User Tools

Site Tools


public_wi-fi

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
public_wi-fi [2019/08/04 16:31] neilpublic_wi-fi [2021/07/06 09:26] (current) – external edit 127.0.0.1
Line 1: Line 1:
 =====Using public Wi-Fi===== =====Using public Wi-Fi=====
 It can often be convenient to connect to public Wi-Fi. But bear in mind that you are connecting to a fundamentally untrusted third party network. It can often be convenient to connect to public Wi-Fi. But bear in mind that you are connecting to a fundamentally untrusted third party network.
-====Key tips:==== +====Key points:==== 
-  * provide fake details where you can +  * [[#Provide fake details where you can|Provide fake details where you can]] 
-  * if you have to give an email address, give a unique one +  * [[#If you have to give an email address, using a unique one|If you have to give an email address, give a unique one]] 
-  * run a VPN over the connection, as soon as you can +  * [[#Don't let your devices join public Wi-Fi networks automatically|Don't let your devices join public Wi-Fi networks automatically]] 
-  * if in doubt, don't connect: tether your phone instead+  * [[#Run a VPN over the connection, as soon as you can|Run a VPN over the connection, as soon as you can, or use Tor]] 
 +  * [[#Connect using your phone instead|If in doubt, don't connect: tether your phone instead]]
  
 ====Provide fake details where you can==== ====Provide fake details where you can====
 You'll often be asked for your title, name, and possibly even your address or other irrelevant information. You'll often be asked for your title, name, and possibly even your address or other irrelevant information.
  
-There's no law (in Englandwhich requires thisand so the Wi-Fi hotspot operator is only asking for them because they are going to use them for something.+If you can get away with giving fake details (i.e. you can be comfortable that you are not committing an offence, such as fraud), it might be sensible to do so.
  
-If you can get away with giving fake detailsit'sensible to do so.+(Alternatively, you could read their terms of serviceand their privacy notice, but there'no guarantee that they actually do what they say they do, and you're probably better of protecting yourself rather than relying on them anyway.)
  
 ====If you have to give an email address, using a unique one ==== ====If you have to give an email address, using a unique one ====
-If you need to sign up with an email address, use a [[unique_email_addresses|unique email address]] for that service.+If you need to sign up with an email address, use a [[passwords#use_a_unique_email_address_and_a_unique_password_for_every_site_and_service|unique email address]] for that service.
  
-====What data do they collect?==== 
-What are they doing with your data? Selling it? 
-Reading their privacy policy. 
-====Encrypted?==== 
-Is the network encrypted? Not all public Wi-Fi networks encrypt the communication between your computer or phone and the wireless access point which broadcasts the Wi-Fi signal.  
-====Who is the operator?==== 
-Even if the connection is encrypted, how do you know that it is not some rogue third party operating the access point? 
  
-Anyone can set the broadcast name of a Wi-Fi network  — what is known as the SSID — to anything they like.+====Don't let your devices join public Wi-Fi networks automatically====
  
-But if anyone can set any network name that they wanthow do you know that the network called “Starbucks”, for example, is actually operated on behalf of Starbucks? It could be anyoneincluding someone just sitting with device in their bag, pretending to be the Starbucks network, and capturing the traffic you send across their network.+Even if the connection is encrypted, you cannot be sure that it is a "genuine" access pointand not one run by rogue third party. Anyone can set the broadcast name of a Wi-Fi network — what is known as the SSID — to anything they like.
  
-====Disable automatic Wi-Fi connections==== +So even if you see a network called “Starbucks”, for example, it might not be operated by Starbucks, and could just be someone sitting with device in their bag, pretending to be the Starbucks network, trying to capture the traffic you send across their network.
-If you permit your device to connect automatically to known networks, may connect to rogue network, and start sending data over to an unknown third party before you even realise it. +
-====Captive portals==== +
-Wi-Fi which requires login page (a “captive portal”): requires you to connect to it without going through your VPN, you’ll need to connect to their login page directly.+
  
-You will need to communicate with a “captive portal” without connecting to the VPN, and that give an opportunity for a malicious actor to acquire information from your device, or see where your device is trying to send traffic. +If you permit your device to connect automatically to known networks, it may connect to a rogue network, and start sending data over to an unknown third party before you even realise it. 
-====VPN==== + 
-If you do want to rely on the Wi-Fiprobably want to run a [[virtual_private_networks|VPN session]] over it. Or you could use [[tor|Tor]].+When you join a network, your operating system may prompt you to say if you want to "remember" the network, or join automatically in future. If it doesn't prompt you, you may need to go into your computer's settings, and tell it not to connect automatically. 
 + 
 +For example, in macOS, you need to untick the box "Automatically join this network"
 + 
 +{{:screenshot_2019-08-04_at_17.53.09.png?400|}} 
 + 
 +====Run a VPN over the connection, as soon as you can==== 
 +If you do want to use the Wi-Fi, run a [[virtual_private_networks|VPN session]] over it. Or you could use [[tor|Tor]]. 
 + 
 +Some Wi-Fi networks block VPNs, and some block Tor. In those cases, don't use that Wi-Fi network — why would you want to trust a network which is trying to stop you operating securely? Consider [[#Connect using your phone instead|tethering]] instead. 
 + 
 +===Wi-Fi which requires a login may not work if you use a VPN=== 
 +Wi-Fi which requires a login page (a “captive portal”) may not work if your VPN is attempting to connect automatically. Typically, a captive portal requirse you to connect to it without going through your VPN, as you need to connect to their login page directly. 
 + 
 +If you need to communicate with a “captive portal” without connecting to the VPN, that gives an opportunity for a malicious actor to acquire information from your device, or see where your device is trying to send traffic. 
 + 
 +The best approach is to avoid these hotspots. 
 + 
 +====Connect using your phone instead==== 
 + 
 +If you do not trust the network less than you trust your mobile network operatoryou may be better off connecting your computer to the Internet via your phone's data plan. This is commonly known as "tethering"
 + 
 +You might want to run a [[virtual_private_networks|VPN]], or use [[tor|Tor]], over the top of your mobile connection anyway. 
 + 
 +You can normally tether via a USB cable, or else over Wi-Fi or Bluetooth. Using Wi-Fi or Bluetooth has the advantage that you can leave your phone in your pocket, but it comes at the cost of draining your //phone's// battery more quicklyConnecting via a cable is usually more reliable, but may drain your //computer's// battery more quickly, as it is probably charging your phone too. 
 + 
 +===Tethering on iOS === 
 + 
 +If you use an iPhone or iPad, rather than calling it "tethering", Apple calls it "Personal Hotspot". By default, this is turned off, but you can enable it in Settings / Personal Hotspot. 
 + 
 +Guidance for setting it up is [[https://support.apple.com/en-us/HT204023|here]].
  
-But, for the reasons discussed above, particularly in the context of “captive portal” Wi-Fi, it is not a perfect solution. 
  
-Good guidance from the National Cyber Security Centre: 
-https://www.ncsc.gov.uk/guidance/end-user-devices-common-questions 
-====Alternatives: tethering==== 
-May be better off connecting to your phone, rather than relying on some questionable Wi-Fi. Depending on how much you trust your mobile phone provider. 
public_wi-fi.1564936265.txt.gz · Last modified: 2021/07/06 09:26 (external edit)