How to Protect Your Data on Public Wi-Fi Networks

cyber

Connecting to a public Wi-Fi network is always a risk. Most public access points are not protected in any way. They are installed so that visitors stay longer in cafes and shopping centers. At the same time, no one thinks about users’ personal data.

An information security specialist hacked into a wireless network without any training and gained access to all the data that passengers were transmitting to the internet.

In this article, we will look at the threats associated with public wireless networks and ways to protect against them.

Types of attacks

“Man in the middle” is the name of the hacker attack that the Sapsan was subjected to. To understand the essence of the attack, you need to understand how a Wi-Fi network works.

A wireless network consists of clients (user devices) and an access point (router), which serves as a signal source and a window to the internet. Usually, the client and the router send data directly to each other.

The easiest way to attack a Wi-Fi network is to intercept information halfway between clients and the access point. In this case, the hacker acts as a Wi-Fi signal repeater. They receive signals from clients sent to the router, store the information they contain, and send it on.

You don’t need to be a highly skilled hacker to carry out this attack. All you need is the right set of programs and a smartphone. What’s more, it’s virtually impossible to detect this type of interference on your own. To do so, you need to know the parameters of the real router and the exact time it takes for the signal to travel through the wireless network.

Another popular type of attack is called “evil twin,” in which the hacker uses their own access point. With it, they can set a trap — launch a new open network, name it “Name of a popular mobile operator” Free Wi-Fi, and wait for unsuspecting users.

If you add a powerful radio transmitter, you can copy the settings of the real access point, then jam and replace the signal. In this case, the smartphone may connect to the fake network automatically.

In both cases, all the data that the user sends to the Internet goes to the attacker.

The hacker does not have to wait for the user to decide to open the banking app. The fraudster can change the data transmitted between the client and the router and, under a plausible pretext, redirect the user to a fake banking page.

This attack is more effective and dangerous than MITM. Until recently, it required skill and training, but now it has become much easier to purchase pre-configured equipment to carry it out.

What data is at risk?

Hackers can access all information transmitted via a compromised wireless network. They are most interested in:

  • emails and chat messages;
  • files sent, such as photos;
  • passwords and other confidential information;
  • login details for various services.

In addition to hackers, store owners, advertising agencies, and spammers are also interested in the data of public Wi-Fi users. Don’t be surprised if, after connecting to Wi-Fi in a store, you see advertisements for its products all over the internet for a long time.

Wi-Fi networks are a reliable source of information for marketers and business owners. Which websites do customers spend more time on than they are interested in buying? Formally, no laws are being broken, but collecting such data threatens the privacy of ordinary users.

The phone number required to access the internet, as well as the unique MAC address of the connected device, can be used to target banner ads that will follow the user across the internet.

Protection methods

Following even the simplest recommendations significantly increases security on open Wi-Fi networks:

  • Refrain from shopping. First and foremost, it is important to remember that you should not visit banking websites or make purchases using public Wi-Fi networks. You should also avoid using email and logging into social media accounts. You will likely only realize how much important information is stored there once it has been stolen.
  • Avoid logging in. Regular internet surfing and watching videos via public Wi-Fi are relatively safe, but even then, it is best to avoid logging in. If you do not use password managers, your passwords are likely to be repeated, and an attacker could use them to access more important websites.
  • Do not share your main phone number. To avoid unwanted advertising calls, it is better to get a separate SIM card for connecting to public access points.
  • Read the user agreement. Before using public Wi-Fi, you are usually asked to accept a user agreement. It often includes consent to collect user information and send advertisements. There may also be a clause giving the access point owner permission to share the collected information with other parties.
  • Before checking the box or clicking “agree,” it is worth at least skimming through the agreement. Suspicious clauses are easy to spot.
  • Do not install anything. You do not need additional programs, certificates, or browser extensions to connect to Wi-Fi — these are all tricks that hackers use to gain access not only to data on the Wi-Fi network, but also to the device’s hard drive.
  • Turn off Wi-Fi when you no longer need a connection. This will protect your device from automatically connecting to fake access points.
  • Smartphones periodically check email and messengers on their own to display pop-up notifications. If the device is using an unsecured Wi-Fi network at that moment, data can be stolen. In addition, you will slightly extend the battery life.
  • Connect via HTTPS. This protocol provides an encrypted connection. With it, it will be much more difficult for a hacker to steal your data.
  • Use a VPN. A virtual private network provides the highest level of security when connecting to public Wi-Fi networks. It protects both sent and received data with encryption. The encrypted data stream is sent to the VPN provider’s server and from there to the recipient, whether it is a website, mail server, or other service.

A VPN makes using public networks almost completely safe, but it is important to choose a provider you can trust.

Conclusion

The creators of Wi-Fi are also concerned about the lack of security of their technology. In 2018, they completed the development of an update that should protect wireless networks from hackers.

However, it will be some time before Wi-Fi hotspots that meet the new security standards are installed everywhere. In addition, hackers have already discovered vulnerabilities in them. Unfortunately, connecting to public Wi-Fi will continue to carry risks for a long time to come.

As with many other aspects of information security, the decision to use or not use public Wi-Fi boils down to a trade-off between security and convenience.