You are in a hotel ballroom in Frisco on day one of a two day conference. You open the laptop and the Wi-Fi list shows six networks. There is the hotel one, the conference one, one with the conference name and an underscore, one called Guest, one called Free_WiFi_Fast, and one that is just the name of the coffee shop in the lobby. Nothing tells you which is which. The session starts in four minutes and you need the slides.

Somewhere in your memory is a decade of advice about public Wi-Fi being a den of thieves, and honestly, most of that advice is out of date. The internet got dramatically safer while everybody was still repeating the old warnings. But not all of it got safer, and the parts that did not are not the parts people worry about. So here is what has genuinely changed, what has not, and what to actually do standing in that ballroom.

What HTTPS Already Handles

The old fear was eavesdropping. Someone else on the hotel network watching your traffic go by and reading your password out of it. That fear made sense when most of the web was unencrypted. It largely does not anymore.

HTTPS is the encrypted version of the web, the padlock in the address bar. It scrambles the contents of the conversation between your browser and the website so that anyone in between, including whoever runs the network, sees noise instead of words. Google reports that HTTPS now accounts for the overwhelming majority of page loads in Chrome, high enough across every platform that the company is switching Chrome to warn you before it will even load an unencrypted page. Your email, your bank, your accounting software, your file storage, all of it has been encrypted end to end for years.

So the specific nightmare people picture, a stranger in the lobby reading your banking password as it flies past, is essentially solved for normal browsing. That is a genuine win, and it is worth saying out loud instead of letting people carry an obsolete fear around.

What HTTPS Does Not Cover

HTTPS hides the contents. It does not hide the envelope. Whoever runs the network can still generally see which sites you connected to, when, and roughly how much data moved. They cannot read your message to your attorney, but they can often tell you were on your attorney’s website at four in the afternoon. For most business travel that is a privacy annoyance rather than a security problem.

More importantly, encryption protects the pipe. It does nothing about what you willingly hand over. If you type your password into a convincing fake page, HTTPS will faithfully encrypt it and deliver it to the criminal. The lock icon means the connection is private. It does not mean the site is honest.

The Things That Actually Still Get People

  • The sign in page that asks for too much. That page that appears when you join a hotel network is called a captive portal. A legitimate one asks for a room number, a last name, or an access code. If one ever asks for your email password, your company login, or a credit card you were not expecting to give, close it. That is the single most common way people get hurt on travel networks.
  • The network with a plausible name. Anybody can name a network anything. A network called Conference_Guest_Free proves nothing about who runs it. Ask the front desk or the registration table for the exact name, and if the answer is ambiguous, use your phone instead. This costs you thirty seconds.
  • Certificate warnings you click through. If your browser throws a full page warning that a site’s certificate is invalid, that is the one warning on a strange network that genuinely means something. Do not click past it. Close the tab and switch to your phone connection.
  • Your own unpatched laptop. A machine that is months behind on updates, sharing a network with a few hundred strangers, is a real exposure and always has been. This is boring and it is also the actual answer. Update before you travel.
  • The person sitting behind you. In a conference hall, the highest probability threat to your confidential information is a human being with working eyes. Nothing technical helps here. A privacy screen filter and some awareness of your seat do.
  • Auto connect, quietly rejoining things. Your laptop remembers networks and rejoins them automatically. After the trip, tell it to forget the hotel and the airport. Otherwise it will keep reaching out for them for years.

Two Minutes Of Settings Before You Connect

  1. Mark the network as Public, not Private or Home, when your device asks. That one choice turns off file and printer sharing and makes your machine much quieter on the network.
  2. Confirm your firewall is on. It is by default on current Windows and Mac systems, so this is a ten second check, not a project.
  3. Turn off automatic connection to open networks in your Wi-Fi settings.
  4. Turn on your browser’s always use secure connections setting, which makes it refuse to load unencrypted pages without asking you first.
  5. Make sure your screen locks itself after a few minutes, because you will get up for coffee.

Use Your Phone Instead, And The Honest Answer On VPNs

Here is the simplest rule we give clients, and it replaces a lot of complicated thinking. If the task involves moving money, changing bank details, approving a wire, logging into a system that controls other systems, or handling something that would genuinely ruin your week if it went wrong, do it on your phone’s hotspot instead of the venue network. Not because the venue network is probably hostile. Because the cost of using your own connection is nearly zero and the downside of being wrong is not.

Cellular is a reasonable default for the whole trip if your plan can absorb it. It is your own connection, it does not involve a sign in page, and it removes a whole category of decisions from your day. That is why the hotspot made our travel go bag list. It is a productivity tool that happens to be a security tool.

A virtual private network, or VPN, is an encrypted tunnel between your device and some other server, after which your traffic continues on to its destination. Consumer VPN advertising leans hard on the public Wi-Fi fear, and that pitch is mostly selling you protection HTTPS already provides.

That said, VPNs are not useless, and the National Security Agency’s published guidance on using wireless devices in public still recommends a personal or corporate VPN on untrusted networks. Two places one genuinely earns its keep. First, reaching your own company’s internal systems, which is what business VPNs were built for. Second, hiding which sites you visit from the network operator, which HTTPS does not do. What a consumer VPN does not do is make you anonymous or make a bad decision safe. It moves your trust from the hotel to the VPN company. Sometimes that trade is worth making. Just make it knowingly.

The Bottom Line

Public Wi-Fi is not the minefield it was, because the web quietly encrypted itself while everyone was still repeating the old advice. The risk moved. It is no longer someone reading your traffic. It is you typing a password into a page that asked nicely, clicking past a warning that meant something, or bringing a laptop that has not been updated since spring. Update your devices, treat every sign in page with suspicion, keep the important work on your own connection, and go enjoy the conference.

If your team travels and you would rather have this handled by policy and settings than by everyone remembering a blog post, that is exactly the kind of work we do for businesses in Lewisville, Flower Mound, and across Denton County. Reach out at https://harrisonward.com/contact/.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).