scenarios.&#x20;

**Introduction:**&#x20;

Digital security is the shield individuals and organizations use to safeguard information. In numerous situations, a failure to defend may result in physical threat.

While digital security may appear highly technical and daunting to many, it essentially relies on simple steps that are easy to understand and implement. This training serves as an introduction (or reminder) to these fundamental practices.

This training will cover the following module. But each module can be trained separately as well depending on the needs of the target community.<br>


# Keeping Your Devices and Physical Space Safe

1. Don’t Let Anyone Into Your Device
2. Your Device Can Track or ID You
3. Don’t Let Bad Apps Crash Your Party
4. Enable ‘Find My Phone’

This section will primarily address mobile devices, given their status as primary tools for communication, particularly for defenders on the move. However, the practices covered in this training are equally applicable to laptops/PCs.

1. **Don't Let Anyone Into Your Device**

Don’t give anyone easy access to your device. Doing so would provide them unfettered access to all personal and work-related information stored on your device, including contacts, emails, documents, photo gallery, communication history, and more.

| <p><strong>Suggestion:</strong> </p><ul><li><p>Here, you can encourage participants to share various methods for locking their devices.</p><ul><li>Answers to expect: FaceID, Pin, Biometrics, Pattern, Passphrase </li></ul></li><li><p>Following that, you can ask participants which device lock option they consider ideal for them and why, or you can go through each option and ask participants if they believe the option is secure.</p><ul><li>FaceID: This option lacks security as anyone could potentially coerce you into unlocking the device.</li><li>PIN: A 4-digit PIN is susceptible to easy cracking. Anyone with sufficient time to attempt 10,000 PIN combinations or access to a PIN cracking device can compromise it.</li><li>Biometrics: Similar to FaceID, biometrics can also be coerced, rendering it insecure for defenders.</li><li>Pattern: Patterns are often simple and easy to remember, making them susceptible to cracking.</li><li>Passphrase: Despite being less convenient, a passphrase stands out as the most secure option for locking devices, especially for defenders at risk of device theft or confiscation. <mark style="color:red;"><strong>\* Although this may not be the optimal choice for use in crisis situations. In such cases, having an alternative device is advisable. We will delve deeper into this topic shortly.</strong></mark></li></ul></li></ul> |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

2. **Your Device Can Track or ID You**

***Your Device Can ID You***

When you purchase a SIM card, your SIM provider will collect your personal information for registration. Each time you make a call, the cell tower retains a record of your International Mobile Equipment Identity (IMEI) and International Mobile Subscriber Identity (IMSI), which can be utilized for identification purposes in the future.

* *What is IMSI?*

IMSI stands for International Mobile Subscriber Identity, a unique identification number linked to a cell phone user. It is stored in the SIM card and contains the user's specific details.

\* Users will have to contact their service provider to know that IMSI number. IMSI number may also be found on the SIM card package users get at time of subscription.

* *What is IMEI?*

IMEI stands for International Mobile Equipment Identity, a unique identification number assigned to mobile phones and certain satellite phones.

| <p><strong>Suggestion:</strong></p><ul><li>If  participants are allowed to keep their mobile device with them during the training, you can ask them to dial \*#06# on their phone to know what their device IMEI number is.</li></ul><p>OR</p><ul><li>Android Devices: Device ‘Settings’ > ‘About Phone’ </li><li>iOS Devices: ‘Settings’ > ‘General’ > ‘About’</li></ul> |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

*How are IMSI and IMEI related?*

Once you register your SIM and start using it, both IMSI (International Mobile Subscriber Identity) and IMEI (International Mobile Equipment Identity) numbers become interconnected and registered together with a cellular tower. Therefore, if you ever feel compromised, simply changing your SIM card or phone won't suffice. It's advisable to change both your SIM card and your phone for added security.

***Your Device Can Track You***

Mobile Service Providers can locate you through Cell Tower Triangulation. The combination of your identity recorded by the cell tower using your IMEI and IMSI, and Cell Tower Triangulation, service providers can tell where you are.

*What is Cell Tower Triangulation?*

Cell Tower Triangulation is a widely used technique to determine the location of a phone or device. When a cell phone signal is detected by three or more cell towers, triangulation can be employed. By pinpointing the overlap of signals from these towers, it becomes possible to estimate the location of a cell phone based on its distance from each of the three towers.

<figure><img src="https://lh7-us.googleusercontent.com/vWGy4akgpuKhIhdKjBZ7EEtFF3FJchBhrIF_DUL6K5PHEncB3_SG0kqZr2xDIRsOWZPryy8Uu7v9KXu04wMdOylQw9b2ltEPRNpAuPYNNGgfNGzuzJREg8PDSqdAq715WOmm8srRrDj9LFIeN7eA_zgDpg=s2048" alt="" width="375"><figcaption><p>Cell Tower Triangulation</p></figcaption></figure>

| <p><strong>Suggestions:</strong> (Depending on time available for the training)</p><ul><li>Trainer can either explain what ‘Cell Tower Triangulation’ is</li></ul><p>OR</p><ul><li>The trainer can ask whether participants are familiar with how a mobile phone can assist in tracking them, or if they know the concept of cell tower triangulation.</li></ul><p>OR</p><ul><li>You can either draw a diagram illustrating how triangulation works</li></ul><p>OR</p><ul><li>Invite four participants to volunteer. Position three participants as cell towers in a formation that creates a triangle, and designate one participant as the person with the phone to stand in between the towers. Then, explain how the three towers continuously establish connections with the person's phone. Clarify that the phone's location is determined based on the time it takes for signals to return to each tower. As the person moves around, the connection between the towers persists. Once the person moves further away from the towers, the device connects to other towers, allowing for continuous tracking of the phone's location.</li></ul> |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |

| <p><strong>Absolutely Gotta!</strong></p><ul><li>If you suspect you're being tracked, consider changing both your phone and SIM card, preferably opting for unregistered ones or those not under your name, as this may help evade tracking, unless you're being physically followed.</li><li><p>When participating in a protest where involvement may pose risks, it's advisable not to bring your phone with you. Here is what you can do:</p><ul><li>If you need to communicate with your network during the protest, consider using a new phone, and ideally, refrain from using a SIM card altogether; instead, utilize WiFi networks and keep switching networks to connect. However, if you must use a SIM card, try to obtain an unregistered SIM card if possible, along with a new mobile device. Remember! Using your regular phone with a new SIM card won’t help since your device's IMEI has already been associated with your regular SIM card.</li><li>If communication with your network isn't necessary during the protest but you require a device to document it, opt for a small camera or a new mobile device. Your regular phone might continue connecting to the cell tower and register your IMEI even without a SIM card.</li></ul></li></ul> |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

3. &#x20;**Don’t Let Bad Apps Crash Your Party**

{% embed url="<https://www.youtube.com/watch?index=2&list=PL0Hcq8UCiYqkUVnpduzynZw9dpGRcqNhs&v=TbRrFWy5_t0>" %}

The first topic we discussed, "Don’t Let Anyone Into Your Device," focused on preventing external entities from accessing your device. Now, we'll delve into how to prevent entities already within your device from accessing various data and features.

| <p><strong>Suggestion:</strong> </p><p>Here, we can ask whether participants review app permissions when installing a new app or checking permissions of apps already in use. Depending on their response, you can then prompt them to elaborate on their reasons for doing so or not doing so.</p> |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|                                                                                                                                                                                                                                                                                                     |

