CYBER WELFARE

Protect your Digital Privacy

Protect your mobile hotspot password: long, unique and changed often

You are on a train, the onboard Wi-Fi is not working and you need to send a file before a meeting. You switch on your phone’s hotspot, connect your laptop and within a minute you are online. It is so convenient that we use it without a second thought.

A hotspot, though, is more than a switch: it is a small Wi-Fi network that your phone creates around itself, visible to anyone within a few metres. Only one thing separates that network from strangers: the password. If it is short, obvious or has been shared with too many people over time, your connection and your data allowance become a little less yours.

This recommendation — R14 of the Cyber Welfare Framework — helps you choose a strong mobile hotspot password, keep it safe and renew it when needed. It does not require technical skills: two minutes in your phone’s settings and one habit to pick up are enough.

What this recommendation says

Recommendation R14 states that your phone’s hotspot should be protected by a long, unique password that is changed regularly, and in any case after you have given it to someone on a one-off basis.

First, a definition. A mobile hotspot (also called tethering, meaning “sharing your connection”) is the feature that lets your phone share its mobile data connection with other devices: your laptop, a tablet, a friend’s phone. Whoever connects goes online using your SIM and your data allowance.

The recommendation asks for three things:

  • a long password, hard to guess, made of unrelated words or of a broad mix of letters, numbers and symbols;
  • a unique password, used only for the hotspot: not your home Wi-Fi password, nor the password to any of your accounts;
  • a renewed password, because every device that has connected once remembers it and can reconnect on its own, even months later.

What it is not. It is not a call to stop sharing your connection, or to be suspicious of anyone who asks for it. Lending your hotspot is a normal and often helpful gesture: the recommendation simply makes sure that the sharing starts and ends when you decide.

Where it applies. To every phone or tablet with a data connection that you use as a hotspot, personal or for work, and to small portable routers that work the same way.

Why it matters

When the hotspot is on, your phone behaves like a router: it announces the network name to every nearby device and waits for someone to enter the right key. In busy places — a train, a waiting room, a café, an event — there are plenty of devices within range.

Many phones suggest a default password, sometimes adequate, sometimes short or built on a simple pattern. Then we often change it to something easy to read out: a child’s name, a date, “12345678”. That is understandable, because it is the password we give to other people most often. And that is exactly why it deserves some care.

The consequences of a poorly protected hotspot show up on four fronts:

  • data allowance used up — an unknown device can exhaust your monthly allowance or leave you with extra charges, especially abroad;
  • exposure of connected devices — anyone who joins the network shares the same space as your laptop, and can see it or try to reach it;
  • your connection used in your name — whatever a stranger does online through your hotspot is, at first sight, linked to your line;
  • slow connection and draining battery — more connected devices mean more work for your phone, just when you need it.

There is also a less visible side. A password given out “just this once” does not expire on its own: the recipient’s device stores it and reconnects automatically whenever your hotspot is switched on nearby. Without a periodic change, the list of people who can connect grows over time, and nobody keeps it up to date.

Benefit of a strong, renewed hotspot passwordWhy it counts
Keeps out anyone trying to guessA long password withstands repeated attempts far better than a short one
Protects your data allowanceOnly the devices you have authorised use your data
Protects connected devicesYour laptop stays on a network with only your devices or those of people you know
Closes old sharesChanging the password disconnects every device that remembered it
Puts you back in controlYou know who can connect, and you decide when they no longer can

A concrete example

Mark often works away from the office and uses his phone’s hotspot almost every day. The password has been the same for two years: the name of his football team followed by the year. Easy to remember, easy to read out.

Over those two years he has given it to plenty of people: a colleague on a business trip, his cousin at a family party, a client in a meeting room with no Wi-Fi, a fellow passenger on a train. Each time it was a favour lasting a few minutes.

One month Mark notices that his data runs out earlier than expected. Nothing serious has happened and there is no obvious culprit: some device that knew the password — perhaps his cousin’s tablet, perhaps a colleague’s laptop — simply reconnects whenever the network is within range.

Mark opens his settings, chooses a new long password, saves it in his password manager and checks the list of connected devices: now only his own are there. From that day on, whenever he lends his hotspot, he changes the password as soon as he is done. It takes him a minute, and the people who can connect are once again the ones he has in mind.

When to apply it

The rule always applies, but there are moments when it makes a real difference.

  • The first time you switch on the hotspot. It is the best moment to replace the default password with your own, long and unique.
  • After sharing it with someone. A colleague, a friend, a client, a fellow traveller: once the sharing is over, a new password closes the door without any need for explanations.
  • At regular intervals. Every two or three months is a reasonable rhythm if you use the hotspot often; if you rarely use it, you can change it when you switch it back on after a long break.
  • When travelling and in crowded places. Where there are many devices nearby, a weak password is put to the test more easily.
  • When you use it instead of public Wi-Fi. A personal hotspot is often a more cautious alternative to open networks, as the recommendation on how to avoid handling sensitive data on public Wi-Fi explains — provided it is protected in its turn.
  • When you notice something odd. Data running out early, connected devices you do not recognise, a hotspot that already seems to be in use: all good reasons to change the password straight away.
  • When you change phone or pass one on to a family member. The new device deserves a new password; the old one should not take the previous password with it.

