Skip to content
BeginnerTax and safety

Using networks you do not control

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
4 min

In short

The main risk on public Wi-Fi is less eavesdropping than fake access points and fake sign-in pages. Do anything involving assets on a connection you control, and do not open balances in public. That avoids most of it.

Key points

  • Fake access points named almost exactly like the venue's are a real thing
  • The 'terms of use' or sign-in page that appears on connection is an easy thing to fake
  • Do anything asset-related on your mobile data or your home line
  • In public, the screen itself gets read over your shoulder

Definition

The risks of using networks you do not control — cafés, airports, hotels — and how to avoid them.

Now that transport encryption is standard, having your traffic read verbatim on public Wi-Fi is rarer. The realistic risks have a different shape. One is an attacker running an access point named almost exactly like the venue's — anyone can name a network anything, so the list of names tells you nothing about which is genuine.

The other is the page that appears the moment you connect. 'Accept the terms' and 'sign in with your email' screens are normal at real venues, which makes them an easy place to slip a fake in. Some ask for credentials; some tell you to install a certificate to continue. If you are ever asked to install a certificate, disconnect there and then.

In practice, keep the rule simple: check balances, log in to exchanges, withdraw and sign transactions only on your own connection — mobile data or your home line. On someone else's network, stick to maps and searching. A VPN prevents someone on the path from reading your traffic, but it does not stop you landing on a fake site and it does not stop anyone reading your screen. It is not a blanket solution.

Then there is the line of sight. Open your balance on a train or in a café and the person beside you can see it, and a figure seen is a reason to be targeted later. If you must check something while out, position yourself so the screen is not visible, do only what is necessary, and close it. Make a habit of not plugging your device into public charging cables or USB ports either.

Watch out for

  • · If connecting requires you to install a certificate or an app, disconnect immediately
  • · A VPN does not stop you reaching a fake site, nor anyone reading your screen
  • · Do not plug your device into public USB ports or cables

Frequently asked questions

  • I need to log in to my exchange while travelling abroad. What should I do?

    Use your own mobile data — roaming or a local data SIM — rather than public Wi-Fi. Also note that a login from an unusual country often triggers extra verification or a temporary hold, so settle any settings changes and planned withdrawals before you leave.

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start