Most people don’t have the habit of reviewing app permissions when installing or using an app. Often, apps only request permissions to access features and data that could enhance the functionality. However, there are many apps  that can be sneaky. Here are few considerations before installing an app:

* *Ask yourself, 'do I really need this app?'*
  * Having numerous apps on your device consumes storage space and can slow down your device.
  * It also implies that more apps have access to your data on the device.
* *Choose your apps wisely*
  * Mobile phones carry our lives in it. We have our family and friends, our work contacts, all our communications, memories, banking, finance, everything on them. We must choose apps with a good track record and a good user privacy policy.
  * Know who owns the app.
  * Opting for an app with a server in your country may pose potential risks, particularly if there are laws mandating app service providers to share data with the government.
  * Similarly, selecting an app with its owner closely associated with the regime you are resisting may also pose a potential risk.
  * Moreover, if the app service provider has a track record of handing over information of users, especially from civil society, to the government, there may be potential risks as well.
* *Is the app requesting excessive information?*
  * App permissions dictate what your app can do and access. Not all apps are secure, so it's crucial to review their permissions rather than granting blanket access to device features and data like the camera, microphone, location, calendar, email, contacts, etc. The real risk of app permissions lies in their potential misuse.
  * When installing an app, always scrutinize the permissions it requests. If an app seeks permissions such as device administration, access to Wi-Fi information, or personal data it doesn't need to function, refrain from installing it.
    * For example, a flashlight app's primary function is to provide light, so it makes sense for it to require access to the camera since it utilizes the camera flash for illumination. However, if the flashlight app demands access to your contacts, call logs, or photo gallery, it raises suspicion. Many of these apps behave similarly to malicious software, prioritizing access to our data.

4. &#x20;**Enable ‘Find My Phone’**

| **Reminder:** This feature only works when you phone is connected to WiFi or data |
| --------------------------------------------------------------------------------- |

This feature is typically utilized for locating your device if it's lost or misplaced. However, certain features in Find My Phone can be valuable for defenders, especially when your device is confiscated or falls into the hands of adversaries.&#x20;

Here's how you can enable Find My Phone:

* iPhone: <https://support.apple.com/en-ca/102648>
* Android: <https://support.google.com/accounts/answer/3265955?hl=en>

When your device is confiscated or in the possession of adversaries, consider the following actions based on your situation:

* Log in to android.com/find or icloud.com/find depending on what device you are using.
  * Remotely set up a device PIN number if you haven't already done so. This can delay others' access to your device.
  * Remotely erase data on your device if you have any information that could compromise your safety and the safety of your network.


# Safeguard your Conversation and Shared Secrets

1. Why do we need a secure communication tool?
2. What constitutes secure communication?
3. How to achieve Privacy and Anonymity?
4. What is Secure Data Sharing?

(This section introduces participants to the basic concept of encryption and presents them with tools for communication and options for data sharing that offer protection.)

**Secure Communication: Intro**

Secure communication is essential when two parties wish to converse without the risk of third-party interception or eavesdropping. This necessitates communication methods that are immune to such breaches of privacy.

1. &#x20;**Why do we need a secure communication tool?**

***Your Device Can Listen to You:***

* Your adversaries can potentially listen to your conversations by exploiting the built-in microphone in your phone and laptop/PC, particularly during regular insecure calls that are susceptible to interception.

***Safeguarding Privacy and Identity:***

* Secure communication tools are crucial for safeguarding privacy and identity, particularly when individuals or their contacts are at risk. By ensuring privacy and identity protection, the threat level can be reduced, enabling individuals and networks to continue their work without fear of compromise.

***Prevention of Monitoring by Authorities:***

* In situations where individuals are under constant surveillance by authorities, secure communication tools are essential for preventing access to the content of conversations, thereby maintaining privacy and confidentiality.

***Keeping Platform Service Providers Out:***

* Communication platform service providers may have access to all your conversations depending on whether the platform is encrypted or the level of encryption it provides.&#x20;
* For instance, platforms like WeChat, where the service provider has a direct tie to the regime, have exposed defenders in occupied regions like Tibet and East Turkestan to detention, arrest, and sentencing for sharing and receiving information via WeChat.

2. &#x20;**What constitutes secure communication?**

***Data security when in transit***

When selecting a communication platform, it's essential to consider whether they offer encryption and the level of protection it affords to your data during transit. There are two types of encryption:

* *What is HTTPS?*

HTTPS ensures the security of your data while it travels to its destination. Messages are encrypted in transit between the sender, service provider, and the receiver.

* *What is End-to-End Encryption?*

End-to-end encryption ensures that only the sender and receiver can view the messages. This means that only the devices involved in the communication process can encrypt and decrypt the messages. No intermediary, including the service provider, has the ability to decrypt and access the content of the messages. The end-to-end encryption provides the highest level of privacy and security.

3. &#x20;***How to achieve Privacy and Anonymity?***

Choosing the right communication tool is critical, especially for users under surveillance. Prioritize platforms that offer end-to-end encryption, ensuring only you and the recipient can access the message. Additionally, platforms offering anonymity provide an ideal level of security. It's also important to consider how the platforms handle your data, including what information they collect, how it's stored, and whether it's shared with third parties. Also to consider while selecting is who is behind the platform and who can have control over them. Additionally, for censored platforms, and for enhancing layers of security and privacy, you should use Tor or any trusted or reputable VPNs.

| <p><strong>Suggestion:</strong> (Depending on time available for the training)</p><ul><li>Include the following charts in the training presentation</li></ul><p>OR</p><ul><li>Write the charts on a flipchart before the training session,</li></ul><p>OR</p><ul><li>Ask participants to name popular communication platforms they are using, write them down on the chart, and inquire if the platform provides encryption and/or anonymity.</li></ul> |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

<mark style="color:red;">**Remember!**</mark> <mark style="color:red;"></mark><mark style="color:red;">If a platform does not provide any encryption, ignore it completely.</mark><br>

**Secure Chat**

|        <p><br></p>       |                       **Platform**                      |                         **End-to-End Encryption**                        |                                                                      **Anonymity**                                                                     |
| :----------------------: | :-----------------------------------------------------: | :----------------------------------------------------------------------: | :----------------------------------------------------------------------------------------------------------------------------------------------------: |
| <p>Signal</p><p><br></p> |             App (desktop version available)             |                                     ✔                                    | <p>Somewhat - </p><p>Although a phone no; is required to use Signal, however, you can share just your username and choose to keep your no. private</p> |
|          Element         | App (desktop version available) and browser (web) based |                                     ✔                                    |                             <p>✔</p><p>Yes, if used with an account created without phone number or email registration.</p>                            |
|            Zom           |               App and browser (web) based               |                                     ✔                                    |                                  <p>✔</p><p>Does not require phone number or personal information for registration</p>                                 |
|         Whatsapp         | App (desktop version available) and browser (web) based |                                     ✔                                    |                                                    <p>✖</p><p>Requires phone number registration</p>                                                   |
|          Convene         |                   Browser (web) based                   | <p>.✔</p><p>End-to-End Encryption encrypted while using Private Mode</p> |                                                      <p>✔</p><p>Does not require registration</p>                                                      |

