Public Wi-Fi Security: How to Stay Safe on Shared Networks

Person with a phone seated at a cafe table beside an open laptop and a cup of coffee


There is a specific kind of quiet risk in Nigerian business travel. You are in a hotel in Port Harcourt or Abuja, the room network is called something like Hotel_Guest_WiFi, there is a password written on a card by the kettle, and you connect because you need to answer an email about an invoice. Nothing dramatic happens. That is the problem, because the version of this that goes wrong never announces itself first. Here is what is genuinely at stake, where public wifi security advice overstates the danger, and where it understates it.

What is actually risky on a shared wireless network

Wireless traffic used to be the clearest example of a medium everybody in range can read. That is much less true than it was, and understanding why is the whole of good public wifi security advice. When you visit a site over https, the content is encrypted between your browser and that site, so an attacker in the café cannot read the page, cannot alter it and cannot see your form entries on that connection. A public wifi attack therefore cannot simply listen to everything any more.

What remains genuinely exposed falls into four groups, and they are worth separating because the security advice differs for each.

Risk What the attacker gets How much it matters The control that works
Unencrypted traffic Anything still sent over plain http, including some email and app connections Real, and the commonest genuine leak Use sites that redirect to https; install a tunnel
Fake access point, same name Whatever you send to a network you think is the hotel’s Real where network names are predictable Ask staff for the exact name; read the certificate warning
Captive portal phishing Hotel login details handed to a page that is not the hotel’s Real, and it looks ordinary Never reuse your email password on a portal
Name resolution tricks The direction of your requests, and sometimes where they go Moderate, and the basis of most redirections Https plus a tunnel, and a trusted resolver

The evil twin is the one people ask about, and it deserves a straight description. An attacker sets up a device broadcasting the same network name as the real one, often with a stronger signal, so your phone reconnects to the wrong box. The MITRE catalogue entry for the technique, adversary in the middle through a cloned network, describes the mechanics including the fake captive portal and the forged certificate, and a rogue access point is simply the general term for the unauthorised device. It works because a client cannot tell two devices broadcasting the same name apart.

Where the advice overstates the danger

Two claims are worth correcting because they push people towards expensive or pointless solutions. The first is that anybody nearby can read your browsing on https. They cannot read the content, and the encryption is strong. The second is that you need to buy something to be safe at all. If you do not open banking, you do not reuse passwords, you keep your software updated and you pause when a certificate warning appears, you are in reasonable shape without spending anything.

The reverse is also true and less widely said: a padlock does not save you from a fake login page. If a captive portal asks for your email password, typing it is exactly as dangerous as typing it into any other page, and the connection can be perfectly encrypted throughout. The FBI’s recent alert on consent phishing describes the modern version, where the user grants access to a real application and never types a password at all.

Public wifi security: the checks before you connect

One further distinction helps. A hotel’s main network and its guest network are usually different things, with the guest network deliberately isolated from the rooms and the servers behind it. That isolation is worth having and worth asking about, because on a badly configured network your laptop is directly addressable by every other guest. It is one of the few free security improvements a hotel can make, and it costs them only a switch port.

This is the part that actually reduces risk, and it takes about thirty seconds. Ask the front desk for the exact network name, and check whether it needs a password. A network called HotelWiFi is not the same as Hotel_WiFi_Free_2, and a real hotel’s network is usually written down somewhere you can read. If your phone offers to join a network you do not recognise, or you see two versions of the same name, do not connect and ask. If a browser throws a certificate warning immediately after joining, that is the signal worth trusting. A secure connection was expected and could not be established, and the honest response is to stop rather than click through.

Turn off automatic joining of remembered networks. Every device keeps a list of networks it has joined before and reconnects without asking, which is how you end up silently attached to a network called Free_Airport_WiFi that you visited once. Mozilla’s notes on the risks of public wifi make the same point in shorter form and are worth sending to staff who travel.

What to do while you are connected

Transactions and logins first, browsing later. Open the tunnel before you do anything that matters, not afterwards. Then handle the bank, the inbox, the hosting panel and the online banking security work first, while you are paying attention. The reasoning is in our explanation of VPNs, and the honest version is that a tunnel covers the tunnel and nothing else.

Keep file sharing off. Windows and Android both expose file sharing over a wireless network in some configurations, which makes your files visible to other devices on the same segment. A hotel guest network is the wrong place for that. If you need to move files between your own devices, do it over the internet rather than across the local network.

Do not accept an invitation to sign in again. A pop-up asking you to log in to a company account the moment you join a network is a classic. Close it, and if you need to reach a company system, open the application yourself. And read the certificate warning on any site you reach, because on a hostile network that warning is often the only honest thing you are shown.

Frequently asked questions

Is it safe to use free wifi for online banking in Nigeria?

It is not the right place for it, and there is no need to take the risk. Mobile data on your own line is a much better option for banking, and if you must use a hotel or café network, turn the tunnel on first and read any certificate warning. The account-side controls that matter regardless of where you are sitting are in online banking security.

How do I tell whether a wifi network is fake?

Ask, and watch the obvious tells. A network that needs no password when it needed one yesterday, a captive portal whose logo or wording is slightly wrong, two devices broadcasting the same name, and a certificate warning straight after joining are all signals. Then ask the staff. A hotel that cannot tell you its own network name is telling you something useful about the security of everything else it runs.

Should I turn off wifi on my phone when I am not using it?

On unfamiliar networks, yes, and Bluetooth is worth turning off too when it is not needed, because wireless pairing is a separate door into the same conversation. On networks you trust, with a current operating system and WPA2 or WPA3 configuration, leaving wifi on is not the risk people assume. The WPA3 standard is the current generation of wireless protection and matters far more for your own router than for the café down the road.

Does a VPN make public wifi completely safe?

No, and be sceptical of any product that says so. It closes the tunnel and hides your address, and does nothing about a captive portal that looks genuine, a phishing page, malware already on the device, or somebody reading over your shoulder in a hotel lobby. Combine it with the habits above, with a properly configured router at home and with unique passwords and multifactor authentication, and the residual risk is small.

Key Takeaways

  • Shared wireless networks are far less dangerous than they were, because https already encrypts the connection to most sites.
  • What remains real is plain http traffic, fake access points, captive portal phishing and the direction of your requests.
  • Ask staff for the exact network name, disable automatic joining, and treat any certificate warning as a reason to stop.
  • Turn the tunnel on before you open a bank or an inbox, not after. Device security and connection security are separate problems.
  • Never type an email or bank password into a hotel login page, however official it looks.
  • For banking, use your own mobile data. Good public wifi security starts with choosing not to need the network at all.

Once you are back on a network you control, the next thing worth doing is securing the router, because almost everything else depends on it.

Sources: MITRE ATT&CK description of the evil twin adversary-in-the-middle technique; public wifi networks, captive portals and the associated risks; evil twin networks and how the cloned name works; Mozilla support guidance on the risks of using public wifi; rogue access point; WPA3; FBI alert on consent phishing.

0 Comments

Your email address will not be published. Required fields are marked *