The techniques in this family have changed profoundly over the last ten years, and understanding that is more useful than listing them.
Traffic used to be the target. Today the traffic is encrypted, and attacking it is not worthwhile. So the choice is targeted instead: not what you exchange with the sites, but the decision to join that network and what you hand over at the entrance.
It is a shift from the technical plane to the plane of deception, and it completely changes the defences needed.
It expands on the recommendation sensitive data on public Wi-Fi.
1. The network with a plausible name
It is today’s main technique, and the simplest.
How it works. A wireless network is set up with a name that looks like the venue’s: Central_Cafe_WiFi, Airport_Free, Hotel_Guest. Whoever connects passes through equipment controlled by somebody else.
Why it works. Network names cannot be verified. There is no mechanism linking a name to an owner: anybody can call their network whatever they like, and the device has no way of noticing.
What they get. The position of intermediary, and above all control of the sign-in portal — which is where the value concentrates.
The specific defence. Ask for the network’s exact name from whoever offers it. It is the only verification available, and it works.
2. The portal that asks too much
It is the technique producing the real damage, and it is the natural sequel to the first.
How it works. The sign-in page asks you to “register” with an email address and a password, or to sign in with an existing account, or to enter personal or payment details.
Why it works. The context makes it normal: legitimate public Wi-Fi registration pages really do ask for data, so the request does not jar. And people tend to use their usual password.
What they get. Real credentials, handed over voluntarily, in the clear. No encryption comes into play, because there is nothing to intercept: the data is given.
The specific defence. No network needs a password of yours to give you access. If it asks, you enter a password made for the occasion or you give it a miss.
3. Automatic reconnection
How it works. A device with automatic connection on is continuously looking for the networks it knows. Whoever watches which names it is looking for can create one with that name, and the device connects by itself, asking nothing.
Why it works. Because it is the intended behaviour: the device is doing exactly what it is configured to do.
What they get. A connection the user did not choose and often does not notice.
The specific defence. Turn off automatic connection and delete the networks you no longer need. It is why those two settings appear in every text in this unit.
4. Forced disconnection
How it works. Whoever is within range of the network can, on some standards, send signals that disconnect the connected devices. Those try to reconnect, and at that moment they can latch onto the fake network.
Why it used to work. The older standards did not protect the connection management messages.
Why it works less today. Recent standards authenticate those messages, making forced disconnection ineffective on updated networks.
The specific defence. No direct action: it depends on the infrastructure. But a sudden and repeated reconnection is a signal worth noticing.
5. The neighbour on the same network
How it works. It does not concern traffic towards the internet but the local network: other devices connected to the same network can try to reach yours.
What they look for. Shared folders, printers, listening services, unpatched systems.
How realistic it is. On a computer configured as “public network” and with the firewall on, very little. On a computer presenting itself as if on a home network, more.
The specific defence. Answer “public network” to the system’s question, and check the firewall is on.
6. The twin with a stronger signal
How it works. A network is created with exactly the same name as the legitimate one, but with a more powerful signal. Devices, which prefer the better signal, migrate to it.
Why it works. It is intended behaviour: switching to the antenna with the better signal is what makes Wi-Fi usable in a large building.
What they get. Interception without the user having made any wrong choice at all.
The specific defence. Networks with individual credentials make it harder. For the rest, site-level encryption holds: the traffic stays unreadable.
The overall picture
| Technique | Stopped by encryption? | What actually stops it |
|---|---|---|
| A network with a plausible name | The traffic, yes | Asking for the exact name |
| A portal that asks too much | No | Not handing over real credentials |
| Automatic reconnection | The traffic, yes | Turning off the setting |
| Forced disconnection | The traffic, yes | Updated standards |
| A neighbour on the same network | Not applicable | The “public network” profile and a firewall |
| A twin with a strong signal | The traffic, yes | Little, but the damage is limited |
The highlighted row is the unit’s centre: only one technique produces real damage today, and encryption has nothing to do with it. It is not a technical attack — it is a request that gets answered.
