CYBER WELFARE

Protect your Digital Privacy

Protecting traffic on public networks: what does what

Many proposed solutions circulate on this subject, and most of them solve a problem that is already solved. This post lines up what protects what, so a choice can be made on the basis of what is actually needed.

It expands on the recommendation sensitive data on public Wi-Fi.

The four layers of protection

On a public network there are four independent layers, and each covers something different.

LayerWhat it protectsWho provides it
1. Network encryptionThe radio link between device and routerWhoever runs the network
2. Site encryptionThe content exchanged with each individual siteThe site
3. A tunnel (VPN)All the traffic up to an exit pointA provider you choose
4. Device configurationThe device’s exposure on the networkYou

The most common mistake is thinking they are alternatives. They are not: they act on different stretches of the route. Layer 2 does the heavy lifting, and it is already there.

Layer 1 — Wi-Fi network encryption

It concerns only the stretch between your device and the router.

Kind of networkEncryption of the radio linkWho can read
Open, no passwordAbsent on older networksWhoever is in range, with simple tools
Open, recent standardsPresent, individualOnly whoever runs the network
With a shared passwordPresent, but a common keyWhoever knows the password
With individual credentialsPresent, individualOnly whoever runs the network

There is a little-known positive detail: the more recent standards encrypt the radio link even on open networks, giving each device its own key. They do not verify the network’s identity — so they do not protect against a fake network — but they remove passive listening by the other customers.

In every case, this layer ends at the router. From there on the traffic is in the hands of whoever runs the network, and it is layer 2 that protects it.

Layer 2 — Site encryption

It is the layer that counts most, and it is the one you already have without doing anything.

Every site encrypts its own connection independently, from your device to its own servers. Whoever runs the network, whoever watches it, whoever provides it: none of them can read the content.

What it covers: content, credentials, data entered into forms, apps’ messages.

What it does not cover: which sites you contact, and what you type into the sign-in portal — which is outside this protection because it happens before.

That is why public networks are usable today and were not ten years ago. The network did not change: the web did.

Layer 3 — The tunnel

A VPN creates an encrypted channel between your device and a server you choose. All the traffic passes through it, and comes out from there.

What changes concretely:

AspectWithout a VPNWith a VPN
Traffic contentAlready encrypted by the sitesEncrypted twice
Which sites you contactVisible to whoever runs the networkVisible to the VPN provider
The sign-in portalNot encryptedNot encrypted: the VPN starts afterwards
A fake networkThe risk is presentThe risk is present
Apparent locationYoursThe server’s

The three middle rows are the ones told least often.

A VPN does not remove observation: it moves it. Whoever runs the network no longer sees which sites you contact; the VPN provider does. It is an improvement only if you trust the second more than the first — which, on an airport’s network, is often true, but is worth saying rather than assuming.

A VPN does not protect the portal, because connecting to the portal precedes the tunnel starting.

A VPN does not tell you which network you joined. If the network is fake, it stays fake: it simply will not see your traffic.

When it genuinely makes sense. When you cannot choose the network and the destination itself is information you would rather not make observable; when you have to reach company resources; when you are in contexts where traffic observation is a concrete concern.

Layer 4 — Device configuration

The only layer entirely under your control, and the one covering the residual risks.

SettingWhat it prevents
Automatic connection turned offJoining a network with a known name but a different owner
Networks forgotten after useThe device looking for and revealing past networks
The “public network” profileOther devices reaching yours
An active firewallIncoming connections from the local network
A private network addressBeing recognised across different places

It is the layer with the best ratio of effort to result, because it covers exactly what the other three do not: the device’s behaviour before and during the connection.

The mobile connection: a case apart

It is worth explaining how it works, because it is the most recommended countermeasure in this unit.

A phone’s data connection has three properties setting it apart:

The radio link is encrypted by the operator, with individual keys tied to the phone’s SIM. It is not a network shared with other customers in the same venue.

