A network does not come with a label. The name is chosen by whoever sets it up, and the device has no way to verify it.
What is left are indirect clues: things you notice before connecting, during the connection, and afterwards. This post lines them up and — just as importantly — separates the ones that count from the ones with ordinary explanations.
It expands on the recommendation sensitive data on public Wi-Fi.
Before connecting
Two networks with almost identical names
It is the most significant clue in the whole unit. Hotel_WiFi and Hotel_WiFi_Free, or the same name with and without a padlock, or with one letter different.
A venue runs one network for customers. The presence of almost identical variants is anomalous, and the correct response is to ask which is the right one — not to pick one.
An open network where a protected one would be expected
An airport, a chain hotel, a station offering a completely open network with no portal at all is unusual: almost every large operator requires at least an acceptance of terms.
A signal too strong for the place
A network showing up very strongly at a point where the venue’s router cannot be — outside, say, or on a different floor — may be coming from equipment near you rather than from the venue’s infrastructure.
It is a weak clue on its own, but it adds to the others.
A network that has only just appeared
If you regularly use a place and see a network appear that was not there before, with a plausible name, it is worth a question.
While connecting
The portal asks for more than it needs
It is the most important signal and the easiest to recognise.
| What the portal asks for | Assessment |
|---|---|
| Accepting the terms | Normal |
| An email address | Common, often for commercial purposes |
| First and last name | Frequent, and debatable but not anomalous |
| A password | Anomalous: it is not needed to give access to a network |
| Signing in with an existing account | Anomalous: it asks for real permissions |
| Payment details for a free service | Anomalous |
| Installing a certificate or program | Stop: no legitimate network requires it |
The four highlighted rows share one element: they ask for something not needed to make a connection work. It is the most reliable criterion in this unit.
The portal does not resemble the place
A chain hotel will have a page with its own branding. A generic page, in the wrong language, with obvious errors or with no reference to the venue at all, is out of place.
Certificate warnings on several different sites
If opening three different sites produces three certificate warnings, the problem is not the sites: it is whoever is in between. It is one of the strongest clues available, and the correct response is to disconnect immediately.
Every site passes through an intermediate page
A screen appearing before every destination, even after you completed the sign-in, indicates the traffic is being handled by somebody along the route.
After connecting
The device connected by itself. If you notice you are connected to a network you did not choose, the device recognised a known name. It does not mean that network is hostile — it means the mechanism that could take you there exists and is on.
A sign-in alert on an account. If a sign-in alert from an unusual location arrives after using a network, the link is likely.
More unwanted messages. The typical effect of an email address left in a portal: annoying but not serious.
A program behaving differently after a download made from that network.
What is NOT a signal
Essential, because constant alarm leads to ignoring everything.
| What | Why it is not a signal |
|---|---|
| An open network with no password | Many venues offer them that way, for simplicity |
| A portal asking for an email address | Ordinary commercial practice |
| A certificate warning on the portal alone | Common: the portal intercepts the first connection |
| A slow network | It is a bandwidth question, not a security one |
| A strange or jokey network name | Names are chosen freely, often for fun |
| Many networks visible in the same place | In a city centre it is the norm |
| A network asking for your room number | It is a correct verification method, not a risk |
The last row deserves attention because it looks intrusive and is in fact a good sign: a code only the venue could have given you is the only form of network-identity verification available to a user.
The hierarchy of clues
They do not all weigh the same. In descending order:
| Clue | Weight | Action |
|---|---|---|
| A request to install something | Maximum | Disconnect at once |
| Certificate warnings on several sites | Maximum | Disconnect at once |
| A portal asking for a password | High | Do not enter one, use throwaway data or give it a miss |
| Two networks with almost identical names | High | Ask which is the right one |
| A portal that does not resemble the place | Medium | Enter nothing real |
| An unwanted automatic connection | Medium | Turn the setting off |
| A network that appeared recently | Low | Noticing it is enough |
The first two rows are the only ones requiring an immediate reaction. All the others are handled simply by handing nothing over.
The signals on your device, not on the network
Some clues concern your device’s behaviour, and they are useful because you can check them calmly, at home, without having to decide on the spot.
The list of saved networks is very long. If it holds dozens of entries from places you visited once, the device is looking for all those names every time the Wi-Fi is on. It is not a sign of compromise: it is a surface of exposure accumulated with nobody looking at it.
The device connects in places where you never configured it. If your phone shows as connected in a new place, there is a network with a name matching a saved one.
The Wi-Fi turns itself back on. Some systems have an option that switches Wi-Fi back on near known networks even after you turned it off. It is a convenience, and it is worth knowing about.
A manually installed certificate. In the security settings there is a list of certification authorities added by the user. On a personal device it should be empty. If it is not, and you do not remember installing anything, it is the most serious signal this unit can produce.
Unusual battery or data use after a trip. A weak clue, but if it coincides with others it is worth looking at what was installed recently.
These checks take five minutes and get done now and then, not at every connection. It is how this recommendation becomes sustainable: not continuous vigilance, but a periodic check.
The most useful signal is a question
Let us close with the most practical thing in the whole unit, which is not technical.
Before connecting to a network in a place where there is somebody to ask — a cafe, a hotel, an office — ask for the network’s exact name. It takes five seconds and removes at a stroke the whole category of fake networks, which is this unit’s main risk.
It is the only verification of a network’s identity available to somebody with no technical tools, and it works better than any indirect clue listed above.
Why these signals are weaker than elsewhere
A useful admission, because it avoids giving this unit more weight than it can bear.
In the other contexts of this series there are verifiable clues: a sign-in log, a forwarding rule, a connected device, a browser warning. They are facts, there to be consulted.
Here it is not so. A network’s name is not a verifiable fact — it is a freely chosen label. The Wi-Fi signal says nothing about who is transmitting it. A well-made portal is indistinguishable from a legitimate one.
One practical thing follows: in this unit prevention counts far more than detection.
| Approach | Effectiveness here |
|---|---|
| Recognising a fake network from clues | Low: the clues are weak |
| Asking for the network’s exact name | High |
| Handing nothing to the portal | High: it makes the rest irrelevant |
| Turning off automatic connection | High |
| Using your phone’s data for what counts | High |
The four effective rows have one thing in common: they work regardless of whether you manage to recognise the network. They do not require a correct judgement — they require a habit.
It is a structure worth keeping in mind whenever the available clues are weak: when you cannot tell the good case from the bad one, the defence is not to tell them apart better — it is to behave so that the distinction does not matter.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Knowing that a network’s name cannot be verified by the device |
| Skills | Telling an ordinary request from an anomalous one in a portal |
| Secure Behaviour | Asking for the network’s name instead of inferring it |
Reference level: FL2 — Beginner.
Summary
- The most reliable criterion: the portal asks for something not needed to make a connection work.
- Certificate warnings on several sites on the same network: disconnect at once.
- Many clues have ordinary explanations: an open or slow network is not a signal.
- The best check is not technical: asking for the network’s exact name.
One thing to do today. The next time you connect to a venue’s Wi-Fi, ask for the network’s name before looking at the list. It is the action that makes every other clue in this post unnecessary.
Related content
- Sensitive data on public Wi-Fi — the recommendation this expands on
- Attacks on public Wi-Fi — the techniques these signals reveal
- How to use public Wi-Fi safely — the settings that reduce the exposure
- Signs of an unprotected connection — what the browser’s warnings say
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