How to apply it

A few steps are enough, and most of them only need doing once.

  1. Open the hotspot settings. They are usually in the network or connections section of your phone’s operating system: that is where you can see and change the network name and password.
  2. Choose a long password. A passphrase — a sequence of four or five unrelated words — is strong and easy to read out. Alternatively, use a mix of at least sixteen characters across letters, numbers and symbols, as the recommendation on sixteen character passwords explains. Avoid names, dates, teams and words linked to you.
  3. Make it unique. Do not reuse the password for your home Wi-Fi, your email or any other account. Someone who knows it for the hotspot must not be able to open anything else.
  4. Check the network protection. The same settings include the security type: choose the most recent option available, such as WPA3, or WPA2 if your phone offers nothing newer — these are the systems that encrypt, meaning they make unreadable to others, whatever travels across the network. Never leave the network “open”, without a password. Wi-Fi encryption has a recommendation of its own, R15.
  5. Keep it somewhere safe. A password manager — an app that stores your credentials in an encrypted vault — is the right place, because you can find the password when you need it and you are not tempted to pick an easy one. The recommendation on storing passwords safely covers this.
  6. Share it with care. Give it only to people who need it at that moment, ideally by showing it on your screen or through the QR code some phones offer, rather than typing it into a message that stays in your chats.
  7. Change it after every one-off share, and periodically anyway. The change disconnects every device that remembered the previous password. You can reconnect your own in a few seconds.
  8. Switch the hotspot off when you do not need it. A network that does not exist cannot be tried by anyone, and your phone uses less battery.

Common mistakes to avoid

  • Keeping the default password without looking at it. Sometimes it is adequate, sometimes not: it is worth checking and, if it is short or simple, replacing it.
  • Choosing a password “for reading out”. 12345678, password1, the dog’s name: handy to say aloud, but among the first to be tried.
  • Reusing your home or account password. Whoever received it for the hotspot unknowingly takes away the key to something else as well.
  • Assuming a shared password “expires” by itself. It does not: the other person’s device remembers it until you change it.
  • Sending it by message or writing it on a scrap of paper. Chats get forwarded, notes stay on the desk. Showing it on your screen is more discreet.
  • Putting personal details in the network name. Your full name, phone number or device model are visible to everyone around you. A neutral name gives away less.
  • Leaving the hotspot on all the time. A network that is always visible is a door that is always exposed, even when you are not using it.

How this connects to the Cyber Welfare Framework

R14 brings to connectivity the same principle the Framework applies to account passwords: a strong key, used in one place only, under your control.

PillarHow this contributes
SkillsKnowing how to find the hotspot settings, choose a long password and pick the most suitable level of protection
AwarenessUnderstanding that a hotspot is a real network, visible to the people around you, and that every share leaves a trace on other people’s devices
Secure BehaviourRenewing the password after every one-off share and switching the hotspot off when it is not needed

Digital maturity levels.

  • FL1 — Basic. You use the hotspot with the default password or a simple one, and you have never changed it. It is the most common starting point, not a fault.
  • FL2 — Beginner. You have set a long, unique password for the hotspot, you keep it somewhere safe and you change it when you remember having given it to someone.
  • FL3 — Autonomous. You change the password after every one-off share and at a regular rhythm, use the most recent protection available, switch the hotspot off when it is not needed and check the connected devices from time to time.
  • FL4 — Skilled. You treat the hotspot like any network you are responsible for: a neutral name, a limited number of devices, periodic checks and a routine that does not rely on memory.
  • FL5 — Expert-Guide. You help other people — in your family, your team, the colleagues you travel with — set up and manage their own hotspot in the same way.

R14 is a typical FL2 recommendation: it turns a forgotten setting into a conscious choice, and it prepares the ground for the regular habits of level FL3.

How to check you are applying it properly

Three questions, to be answered honestly.

  1. Could I say, without looking, how many people know my hotspot password today?
  2. Is my hotspot password different from my home Wi-Fi password and from the password to every one of my accounts?
  3. When did I last change my mobile hotspot password?

Quick checklist

  • ☐ My hotspot password is not the default one, or I have checked it and consider it adequate
  • ☐ It is at least sixteen characters long, or it is a passphrase of four or five words
  • ☐ It contains no names, dates or references to me or my family
  • ☐ It is not used for any other network or account
  • ☐ It is stored in a password manager or another protected place
  • ☐ I change it after every one-off share and at least every two or three months
  • ☐ The network protection is set to the most recent option available, never “open”
  • ☐ I switch the hotspot off when I am not using it

If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.

In short

Your phone’s hotspot shares your connection and your data allowance with others. The password is the only thing that decides who can get in: if it is short, predictable or has been given to too many people over time, that decision stops being yours.

The solution takes just a few steps: a long, unique password, the most recent protection available, a safe place to keep it, a change after every one-off share and at regular intervals, and the hotspot switched off when you do not need it.

Security here does not mean giving up the kindness of lending your connection. It means being able to offer it with peace of mind, knowing that the door closes again when you decide.

Something to think about. If someone asked you today for the list of devices that can connect to your hotspot, could you write it down?

Explore this recommendation

This recommendation is the pivot of a content unit. Each post looks at a different aspect.

Related resources

Short reads from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.