This guide will not tell you to avoid public networks. They are useful, and with encryption everywhere they can be used with reasonable calm.
It will tell you instead which five settings to change once, and which two habits to adopt. With that done, the subject is closed and you do not have to think about it each time.
It puts into practice the recommendation sensitive data on public Wi-Fi.
The five settings
1. Turn off automatic connection
It is the most important of them all. A device that reconnects by itself to any network with a name it has seen before will also connect to a copy with the same name.
On Android: Settings → Network and internet → Internet → the settings icon beside the network → turn off “Connect automatically”. Also check, in the general Wi-Fi preferences, that the options for connecting automatically to open or “high quality” networks are off.
On iPhone: Settings → Wi-Fi → tap the “i” beside the network → turn off “Auto-Join”. On the main Wi-Fi screen, set “Ask to Join Networks” to “Ask” or “Notify”.
On Windows: at the moment of connecting, untick “Connect automatically”. For networks already saved: Settings → Network and internet → Wi-Fi → Manage known networks.
On macOS: System Settings → Wi-Fi → Advanced → untick “Auto-join” for public networks.
2. Forget networks after use
Every saved network is a name the device looks for and might reconnect to. Hotel, airport and cafe networks are of no further use after the stay.
It is the same settings screen as above: look for “Forget this network” or “Remove”.
How many do you have? Many devices have dozens, accumulated over years. It is worth clearing them out once, and then keeping it that way.
3. Declare public networks as such
When you connect to a new network, the system asks what kind it is — with wordings like “public network” or “private network”, or by asking whether you want the device to be discoverable.
Away from home the correct answer is always “public” or “no”. That turns off file and printer sharing and makes the device less visible to the others connected.
If you answered wrongly in the past, it can be corrected in the network’s properties.
4. Check the firewall
On every modern system it is on by default, but a check is worth it — it is the defence stopping other devices on the same network reaching yours.
Windows: Windows Security → Firewall and network protection.
macOS: System Settings → Network → Firewall.
On a phone: not needed, the system exposes no listening services.
5. Turn on network address privacy
Recent devices can present a different identifier to each network, making it harder to be recognised and followed from one place to another.
Look in the network’s settings for an entry like “Private address”, “Randomised address” or “Private Wi-Fi” and turn it on. On recent devices it is already on by default.
The two habits
Habit 1 — Phone data for the things that count
It is the most effective countermeasure in this unit, and it needs no configuration at all.
A mobile connection is encrypted over the radio link by the operator, is not shared with other people in the same venue, and has no sign-in portal. For a bank transfer, a banking session, or opening a confidential document, using it removes the whole category of problems.
If you are on a computer, the phone can share its connection — the feature is called tethering or personal hotspot.
The opposite case holds too: if data use is a constraint, use the public network for everything else and switch to data only for those few minutes.
Habit 2 — Never real credentials in the portal
The sign-in portal is the only unencrypted part of the connection, and it is where the risk concentrates.
| What it asks for | What to do |
|---|---|
| Only accepting the terms | No problem |
| An email address | Use a secondary one |
| Email and a password | Create a new password for the occasion |
| Signing in with a social account | Refuse: it grants real permissions |
| Payment details | Consider whether it is really needed |
| To install something | Always refuse: no legitimate network requires it |
The last two rows admit no exceptions. A portal asking you to install a certificate or a program is not a network to trust: change network or use your phone’s data.
Before connecting: check the name
It sounds trivial and it is the point where almost everybody goes wrong, because a network’s name cannot be verified by the device.
Ask for the exact name from whoever runs the place, instead of inferring it from the list. In an airport or a station, the official name is usually shown on the signs.
Be wary of variants. If you see Hotel_WiFi and Hotel_WiFi_Free, one of the two may not be the hotel’s. When in doubt, ask.
Be wary of open networks with no portal in places where one would be expected. An airport asking for nothing is unusual.
Prefer the network with individual credentials, where one exists — the hotel’s, tied to your room number, for instance. It is no more encrypted, but it can be verified: only the hotel could have given you that code.
The case of travelling abroad
It deserves a few lines, because it is the context where this recommendation counts most.
