CYBER WELFARE

Protect your Digital Privacy

Attacks on public Wi-Fi

The techniques in this family have changed profoundly over the last ten years, and understanding that is more useful than listing them.

Traffic used to be the target. Today the traffic is encrypted, and attacking it is not worthwhile. So the choice is targeted instead: not what you exchange with the sites, but the decision to join that network and what you hand over at the entrance.

It is a shift from the technical plane to the plane of deception, and it completely changes the defences needed.

It expands on the recommendation sensitive data on public Wi-Fi.

1. The network with a plausible name

It is today’s main technique, and the simplest.

How it works. A wireless network is set up with a name that looks like the venue’s: Central_Cafe_WiFi, Airport_Free, Hotel_Guest. Whoever connects passes through equipment controlled by somebody else.

Why it works. Network names cannot be verified. There is no mechanism linking a name to an owner: anybody can call their network whatever they like, and the device has no way of noticing.

What they get. The position of intermediary, and above all control of the sign-in portal — which is where the value concentrates.

The specific defence. Ask for the network’s exact name from whoever offers it. It is the only verification available, and it works.

2. The portal that asks too much

It is the technique producing the real damage, and it is the natural sequel to the first.

How it works. The sign-in page asks you to “register” with an email address and a password, or to sign in with an existing account, or to enter personal or payment details.

Why it works. The context makes it normal: legitimate public Wi-Fi registration pages really do ask for data, so the request does not jar. And people tend to use their usual password.

What they get. Real credentials, handed over voluntarily, in the clear. No encryption comes into play, because there is nothing to intercept: the data is given.

The specific defence. No network needs a password of yours to give you access. If it asks, you enter a password made for the occasion or you give it a miss.

3. Automatic reconnection

How it works. A device with automatic connection on is continuously looking for the networks it knows. Whoever watches which names it is looking for can create one with that name, and the device connects by itself, asking nothing.

Why it works. Because it is the intended behaviour: the device is doing exactly what it is configured to do.

What they get. A connection the user did not choose and often does not notice.

The specific defence. Turn off automatic connection and delete the networks you no longer need. It is why those two settings appear in every text in this unit.

4. Forced disconnection

How it works. Whoever is within range of the network can, on some standards, send signals that disconnect the connected devices. Those try to reconnect, and at that moment they can latch onto the fake network.

Why it used to work. The older standards did not protect the connection management messages.

Why it works less today. Recent standards authenticate those messages, making forced disconnection ineffective on updated networks.

The specific defence. No direct action: it depends on the infrastructure. But a sudden and repeated reconnection is a signal worth noticing.

5. The neighbour on the same network

How it works. It does not concern traffic towards the internet but the local network: other devices connected to the same network can try to reach yours.

What they look for. Shared folders, printers, listening services, unpatched systems.

How realistic it is. On a computer configured as “public network” and with the firewall on, very little. On a computer presenting itself as if on a home network, more.

The specific defence. Answer “public network” to the system’s question, and check the firewall is on.

6. The twin with a stronger signal

How it works. A network is created with exactly the same name as the legitimate one, but with a more powerful signal. Devices, which prefer the better signal, migrate to it.

Why it works. It is intended behaviour: switching to the antenna with the better signal is what makes Wi-Fi usable in a large building.

What they get. Interception without the user having made any wrong choice at all.

The specific defence. Networks with individual credentials make it harder. For the rest, site-level encryption holds: the traffic stays unreadable.

The overall picture

TechniqueStopped by encryption?What actually stops it
A network with a plausible nameThe traffic, yesAsking for the exact name
A portal that asks too muchNoNot handing over real credentials
Automatic reconnectionThe traffic, yesTurning off the setting
Forced disconnectionThe traffic, yesUpdated standards
A neighbour on the same networkNot applicableThe “public network” profile and a firewall
A twin with a strong signalThe traffic, yesLittle, but the damage is limited

The highlighted row is the unit’s centre: only one technique produces real damage today, and encryption has nothing to do with it. It is not a technical attack — it is a request that gets answered.

Why phishing became the real threat on public networks

It is worth drawing the threads together, because it changes where to put your attention.

Ten years ago public Wi-Fi was a problem of interception: people went there to read other people’s traffic, and it worked.

Today the traffic is unreadable, and anyone wanting credentials has a much simpler route: set up a page that asks for them. It requires no technical skill, it requires decrypting nothing, and it has a high success rate because it exploits a context where the request looks legitimate.

The result is that effective defence on public networks looks more like the defence against phishing than the defence against interception: it is not a tool to install, it is a rule to apply — what am I about to hand over, and to whom?

Where these techniques concentrate

Not all places are equal. Setting up a fake network takes a minimal but non-zero investment — equipment, a presence on site — and so it concentrates where the return is greatest.

PlaceAttractivenessWhy
Airports and stationsVery highMany people, all waiting, all connected
Trade fairs and conferencesVery highA professional audience, company devices
Large hotelsHighGuests connecting for days
Shopping centresMediumPlenty of footfall, little dwell time
Cafes and restaurantsLowFew people at a time
Libraries and universitiesLowManaged networks, often with individual credentials

The first two rows share a characteristic worth noting: not knowing the correct network’s name is normal there. In a cafe you can ask at the counter; in a large airport, with dozens of networks visible and nobody to ask, verification is far harder.

That is exactly where the two habits that do not depend on recognition count most: hand nothing to the portal, and use your phone’s data for what matters.

There is then a seasonal factor worth a line: periods of heavy travel — holidays, returns, big events — concentrate in the same place many people who are tired, in a hurry, and need the connection right away. It is the combination in which critical judgement works worst, and it is why the useful decisions get taken before setting off.

How the defence is put together

Three actions, in order of effectiveness.

1. Do not hand real credentials to the portal. It covers the only technique producing certain damage.

2. Turn off automatic connection and delete old networks. It covers the two techniques acting without you choosing anything.

3. Ask for the network’s exact name. It covers the main technique at source.

Everything else — traffic encryption, detecting alterations, protecting content — already happens without you having to do anything. It is why this recommendation, despite its air of technical complexity, comes down to three simple actions.

What does not belong to this family

Drawing boundaries helps, because “Wi-Fi attack” gets used for very different things.

Phishing received by email while you are connected. It has nothing to do with the network: it would have arrived anyway. The network is just where you happened to be.

An app collecting data. It is a question of permissions, covered in another unit. It happens identically on a home network.

The theft of a device while you work in a cafe. It is a real and frequent risk in that context, but it belongs to the units on screen locking and encryption.

Somebody reading your screen from behind. That too belongs to the physical context, not the network — and it is statistically likelier than all six techniques described above.

A home router being compromised. It concerns a network you control, and the defence is different: router updates and a changed administration password.

The useful distinction: this family includes only what exploits the fact that the network is not yours. Everything else would have happened anyway, elsewhere.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that the attack shifted from the traffic to the choice
SkillsRecognising which technique encryption does not cover
Secure BehaviourApplying three rules instead of looking for a tool

Reference level: FL3 — Autonomous.

Summary

  • The techniques shifted from traffic to deception: attacking the traffic is no longer worthwhile.
  • Network names cannot be verified: it is the point almost everything else rests on.
  • Only one technique produces certain damage: the portal asking for real credentials.
  • Effective defence resembles the defence against phishing: a rule, not a tool.

One thing to do today. Decide now, calmly, what you will answer the next time a Wi-Fi portal asks you for an email and a password. The decision taken now is worth more than any judgement made with a suitcase in your hand.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.