**Mobile Voice Call**<br>

| <p><br></p> |                       **Platform**                      | **End-to-End Encryption** |                                                    **Anonymity**                                                   |                                                                                  **Data Storage**                                                                                 |
| :---------: | :-----------------------------------------------------: | :-----------------------: | :----------------------------------------------------------------------------------------------------------------: | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: |
|    Signal   |             App (desktop version available)             |             ✔             | <p>✔</p><p>Yes, if used with an account created without phone number or personal information for registration.</p> |                                                                             Does not collect any data                                                                             |
|   Whatsapp  | App (desktop version available) and browser (web) based |             ✔             |                                  <p>✖</p><p>Requires phone number registration</p>                                 | Does not store call logs on their server. Logs are stored locally on user devices. But metadata such as call duration, time of call, etc. are stored temporarily on their server. |
|    Viber    |             App (desktop version available)             |             ✔             |                                  <p>✖</p><p>Requires phone number registration</p>                                 | Does not store call logs on their server. Logs are stored locally on user devices. But metadata such as call duration, time of call, etc. are stored temporarily on their server. |
|    WeChat   | App (desktop version available) and browser (web) based |             ✖             |                                  <p>✖</p><p>Requires phone number registration</p>                                 |                                                      Does retain call and message data as well as user location information.                                                      |

**Video Call or Conference**<br>

| <p><br></p> |                       **Platform**                      | **End-to-End Encryption** |                                                    **Anonymity**                                                   |                                               **Data Storage**                                              |
| ----------- | :-----------------------------------------------------: | :-----------------------: | :----------------------------------------------------------------------------------------------------------------: | :---------------------------------------------------------------------------------------------------------: |
| Signal      |             App (desktop version available)             |             ✔             | <p>✔</p><p>Yes, if used with an account created without phone number or personal information for registration.</p> |                                          Does not collect any data                                          |
| Element     | App (desktop version available) and browser (web) based |             ✔             |           <p>✔</p><p>Yes, if used with an account created without phone number or email registration.</p>          | Does not store call logs but its infrastructure provider Matrix ip addresses and timestamps might be stored |
| Jitsi       | App (desktop version available) and browser (web) based |             ✔             |                <p>✔</p><p>Does not require phone number or personal information for registration</p>               |                                  Does not retain user data on its servers.                                  |
| Google Meet |               App and browser (web) based               |             ✔             |                            <p>✖</p><p>Requires phone number registration</p><p><br></p>                            |                        Google stores data but it is encrypted in-transit and at rest                        |
| Whatsapp    | App (desktop version available) and browser (web) based |             ✔             |                                  <p>✖</p><p>Requires phone number registration</p>                                 |            Based on its privacy policy, Whatsapp does not store message contents once delivered.            |

4. **What is Secure Data Sharing?**

Just as maintaining high levels of privacy and anonymity is crucial for communication, it's equally important for sharing data securely. Prioritizing platforms with end-to-end encryption should be a top consideration. Additionally, there are various methods for sharing files, depending on the context and recipients, some of which involve sharing over the internet and others that do not.

***Different methods for sharing file:***

* Local Sharing
  * When both the sender and receiver are in close proximity, it's advisable to avoid using the internet for file sharing. Instead, utilize nearby features available on the device for sharing files directly. This method eliminates the need for data to travel over potentially insecure networks, enhancing security and privacy.
    * Bluetooth
    * Near Field Communication (NFC)
    * AirDrop
    * SD Cards, External Hard Drives
* App and Browser Based File Sharing Platforms

**Secure Data Sharing Tools**<br>

| <p><br></p>                                                                                         |             Platform            | End-to-End Encryption |                                                      Anonymity                                                     |                                                   Data Storage                                                  |
| --------------------------------------------------------------------------------------------------- | :-----------------------------: | :-------------------: | :----------------------------------------------------------------------------------------------------------------: | :-------------------------------------------------------------------------------------------------------------: |
| <p>Signal</p><p>(100 MB size limit)</p>                                                             |            App based            |           ✔           | <p>✔</p><p>Yes, if used with an account created without phone number or personal information for registration.</p> |                                             Does not store call logs                                            |
| Tresorit                                                                                            |   App and browser (web) based   |           ✔           |                    <p>✔</p><p>Yes, if used with an account created without a phone number. </p>                    |          <p>Does not store user encryption keys thus Tresorit cannot access user data. </p><p><br></p>          |
| Google Drive                                                                                        |   App and browser (web) based   |           ✔           |                                  <p>✖</p><p>Requires phone number registration</p>                                 | Google has access to all data stored but not authorized users as they are all encrypted in-transit and at-rest. |
| <p>Nextcloud</p><p>(Groups can host their own nextcloud server and have more control over data.</p> |   App and browser (web) based   |           ✔           |               <p>✔</p><p>Does not require phone number or personal information for registration.</p>               |           Since it’s a self-hosted file sharing platform, it does not retain user data on its server.           |
| OnionShare                                                                                          | App (desktop version available) |           ✔           |                                                          ✔                                                         |                             Does not retain data shared through onion or user data.                             |


# You are the Best Antivirus

1. Strong Password
2. Do the 2-Step!
3. Detach from Attachments!
4. Think Before You Click!
5. Don’t Be a Phish!
6. Don’t Wait, Update!
7. Browser Security
8. Don’t Be a Hoarder
9. Don’t Share Drives
10. Be a 30-sec Detective
11. Keep Your Data Under Wraps

This section aims to introduce or remind participants of the best practices to maintain good digital security hygiene.

**Digital Security Best Practices: Intro**

Having antivirus software running on your device offers an additional layer of security; however, it's crucial to recognize that antivirus software may not always suffice, particularly in the face of zero-day attacks. Your first line of defense should always be yourself. By adhering to straightforward daily best practices, you can effectively thwart potential adversaries.&#x20;

{% embed url="<https://www.youtube.com/watch?list=PL0Hcq8UCiYqlKxhKpH_K4P1m-HFSjdu7w&v=CztQyVYiXQs>" %}
Be A Cyber Superhero! By Tibet Action Institute
{% endembed %}

1. &#x20;**Strong Password**

It's often tempting to create simple, easy-to-memorize passwords for all the platforms you need access to, simply because there are so many to remember. However, this approach can inadvertently grant adversaries and cybercriminals easy access to all your accounts.

* Avoid using passwords that can be easily guessed, such as your name, date of birth, important dates, family members' names, birthplace, etc.
* Instead, passwords should be complex and incorporate a mix of uppercase and lowercase letters, numbers, and symbols. Utilizing multiple characters makes it significantly more challenging for anyone to guess.
  * Here's an example of how to create a complex yet memorable password::
    * Construct a sentence that is easy to remember. For example: "My list of favorite activities definitely doesn't involve jogging at six in the morning!"
    * Use the initials of each word in the sentence, including capital letters, and replace words with numbers or symbols where possible. For instance: "Mlofaddij\@6itm!"
* Remembering numerous sentences for different accounts can be challenging. To simplify this process, consider using password managers like Bitwarden, which fully encrypts data, ensuring that even the creators of the tool cannot access your data. With a password manager, you only need to remember one master password to access Bitwarden, where you can securely store passwords for all your accounts.

2. &#x20;**Do the 2-Step!**

Now that you've strengthened your password, you've bolstered your account security. However, attackers may still find other avenues to gain unauthorized access. To add an extra layer of protection, consider enabling two-step authentication or verification if the platform offers this feature. Instead of relying on SMS verification, which can be intercepted, opt for a trusted authenticator app. By doing so, even if an attacker manages to crack your password, they'll still be unable to access your account without the second verification step.

* Additionally, if your device is at risk of theft or confiscation, it's essential to save backup codes. These codes will serve as a lifeline, allowing you to regain access to your account if you lose access to your authentication app.

