← all articles

Public wifi and what the risk actually is

privacy public-wifi travel captive-portal network-security

The most revealing thing I can pull off a network I run is a text file of domain names.

Not traffic. Names. One line per lookup, with a timestamp and a device identifier beside it, and it builds itself without anybody configuring anything unusual. That file is the honest answer to what a network operator sees, and I am on the operator side of this for a living. I put SIM cards in modems and rent the lines to businesses that need traffic leaving from a particular carrier.

Customers ask what I can see, usually in their first week. Which names your device asked for, and how many bytes moved. Nothing inside any of it. A cafe is in the same position, with worse equipment.

The argument that is finished

The coffee shop attacker everybody was warned about needed your traffic readable in transit. The web encrypted itself while that warning was still circulating, and your browser now complains loudly at any site that has not. I have written that argument out in full elsewhere on this site and there is no point repeating it.

So the threat that sold a decade of subscriptions is gone. Everything below is what stayed behind, and none of it is the thing you were told to worry about.

The list, not the reading

Before your laptop can reach a site, something has to turn the name into an address. Unless you deliberately arranged otherwise, that question goes to the network you are sitting on.

Encrypted DNS is on by default in most browsers now and it closes that half. The other half is the handshake, which has historically carried the name of the server you want in the open, because the machine at the far end needs to know which site you are asking for before it can present the right certificate. That is closing too, slowly, and it depends on the site as much as on you.

What the venue ends up with is a browsing list. This device went to a bank, a health forum, four news sites and a dating app between nine and ten on Tuesday. Not one word of the contents.

Whether that bothers you is a question about the venue rather than about the technology. A conference wifi run by a vendor whose product you are evaluating is a different proposition from the cafe under your office.

There is a second record, which is your device’s address on the network. Phones randomise it per network now, and that killed the old trick of tracking one handset through every branch of a chain. It survives exactly one event. Sign into the portal with your email and you have connected that random address to a person yourself, and the chain can rejoin your visits from its own database.

The sign in page is the one legitimate interception

A captive portal works by hijacking you. Your device sends a plain request to a known address to check whether it has internet yet, the network replies with its own page instead of the expected answer, and your phone throws that page up as a notification.

That is normal, it is how every hotel has worked for fifteen years, and it has trained everybody to accept a web page appearing unprompted, on a network they met four seconds ago, served by a party they cannot identify.

Which is precisely why a fake one looks fine. There is nothing anomalous to spot. The anomaly is the thing you were taught to expect.

So the test has to be what the page asks for. A real portal wants a room number, an email, a code off a receipt, a tick on some terms. All of that is cheap to give away and mostly worthless to steal.

A real portal does not want your card number unless you are genuinely buying access, and when you are, it hands you to a payment page it does not operate. It never wants the password to another account. It never needs you to install an app or a configuration profile. If it throws a certificate warning at you, close the laptop. That one has no grey area in it.

A name is not an identity

An open wifi network has a name and nothing else. The name is text, and any radio in the room can broadcast it.

Stand up a device announcing the same name as the venue, sit where you have the stronger signal, and phones arrive. A phone chooses by name and signal strength, because it has nothing else to choose by. The password on the chalkboard does not help here, since whoever runs the fake can read the chalkboard.

Once a device is on a network you control, you answer its questions. You serve the portal. You answer the name lookups, so you decide what machine a name resolves to. You still cannot read the encrypted traffic, but you can break it and wait to see whether a tired person in a boarding queue clicks through the warning.

The part that actually changed my habits is what happens afterwards. Your phone saves the name, along with an instruction to rejoin it automatically. Not the venue. The name, anywhere on earth, indefinitely.

Mine joined a network in an airport I had never landed in, on its own, while it was still in my pocket, because eleven months earlier I had used a network with that name in a different airport in a different country. One connection in one building had turned into a standing invitation that travelled with me.

Forget the network when you leave. Two taps, and it is the highest value habit in this article.

Your laptop is also answering

This one has nothing to do with your traffic, and I have never seen it in a public wifi guide.

Plenty of these networks are flat, meaning every device on them can address every other device directly, the way machines in your house can. Your laptop makes requests on that network and it also sits there answering them. File sharing, printer discovery, media casting, remote access, screen sharing. Usually something a colleague switched on two years ago to move a folder across the office and never switched off.

At home that is convenient. On a hotel network it puts a shared folder in front of everyone in the building, including whoever is parked outside it.

This is what Windows is asking when it wants to know if a network is public or private, and it asks badly. The useful phrasing would be: should the strangers here see your shared folders. Say public. On a Mac the controls live in the sharing settings and their state depends on what you plugged in and agreed to over the last decade.

Check it tonight rather than on your next trip. One look, and then it stays fixed.

The one with the best hit rate

None of the above. It is the person behind you reading your screen.

No equipment, no skill, nothing anyone could later charge them with, and it operates on what you are actually doing rather than a list of domain names. It is the only item here where somebody leaves with contents.

I have read a stranger’s email in a departure lounge without meaning to, from two rows back, because the screen was bright and tilted up and my flight was late.

A privacy filter costs about thirty dollars and does more in an airport than anything you can install on the machine. Mostly though it is about where you sit, and a wall behind you is free.

What I had wrong about the password

For years I assumed a password on a wifi network meant the people on it could not read each other. That is wrong on the ordinary setup, and I should have worked it out sooner given what I do all day.

When everyone shares one passphrase, the session key your device negotiates comes from that passphrase plus a short exchange that happens in the clear the moment you join. Somebody who has the password and was listening when you connected can derive that key and read your wifi layer traffic. The password excludes people who do not have it. It does nothing about the forty people in the cafe who do.

The newer standard fixes this and gives every device its own key, and there is a variant that encrypts open networks with no password at all. Both are years into a slow rollout, and the icon in the corner of your screen will not tell you which one you got.

It matters less than it sounds, for the reason at the top: everything above that layer is encrypted anyway. But I had the mechanism wrong and I was giving advice built on top of it.

The order I actually do things in

Ranked, because a ranked list is more useful than a complete one.

Sit where nobody is behind you. I nearly put that last as a joke and then thought about the hit rate.

Use your own phone’s hotspot for anything involving money. Mobile data is cheap, I am in the business of it, and your own line deletes every item in this article at once instead of mitigating them one by one.

Forget the network afterwards, and turn off automatic rejoining for anything public.

Set the network to public on the laptop so it stops introducing itself to the room.

Give a portal an email address and a room number and nothing else. No card, no account password, no certificate, no download.

Leave encrypted DNS on, knowing it is half a fix.

The tool everyone expects at the top of that list is missing from it, and that is deliberate. It is the wrong shape for this problem. It takes the browsing list off the cafe and hands it to whoever runs the tunnel, so the list still exists somewhere. And it does nothing whatsoever about the twin, the portal, the shared folder, or the man behind you.

Read honestly, public wifi costs you a list of where you went, plus a small chance of a bad afternoon if you connect to something wearing a familiar name. That is worth twenty seconds of habit. It was never the thing that empties an account.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →