Public Wi-Fi just got riskier. Follow these 4 security tips

Welcome to Safe Mode, your weekly report for pressing security and privacy news—and what steps to take next. Want this newsletter to come directly to your inbox? Sign up on our website

It relies on a technique called ClickFix, where a popup appears with instructions that claim to fix a problem with an account or on your PC. Obviously, a phishing page is bad enough, but the malware deposited by this upgraded hack lets bad actors spy on you in addition to potentially stealing a Microsoft 365 account. And most people rarely question hotel Wi-Fi with a captive portal login system. At a property that nice, you’ll likely assume other users are a threat, not the portal itself.

So what should you do to stay safe when on public Wi-Fi, whether fully open or kept behind a portal? Here are the four things I always recommend:

  1. Ensure you’re on the official public Wi-Fi network. Smart hackers will create networks that sound similar to legitimate ones, hoping to catch people who aren’t paying close attention. For example, just the other day, I saw an “XfinityWifi” hotspot available in a location that seemed unusual.
  2. If you’re routed through a portal, pay attention to the instructions. Most will ask you to agree to terms before proceeding. Hotel portals may ask for your surname and your room number. No legitimate portal will tell you to run commands on your device, or input your login information for an account. (Especially an unrelated account.)
  3. Once connected, use a VPN. This sets up an encrypted tunnel, where all your web traffic routes through a secure server. If someone also on the same public Wi-Fi network as you tries to snoop on your activity, they will only see that you’re connecting to the VPN service. (Obviously, this method is only as good as the VPN you choose, so pick one that has strong security, plus a verified no-logs policy to maintain your privacy.)
  4. If you can’t use a VPN, avoid browsing insecure websites—anything that only has HTTP (no S) in the address. Such sites are not encrypted, meaning that anyone else on that public Wi-Fi network can see the exact data passed back and forth between your device and that insecure website. Also consider avoiding use of sensitive apps and websites (e.g., financial).

Of course, the easiest way to stay safe on public Wi-Fi is to just not use it. Cell phone connections are harder to hack—so keep using the data on your phone. If you need a connection for your PC, turn on your phone’s hotspot. If you have enough data on your plan, this solution requires the least amount of effort.

Table of Contents

In the news

Hackers of all stripes stayed busy this week. On one side, Def Con attendees showed off their skills at this year’s annual hacking and cybersecurity conference. (Also allegedly outside of it, too.) On the other, bad actors breached multiple companies, with a couple smaller leaks affecting consumers directly. A third data leak is huge and its impact remains to be seen.

Even now, insecure USB devices can end up compromising your PC.

Pexels: Karolina Grabowska

The bad

  • A European distributor of Steam Machines was hacked, prompting Valve to alert buyers that their names, addresses, phone numbers, email addresses, and order information may have been leaked. Those affected should screen emails, texts, and phone calls carefully for potential scam attempts.
  • Modular PC maker Framework also experienced a similar breach with names, email addresses, physical addresses, and phone numbers for “all customers” stolen. The leak was a result of a hack on partner Metabase, a business intelligence service.
Exit mobile version