NETWORK AND WIFI SECURITY CyberArtical Editorial Team

The look-alike hotspot, and why the old public Wi-Fi warning missed it

A mobile phone mast mounted on the corner of a building against a clear blue sky

Walk through any city with Wi-Fi enabled and your phone will find dozens of open networks: cafés, transport, hotels, shops, and a few with names that look official but belong to nobody you can identify. The standard warning about this situation — never do anything sensitive on public Wi-Fi — has been overtaken. The FTC’s current position is that "connecting through a public Wi-Fi network is usually safe" because "most websites do use encryption to protect your information." That does not mean nothing has changed. It means the risk moved.

What the FTC says now

  • "In the past, if you used a public Wi-Fi network to get online, your information was at risk."
  • "Today, most websites do use encryption to protect your information" and "connecting through a public Wi-Fi network is usually safe."
  • The residual risk is the destination: scammers "create fake websites and encrypt them to make you think they’re safe when they’re not."
  • "Your data may be encrypted on its way to the site, but it won’t be safe from scammers operating the site."
  • FBI: "Do not trust a website just because it has a lock icon or ‘https’ in the browser address bar."

How the old warning worked, and why it expired

The original concern was interception. On an open network, traffic travelled in the clear, so anyone within range with the right software could read what you sent — including credentials typed into websites that did not encrypt their login pages.

That threat depended on unencrypted websites, and those have largely gone. The FTC now contrasts the two eras explicitly: in the past your information was at risk; today most websites use encryption, and connecting through public Wi-Fi is usually safe.

The warning did not stop being repeated when the condition it depended on disappeared. That is worth noticing generally: security advice tends to outlive its evidence, because repeating it feels cautious and correcting it feels reckless.

What someone on an open network can still do

The interception threat shrank; it did not become nothing, and the shape of what remains is different from what people expect.

The clearest remaining case is a network that is not what it claims to be. Anyone can create a wireless network and name it whatever they like — the name of the café you are sitting in, or something plausible like the venue’s name with "Free" attached. Devices that reconnect automatically to remembered names make this easier than it should be.

What that gets an operator is control of the route: which server your device reaches when it asks for an address, and therefore an opportunity to send you somewhere. It is best understood as a delivery mechanism for the fraud that follows, rather than as eavesdropping.

The captive portal, and what it is allowed to ask for

The sign-in page that appears when you join a public network is the friction point worth being careful about, because it is a web page you did not choose to visit, presented at a moment when you expect to be asked for something.

A legitimate portal might reasonably ask you to accept terms, enter a room number, or provide an email address. It has no business asking for a payment card for a free network, for the password to any other account, or for you to install anything. Requests to install a certificate or an application to "access the network" should end the session.

If a portal wants an account, treat it as a throwaway. A network sign-in is not a good reason to reuse a password you care about.

What gives a fake network away

  • Nobody can tell you the network name. Ask staff. A venue that offers Wi-Fi knows what it is called; two similar names is a genuine warning sign.
  • The portal asks for more than access requires — card details for a free service, an account password, or a download.
  • Certificate warnings appear. NCSC treats the ability to bypass these as something to remove entirely, and the FTC’s rule is to heed browser warnings. On an unfamiliar network, a certificate warning is a stop signal, not a formality.
  • You end up somewhere you did not navigate to, particularly a login page for a service you were not using.

What actually matters in public, in order

Notice what is not on that list. The FTC’s public Wi-Fi article does not mention VPNs at all; its four recommendations are recognising HTTPS, strong passwords, two-factor authentication, and spotting fraudulent websites.

  1. Read the address bar before entering anything. The FBI’s rule is to check for misspellings or wrong domains — an address that should end in .gov ending in .com, for example.
  2. Reach important sites by typing the address or using a saved bookmark, rather than following a link or a search result.
  3. Have a second factor on your accounts, ideally a passkey or security key. The FTC’s own public Wi-Fi guidance names two-factor authentication as one of its four recommendations.
  4. Turn off automatic joining for open networks so your device does not reconnect to a name it once saw.
  5. Do not install anything a network asks you to install.
  6. Treat the padlock as meaningless for judging honesty — the FBI’s PSA exists precisely because criminals fit valid certificates to fraudulent sites.

If something goes wrong on a public network

If you entered credentials somewhere you now doubt, change that password from a device on a network you trust, and check the account’s active sessions and enrolled second factors.

Report a fraudulent site to the FBI’s IC3 and to the FTC at ReportFraud.ftc.gov. If you handed over card, bank or Social Security details, IdentityTheft.gov is the route — it produces a personal recovery plan rather than simply recording a complaint.

And if you were pushed to the fake site by a message rather than the network, forward phishing emails to reportphishing@apwg.org and phishing texts to SPAM (7726).

Sources: FTC — Are public Wi-Fi networks safe? · FBI IC3 — PSA I-061019 on the lock icon and HTTPS · NCSC UK — Managing web browser security · FTC — How to recognize and avoid phishing scams · FTC — IdentityTheft.gov

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, the FBI and NCSC UK. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories