CYBER WELFARE

Protect your Digital Privacy

Do not handle sensitive data on public Wi-Fi

Two opposite positions circulate about this recommendation, both imprecise: “public networks are extremely dangerous” and “there is no problem any more”.

The reality sits in between, and it is more useful than either. The main risk of public networks today is not that somebody reads your traffic — that is encrypted. It is that you do not know who you connected to, and that the network itself is the instrument of the deception.

What this recommendation says

Recommendation R10 establishes that you should avoid operations involving sensitive data when connected to a Wi-Fi network you do not control, and take some precautions when using one is necessary.

By “sensitive data” we mean: banking and payment operations, access to confidential documents, handling credentials, and in general anything you would not want to repeat in front of a stranger.

By “a network you do not control” we mean: cafes, hotels, airports, trains, shopping centres, libraries, other people’s offices, and an acquaintance’s network too.

What it is not. It is not an invitation to avoid public networks. They are a useful tool and, with encryption everywhere, reasonably safe for ordinary use. The recommendation concerns a category of operation, not the connection itself.

Scope. Any device connecting to networks that are not yours.

Why it matters

The risk has shifted in recent years, and it is worth seeing where to.

RiskHow relevant it used to beHow relevant it is today
Reading the trafficVery highLow: the traffic is encrypted
Altering pagesHighLow: encryption detects it
A fake network with a plausible nameMediumHigh: it is the main technique
A deceptive sign-in portalLowHigh: it asks for data and nobody notices
Automatic reconnection to known networksLowMedium-high: it happens without you knowing
The device’s exposure on the local networkMediumMedium: it depends on the settings

The three highlighted rows describe the contemporary risk, and they have one thing in common: they do not concern the traffic, they concern the network’s identity. Whoever sets up a fake network does not need to decrypt anything — it is enough that you type something into their sign-in page.

A concrete example

Helen is at the airport and looks for the Wi-Fi. She sees two networks with similar names: Airport_WiFi and Airport_WiFi_Free. She picks one.

A page opens asking her to register with an email address and a password to “create an access account”. Helen enters her personal email and the password she usually uses.

The traffic afterwards will be encrypted and unreadable. But she has already handed over the credentials voluntarily, on a page in the clear, to a party she did not check.

The point: the encryption worked perfectly and was of no use at all, because the problem was not interception.

When to apply it

  • Before a banking operation or a payment, even a small one.
  • When the network asks you to register with the credentials of existing services.
  • In airports, stations and hotels, where the number of people makes setting up fake networks worthwhile.
  • When your device connects by itself to a network you do not remember choosing.
  • Before opening confidential work documents from a network that is not yours.
  • When travelling abroad, where network names are less familiar and harder to verify.
  • On devices your children also use, since they tend to connect to any open network.

How to apply it

  1. Prefer your phone’s data for sensitive operations. It is the most effective countermeasure and the least demanding: the mobile connection is encrypted over the radio link and is not shared with strangers.
  2. Check the network’s exact name by asking whoever runs the place, instead of inferring it. It is the only way to tell the real one from a copy.
  3. Do not enter other services’ credentials into the sign-in portal. If the network asks for an email and a password, use a secondary address and a password made for the occasion — or give it a miss.
  4. Turn off automatic connection to known networks. Otherwise the device reconnects to any network with a name it has seen before, even if it is not the same one.
  5. Forget public networks after use. It avoids future reconnections and reduces the information the device broadcasts looking for them.
  6. Turn off file and printer sharing when you connect to a public network. Many systems ask at the first connection: the correct answer is “public network”.
  7. Use official apps instead of the browser for banking and financial services, when you really have to.

Common mistakes to avoid

  • Registering on the portal with your main email and usual password. It is the most costly mistake and the most frequent.
  • Trusting the network’s name. Anybody can call their network whatever they like: the name cannot be verified.
  • Leaving automatic connection on. It is how people connect to networks they never chose.
  • Thinking a password-protected network is secure. A cafe’s password is known to every customer: it does not separate you from the others.
  • Believing a VPN covers every case. It protects the traffic, it does not tell you which network you connected to nor what you type into the portal.
  • Overlooking the sharing settings. On a public network your device can be visible to the others connected.
  • Considering only open networks “public”. A client’s office network is also a network you do not control.

