There is one thing that makes this unit different from the others: much of what people fear is no longer true, and what they should be wary of is almost never mentioned.
This post tries to line the two up, because a badly described risk leads to the wrong precautions — usually too many in the useless direction and none in the one that counts.
It expands on the recommendation sensitive data on public Wi-Fi.
What whoever runs the network sees
The right question is not “is the network secure?” but “what does whoever runs it see?”.
| Information | Visible on an untrusted network? |
|---|---|
| The content of encrypted pages | No |
| Credentials typed on encrypted sites | No |
| Messaging apps’ messages | No |
| Which sites you contact | Largely yes |
| Which apps you use and when | Yes, partly |
| Your device’s name and type | Yes |
| What you type into the sign-in portal | Yes, in the clear |
| The time and length of your stay | Yes |
The last two rows are the centre of this unit: the sign-in portal is the only unencrypted part of the connection, and it is exactly the point where some networks ask for data.
The fourth row deserves an honest clarification: the content is protected, but the list of sites you visit can largely be reconstructed. That is data saying a great deal — which banks you use, which services, what interests you have — without a single line being read.
1. Confidentiality: the profile, not the content
A practical example
Two hours of work from a hotel’s Wi-Fi. All the traffic is encrypted.
What the incident looks like
Whoever runs the network reads nothing of what you do. But they can build a profile: which services you use, how often, at what times, for how long.
For most people that has no practical consequence. It weighs for anyone with specific reasons for confidentiality — a negotiation under way, a delicate professional activity, a personal situation they would rather not make observable.
The serious exposure of confidentiality here is a different one, and it does not pass through the network: it is what you type into the sign-in portal. That is in the clear and goes straight to whoever built the page.
What to watch for
- the portal asks for a password as well as an email address;
- the portal asks for more data than it needs to identify you;
- the registration offers to sign in with an existing social account.
What to do
In the portal, minimal data and never real credentials.
2. Integrity: the residual risk
A practical example
A download started from an airport’s network.
What the incident looks like
With encryption everywhere, altering traffic in transit is largely prevented: the browser detects the alteration and refuses the content.
Two gaps remain:
The sign-in portal, which, being in the clear, can contain anything — including a request to install a certificate or a program “needed for the connection”. No legitimate network needs one.
Downloads from unencrypted sites, now rare but still present on dated portals.
There is then a third case, which concerns not the traffic but the device: on a shared local network, other connected devices can try to reach yours. If file sharing or listening services are on, that is a real point of contact.
What to watch for
- requests to install certificates or programs to access the network;
- certificate warnings on several different sites on the same network;
- the system asking whether to make the device discoverable on the network.
What to do
Answer “public network” to the system’s question, and never install anything a network asks for.
3. Availability: contained but real
A practical example
The hotel’s network blocks some services or is so slow it makes them unusable.
What the incident looks like
Whoever controls the network decides what passes. In most cases these are ordinary limitations — blocking bandwidth-heavy services, content filters — not hostility.
The practical impact is one of convenience rather than security. It becomes relevant in one case: if a connection to a critical service breaks off in the middle of an operation, it is worth checking the outcome before repeating it.
What to do
For operations that cannot tolerate interruption, your phone’s data.
| Aspect | Risk on a public network | Where it concentrates |
|---|---|---|
| Confidentiality | Medium | In the sign-in portal, not in the traffic |
| Integrity | Low-medium | Portal, downloads, local exposure |
| Availability | Low | Ordinary filters and limitations |
The risk nobody names: the device that goes looking
There is an exposure happening before you even connect, and almost nobody considers it.
A device with automatic connection on is continuously looking for the networks it knows. To do so, in some conditions, it broadcasts their names.
That produces two effects:
It reveals where you have been. The list of saved networks tells habits: the name of your home network, your office’s, a hotel’s, a bar’s. Put together, they are a trail.
It makes a made-to-measure network possible. Whoever watches which networks your device is looking for can create one with that name. The device, recognising it, connects by itself — without asking anything.
It is why two trivial settings count for more than many complicated precautions: turning off automatic connection and forgetting public networks after use.
Who is more exposed than others
The risk is not uniform. Some categories of people have structurally higher exposure, and it is worth seeing whether you recognise yourself among them.
People who travel often for work. Dozens of different networks a month, many in unfamiliar settings, often with devices holding company material. It is the profile with the greatest cumulative exposure.
People who habitually work away from an office. Shared spaces, cafes, libraries. The exposure here is less about the network and more about the physical environment.
People handling third parties’ data. Professionals, consultants, anybody working with clients’ or patients’ information. Not because the technical risk is greater, but because the consequences involve people who did not choose that network.
People in roles of specific interest. Journalists, lawyers, researchers, people with significant corporate responsibilities. Here targeted observation stops being theoretical.
Teenagers and their devices. They tend to connect to any open network available, with automatic connection on and without weighing up the portals. It is the profile where configuration is worth more than advice.
For everybody else — most people, on most days — the real exposure on a public network is modest, and it is what the five rows of the earlier table describe.
What encryption actually solved
It is worth acknowledging, because it is why this recommendation is less restrictive today than ten years ago.
| Scenario | Before | Today |
|---|---|---|
| A password read off the network | Frequent | Practically ruled out |
| A session captured and reused | Frequent | Rare |
| A page altered in transit | Possible | Detected and blocked |
| Messages read in transit | Possible | No, the apps encrypt |
Four serious risks, all largely closed by a technology that is now on by default.
What remains is of a different nature: it is not an encryption problem, it is a misplaced-trust problem. And that is why the countermeasure is not technical but behavioural — check which network you are connecting to, and hand nothing over to its sign-in page.
The exposure that does not go through the network
There is a category of impact belonging to this recommendation that has nothing to do with technology, and which in practice is the most frequent of all: the physical environment.
Anybody using a public network is almost always in a public space. And in a public space:
| Exposure | What it means |
|---|---|
| The screen is visible | Whoever sits beside you reads documents, messages, notifications |
| The keyboard is observable | A typed password can be seen |
| Video calls are audible | Whoever is nearby hears both sides |
| The device is reachable | A moment of distraction and it is left unattended |
| Phone calls are heard | Numbers, names, information said out loud |
None of these is a question of encryption, of a VPN or of configuration. They are all questions of position and attention.
And they are far likelier to occur than any technique described in the unit on attacks: on a train, somebody reading your screen is nearly certain; somebody intercepting your traffic is remote.
The countermeasures are trivial and none requires tools: sit with the screen towards a wall, use a privacy filter on a laptop, turn off notification previews, postpone the delicate phone call, and — for confidential video calls — find an enclosed space or postpone.
It is worth saying explicitly because it is where this recommendation gets misunderstood most often: the main risk of working in a cafe is not the cafe’s network.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Telling the perceived risk from the current one |
| Skills | Understanding what stays visible despite encryption |
| Secure Behaviour | Turning off automatic connection and forgetting the networks used |
Reference level: FL2 — Beginner.
Summary
- The content of the traffic is no longer readable; the list of sites largely is.
- The only unencrypted part is the sign-in portal: that is where the risk concentrates.
- A device with automatic connection looks for known networks and can join a copy.
- Four historical risks are largely closed: what remains is about trust, not encryption.
One thing to do today. Open the list of Wi-Fi networks saved on your phone. Delete all the ones from places and hotels you will not return to: each is a name your device would reconnect to on its own.
Related content
- Sensitive data on public Wi-Fi — the recommendation this expands on
- Consequences of using a public network — the concrete effects
- Attacks on public Wi-Fi — the techniques exploiting these gaps
- How to use public Wi-Fi safely — the settings that close the exposure
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