3. &#x20;**Detach from Attachments!**

{% embed url="<https://www.youtube.com/watch?index=6&list=PL0Hcq8UCiYqn7PhgxpY2uiA4QkGVj_V1c&v=v4E1SRDmtZE>" %}
Detach from Attachments! By Tibet Action Institute
{% endembed %}

In Buddhism, Attachment is considered the root of all suffering, and this principle holds true in digital security as well. Adversaries often seek access to your systems to gain control and manipulate your devices and accounts, thereby obtaining complete access to your data. One of the most popular ways for attackers to achieve their goals is by enticing their targets to open malicious attachments.&#x20;

Most targeted attacks are socially engineered, often leveraging emails or messages on platforms like WhatsApp containing content highly relevant to you or your group. These messages exploit our interests and concerns, making them more convincing. We must know that even in high-profile compromises within the government, vulnerabilities can stem from individual mistakes made by employees, like downloading and opening a malicious attachment, despite robust cyber defense measures in place.

Malware could provide intruders with access to your network, files, camera, microphone, keyboard log, and other sensitive information as soon as you download and open it. To prevent compromise, it's crucial to detach from attachments. Instead of sending attachments, prioritize using encrypted shareable drives like Google Drive, Tresorit, etc., to securely share files with your contacts or network.&#x20;

If you receive an attachment that appears genuine, refrain from downloading and opening it immediately. Instead, verify its legitimacy with the sender through another platform before taking any further action.&#x20;

4. &#x20;**Think Before You Click!**

Sending malicious links is another tactic adversaries use to attack you. Similar to malicious attachments, adversaries may craft personalized messages or emails to entice you into clicking on these links, potentially compromising your network, personal data, or organizational information, or taking control of your device. In targeted attacks, the links displayed in the message, especially in emails, may not lead to the destinations they appear to. Here are some tips on how to handle such situations:

* Do not click on links in emails or messages unless absolutely necessary. If you feel compelled to open a link, verify its legitimacy with the sender through another platform before clicking it.
* If you're using a laptop or PC, hover your mouse over the link and check if the link that appears matches the one in the email. Be aware that adversaries often create links very similar to those of legitimate companies, organizations, or news agencies to deceive recipients. Examine the link carefully for any discrepancies. For example, if the link appears to lead to google.com, it may actually be go0gle.com or goo9le.com, or google-com.com, etc.

5. &#x20;**Don’t Be a Phish!**

{% embed url="<https://www.youtube.com/watch?index=3&list=PL0Hcq8UCiYqkUVnpduzynZw9dpGRcqNhs&v=gNRzivSBonQ>" %}
Don't Be  Phish! By Tibet Action Institute
{% endembed %}

Phishing is another tactic adversaries could employ to steal your personal information, such as passwords or bank login details. Phishing attacks can vary in scale, from targeted attempts to widespread campaigns, depending on the motive.

In such attacks, particularly when targeted, the perpetrators may impersonate individuals or groups with whom you have affiliations or whom you would naturally trust, such as partner organizations or funders. They may also pose as reputable organizations like Google or banks (names varying by region) and send emails enticing you to enter your personal information into a fake login page.

* Never enter your username and password if you receive an email or message requesting such information.&#x20;
* While organizations, banks, and email service providers may send notifications in case of a breach, attackers exploit this by attempting to deceive you. If you're unsure about the legitimacy of an email, contact the organization or bank directly to confirm its authenticity.
* Additionally, for your email and other communication platforms, enable 2-step verification as an added layer of security.

6. &#x20;**Don’t Wait, Update!**

Often, when individuals receive notices on their computers prompting them to update software with options like 'Update Now' or 'Remind Me Later,' they might opt to postpone the update due to being engaged in other tasks. However, updates not only introduce new and improved features but also crucially provide security patches for any vulnerabilities detected in previous versions.

* Opting to 'Update Now' is a simple yet powerful way to enhance online safety. This is because many malicious attacks exploit vulnerabilities found in older versions of operating systems, software, and apps.

7. &#x20;**Browser Security**

Browsers serve as the gateway to the internet, facilitating access to a wealth of information. However, they also store significant amounts of personal data, including browsing history, user credentials, and banking information. Moreover, accessing malicious sites can expose users to various threats, serving as entry points for attackers. Therefore, adopting good practices around browser security is essential to defend against potential threats. Here are a few steps you can take to ensure secure browsing:

***Choose the Right Browser:***

* Choose browsers that prioritize security. Options like Chrome, Brave, Firefox, and others are known for their focus on privacy and security features.

***Keep your Browser Up-to-Date***

* Regularly updating your browser is crucial for security. Many attacks target vulnerabilities found in older versions, so staying up-to-date helps keep attackers at bay.

***Use add-ons/extensions to enhance browser security:***

* Add-ons like uBlock Origin, NoScript, and Privacy Badger help block malicious scripts and trackers, reducing the risk of compromise while browsing.
* HTTPS Everywhere enforces HTTPS encryption whenever possible, enhancing privacy and security whenever possible and provide privacy while browsing&#x20;

***Use Incognito/Private Browser:***

* When browsing sensitive websites or conducting private activities, utilize the Incognito or Private Browsing mode available in most browsers. This mode automatically deletes browsing history and cookies when the session is closed, minimizing the risk of exposure.

***Delete Browser History:***

* Regularly clear your browsing history to remove any traces of your online activity. This helps protect your privacy and prevents unauthorized access to your browsing habits.

***Do not save personal information:***

* Avoid saving login credentials, banking details, or other sensitive information in your browser. While it may seem convenient, storing this information makes it easily accessible to anyone who gains access to your device.

8. &#x20;**Don’t Be a Hoarder**

{% embed url="<https://www.youtube.com/watch?index=1&list=PL0Hcq8UCiYqkUVnpduzynZw9dpGRcqNhs&v=xLMH4DK-Y1I>" %}
Don't be a hoarder! By Tibet Action Institute
{% endembed %}

In our fast-paced digital world, it's easy to accumulate a clutter of personal and work-related information in our digital closets. These may include emails, chat conversations, photos, and files, posing potential risks not only to ourselves but also to our families and networks, depending on the sensitivity of the content. While it's challenging to find time for digital cleanup amidst our busy schedules, dedicating a specific time annually to deep clean can be immensely beneficial. Not only does it safeguard us against future threats, but it also enhances device performance. Here are a few tips to avoid digital hoarding:

* Regularly delete sensitive communications or chats from both ends once the conversation is concluded.
* Delete media and other files promptly after use if they serve no further purpose.

9. &#x20; **Don’t Share Drives**

Thumb drives may seem like relics to many, but external storage devices remain crucial for data backup and offline storage. However, it's important to exercise caution when using these drives. Avoid sharing or connecting them to devices that are not your own. If the other device is compromised, it could pose a risk to the data stored on your drive as well as your laptop or PC.

* Use file sharing platforms such as Google Drive, Tresorit, or similar services to securely share drives online.
* If online sharing is not feasible, consider using features like AirDrop, Bluetooth, or other nearby sharing options to transfer data securely between devices.

10. &#x20;**Be a 30-sec Detective**

In the realm of digital communication, much like a traditional letter, an email bears crucial information about its origin and destination. Even when the sender is familiar, it's imperative to verify the authenticity of emails containing links or attachments. Dedicate at least 30 seconds to scrutinize for potential red flags, including:

* Spelling discrepancies in the sender's name (e.g., "Callvin" instead of "Calvin").
* Recognizable senders using unfamiliar domains (e.g., "<calvin@yahoo.com>" or “<calvin@gmaiil.com>” instead of "<calvin@gmail.com>") can be a red flag for potential phishing attempts.
* Presence of links or attachments within the email.
* Generic or impersonal content in the email body.