There is no sign-in portal. The whole gap described in this unit simply does not exist.

The network’s identity is verified by the SIM, which recognises the operator. It is not possible to “connect by mistake” to somebody else’s mobile network with the same name.

An intermediary remains — the operator — with visibility over the metadata, exactly like any internet access provider. But from the point of view of this unit’s specific risks, a mobile connection closes nearly all of them with no configuration at all.

What does not work as promised

For completeness, and without naming names.

Programs that “protect your Wi-Fi”. Many do no more than check the network’s settings and show a verdict. The traffic was already protected before and stays protected afterwards.

Antivirus “insecure network” warnings. They report that the network is open or uses a dated standard. It is correct information, but it concerns layer 1 — the one layer 2 makes largely irrelevant.

Free VPNs. A VPN service has real infrastructure costs. If you are not paying them, something else is — and in this case what the provider has to monetise is exactly the traffic you are entrusting to it. It is the opposite of what you were looking for.

The case of the corporate VPN

It deserves a distinction, because its logic differs from a personal one.

A corporate VPN does not exist to protect the user’s traffic: it exists to bring the device inside the organisation’s network, so it can reach internal resources not exposed to the internet.

Two practical consequences follow:

The traffic leaves from the company’s premises, so the organisation sees the browsing — declared in the policies and legitimate on a work device, but worth knowing if the same device is also used for personal things.

Security stops depending on whichever network happens to be chosen, which is the real reason it is required on mobile devices. With the VPN on, whether the connection comes from a hotel’s Wi-Fi or an airport’s makes little difference.

If you use one, two points of care: check it is on before working — many disconnect when the network changes — and do not turn it off for convenience when it slows things down, because that is the moment it stops doing its job.

How to choose, in practice

Your situationWhat you need
I browse, read and work on non-confidential thingsLayers 2 and 4: you have the first, configure the second
I have to do a banking operationA mobile connection
I reach company resourcesThe organisation’s VPN
I do not want the network to know which sites I visitA paid VPN you trust
I am in a high-confidentiality contextVPN + mobile connection + care with the portal

The first row covers most everyday situations. For most people, device configuration is worth more than any additional tool.

How to judge a VPN provider, if you decide to use one

Since a VPN moves observation rather than removing it, the decisive question is who you are trusting. A few concrete criteria, in order of importance.

The business model. A VPN service has significant infrastructure costs. If it is free, those costs are covered another way, and what the provider has to sell is the traffic you entrust to it. It is the most decisive criterion of all.

The logging policy. What it states it keeps, for how long, and in which jurisdiction. A generic declaration of “we keep nothing” is worth little without detail.

Independent verification. Some providers submit to external audits of their practices. It is the only element turning a declaration into something verifiable.

The legal seat and jurisdiction. It determines which retention obligations and which requests the provider is subject to.

Transparency about ownership. Knowing who owns the service is basic information that not every provider makes easy to find.

Behaviour if the connection drops. An option blocking the traffic if the tunnel breaks stops data leaving in the clear without you noticing. Check it exists and is on.

An honest clarification: none of these criteria can be fully verified by a user. Choosing a VPN is, ultimately, a choice of trust. That is one more reason to use one when it is genuinely needed, rather than as a generic precaution.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsTelling the four layers apart and what each one covers
AwarenessUnderstanding that a VPN moves observation, it does not remove it
Secure BehaviourChoosing the tool according to the real risk

Reference level: FL3 — Autonomous.

Summary

  • The four layers are not alternatives: they act on different stretches.
  • Layer 2 — site encryption — does the heavy lifting and is already there.
  • A VPN moves observation from the network’s operator to the VPN provider.
  • A mobile connection closes nearly every risk in this unit with no configuration.

One thing to do today. Before looking for a tool, check layer 4: automatic connection off, old networks deleted, the “public network” profile. It costs five minutes and covers more than many paid solutions.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.