How does public Wi-Fi work?
When setting up public Wi-Fi, security is often given less attention than the quality of the connection. But if the network doesn't even have a password, traffic between your device and the router is definitely sent without encryption, so theoretically anyone sitting next to your laptop could intercept your data.
There are networks where you need to be authorized before connecting: you can usually meet them at airports or hotels. When you connect to such Wi-Fi, a page opens with authorization - by room, ticket or phone number. Such networks appear to be more secure, but the difference is not as great as it might seem. Authentication using a room or phone number can help you understand who was using the network if something happens, but it does not protect your data. In addition, scammers do not have to connect to this particular Wi-Fi. But first things first.
What is sniffing?
This is the name for the process of intercepting and analyzing network traffic. That is, a person on the same network as you turns on the “network vacuum cleaner” and simply collects all the traffic that is transmitted over Wi-Fi. For this, Wi-Fi adapters are used - small devices that improve the quality of wireless communications. On some models, you can enable the so-called “wiretapping mode” - and the device will receive all data packets on the air. These data are then analyzed by special programs. This way you can see, for example, device requests, MAC addresses and other service data. By themselves, they do not provide full access to someone else’s device, but scammers use all this as “intelligence”: to understand which users are on the network, how they behave and what services they use.
Now sniffing is not as dangerous as it used to be. Most modern websites operate using the HTTPS protocol, which means their traffic is encrypted. Yes, sniffers can see the metadata and domains you request. For example, that you visited YouTube, as well as where and what time it happened. But what exactly you watched or what password you entered is no longer there.
How can they give you a fake website?
Another threat is a Man-in-the-Middle attack. Imagine: you are sitting in a cafe, connected to the local Wi-Fi, working or paying bills. At this moment, there may be another person between you and the router - a scammer.
Using a Wi-Fi adapter, a hacker can send fake technical messages to the network: for example, “tell” other devices that his laptop is a router. And after that, your phone will send all traffic not to the real router, but to the scammer’s computer. It studies the data and then sends it further to the router to establish a connection between you and the site (but with itself as an intermediary).
If such an attack is combined with phishing or fake security certificates, the consequences can be very serious. For example, they can intercept your work email or session in a banking application, which means they can steal money from your account.
Technically, this happens in different ways. Typically, attackers change the path to the site and show you a fake page - almost like a real bank or post office. You enter your password, and it goes to the scammers.
Attackers may also try to transfer the connection to an unsecured HTTP version of the site or slip in a fake TLS certificate - this is a “digital passport” of the site, which confirms that you have really connected to the desired service. The browser will warn you about a suspicious connection, but if you force the site to open, the attack may work.
It is quite difficult to notice such manipulations - in general, the Internet will look as usual. The only strategy that works is to not ignore browser warnings and use a VPN. The latter creates an encrypted tunnel between your device and a separate server. Even if someone on the same public network intercepts the traffic, they only see the encrypted data and cannot spoof or redirect the connection within the network.
How to deceive people through the name of the network?
The third threat is called Evil Twin. For example, Wi-Fi at an airport is called Airport_FREE, but there is another one in the list of available networks - with exactly the same or very similar name. You connect to it, but it turns out to be fraudulent.
Sometimes you don’t even need to press anything: if the network copies the name and settings of the real one, and its signal is better, the phone may try to connect to it on its own if you have auto-connection to familiar networks turned on.
Network doubles appear regularly. For example, in 2024, a man was detained in Australia for setting up fake Wi-Fi points in airports and even on airplanes during domestic flights. Passengers saw the familiar name of the network and connected. Users were redirected to a fake page with the airline's logo. And in order to “gain access to Wi-Fi,” people were asked to enter their email or social network password.
The man saved all logins and passwords, and then went through the victims’ accounts, collected personal photos and videos, including intimate ones, and gained access to other services where the same passwords were used. As a result, the hacker was sentenced to more than seven years in prison for creating evil twin networks and stealing personal data.
How to protect yourself from all this?
Everyone needs to use public Wi-Fi sometimes. The best way to do this safely is to use a reliable VPN. A good service encrypts all your traffic and reduces the risk of packet interception.
Here are some more ways to keep your data secure:
Public Wi-Fi is not evil in itself. When you need the Internet somewhere outside the home, open networks are very helpful. Just remember that you are not alone in this network.