You have heard the warning a hundred times. Never check your bank account on coffee shop Wi-Fi. Somebody two tables over is quietly reading everything you type. For a long stretch of internet history, that warning was completely fair. A lot of web traffic used to travel in plain readable text, and a person on the same network with free software really could pull passwords and emails out of the air.
That is not the internet we use anymore. The honest answer today is more boring than the warning, and more useful: public Wi-Fi is mostly fine, and the things that can still hurt you on it are not the things the old advice talks about. A scary rule that is out of date teaches you to worry about the wrong thing. Here is what changed, what did not, and when we still tell folks to skip the free network and use their phone.
What Actually Changed
Encryption went from optional to standard. When you visit a site today, the connection between your device and that site is almost always scrambled, so anyone sitting in the middle sees noise instead of content. The Federal Trade Commission’s consumer guidance on public Wi-Fi puts it plainly: most websites do use encryption to protect your information, and because encryption is now so widespread, connecting through a public Wi-Fi network is usually safe.
You can check this yourself in about a second. The FTC advice is to look for a lock symbol or “https” in the address bar to the left of the website address, and it notes this works on a mobile browser too. Apps are harder to inspect because there is no address bar, but the FTC says the majority of mobile apps use encryption as well.
One limit is worth understanding, because it explains most of what follows. The same FTC guidance points out that encryption protects your information on its way to the site, but it does not protect you from scammers who are operating the site. A fake website can have a perfect lock icon. The lock tells you nobody read your data in transit. It does not tell you that you sent it to the right people.
The Threat That Still Works: A Network With a Familiar Name
Anyone can name a Wi-Fi network anything. That is the whole trick. Someone sets up a hotspot in an airport terminal and calls it “Airport Free WiFi,” or broadcasts a name one character off from the hotel’s real one. Your phone joins because the name looks right, and now a stranger controls what your device sees.
The Federal Communications Commission’s consumer guidance on wireless connections gives the fix, and it is refreshingly low tech. Check the validity of available Wi-Fi hotspots, and if more than one hotspot appears claiming to belong to the establishment you are in, check with the staff to avoid connecting to an imposter hotspot. Ask the barista. Ask the front desk. They know their network name.
Two habits shrink this risk to almost nothing. Turn off the setting that automatically joins open networks. And when you leave, tell your device to forget that network so it stops looking for a name a stranger can imitate later.
The Sign-In Screen Is Where It Gets Weird
Most public networks push you to a sign-in page before they let you online. That page is normal. What it asks for is the part to watch, because a hostile hotspot controls that page completely, and it is the easiest place to ask you for something you should never hand over.
- Anything asking you to install software. A certificate, a “network security tool,” a helper app. No coffee shop, hotel, or airport needs you to install anything to browse the web. Close it and use your phone’s data instead.
- Anything asking for an account password. If the Wi-Fi page wants your email password, your Google or Apple password, or your bank login, that is not Wi-Fi. It is a phishing page wearing a Wi-Fi costume.
- Anything asking for card details on a free network. Paid airport and hotel Wi-Fi is real, but make sure you are buying access from the actual provider and not typing a card number into a stranger’s form.
- What is fine. Accepting terms, tapping in a room number, entering an email address you do not mind sharing, or sitting through a short ad. Annoying, not dangerous.
The Person Behind You Is a Bigger Risk Than the Network
This is the part nobody puts in the warnings, and it is the one we actually see cause problems. Laptop screens are large, bright, and pointed at the room. In an airport gate area or a busy coffee shop in Denton, the people around you can read your email, your customer list, and the numbers on your screen with no technical skill at all.
Talking counts too. A phone call about a patient, a client, or a payroll problem carries farther than you think. Angle away from foot traffic, consider a privacy screen filter, and save the sensitive call for the car.
When to Skip the Free Wi-Fi and Use Your Phone
Your phone’s cellular connection is a private link between you and your carrier, and sharing it as a personal hotspot takes a few taps on any modern phone. The FCC guidance says this directly: when transmitting sensitive information, using your cellphone data plan instead of Wi-Fi may be more secure. That is our tiebreaker.
- You cannot confirm the network name. Nobody around to ask, several similar names, or a network that appeared out of nowhere.
- You are about to move money. Wire instructions, payroll, taxes, closing documents. A few megabytes of data removes all doubt.
- Your browser throws a certificate warning. A security warning on a site you visit all the time is your device telling you something is off. Do not click past it on a network you do not control.
The Habits That Beat Avoiding Public Wi-Fi
Here is the contrarian part. If you spent the energy you currently spend avoiding coffee shop Wi-Fi on the list below instead, you would be dramatically safer. The FTC’s own public Wi-Fi guidance leads with these rather than with network avoidance.
- Use strong, unique passwords. A password manager makes this painless, and reused passwords cause far more damage than every coffee shop in Texas combined.
- Turn on multifactor authentication everywhere it is offered. Email first, then banking, then the rest. For the plain English version of the options, see YubiKey vs passkey vs MFA.
- Keep your device and browser updated. Updates close the holes a hostile network would otherwise need.
- Turn Bluetooth off when you are not using it. The FCC recommends exactly that, along with using hidden rather than discoverable mode.
- Slow down on login pages. Nearly every account takeover we help clean up started with a real password typed into a fake page. That happens on any network, at home or away.
The Bottom Line
Public Wi-Fi is not the danger zone it once was, and pretending otherwise teaches people to tune out security advice generally, which is worse. Use the coffee shop network. Check the name with a human before you join. Never install anything or type an account password to get online. Notice who can see your screen. And when you are handling money or sensitive records and something feels off, your phone’s hotspot is already in your pocket.
If you have been carrying a rule about public Wi-Fi since 2012 and were not sure whether it still applied, now you know. We are happy to answer a question like this for folks around Denton County whether you are a client or not, and there is no pitch attached. Contact us today.
Sources:
Comments are closed