A password-protected network is not a private network

It deserves clarity, because it is this recommendation’s most widespread misunderstanding.

A password on a network stops passers-by connecting. It stops nothing for whoever has the password — and in a cafe every customer has it, often written on the menu.

Kind of networkWho can connectWho can observe
Open, no passwordAnybodyWhoever is connected, with simple tools
With a shared passwordEvery customerWhoever knows the password
With individual credentialsWhoever has an accountOnly whoever runs the network
Your home networkThe people you live withOnly whoever controls the router

The first two rows are the typical situation in a public place. The difference between them, from the point of view of somebody wanting to observe, is minimal.

What still makes them acceptable to use is the site-by-site encryption of the traffic — not the network’s password.

What “sensitive data” means concretely

The recommendation’s wording contains a term worth making operational, because otherwise it stays a piece of guidance everybody interprets their own way.

ActivityOn a public networkWhy
Reading news, watching videoNo problemEncrypted traffic, nothing to hand over
Checking personal mailNo problemThe session is already active, the content encrypted
Video callsMind the surroundings, not the networkWhoever is beside you can hear
Working on company documentsCheck the policyOften governed by rules
Signing in to a new service with credentialsAcceptable if the site is encryptedThe credential does not pass in the clear
Banking operations and paymentsBetter on your phone’s dataNot for interception: for the context
Registering on the network’s portalNever with real credentialsIt is the only part that is not encrypted

The last two rows are the only ones where the recommendation really imposes a change. Everything else is usable.

It is worth explaining why banking operations stay on the list despite the encryption: not because the traffic is readable, but because they are operations where an interruption, a doubt or a mistake carries a high cost, and where the physical context — a visible screen, an observable keyboard — weighs more than the network.

The perimeter almost nobody considers

“Public network” evokes the cafe or the airport. In fact the useful definition is wider: any network whose router you do not control is public.

That includes situations nobody usually classifies that way:

  • the network at friends’ or relatives’ homes, whose configuration you do not know;
  • the network at a client’s or supplier’s office;
  • the network of an accommodation provider, however upmarket;
  • the network of a coworking space;
  • the network of a school or university;
  • a hotspot shared from somebody else’s phone.

It does not mean they are hostile — in almost every case they are not. It means the configuration, the updates and the management of that router do not depend on you, and that the same care therefore applies.

How this connects to the Cyber Welfare Framework

PillarHow it contributes
AwarenessUnderstanding that the risk is the network’s identity, not the reading of traffic
SkillsConfiguring automatic connection and sharing correctly
Secure BehaviourMoving sensitive operations onto your phone’s data

Digital maturity levels.

  • FL1 — Basic. Connecting to any open network, automatic connection on, registering with the usual credentials.
  • FL2 — Beginner. Banking operations on public networks are avoided.
  • FL3 — Autonomous. Automatic connection off, networks forgotten after use, the portal never filled in with real credentials.
  • FL4 — Skilled. The network’s name is checked at the source; sharing turned off; phone data as the default choice for sensitive operations.
  • FL5 — Expert-Guide. You help others, particularly frequent travellers, tell the real risk from the perceived one.

R10 rests entirely on R9: it is site-by-site encryption that makes a public network usable. Without it, this recommendation would be far more restrictive.

How to check you are applying it correctly

  1. Does my phone connect by itself to networks I did not deliberately choose?
  2. When I last registered on a public Wi-Fi, which credentials did I use?
  3. If I had to make a bank transfer right now, away from home, which connection would I use?

Quick checklist

  • ☐ Automatic connection to known networks turned off
  • ☐ Public networks forgotten after use
  • ☐ Never real credentials in the sign-in portal
  • ☐ File and printer sharing turned off on public networks
  • ☐ Banking operations done on the phone’s data
  • ☐ The network’s name checked by asking, not inferring
  • ☐ Official apps instead of the browser for financial services

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

Public networks are not to be avoided: they are to be used knowing what they protect and what they do not.

The traffic is encrypted and unreadable. What stays uncovered is everything happening before the encryption: choosing the network, the sign-in portal, and the settings your device presents itself with.

One rule, if only one were to remain: for the operations that count, use your phone’s data. It costs nothing and closes the whole category of problems.

Something to think about. How many Wi-Fi networks are saved on your phone right now — and how many would it reconnect to on its own, without asking you?

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.