If you’ve ever had an airport layover, stayed at a hotel or set up at a coffee shop or coworking space for the day, chances are you’ve used a public WiFi hotspot. These free networks are everywhere, and they’re a convenient way to stay connected without driving up your data usage. But they can leave users vulnerable. Unlike the private network you might have at home or the office, there’s no way to know who set up an open network, or who else is using it. These are the main public WiFi security risks, plus tips for how to use public wifi safely.
Malware attacks
Malware is short for “malicious software,” and it basically infects your device or network with code that destroys, damages, or steals your data. It’s an umbrella term that covers many types of attacks, including ransomware, spyware, adware, viruses, worms, and Trojan horses. These are presented in different ways, but they can result in devastating data breaches or losses.
Cybercriminals can pull off malware attacks by exploiting a vulnerability in your system or network, especially if you’re not already using antivirus software across your devices. Public WiFi networks are, unfortunately, a good target for malware attacks. Thanks to their lack of security, hackers can compromise the connection to activate malware on any devices that take advantage of the free internet.
Imposter networks
When you go to join a public WiFi network, you probably scan the list of available networks and choose the one that sounds like the location. For example, if you’re at Sydney Airport, you’d choose Sydney Airport WiFi, and if you’re staying at the Melbourne Hotel, Melbourne Hotel Guest sounds right. Sometimes, hackers set up “rogue access hotspots,” which are basically imposter networks that trick users with legitimate names. If a user hops onto a malicious network set up by cybercriminals, their personal data could be compromised.
Man-in-the-middle attacks
In the cybersecurity world, man-in-the-middle (MitM) attacks are a form of eavesdropping. Most communication online is a two-party transaction: the device is on one end, and the server is on the other. With MitM attacks, a hacker (the “man in the middle”) crawls in between those parties. From that point, any communication flows through the hacker, putting the client’s data at risk.
Unfortunately, public WiFI networks are a common point of entry for cybercriminals. They’re typically not secured, and users tend to visit the same sites and apps they do when they’re on a secured network — think banking or work email accounts. This makes it easier for hackers to take over your web traffic and interfere with the transmission from your device and the network. They can then use your data for malicious purposes, making man-in-the-middle attacks one of the risks of using public wifi.
7 tips for using public WiFi safely
Public WiFi networks aren’t ideal, but sometimes, they’re the best and most cost-effective option. In those situations, follow these tips to reduce risk and learn how to stay safe on public WiFi.
#1 Don’t access sensitive information
Searching for directions or nearby restaurants is fine, but it’s a good idea to wait to check your bank account, Slack or social media until you can access a private network. The same goes for anything that involves handing over your credit card details, like online shopping or paying your bills. If you’re not sure whether you should visit a site on a public network, ask yourself: how would I feel if someone could see exactly what I was doing online? If the answer is “not good” but you need to hop online. rely on your cellular data, like 4G or 5G.
#2 Stick to secure sites
Check the URL of every site you visit. If the URL bar has a lock and the site’s address starts with “https” instead of “http,” that means it has a Secure Socket Layer (SSL) certificate. In other words, it’s a secure site and generally safe to browse. HTTPs addresses are encrypted, which means there’s technology that safeguards the site from cyber attacks and protects information submitted by the site’s users. Any data that passes between the site’s visitors and servers is private. Think usernames, passwords, tax file numbers and credit card details.
#3 Learn the signs of malware
Some of the most common red flags include excessive pop-ups, unusual logos or images, suspicious redirects and maladvertising, such as ads that promise things that are too good to be true. If you see any of these features online, leave the site immediately. There’s a chance your traffic will be visible to other people using the network.
#4 Use a Virtual Private Network
If you can’t avoid jumping onto an open WiFi network, join a Virtual Private Network (VPN) before you start browsing. By doing this, you’ll be accessing a private network known as a VPN tunnel. This will encrypt the traffic between the VPN server and your device, which goes a long way in protecting your privacy and personal information from prying eyes. A VPN’s main job is to hide your IP address from your Internet Service Provider (ISP) and other third parties, so that they can’t see the sites you visit or the data you’re sending and receiving. Even with a VPN, try not to use any sites or accounts that contain sensitive information.
#5 Switch off automatic connections
Go to the wireless settings on your device to check whether it automatically connects to available public hotspots. If that setting is enabled, turn it off so your device doesn’t auto-connect or search for known WiFi networks. This is a simple step that makes it a little harder for hackers to create imposter networks with the same name as the networks you join all the time.
#6 Activate two-factor authentication
With two-factor authentication (2FA), you’ll need to provide a username, password and another piece of information — like a text sent to your phone — before you can log into your accounts. 2FA adds an extra layer of security to the login process for your accounts, and it’s worth activating if you use public WiFi networks. If a cybercriminal manages to gain access to your passwords, they likely won’t have that second piece of information.
#7 Update your operating system
Whenever you get a notification that your device’s software is ready for an update, accept it! Manufacturers like Apple and Microsoft constantly release security patches to tighten security and address new threats so you can use public WiFI safely.
Let antivirus software do the heavy lifting
Installing antivirus software is another way to protect your data while using public WiFi networks. ESET’s programs detect and combat a range of cyber threats, such as malware, viruses and phishing scams, so you can browse safely with no additional effort on your part.