# How safe are public wireless hotspots?

**URL:** <https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661>\
**Category:** Factual Questions\
**Created:** [March 16, 2009, 8:27pm UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661 "2009-03-16T20:27:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [March 16, 2009, 8:27pm UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/1 "2009-03-16T20:27:00Z")

</div>

What are the security issues involved with public wireless hotspots? How can you protect yourself when working with a laptop outside the home or office?

What is a virtual private network (VPN) and does it help? Examples include [WiFi Guardian](http://www.pcworld.com/downloads/file/fid,70077-order,4/description.html) and [Hotspot Shield](http://www.pcworld.com/downloads/file/fid,71209-order,4/description.html). Why can’t I just use a decent firewall like ZoneAlarm or Comodo? (A?: It seems that the VPN operates via an external server. Huh? How does that help?)

What special considerations are involved with public wireless hotspots: what vulnerabilities exist for the laptop that has run Windows update within the past month and has a non-MS firewall and antiviral package?

Previous thread: [Airports, etc:“Free Public Wi-fi” network](http://boards.straightdope.com/sdmb/showthread.php?t=453700&highlight=wireless+hotspots). One poster quotes Cache, Johnny, and Vincent Liu. _Hacking Exposed Wireless: Wireless Security Secrets & Solutions_. New York: McGraw-Hill, 2007.

Google:  
[7 tips for working securely from wireless hotspots](http://www.microsoft.com/AtWork/stayconnected/hotspots.mspx)

[How do I safely use public wireless hotspots? (#8696)](http://www.dslreports.com/faq/8696)  
Bonus question/hijack: List recommended software for wireless public hotspots. How does that software work: what does it do and not do? I’m thinking about NetStumbler, but other tips are welcome.

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [March 16, 2009, 9:21pm UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/2 "2009-03-16T21:21:36Z")

</div>

The primary threats are basically like eavesdropping. If the wireless network doesn’t have any encryption, anyone can see what’s being sent between your computer and the access point. Whoever’s listening can pick out email passwords, login information to commerce or banking websites, credit card numbers if you buy things, etc. Setting up a VPN gives you an encrypted tunnel: your computer encrypts a message, sends it to the VPN server, which decrypts it and sends it on its merry way. It’s assumed that the VPN server is more secure than your public access point, since any schmoe with a laptop and the right experience can listen to everything that’s broadcast on a wifi connection.

Firewalls will help prevent someone trying to directly hack your computer, but they won’t stop anyone from listening to your communications.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [March 16, 2009, 9:58pm UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/3 "2009-03-16T21:58:05Z")

</div>

> [@lazybratsche](#):
>
> The primary threats are basically like eavesdropping. If the wireless network doesn’t have any encryption, anyone can see what’s being sent between your computer and the access point. Whoever’s listening can pick out email passwords, login information to commerce or banking websites, credit card numbers if you buy things, etc. …

Thanks lazybratsche.

But most ecommerce and financial sights work with SSL. Assuming that the bad guys don’t install a keylogger, how could they capture your password?

And if they do install a keylogger, a VPN wouldn’t help, would it? That’s what antivirals and firewalls are for.

Separately, if the VPN server isn’t wholly trusted, SSL would protect you from them, right?

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [March 17, 2009, 2:18am UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/4 "2009-03-17T02:18:40Z")

</div>

> [@Measure\_for\_Measure](#):
>
> Thanks lazybratsche.
> 
> But most ecommerce and financial sights work with SSL. Assuming that the bad guys don’t install a keylogger, how could they capture your password?
> 
> And if they do install a keylogger, a VPN wouldn’t help, would it? That’s what antivirals and firewalls are for.
> 
> Separately, if the VPN server isn’t wholly trusted, SSL would protect you from them, right?

You have to be sure that you’re accessing the SSL version of the site directly, i.e. http **s** ://www.mybank.com and not [http://www.mybank.com](http://www.mybank.com).

This is a subtle but dangerous difference and it’s a very easy mistake to make. If you leave out the “s” or if you simply type in “[mybank.com](http://mybank.com)”, your browser will take you by default to the insecure version of the site. Somebody controlling the router or acting as a fake wireless access point can show you a fake version of your bank site and get your login that way.

If you do any SSL stuff over a public wifi at all, make sure to have the SSL version bookmarked beforehand and use that every. single. time.

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [March 17, 2009, 2:20am UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/5 "2009-03-17T02:20:44Z")

</div>

If the access point is controlled by an attacker, I think they can even break SSL with a man-in-the-middle attack.