By remaining vigilant and identifying these warning signs, you can safeguard yourself against potential phishing attempts or fraudulent activity.

11. &#x20;**Keep Your Data Under Wraps**

If you reside in an area with significant censorship and surveillance, if you're under active monitoring, incorporating Tor or trusted or reputable VPNs into your digital security practices whenever feasible is crucial. This is especially important when transmitting or accessing sensitive information.

* VPN - a trusted or good VPN will provide:
  * **Privacy**
  * Accessibility&#x20;
  * Security
  * Ex.:Psiphon, Lantern
* Tor provides:
  * **Privacy**
  * Accessibility
  * Security
  * **Anonymity**
  * Ex.: Tor browser, Orbot<br>


# Better Living through Threat Modeling!

| <p><strong>Explanation:</strong> </p><p>Normally, we conduct threat modeling training at the beginning, allowing participants to continuously update their Assets, Risks, Vulnerabilities, and Mitigation as they recognize them throughout the training. This approach is suitable for 2-3 day training sessions. However, for shorter sessions, we've found that conducting threat modeling at the end, after participants have comprehended all the mitigation steps, proves to be more effective.</p> |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

As we explore digital security practices to safeguard against potential cyber threats, it's essential to recognize that cybersecurity is highly individualized. What may work for one person may not be effective for others, given their unique circumstances. Factors such as personal objectives, associated risks, and mitigation strategies all come into play.

In the ever-evolving landscape of digital security, continual updates and adaptability are crucial. To facilitate this understanding, we'll delve into a condensed version of the Threat Modeling exercise. This exercise serves as a valuable framework for evaluating risks and implementing protective measures.

**Instruction:**

* Divide the participants into 3 groups and assign each group a scenario. Add more scenarios (and groups) based on the number of participants or regional needs and experiences.
* During the exercise, each group will address their assigned scenario and work together to devise solutions based on the content covered in modules 1, 2, and 3. Participants are also encouraged to draw from their own experiences and include additional solutions not covered in the modules. Real-life experiences should be taken into consideration when formulating solutions. The answers to the following questions will lay the groundwork for their individual threat models, shaping their approach to digital security:
  * What assets do I/we aim to protect?
  * Who poses potential threats to these assets?
  * What are the consequences of a security breach?
  * How likely is it that I/we will need to protect these assets?
  * What steps would I/we and I/our colleagues take to protect these assets?

**Suggestion:**

The scenarios for this exercise can be based on the real-life experiences and insights of the participants and their region. Drawing from actual scenarios will help generate more authentic mitigation strategies.

***Scenario 1:***

You and your team of defenders are organizing a significant public event in five months to protest a government policy that undermines basic human rights. Anticipating the government's relentless efforts to impede your organization of this event, heightened vigilance and strategic planning are imperative.

In a week, you have your inaugural meeting with the entire organizing team, comprising defenders and partners with varying risk levels - low, medium, and high. During this session, you'll discuss confidential information and make pivotal decisions regarding event planning and your team of organizers will have to continue communication for the next five months.

***Scenario 2:***

It's already been 5 months, and there are only two days left until the big event. Congratulations on making it this far! Despite facing intimidation from the authorities over the past five months, you and your team have persevered. However, there's concerning news: word has spread that the government plans to bring in police forces from neighboring states or provinces as backup and intends to crack down on the event. As an organizer participating in the event, there's a high likelihood of being arrested either before or during the event.

***Scenario 3:***

You are collaborating with a highly targeted community in \[Name of Remote Region], which is resisting mining supported by the local government. The local authority and the mining company persistently intimidate community leaders and threaten to harm or arrest them if they're discovered scheming against the government.

Your role involves assisting the community in collecting all evidence related to the mining operation, which could include proof of corruption, pollution, adverse effects on the health and well-being of the local population and wildlife, and other pertinent issues. However, you're only able to visit the region once every three months, and most of your communication with the community occurs via your mobile phone.


# Physical Security

Best Practices for Safety & Security

As Human Rights Defenders, we can sometimes find ourselves at our most vulnerable: traveling in unfamiliar terrain and potentially meeting new people or doing things we wouldn't otherwise do.&#x20;

In this section, you'll discover some ways to anticipate security risks as well as measures you can put in place to prevent or respond to them.&#x20;

Remember, every context has its specific dangers and every person has their specific vulnerabilities - only by identifying both of these aspects, can we determine the security risks.


# Analyzing Risk

What risks do you face in your work?

One of the best ways to identify threats and your personal vulnerabilities is to conduct a risk analysis.

A risk analysis does not have to be a long, drawn-out process. A rapid-style risk analysis can be completed relatively quickly to identify threats that you could be vulnerable to due to your individual profile and/or the activities that you will be conducting. Below is a template for a rapid risk analysis that you can do on your own or with your colleagues.

| Rapid Risk Analysis                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Relevant context information: What do you need to know about the environment? The best resources are local contacts or partners, but you can also use websites such as [U.S. State Department Travel website](https://travel.state.gov/content/travel/en/international-travel/International-Travel-Country-Information-Pages.html) if you'll be traveling to a new area. | <p>Q<em>uestions to consider:</em></p><ul><li><em>Are there upcoming elections in the area, i.e. could demonstrations or marches be planned?</em></li><li><em>What are common crimes (pick-pocketing, sexual harassment)?</em></li><li><em>How is the rule of law and law enforcement capability?</em></li><li><em>Are medical facilities widely available?</em></li><li><em>What are the road conditions?</em></li><li><em>Is the area prone to natural disasters?</em></li><li><em>Is there any political repression?</em></li><li><em>What are the laws regarding LGBTQ+ rights?</em></li><li><em>Can you rely on local media or social media for news? Is misinformation common?</em></li></ul> |
| Are there any specific risks due to your individual profile?                                                                                                                                                                                                                                                                                                             | *What makes you vulnerable to any of the contextual threats that you just identified? An example could be that you are at higher risk of sexual harassment due to the high rates in country and being a female traveler.*                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Are there any specific risks related to the activities you'll be conducting or your organisation's image/reputation?                                                                                                                                                                                                                                                     | *Does the nature of your work or the organization that you work for put you at additional risk? An example could be that you are at a higher risk of surveillance due to the fact that you are an LGBTQ+ activist in a country where it is criminalized.*                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| What specific security measures can you put in place?                                                                                                                                                                                                                                                                                                                    | <p><em>Based on the risks that you identified, what measures can you put in place to mitigate the risk? Some examples could be:</em></p><ul><li><em>No walking alone.</em></li><li><em>Be back at the hotel at 22:00.</em></li><li><em>No use of public transportation.</em></li><li><em>Use of code names.</em></li></ul>                                                                                                                                                                                                                                                                                                                                                                          |


# A Safe Trip: It's All in the Preparation

What to document and establish prior to traveling

### Key Contacts & Locations

It is important to gather as much information as possible regarding the places and people you'll be visiting prior to travel. Below is a template for listing the contacts and locations. It is important to share the following information with family or colleagues before you travel. Try to be as specific as possible and include screenshots of relevant maps, such as from the airport to the hotel, as much as you can. This is one of the ways that others can try to locate you if you are in trouble or not checking in. It also may be useful to share your agenda with contacts back home.

