Most connections are now encrypted, which removes the classic interception risk. What remains is fake networks, unattended devices, visible screens, and the accounts you happen to be logged into.

What has changed

The advice about public networks is largely inherited from an era when most web traffic was unencrypted, and it has not kept up.

Nearly all sites now use encrypted connections, which means somebody on the same network cannot read what you are sending in the way they once could. Mail applications and business tools encrypt as well.

That removes the headline risk. It does not remove several others, and being precise about which is what makes sensible behaviour possible rather than vague anxiety.

What actually remains a risk

Networks that are not what they claim

Somebody creates a network named plausibly for the venue and waits. Connecting to it means your traffic passes through their equipment.

Encryption still protects the contents, and they can see which sites you visit, and can attempt to interfere with anything unencrypted.

The practical response is asking the venue for the network name rather than guessing from the list.

Certificate warnings

The one warning that genuinely matters on an untrusted network. A browser saying a connection is not private, on a site that normally works, is the signal that something is between you and the destination.

Clicking through it is the mistake. On a network you do not control, that warning should end the session rather than be dismissed.

The screen and the room

Frequently the largest real exposure and rarely mentioned. Somebody behind you can read a customer list, an invoice, or a password being typed.

Sitting with your back to a wall costs nothing and addresses more actual risk than most technical measures.

The unattended device

A laptop left open while you collect a coffee is an unlocked session containing everything. This is a more likely loss than any network attack.

Automatic reconnection

Devices remember networks and rejoin them, which means a device can connect to something with a familiar name without you noticing.

Removing saved public networks after use prevents it.

The tethering alternative

The simplest answer and the one most people overlook.

Using your phone's own connection removes the untrusted network entirely. Modern data allowances make this practical for ordinary work, and it is faster than most venue networks.

For anything involving banking, payroll, or client financial information, this is the sensible default rather than a precaution.

Whether a VPN helps

A qualified yes, and less than the advertising claims.

What it does: encrypts your traffic between your device and the provider, which hides your activity from the local network and from a fake access point.

What it does not do: protect you from a compromised device, prevent somebody reading your screen, or make an unencrypted site safe beyond the provider's exit point.

It also moves your trust rather than removing it, since the provider can see what the local network would have seen. That makes the choice of provider a real decision rather than a formality.

For most small businesses, tethering achieves the same practical benefit with less to think about.

Client sites specifically

A situation worth separating, because the network is not anonymous and the concerns differ.

A client's network is likely monitored and logged, which means your browsing there is visible to them. That is a reason to keep personal activity off it rather than a security risk.

It may also have restrictions that break your tools, so knowing you can fall back to tethering avoids an awkward afternoon.

And where you connect a device to a client network, it is worth removing that connection afterwards for the same reason as any saved network.

The proportionate habits

  1. Verify the network name with the venue.
  2. Never dismiss a certificate warning on an untrusted network.
  3. Lock the screen whenever you stand up.
  4. Tether for anything financial.
  5. Sit where your screen is not visible.
  6. Forget the network afterwards.
  7. Have two-factor enabled anyway, which limits the damage of a stolen credential regardless of how it was taken.

The last is the one that matters most and has nothing to do with the network, since a password captured anywhere is far less useful when a second factor is required, which is the same protection discussed in passwords when more than one person needs access.


Frequently asked questions

Is public wifi still dangerous?

Less than the inherited advice suggests. Nearly all sites now encrypt, which removes the classic interception risk, but several other exposures remain.

What is the main remaining network risk?

A network that is not what it claims. Ask the venue for the exact name rather than guessing from the list, and never dismiss a certificate warning.

What is the largest real exposure?

Usually the room rather than the network. Somebody reading your screen, or an unattended open laptop, is more likely than any network attack.

Does a VPN solve it?

Partly. It hides activity from the local network but does not protect a compromised device or a visible screen, and it moves your trust to the provider.

What is simpler than a VPN?

Tethering to your phone, which removes the untrusted network entirely and is the sensible default for banking, payroll, or client financial work.

What matters most regardless of network?

Two-factor authentication, since a password captured anywhere is far less useful when a second factor is required.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Staff working from client sites and coffee shops?

We set the handful of habits that address the real exposures, most of which are not about the network at all.

Start a Conversation