And, the same might even apply for a VPN…

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [March 17, 2009, 2:23am UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/6 "2009-03-17T02:23:51Z")

</div>

> [@lazybratsche](#):
>
> If the access point is controlled by an attacker, I think they can even break SSL with a man-in-the-middle attack.
> 
> And, the same might even apply for a VPN…

[del]Not typically, unless they can sign themselves as the proper owner of a given domain name – which doesn’t happen very often, and when it does, it’s usually due to human error on the Certificate Authority’s part – or they exploit some obscure browser/user flaw. SSL, when implemented and used correctly, is THEORETICALLY safe against man-in-the-middle attacks at least until the underlying math is broken.

ETA: I believe the same applies to VPNs with properly pre-configured keys, but don’t quote me on that.[/del]

Actually, I’m not so sure about this. Going to wait for someone more knowledgeable to chime in.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [March 17, 2009, 4:35am UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/7 "2009-03-17T04:35:07Z")

</div>

> [@Reply](#):
>
> You have to be sure that you’re accessing the SSL version of the site directly, i.e. http **s** ://www.mybank.com and not [http://www.mybank.com](http://www.mybank.com)…  
> If you do any SSL stuff over a public wifi at all, make sure to have the SSL version bookmarked beforehand and use that every. single. time.

Agreed, but how many banks have login screens that are not ssl secured? Often at least, the http site will _link_ to the https site, where you can login.

Another question: there are a number of sites that are not https, but claim that the password is nonetheless entered securely. I think Amazon does this; yahoo used to but no longer does; [www.inbox.com](http://www.inbox.com) does it now. Are they blowing smoke? It should be possible to encrypt the password but not the whole webpage, right?  
I also await with interest further elaboration on a man in the middle attack on SSL. Thanks for all the replies.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [March 17, 2009, 4:54am UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/8 "2009-03-17T04:54:11Z")

</div>

> [@Measure\_for\_Measure](#):
>
> Agreed, but how many banks have login screens that are not ssl secured? Often at least, the http site will _link_ to the https site, where you can login.

Sure, but if you make a habit of going to the insecure site, out of sheer force of habit you could very well fall for a lookalike hijacking site. Unless you check the SSL status or certificate after the redirection _every single time_, it’s entirely possible for a hijacker to put up a fake version of the insecure page, including redirecting to another legit-looking secure site.

It’s even worse when a bank uses more than one domain name legitimately (like Citi does for [Citi.com](http://Citi.com), [Citibank.com](http://Citibank.com), [Citicards.com](http://Citicards.com)) – it’d be way too easy for spammers to make a fake [Citibillpay.com](http://Citibillpay.com) or [Citicreditcheck.com](http://Citicreditcheck.com) or something similar and unsavvy consumers won’t think twice because Citi does that for everything else.

> [@](#):
>
> Another question: there are a number of sites that are not https, but claim that the password is nonetheless entered securely. I think Amazon does this; yahoo used to but no longer does; [www.inbox.com](http://www.inbox.com) does it now. Are they blowing smoke? It should be possible to encrypt the password but not the whole webpage, right?

Even if this is possible (and I think it is), it makes it incredibly difficult for the end-user to gauge whether a site is in secure mode. And, again, it’s even easier to fake for a hijacking.

---

<div class="post-metadata">

**Author:** ![c\_goat](https://avatars.discourse-cdn.com/v4/letter/c/f4b2a3/32.png) [@c\_goat](https://boards.straightdope.com/u/c_goat)\
**Post date:** [March 17, 2009, 2:58pm UTC](https://boards.straightdope.com/t/how-safe-are-public-wireless-hotspots/489661/9 "2009-03-17T14:58:15Z")

</div>

> [@Reply](#):
>
> Even if this is possible (and I think it is), it makes it incredibly difficult for the end-user to gauge whether a site is in secure mode. And, again, it’s even easier to fake for a hijacking.

Usually this means that only the login info is encrypted during the login process. So somebody listening would not be able to get your password because it’s encrypted before your computer sends it over the air. The problem is that once logged in, while you’re reading your email it might be unencrpyted over the air, so all the content of the email could be picked out by someone listening. Thus if you read an email that contains sensitive info someone else might see it. There was also a hack I read about that grabbed the login cookie from the air and was able to then use it to access the victim’s gmail account from the attacker’s computer. No password needed.

This is why I have [https://mail.google.com/mail](https://mail.google.com/mail) bookmarked on my laptop, so that everything is encrypted, not just the login. I also have a policy of never doing any online banking over wireless just in case.
