Working From Home
4 min readBy ARK Computer Repair technicians

Staying safe on public Wi-Fi

Public Wi-Fi used to be genuinely dangerous: anyone on the network could read what you were doing. Almost every website is encrypted now, so the old horror stories are largely out of date.

Some real risks remain, though, and they're not the ones people worry about.

What's still worth worrying about

The threats that survive are about who you're connecting to, not what passes over the air.

  • Fake hotspots named to look official — "Hotel Guest WiFi Free" sitting next to the real one
  • Sign-in pages that ask for far more than they need, or ask you to install something
  • Certificate or security warnings in the browser, which you should never click past on a public network
  • File sharing left switched on, exposing folders to everyone else on the network
  • Someone simply reading your screen over your shoulder

Simple habits that cover most of it

None of this requires extra software.

  • Ask staff for the exact network name rather than guessing from the list
  • Turn off automatic joining of open networks, so your phone doesn't reconnect to a fake one later
  • Set the network as Public on Windows, which switches off sharing
  • Use your phone's own mobile hotspot for anything sensitive — it's usually faster anyway
  • Keep the device patched, and keep antivirus running

Does a VPN help?

It genuinely does two things: it stops the network operator and anyone else on it seeing which sites you visit, and it protects you on badly configured or hostile networks. On a hotel, airport or conference network that's worth having.

What it doesn't do is make you anonymous or protect you from phishing, malware or a weak password. Treat it as one sensible layer rather than a shield. If you use one, pay for a reputable service — free VPNs make their money by selling the very browsing data you installed them to protect.

For people working away from the office

If work data travels with you, a VPN stops being optional. So does full-disk encryption (BitLocker on Windows, FileVault on a Mac), because the realistic loss is a laptop left on a train rather than anything clever happening over Wi-Fi.

Make sure remote access to the office goes through a VPN or a properly secured gateway with two-factor authentication — exposed remote desktop is still one of the most common ways businesses are breached.

More from the advice centre