Why phishing became the real threat on public networks
It is worth drawing the threads together, because it changes where to put your attention.
Ten years ago public Wi-Fi was a problem of interception: people went there to read other people’s traffic, and it worked.
Today the traffic is unreadable, and anyone wanting credentials has a much simpler route: set up a page that asks for them. It requires no technical skill, it requires decrypting nothing, and it has a high success rate because it exploits a context where the request looks legitimate.
The result is that effective defence on public networks looks more like the defence against phishing than the defence against interception: it is not a tool to install, it is a rule to apply — what am I about to hand over, and to whom?
Where these techniques concentrate
Not all places are equal. Setting up a fake network takes a minimal but non-zero investment — equipment, a presence on site — and so it concentrates where the return is greatest.
| Place | Attractiveness | Why |
|---|---|---|
| Airports and stations | Very high | Many people, all waiting, all connected |
| Trade fairs and conferences | Very high | A professional audience, company devices |
| Large hotels | High | Guests connecting for days |
| Shopping centres | Medium | Plenty of footfall, little dwell time |
| Cafes and restaurants | Low | Few people at a time |
| Libraries and universities | Low | Managed networks, often with individual credentials |
The first two rows share a characteristic worth noting: not knowing the correct network’s name is normal there. In a cafe you can ask at the counter; in a large airport, with dozens of networks visible and nobody to ask, verification is far harder.
That is exactly where the two habits that do not depend on recognition count most: hand nothing to the portal, and use your phone’s data for what matters.
There is then a seasonal factor worth a line: periods of heavy travel — holidays, returns, big events — concentrate in the same place many people who are tired, in a hurry, and need the connection right away. It is the combination in which critical judgement works worst, and it is why the useful decisions get taken before setting off.
How the defence is put together
Three actions, in order of effectiveness.
1. Do not hand real credentials to the portal. It covers the only technique producing certain damage.
2. Turn off automatic connection and delete old networks. It covers the two techniques acting without you choosing anything.
3. Ask for the network’s exact name. It covers the main technique at source.
Everything else — traffic encryption, detecting alterations, protecting content — already happens without you having to do anything. It is why this recommendation, despite its air of technical complexity, comes down to three simple actions.
What does not belong to this family
Drawing boundaries helps, because “Wi-Fi attack” gets used for very different things.
Phishing received by email while you are connected. It has nothing to do with the network: it would have arrived anyway. The network is just where you happened to be.
An app collecting data. It is a question of permissions, covered in another unit. It happens identically on a home network.
The theft of a device while you work in a cafe. It is a real and frequent risk in that context, but it belongs to the units on screen locking and encryption.
Somebody reading your screen from behind. That too belongs to the physical context, not the network — and it is statistically likelier than all six techniques described above.
A home router being compromised. It concerns a network you control, and the defence is different: router updates and a changed administration password.
The useful distinction: this family includes only what exploits the fact that the network is not yours. Everything else would have happened anyway, elsewhere.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that the attack shifted from the traffic to the choice |
| Skills | Recognising which technique encryption does not cover |
| Secure Behaviour | Applying three rules instead of looking for a tool |
Reference level: FL3 — Autonomous.
Summary
- The techniques shifted from traffic to deception: attacking the traffic is no longer worthwhile.
- Network names cannot be verified: it is the point almost everything else rests on.
- Only one technique produces certain damage: the portal asking for real credentials.
- Effective defence resembles the defence against phishing: a rule, not a tool.
One thing to do today. Decide now, calmly, what you will answer the next time a Wi-Fi portal asks you for an email and a password. The decision taken now is worth more than any judgement made with a suitcase in your hand.
Related content
- Sensitive data on public Wi-Fi — the recommendation this expands on
- Signs of an untrustworthy Wi-Fi network — how to recognise these techniques in action
- Protecting traffic on public networks — what stops what, layer by layer
- Traffic interception — the technical family of reference
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