| Destination Country                                                    | <p><br></p> |
| ---------------------------------------------------------------------- | ----------- |
| Destination Cities                                                     | <p><br></p> |
| Dates                                                                  | <p><br></p> |
| Fellow Travellers                                                      | <p><br></p> |
| Security/head office backstop                                          | <p><br></p> |
| Flight information (airline, flight number, departure & arrival times) | <p><br></p> |
|                                                                        |             |

| Local Contact/Partner Information |             |
| --------------------------------- | ----------- |
| Name & organization               | <p><br></p> |
| Phone                             | <p><br></p> |
| Email                             | <p><br></p> |

| Accommodation Information |             |
| ------------------------- | ----------- |
| Hotel/residence           | <p><br></p> |
| Phone                     | <p><br></p> |
| Email                     | <p><br></p> |
| Address/GPS               | <p><br></p> |

| Office / Meeting Location Information |             |
| ------------------------------------- | ----------- |
| Venue                                 | <p><br></p> |
| Phone                                 | <p><br></p> |
| Email                                 | <p><br></p> |
| Address/GPS                           | <p><br></p> |

### Pre-Travel Administrative & Logistic Checklist

In addition to listing out the contacts and locations, it can be useful to keep a checklist to ensure that you’ve covered all of the logistical and administrative aspects of the trip. It is especially important to establish a regular check-in procedure with someone back home (either a family member or colleague). This can be as simple as establishing that you’ll send a Signal message that you’re okay every day at 17:00. Below is a template that can help you ensure you have everything prepared prior to your trip.

| Provide specifics or additional information as necessary |                                                                                                                                                                                                                                                        |
| -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ☐                                                        | <p>What is your "official story?" You may not be able to be upfront about what you are doing in country. Make sure that you have a solid story (that you’ll be able to remember easily) and that you’ve shared it with your colleagues.</p><p><br></p> |
| ☐                                                        | <p>Visa</p><p><br></p>                                                                                                                                                                                                                                 |
| ☐                                                        | <p>Pre-departure security briefing with a local partner or contact</p><p><br></p>                                                                                                                                                                      |
| ☐                                                        | <p>Communications / check-in procedure established with head office or family member </p><p><br></p>                                                                                                                                                   |
| ☐                                                        | <p>Signal group created with travelers and security/head office backstop</p><p><br></p>                                                                                                                                                                |
| ☐                                                        | <p>Emergency cash available or bank card approved for international use</p><p><br></p>                                                                                                                                                                 |
| ☐                                                        | <p>Airport pick-up arranged</p><p><br></p>                                                                                                                                                                                                             |
| ☐                                                        | <p>Nearest medical facilities identified</p><p><br></p>                                                                                                                                                                                                |
| ☐                                                        | <p>Insurance coverage (health, medical evacuation, etc.)</p><p><br></p>                                                                                                                                                                                |
| ☐                                                        | <p>Decision on visibility/profile - will you be low-profile or can you be open about what you and/or your organisation are doing in country?</p><p><br></p>                                                                                            |

### When travelling, don't forget to...

* Register with your embassy or consulate before travel. It is possible to due this online for several nationalities.
* Keep your home office backstop informed of daily plans utilizing your Signal group.
* Pre-program emergency numbers into your phone, and keep a separate emergency contact list in case your phone is stolen or lost.
* Learn key words or phrases in the local language to signal for help.
* Maintain a low profile; dress and behave appropriately and be considerate of local customs.
* Avoid political discussions, and respect cultural sensitivities.
* Get enough sleep, manage stress, and avoid abusing drugs or alcohol in order to respond appropriately during a potential or actual safety or security incident.
* Choose airlines with [IATA certification](https://www.iata.org/en/about/members/airline-list/).
* Only take licensed taxis or Ubers and always settle on the fare BEFORE beginning the trip. Have the destination address written in the local language to show the driver if necessary. When in the vehicle, ensure that all doors and windows can be securely closed and locked.
* Stay calm in all situations; be non-provocative when confronted with actual or potential hostile situations.
* Learn to recognize signs of threats and be conscious of escape routes.
* Maintain constant situational awareness of surroundings and broader operational context. Stay alert, and listen to people’s advice.


# Device Security: Preparing for Theft, Loss or Confiscation

Straightforward steps you can take to protect your mobile devices

Whether crossing an international border or checkpoint, attending a demonstration, or walking around an unfamiliar city, our devices, especially our mobile phones, are always at risk of being stolen, misplaced or confiscated.&#x20;

Before traveling or attending an event that could lead to your detention or arrest, back up as much as possible from your devices to cloud storage or your organization’s server, including passwords, messaging conversations, and documents.

**Documents & Files**

* Delete any sensitive files from the device or move them to an encrypted volume.
* Clear all content from Downloads, Pictures, Music and Video folders.
* Empty the recycle bin.

**Encryption Software & Messaging**&#x20;

* Uninstall encryption software, and only reinstall once destination is reached.
* Once conversations are backed up, you should log out of and uninstall any sensitive messaging applications.
* If you need to keep a messaging application for communication purposes, set disappearing messages for as short a time as possible.
* Delete any email applications and rely on webmail as much as possible.

**Web Browsers**

* Log out of all websites and services.
* Clear temporary internet files and browsing history.

**Virtual Private Networks (VPN)**

* VPN logs and profiles should be cleared.

**Windows Temporary Files and Caches**

* Click on Start, and then type ‘Disk Clean-up’ into the search Programs and Files Bar.
* Choose Drive C: from the drop down list and press OK.
* Tick all options in the ‘Files to Delete’ box and press OK.


# Hotel Security

How to stay safe where you're staying

It is important to ensure you feel safe in the place that you’ll be staying. Take the time to conduct the following security assessment upon arrival in a new place:&#x20;

* Check the room’s access points (doors, windows, fire exits).
* Examine the room, including cabinets, bathrooms, beds, and window areas for anything that appears suspicious.
* Make sure the telephone is working properly by calling the front desk.
* Make sure colleagues have the hotel location, room number and telephone number.
* Note the evacuation route in case of fire or emergency, and use the stairways at least once to become familiar with them.<br>

Keep in mind the following best practices when staying in a hotel:

* Always secure doors when inside the room with locks and security chains.
* Keep room curtains closed when it is dark outside.
* Don’t open the door to visitors (including hotel staff) unless it is possible to positively identify them. Use the peephole or call the front desk for verification.
* If available, use the hotel’s safe deposit boxes to store cash, credit cards, passport, and any other valuables. Don’t leave valuables or sensitive documents in the room.
* Carry a copy of your passport and visa and leave the originals in the hotel or the office. Additionally, keep a copy of your passport back home.<br>

### Hotel Safety & Security Assessment

Below is a checklist that can help you remember what to look for when checking into a new hotel or evaluating one prior to reserving a room. While not all items on this list are always necessary or available, it is important to try to check as many boxes as possible. It could be a red flag if you notice that the hotel has very few protective security measures in place, and therefore important to address with your colleagues or line manager.&#x20;

Fire Safety

☐ Fire emergency plan/map

☐ Smoke detectors

☐ Sprinklers

☐ Emergency exit doors

☐ Fire alarm system

☐ Fire extinguishers

☐ Emergency stairwells

☐ Multiple exits/entrances<br>

Security systems and equipment

☐ CCTV surveillance system

☐ Controlled parking

☐ Key/badge controlled access

Environment

☐ Major road access

☐ Barriers/fencing/gates

☐ Sufficient standoff distance (from perimeter to hotel)

