Additional resource for the lesson “Wi-Fi Security: When a Connection Is Safe Enough” — Online Security course
Wi-Fi security used to be a simple rule: never do anything important on a public network. That rule is now out of date, and the honest version is more useful — most of what mattered is handled by the encryption every site already uses.
A. Why this matters
Wi-Fi carries everything: messages, email, passwords, banking, work files. For years the advice was that a public network meant anyone nearby could read all of it.
That was true, and it largely stopped being true. Nearly every site now uses HTTPS, which encrypts the content between your device and the site regardless of the network in between. Somebody on the same café Wi-Fi can generally see which sites you visited, and not what you did there.
The key idea: the network is no longer where most of your protection comes from. Understanding what it still exposes is more useful than avoiding it entirely.
What remains worth knowing: how to recognise a network that should not be trusted, what a VPN does and does not do, and how to secure the one network you control.
B. Key concepts
Seven ideas, including the two that changed.
Public Wi-Fi
An open network in a café, hotel, airport or station, usually with no password or a shared one.
Why it matters to you: Others on the same network can see which sites you connect to. With HTTPS, they cannot see the content — which is most of what people worry about.
HTTPS
The encryption between your browser and the site, indicated by the padlock. It is now the default across the web.
Why it matters to you: This is what made the old advice out of date. It is also why the useful habit is checking the address rather than avoiding networks.
Your home network
A private network protected by a password, using WPA2 or WPA3 encryption.
Why it matters to you: The one network you actually control. The companion resource on home network security covers what to change on the router.
WPA2 and WPA3
The encryption standards protecting a wireless network. WPA3 is current; WPA2 is still acceptable.
Why it matters to you: If your router still offers WEP or WPA, it is old enough that the encryption is the smallest of its problems.
Evil twin hotspots
A network deliberately named to look like a legitimate one — the café’s name, the hotel’s name — set up by someone nearby.
Why it matters to you: This is the risk that did not go away. Connecting is voluntary, so the defence is checking the exact name with staff rather than picking the plausible one.
VPNs, honestly
A VPN encrypts your traffic to the provider’s server, then it continues normally from there.
Why it matters to you: It hides your activity from the local network and your internet provider, and moves that visibility to the VPN provider instead. Useful in specific situations; not the general protection it is often sold as.
Captive portals
The sign-in page that appears when you join a hotel or airport network.
Why it matters to you: Worth knowing that these legitimately intercept your connection to show the page — which is also why a page appearing unprompted later is worth a second look.
C. A practical example: the airport network
You are at an airport and two networks appear with almost the same name. One belongs to the airport; one does not.
If you connect to the wrong one
- Whoever runs it can see which sites you visit.
- With HTTPS, the contents of those sessions remain encrypted.
- They can, however, present a convincing sign-in page and hope you enter something into it.
Which is the real risk here: not interception, but a page asking for credentials that looks like it belongs to the network, the airline, or a service you use.
The habits that cover it
- Ask which network is the right one, rather than choosing the plausible name.
- Do not enter credentials on any page that appears because you joined a network.
- Let your password manager decide: if it does not offer to fill, the address is not the one you saved.
- Use mobile data instead when it matters and you are unsure.
Notice that three of those four are the same habits as the phishing resources. The network changed; the underlying skill did not.
D. Try it yourself: two checks
One at home, one for the next time you travel.
Step 1 — Your home network
- Open your router settings and confirm the encryption is WPA2 or WPA3.
- Confirm the Wi-Fi password is not the one printed on the router, and is not shared with anything else.
- The companion resource on home network security covers the rest of the settings.
Step 2 — Your phone’s saved networks
- Look at the list of networks your phone reconnects to automatically.
- Remove the ones you will not use again — a hotel from two years ago, a conference network.
- Turn off automatic joining of open networks, which is what makes an evil twin effortless.
Step 3 — Decide your own rule for public networks
- A reasonable one: ordinary browsing is fine; banking and anything you would not want associated with you goes over mobile data.
- Not because interception is likely, but because the decision is then already made.
Step 2 is the one worth doing today. Most phones carry a long list of remembered networks, and each one is a name an attacker could reuse.
E. Videos, articles and further resources
Independent and institutional sources in English.
CISA — Securing your home Wi-Fi
Practical router settings for the network you control, from the US cyber security agency.
https://www.cisa.gov/audiences/high-risk-communities/projectupskill/module5
NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
FTC — Online privacy and security
Consumer guidance covering home networks and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security
Electronic Frontier Foundation — Surveillance Self-Defense
Deeper background on what encryption protects and where a VPN fits.
https://ssd.eff.org/
CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online
Links checked in August 2026.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Secure Behavior pillar at level FL2, and involves unlearning advice that used to be correct.
Skills
- Checking the encryption and password on your own network.
- Managing the list of remembered networks on a phone.
- Recognising a captive portal and knowing what not to enter into one.
For professionals and organizations
- Providing guidance that matches how the web works now, rather than repeating advice from a decade ago.
Awareness
- Understanding that HTTPS changed what a public network can see.
- Recognising the evil twin as the risk that remains, and that connecting to it is a choice.
- Knowing what a VPN moves rather than removes.
For future instructors and ambassadors
- Correcting the old advice openly. People trust guidance more when it acknowledges what has changed.
Secure Behavior
- Confirming the network name rather than assuming.
- Not entering credentials on pages that appear after joining a network.
- Using mobile data for the things you would rather keep off an unknown network.
For organizations
- Providing mobile data allowances rather than expecting staff to judge each network (R10, R11).
G. Questions to sit with
- How many networks does your phone remember and reconnect to automatically?
- Do you know the encryption setting on your own router?
- When you last joined a public network, did you check the name with anyone?
- Do you have a VPN? If so, what did you expect it to protect, and does it?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database on connections.
Connections
- R9 — Connect over HTTPS only, and check the address before entering anything.
- R10 — Avoid reaching sensitive services over a network you do not control.
- R11 — Use a VPN when you need to handle confidential information away from a trusted network.
Minimum commitment: R11 is worth reading alongside the honest description above: a VPN moves the visibility rather than eliminating it.
The network you control
- MS10 — Consider a VPN at router level for a more advanced home setup.
- MS5 — Use a browser that defaults to secure connections.
- R6 — Keep the router firmware updated, which is the setting most often left alone.
In short
- HTTPS changed the picture: a public network sees where you go, not what you do.
- The evil twin is the risk that remains, and joining one is a choice you can check.
- A VPN moves visibility from the local network to the VPN provider.
- Clear the remembered networks on your phone — it is a short list of names someone could reuse.
Related resources in this course
The network you control, and what runs on it:
- Home Internet Security: Protecting Your Life
- Setting Up a VPN on Your Home Router
- The Importance of Secure Browsers for Online Protection
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply