CYBER WELFARE

Protect your Digital Privacy

Signs of an untrustworthy Wi-Fi network

A network does not come with a label. The name is chosen by whoever sets it up, and the device has no way to verify it.

What is left are indirect clues: things you notice before connecting, during the connection, and afterwards. This post lines them up and — just as importantly — separates the ones that count from the ones with ordinary explanations.

It expands on the recommendation sensitive data on public Wi-Fi.

Before connecting

Two networks with almost identical names

It is the most significant clue in the whole unit. Hotel_WiFi and Hotel_WiFi_Free, or the same name with and without a padlock, or with one letter different.

A venue runs one network for customers. The presence of almost identical variants is anomalous, and the correct response is to ask which is the right one — not to pick one.

An open network where a protected one would be expected

An airport, a chain hotel, a station offering a completely open network with no portal at all is unusual: almost every large operator requires at least an acceptance of terms.

A signal too strong for the place

A network showing up very strongly at a point where the venue’s router cannot be — outside, say, or on a different floor — may be coming from equipment near you rather than from the venue’s infrastructure.

It is a weak clue on its own, but it adds to the others.

A network that has only just appeared

If you regularly use a place and see a network appear that was not there before, with a plausible name, it is worth a question.

While connecting

The portal asks for more than it needs

It is the most important signal and the easiest to recognise.

What the portal asks forAssessment
Accepting the termsNormal
An email addressCommon, often for commercial purposes
First and last nameFrequent, and debatable but not anomalous
A passwordAnomalous: it is not needed to give access to a network
Signing in with an existing accountAnomalous: it asks for real permissions
Payment details for a free serviceAnomalous
Installing a certificate or programStop: no legitimate network requires it

The four highlighted rows share one element: they ask for something not needed to make a connection work. It is the most reliable criterion in this unit.

The portal does not resemble the place

A chain hotel will have a page with its own branding. A generic page, in the wrong language, with obvious errors or with no reference to the venue at all, is out of place.

Certificate warnings on several different sites

If opening three different sites produces three certificate warnings, the problem is not the sites: it is whoever is in between. It is one of the strongest clues available, and the correct response is to disconnect immediately.

Every site passes through an intermediate page

A screen appearing before every destination, even after you completed the sign-in, indicates the traffic is being handled by somebody along the route.

After connecting

The device connected by itself. If you notice you are connected to a network you did not choose, the device recognised a known name. It does not mean that network is hostile — it means the mechanism that could take you there exists and is on.

A sign-in alert on an account. If a sign-in alert from an unusual location arrives after using a network, the link is likely.

More unwanted messages. The typical effect of an email address left in a portal: annoying but not serious.

A program behaving differently after a download made from that network.

What is NOT a signal

Essential, because constant alarm leads to ignoring everything.

WhatWhy it is not a signal
An open network with no passwordMany venues offer them that way, for simplicity
A portal asking for an email addressOrdinary commercial practice
A certificate warning on the portal aloneCommon: the portal intercepts the first connection
A slow networkIt is a bandwidth question, not a security one
A strange or jokey network nameNames are chosen freely, often for fun
Many networks visible in the same placeIn a city centre it is the norm
A network asking for your room numberIt is a correct verification method, not a risk

The last row deserves attention because it looks intrusive and is in fact a good sign: a code only the venue could have given you is the only form of network-identity verification available to a user.

The hierarchy of clues

They do not all weigh the same. In descending order:

ClueWeightAction
A request to install somethingMaximumDisconnect at once
Certificate warnings on several sitesMaximumDisconnect at once
A portal asking for a passwordHighDo not enter one, use throwaway data or give it a miss
Two networks with almost identical namesHighAsk which is the right one
A portal that does not resemble the placeMediumEnter nothing real
An unwanted automatic connectionMediumTurn the setting off
A network that appeared recentlyLowNoticing it is enough

The first two rows are the only ones requiring an immediate reaction. All the others are handled simply by handing nothing over.

The signals on your device, not on the network

Some clues concern your device’s behaviour, and they are useful because you can check them calmly, at home, without having to decide on the spot.

The list of saved networks is very long. If it holds dozens of entries from places you visited once, the device is looking for all those names every time the Wi-Fi is on. It is not a sign of compromise: it is a surface of exposure accumulated with nobody looking at it.

The device connects in places where you never configured it. If your phone shows as connected in a new place, there is a network with a name matching a saved one.

The Wi-Fi turns itself back on. Some systems have an option that switches Wi-Fi back on near known networks even after you turned it off. It is a convenience, and it is worth knowing about.

A manually installed certificate. In the security settings there is a list of certification authorities added by the user. On a personal device it should be empty. If it is not, and you do not remember installing anything, it is the most serious signal this unit can produce.

Unusual battery or data use after a trip. A weak clue, but if it coincides with others it is worth looking at what was installed recently.

These checks take five minutes and get done now and then, not at every connection. It is how this recommendation becomes sustainable: not continuous vigilance, but a periodic check.

The most useful signal is a question

Let us close with the most practical thing in the whole unit, which is not technical.

Before connecting to a network in a place where there is somebody to ask — a cafe, a hotel, an office — ask for the network’s exact name. It takes five seconds and removes at a stroke the whole category of fake networks, which is this unit’s main risk.

It is the only verification of a network’s identity available to somebody with no technical tools, and it works better than any indirect clue listed above.

Why these signals are weaker than elsewhere

A useful admission, because it avoids giving this unit more weight than it can bear.

In the other contexts of this series there are verifiable clues: a sign-in log, a forwarding rule, a connected device, a browser warning. They are facts, there to be consulted.

Here it is not so. A network’s name is not a verifiable fact — it is a freely chosen label. The Wi-Fi signal says nothing about who is transmitting it. A well-made portal is indistinguishable from a legitimate one.

One practical thing follows: in this unit prevention counts far more than detection.

ApproachEffectiveness here
Recognising a fake network from cluesLow: the clues are weak
Asking for the network’s exact nameHigh
Handing nothing to the portalHigh: it makes the rest irrelevant
Turning off automatic connectionHigh
Using your phone’s data for what countsHigh

The four effective rows have one thing in common: they work regardless of whether you manage to recognise the network. They do not require a correct judgement — they require a habit.

It is a structure worth keeping in mind whenever the available clues are weak: when you cannot tell the good case from the bad one, the defence is not to tell them apart better — it is to behave so that the distinction does not matter.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessKnowing that a network’s name cannot be verified by the device
SkillsTelling an ordinary request from an anomalous one in a portal
Secure BehaviourAsking for the network’s name instead of inferring it

Reference level: FL2 — Beginner.

Summary

  • The most reliable criterion: the portal asks for something not needed to make a connection work.
  • Certificate warnings on several sites on the same network: disconnect at once.
  • Many clues have ordinary explanations: an open or slow network is not a signal.
  • The best check is not technical: asking for the network’s exact name.

One thing to do today. The next time you connect to a venue’s Wi-Fi, ask for the network’s name before looking at the list. It is the action that makes every other clue in this post unnecessary.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.