☐ No nearby government/military buildings

☐ Low crime area

Lighting

☐ Emergency lighting in public areas and evacuation stairwells

☐ Lighted parking areas

☐ Lighted premises and grounds<br>

Profile

☐ Low profile hotel, unlikely to be targeted

☐ Not heavily frequented by international travellers, e.g. NGO workers, tourists, etc. (In some areas, higher-end, Western-chain hotels with many tourists or foreigners present could be targeted by extremist groups. However, these hotels often have very good protective security measures. This is one of the reasons why it is so important to conduct a Rapid Risk Analysis prior to travel or booking a hotel. It is vital to weigh the risks based on the context.)<br>

Guarding

☐ Onsite security staff 24 hours/day

☐ Security patrols

☐ Supervised access to public entrances/exits

☐ Staffed command centre

☐ Armed guards (only advisable in certain contexts, otherwise it may draw more attention and create more risk for the traveller)

Health Safety

☐ First aid/trauma kits

☐ AED equipment<br>

Guest Room&#x20;

☐ Deadbolt locks

☐ Door chain/wishbone latch

☐ Peepholes

☐ Safety exit maps

☐ Window bars/locks

☐ Safe

☐ Wi-Fi/Internet access


# Tips to Mitigate Common Risks

What to do in the event of...

### Surveillance & Counter-surveillance

Your movements or activities could be physically monitored by a hostile individual or group in order to determine your vulnerabilities and/or plan an attack. Some signs that you’re under physical surveillance could include:

* Strangers asking intrusive questions about your colleagues or work
* Seeing the same stranger in several different places
* A suspicious number of calls from people claiming to have reached a wrong number
* Being followed, either on foot or in a vehicle
* New or unusual vendors, beggars, loiterers, etc., around your home or office

Observing the following precautions may increase safety:

* Avoid predictable routines such as jogging or shopping at the same time every day, especially when alone
* Travel with others and in groups, and with trusted local partners to the extent possible
* Change routes and travel times regularly
* Use different vehicles if possible, and alter routes, times, and sequences – sharing information on a “need to know” basis
* Avoid attracting attention to yourself: do not wear expensive watches or jewellery or show large quantities of cash; dress modestly; do not talk on the phone or wear headphones while walking in public
* If you feel that you are under surveillance, proceed to a secure, well-lit location where others are present and seek assistance.

### Sexual Harassment

Sexual harassment is not limited to women – men and women, of all ages, ethnicity and economic groups are at risk. However, certain aspects of your individual profile, such as gender identity, sexual orientation or ethnicity can make you more vulnerable to sexual harassment. Sexual harassment and assault are under-reported; victims are often targeted in advance and the assailant is often a known acquaintance. It is **never** your fault if you are sexually harassed. Observing the following precautions may increase safety, but are not foolproof and, ultimate responsible always lies with the perpetrator:

* Listen to instincts - if something does not feel right, leave the situation as quickly as possible.
* Personal boundaries (privacy, personal space, etc.) are different everywhere. Ask about, and follow, local cues.
* Dress appropriately, with respect for the local culture.
* When staying at a hotel, try to receive any guests in the lobby or in a neutral area, not your hotel room.
* Keep personal information private. Do not disclose personal information such as hotel name, address, or cell phone number. Offer to take the person’s contact information rather than providing your own.
* Always report any suspicious or threatening behavior to your organisation or someone you feel safe with.

### Civil Unrest

Civil unrest can occur for a variety of reasons, most of which are related to social or political issues. Countries undergoing widespread political upheaval may experience sustained bouts of politically motivated unrest ranging from small, unorganized rallies to large-scale demonstrations and rioting, any of which can turn violent with little to no warning. While it is rare for visitors to be directly targeted during incidents of unrest, observing the following precautions may increase safety:

* Monitor local and international news.
* Familiarize yourself with local conditions. Ascertain whether there have been recent incidents of unrest, and if so, their cause, severity and how the authorities responded.
* Avoid areas where demonstrations are taking place or stay indoors until it becomes clear that the situation has stabilized.
* Leave the area and find an alternate route to the intended destination if you find yourself near an area of unrest.
* Do not travel alone to areas where there is a strong likelihood of demonstrations.

If you find yourself in crowd:

* Keep close to, and maintain visual contact with the person you are with.
* Avoid any situation where police or security forces are actively engaged with demonstrators. Authorities in some countries do not tolerate dissent and may use excessive force in an effort to quell unrest.
* Keep calm, as crowds are likely to dissipate in a short period of time.
* Keep to the edge of the crowd, and stay away from leaders and agitators. Try to avoid being identified as one of the demonstrators.
* Create space in a crowd by grasping wrists and bracing elbows away. Bending over slightly will allow breathing room.
* Stay clear of glass shop fronts, and move with the flow of the crowd.
* If pushed to the ground, try to get against a wall, roll into a tight ball and protect head with hands until the crowd dissipates.
* Break away and seek refuge in a nearby building at the first opportunity. Alternatively, find a suitable doorway or alley and remain there until the crowd passes.
* Avoid drawing attention. When leaving the area of a demonstration, walk away slowly and avoid the temptation to run.
* If shooting breaks out, try to find cover.
* If arrested by security forces, do not resist.

### Public Transportation

The high density of people using public transportation creates ideal conditions for criminal conduct as it increases the number of potential victims and provides anonymity to the perpetrator. Common incidents may include petty crime such as theft or pick- pocketing, or more serious incidents such as kidnapping. Observing the following precautions may increase safety:

* Never hitchhike or accept a ride from strangers
* Avoid traveling alone
* Have the proper token or change ready when approaching the ticket booth or machine
* Be mindful of pickpockets and thieves while waiting for transportation
* Wait for the bus or train in well-lit, designated waiting areas, particularly during off-peak hours
* Leave any public transportation that feels uncomfortable or threatening.
* After getting off, check to be sure no one is following.
* Avoid traveling by bus or train at night. If this is unavoidable:
  * Avoid empty buses or train cars
  * Sit near the driver on buses or in the middle car with other passengers on trains
  * Sit by a window or near doors, which allow for a quick exit in the event of an accident

### Walking

* Use well-travelled and well-lit routes and seek advice on local areas considered safe for walking.
* Check a local street map or Google Maps before leaving.
* Avoid walking alone or at night.
* Walk with confidence, but stay alert to potential problems.
* Do not wear headphones, which can reduce situational awareness and might indicate wealth.
* Avoid walking too close to bushes, dark doorways, and other places where criminals might hide.
* Be aware of jostling in crowded areas. Divide money and credit cards between two or three pockets or bags, as pickpockets often work in pairs and use distraction as their basic ploy.
* Keep backpack or purse close to the body to prevent snatch-and-run theft. Don’t carry valuables in these bags; instead, leave valuables in a secure place.
* Carry only a small amount of money and a cheap watch to hand over if threatened.
* If a driver pulls alongside to ask for directions, don’t approach the vehicle.
* If someone seems suspicious, cross the street or change directions to get away from the person. If necessary, cross the street several times. If the person is following or becomes a threat, use whatever means necessary to attract another bystander’s attention. Yelling “Fire!” often attracts more attention than yelling “Help!” Remember, it is better to be embarrassed for being overcautious than be a victim of crime.

### Theft or Intimidation

* Do not try to intimidate the assailant or be aggressive. Instead, be polite, open, and confident; try not to show anger or fear.
* Speak calmly and clearly.
* Keep hands visible, and move slowly with precise gestures.
* Respond to requests, but don’t offer more than what is requested.
* If in a group, do not talk more than is necessary, particularly in a language the assailants do not understand.
* Report the incident to your organisation or the authorities as soon as possible.
* Life cannot be replaced, never risk life to protect property or money.