Network names are in a language you do not know, the reference points are less familiar, and the temptation to connect to anything is stronger because mobile data can be expensive.
Three practical points:
Check the cost of data before leaving. Many operators offer options abroad at contained prices; knowing you can use them changes the choices you make on the spot.
Do the sensitive operations before leaving, or at the hotel on data, not in the lobby or at the airport.
On your return, clear out the saved networks. A trip easily adds a dozen.
What to do when the portal asks you to register
It is the most frequent situation and the one where most mistakes get made, so an explicit procedure is worthwhile.
First question: do I really need this network? If you have enough data and you will be there for half an hour, the answer is often no. That is the quickest solution of all.
If you do need it, look at what it asks for.
| Request | Answer |
|---|---|
| Accept the terms | Proceed |
| An email address | Use a secondary address, not your main one |
| First and last name | You can give them: they open nothing |
| A password | Create a new one, used only there and nowhere else |
| Sign in with a social account | Refuse: it grants real permissions on your account |
| A phone number | Consider it: it is data allowing you to be contacted again |
| Payment details | Only if the service really is paid and you want it |
| Installing something | Always refuse |
A secondary address is the most elegant solution. Five minutes to create one, and from then on every network registration, hotel Wi-Fi, free trial and occasional service goes through it. It receives nothing important, it is connected to nothing, and it does not appear in the breaches that matter.
On the password vault, a practical note. If you use one, generating a new password for the portal takes three seconds and it is already saved. It is a case where the tool you have for other reasons solves this too.
What is not needed
For completeness, some things often recommended that solve less than people think.
A VPN, if the problem you fear is your traffic being read. That is already encrypted. A VPN has a real use, but a different one, and it is covered in another unit.
Avoiding public networks entirely. It is a disproportionate sacrifice: browsing, reading and working on non-confidential documents does not expose the content.
Programs promising to “protect your Wi-Fi”. The traffic is already protected by the sites; what stays uncovered — the portal, the choice of network — no program can handle for you.
A fifteen-minute plan
If you would rather do it all at once than a piece at a time.
Minutes 1-5 — Clearing out the saved networks. Open the list on your phone and delete everything that is not home, office and the two or three places you actually return to. On many devices that is dozens of entries: it is the longest part and the most useful.
Minutes 6-9 — The settings. Automatic connection off for the networks that remain; the “ask before connecting” option on; a private network address on.
Minutes 10-12 — The computer. The same settings, plus checking the firewall and the network profile.
Minutes 13-15 — The rest. Tablets, a second laptop, family members’ devices if you manage them. And, if you do not have one, create the secondary email address to use for portal registrations.
Once that is done, there is no need to come back to it except after a trip, to clear out the networks accumulated. It is two minutes of maintenance now and then, not a daily habit.
How your device stands right now
Three questions to see where you are starting from, before configuring.
How many networks are saved on your phone? If it is more than ten, you have a surface of exposure accumulated without noticing.
Has your phone ever connected by itself to a network in a new place? If so, automatic connection is on and working exactly as designed — which in this case is not what you want.
What password did you use the last time you registered on a Wi-Fi? If it is the same as some real service’s, it is the one thing in this unit to sort out today.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Configuring automatic connection, network type and firewall |
| Secure Behaviour | Phone data for sensitive operations, never credentials in the portal |
| Awareness | Telling the useful precautions from the ineffective ones |
Reference level: FL2 — Beginner. The step to FL3 comes when the five settings are on across every device.
Summary
- Turning off automatic connection is the single most useful setting.
- The sign-in portal is the only unencrypted part: never real credentials, never installations.
- For the operations that count, your phone’s data closes the whole category of problems.
- A network’s name cannot be verified by the device: you ask.
One thing to do today. Open your phone’s Wi-Fi settings, look at the list of saved networks and delete the ones from places you will not return to. Then turn off automatic connection on the ones that remain.
Related content
- Sensitive data on public Wi-Fi — the recommendation this guide comes from
- Signs of an untrustworthy Wi-Fi network — what to notice before and after connecting
- Protecting traffic on public networks — the technologies available and what they do
- Impact of untrusted networks — why these settings count
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



