Skip to main content
SPARCS - Topic Of The Week

Public Wi-Fi -- Is It Really That Bad?

Spooky season has returned! It is only right that we dive into some spooky topics, and this week we’ll cover public Wi-Fi. Maybe you work from home and just want to run to a local coffee shop for a change of scenery during your workday, or maybe you are traveling and still want to get a few things done, or maybe you are moving across the country and don’t have a place to work or any other Wi-Fi option to use. Sometimes you can’t avoid a little bit of public Wi-Fi use, whether it is by force or by choice. While it isn’t the most secure option, public Wi-Fi isn’t evil either -- today we will discuss the risks involved with public Wi-Fi, how to help mitigate them, and how to appropriately use public Wi-Fi when doing work here at UMD.

How does Wi-Fi work?

Let's take a few steps back and quickly cover how Wi-Fi even works. When you want to have access to the internet, you need a connection to get there. Here is a quick flow of how your device and Wi-Fi work together to achieve that connection:

You authenticate to a Wi-Fi network using your device
↓
That network comes from a router, which assigns your device with an IP address
↓
You open a website on your device, your device looks up the website’s internet address, then sends that address (using your Wi-Fi) to the router
↓
Your router then sends the website internet address to your internet provider, and the internet provider carries the request to the website
↓
The website then sends the content back, from your internet provider, to your router, to your device
↓
Now you see the website content!

What are the risks associated with using public Wi-Fi?

While the standards for internet security have evolved, it is still important to understand what the risks are of using public Wi-Fi if you don’t have the adequate protections in place. Below are the biggest risks associated with connecting to public Wi-Fi networks:

Man-in-the-middle attacks

This is when an attacker is on the same Wi-Fi network as you and intercepts the messages sent between your device and its destination (such as the router, or the website).

“Evil twin” networks

This is when an attacker presents their own internet connection as the public one you are trying to connect to - such as a network named “Coffee Shop 1” instead of the actual coffee shop network, labeled “Coffee Shop”. Once you connect to the attacker’s Wi-Fi network, they can access all data being sent between your device and the Wi-Fi network.

Network snooping

This is when an attacker is observing what messages are being sent over a network. To achieve this, your messages must not be encrypted, and the attacker would need to have established a method for examining that traffic.

Unpatched devices

If you are accessing a public Wi-Fi network and your device isn’t properly patched, an attacker using the same network can exploit these vulnerabilities to gain access to your information.

Good ole’ shoulder surfing

Let’s not forget, the old fashioned ways can still be effective! If you are in public and using your device, people may easily be able to view your screen and see what you are doing.

How can you limit these risks?

On the bright side, by adding some small tweaks to your device usage you can protect yourself substantially from the risks outlined above.

  • Browse websites that are encrypted: Nowadays, website connections are commonly protected through encryption from the website itself, meaning the messages the website sends to your device are not interceptible. To check if a website is encrypted, look at your search bar - you will see a “lock” symbol by the URL if it is encrypted.
  • Use a VPN: When you enable a VPN on your device, the VPN creates a private tunnel between your device and the VPN server. All communications in this private tunnel are inaccessible to attackers, even if you are on an unsecured network OR an evil-twin network!
  • Double-check that you are connecting to a legitimate Wi-Fi network: No one likes the evil twin. Make sure the network you are connecting to is not an impersonator, 
  • Keep your device up-to-date and patched: Device updates are important, as they may be resolving security issues identified by your device provider. Without updating these security issues, you are susceptible to someone using that weakness to their advantage.
  • Don’t leave your device unlocked and unattended, and consider facing your screen away from others' view: particularly if you are doing something you DON’T want others to see, like typing in your authentication information and then showing the password to make sure it is correctly typed.

At UMD

As an employee at UMD, it is important to understand what the best practice is when accessing public Wi-Fi networks while using your university-provided device to complete work. It is recommended by the Division of Information Technology to use your VPN when accessing campus resources and to avoid the use of unencrypted public Wi-Fi networks. Regardless of the Wi-Fi network being used, when you are working with sensitive information, the University of Maryland requires you to use your VPN. Don’t stop enjoying a coffee-shop work day, and instead make sure to familiarize yourself with what to do to keep coffee-shop work secure.

On
Back to Top