# Border Crossing Best Practices

Protecting Your Devices, Data and Self In Liminal Legal Zones

***

*While some of the advice below is US-specific, it can also be helpful and relevant in any other border crossing situation.*

1. **Create a "Check-In Circle" Group**
   * **INVITE**: Invite at least two people, a friend and family member, who are available to support you, to a dedicated group chat to monitor your travel
   * **CHECK-IN:** When you land, before immigration, let them know where you are, and that you will check-in again in 1-3 hours. Confirm receipt, and wait.
   * **ACTIVATE:** If no response after 3 hours, support circle should activate response to legal and other community resources
2. **Minimize the Data You Carry Across the Border**
   * **LEAVE**: Leave unnecessary devices at home.
   * **BURNER**: Use a temporary device or travel-specific accounts.
   * **PRINT**: Use paper to keep important information like contact phone numbers and travel documents&#x20;
3. **Use Encryption to Protect Your Devices and Data**
   * **ENCRYPT**: Enable **full-disk encryption** on your laptop and phone.
   * **PASSWORD**: Choose **strong passwords** instead of fingerprint or face ID authentication, as biometric data may not be legally protected.
   * **POWER-OFF**: Power off your devices before reaching the border to **reset security protections**.
4. **Avoid Implicit Consent to Searches**
   * **CLARIFY**: If border agents ask for access, **clarify whether it is a request or an order**.
   * **DECLINE**: If it is a request, politely decline.
   * **PROTEST**: If ordered, consider stating that you are complying under protest.
5. **Secure Your Social Media and Online Accounts**
   * **LOGOUT**: Log out of accounts before crossing the border.
   * **REMOVE**: Consider uninstalling sensitive apps or removing saved login credentials.
   * **DEACTIVATE**: Temporarily **deactivate social media profiles** or adjust privacy settings to restrict access.
6. **Know Your Rights and the Risks of Refusal**
   * **SEIZED**: U.S. citizens **cannot be denied entry** but may have their devices seized.
   * **DENIED**: Non-citizens **can be denied entry** if they refuse to comply.
   * **DEPORTED:** Lawful permanent residents and non-citizens alike face potential complications regarding their status.
7. **Use Strong Passwords and Avoid Biometric Authentication**
   * **STRENGTH**: A **complex password** is more secure than a fingerprint or face ID.
   * **PROTECT**: Some courts have ruled that **passwords are protected under the Fifth Amendment**, but fingerprints or other biometrics are not.
8. **Back Up Your Data Before Traveling**
   * **BACKUP**: Have an **encrypted backup** stored at home or in a secure cloud.
   * **LOSS:** If your device is seized, you won’t lose valuable information.
9. **Document Rights Violations**
   * **DETAIL**: write down the details as soon as possible.
   * **IDENTIFY**: Note officers’ badge numbers and names.
   * **COMPLAIN**: Consider filing a complaint with a legal advocacy group.
10. **Stay Calm, Be Respectful, and Do Not Lie**

* **TRUTH:** Lying to a federal agent is a crime.
* **CALM: Do not physically interfere** with agents’ searches.
* **COMPOSED**: Remain composed and **strategically decide whether to comply or refuse**.

\
**Read and review more from these sources:**

* EFF Digital Privacy at the U.S. Border: Protecting the Data On Your Devices: <https://www.eff.org/wp/digital-privacy-us-border-2017>
* EFF Border Search Pocket Guide: <https://www.eff.org/document/eff-border-search-pocket-guide>
* Device Security: Preparing for Theft, Loss or Confiscation: <https://guide.globalsupport.link/physical/device-security-preparing-for-theft-loss-or-confiscation><br>
* A Safe Trip: It's All in the Preparation: <https://guide.globalsupport.link/physical/a-safe-trip-its-all-in-the-preparation><br>

<br>


# About Us

We are people dedicated to supporting communities and individuals who face heightened digital threats due to their activism, journalism, or civil society engagement.

By combining deep expertise in cybersecurity with a commitment to equitable access to knowledge and safety, we develop and share practical tools, resources, and training to strengthen digital resilience.&#x20;

Grounded in open-source principles, end-to-end encryption, and collaborative design, we work globally to empower people in high-risk environments with the technology and support they need to communicate securely and navigate the digital world safely.


# Ask for Help!

All the ways you can reach out to ask for help

**This service is currently being operated pro-bono.** Currently, we can provide limited advice and technical support on topics related to digital security, and in some cases we may refer you to a regional partner or organisation that is better placed to assist.

You can contact us using the following chanels:

* Email: <help@globalsupport.link>
* Signal or WhatsApp: [+447886176827](https://wa.me/+447886176827)
* Telegram: [@GlobalSupportLink\_bot](<https://t.me/GlobalSupportLink_bot >)
* Send SMS via: +12494682242
* Use [RelaySMS](https://relay.smswithoutborders.com/) to send email to <help@globalsupport.link> via secure SMS gateway

**OUR PARTNER HELP DESKS REMAIN FULLY ACTIVE AND CAN BE CONTACTED THROUGH THE INFORMATION BELOW:**

The [Miaan help desk](https://miaan.org/) can be reached through the contact channels below:

* Email[^1]: <helpdesk@miaan.org>
* Signal or WhatsApp: +46 766 860 503
* Telegram: @miaan\_helpline\_bot

\
The [Article 19 help desk](https://www.article19.org/) can be reached through the contact channels below:

* Email: <Escalations@article19.org>
* Signal, WhatsApp or Telegram: +44 73 4000 1385

*This help desk is powered by* [*free, open-source, secure and audited software*](https://digiresilience.org/solutions/link/)*, and hosted in a privacy-focused, environmentally concerned, and physically controlled* [*datacenter*](https://greenhost.net/)*.*

[^1]:


# Eyewitness Reports

Learn how to safely, securely document and share visual evidence

### Situations for Help

During emergencies and crisis moments of many kinds, documenting and sharing verifiably "real" visual evidence can be critical in providing relief and support for those impacted.

### Share Reports

You can share photos and video captured with Proofmode (or other camera apps) through our secure help desk system.&#x20;

You can send attachments or messages via Telegram, Signal, WhatsApp, and Email using the contact info on our [Ask for Help page](/ask-for-help) and show below:

* Email: <help@globalsupport.link>​
* Signal or WhatsApp: [+447886176827](https://wa.me/+447886176827)​
* Telegram: [@GlobalSupportLink\_bot](https://t.me/GlobalSupportLink_bot)​
* **No Internet?**
  * Send SMS via: +12494682242 ([send text](sms:+12494682242))
  * Leave a voicemail at: +254208780067 ([leave voicemail](tel:+254208780067))
  * Use [RelaySMS](https://relay.smswithoutborders.com/) to send email to <help@globalsupport.link> via secure SMS gateway

### How to Install and use Proofmode

[Proofmode Capture](https://proofmode.org/install) is a camera app for smartphones that supports the Coalition for Content Provenance and Authentication (C2PA) standard.

{% embed url="<https://www.youtube.com/watch?embeds_referring_euri=https://proofmode.org/&list=PL4-CVUWabKWdOinhL2O08QvLpor_ZmSjC&source_ve_path=MjM4NTE&v=Z3VxsLp1GLk>" %}

Learn more about how to use Proofmode to capture and share evidence at: <https://proofmode.org/help>


