# PC use in large hotel -- what security protection is needed?

**URL:** <https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519>\
**Category:** Factual Questions\
**Created:** [May 6, 2010, 3:54pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519 "2010-05-06T15:54:24Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2010, 3:54pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/1 "2010-05-06T15:54:24Z")

</div>

I will be visiting a large hotel complex soon, and taking a Netbook (small laptop) computer just to stay in touch with everything. I will be using it to remotely administer some computers and read/write email, so I will have to transmit sensitive login info.

What precautions should I take to avoid revealing this info to the wrong people? I’m not worried about viruses, worms, etc., as I won’t be visiting any sites that I don’t already know. And I’ll have the software firewall turned on. But what about sending login info – I can’t encrypt it if the recipient isn’t expecting that. Can someone with a sniffer pick out critical components of packets as cleartext?

And if file & print sharing are turned off, no one can read or write data in my computer, right?

FYI, it’s a 10" Asus Netbook running Win 7 Starter, nothing fancy, just minimal configuration and WiFi connections to the Internet thru the hotel’s system.

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [May 6, 2010, 4:14pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/2 "2010-05-06T16:14:05Z")

</div>

VPN is the easiest and most reliable way to accomplish this. If the computers you’re administering are on your employer’s network, you should be able to set up a VPN connection. That gives you an encrypted tunnel to your employer’s network, so somebody sniffing packets at the hotel won’t be able to get any useful information. It should be as simple as going to your IT department and installing a VPN client.

You can also set up a VPN host on your home network, if that’s what you’re trying to connect to. I’ve never done this, but it shouldn’t be too hard, especially for someone that’s already remotely administering a few computers.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2010, 6:31pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/3 "2010-05-06T18:31:11Z")

</div>

> [@lazybratsche](#):
>
> VPN is the easiest and most reliable way to accomplish this. If the computers you’re administering are on your employer’s network, you should be able to set up a VPN connection. That gives you an encrypted tunnel to your employer’s network, so somebody sniffing packets at the hotel won’t be able to get any useful information. It should be as simple as going to your IT department and installing a VPN client.

The question isn’t how to administer stuff remotely (I do that all the time), but how to be sure that existing administration is not compromised by going thru a public connection.

I can’t set up VPN on a specialty server or an email server for shared accounts, anyway.

So the question is a security one.

---

<div class="post-metadata">

**Author:** ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)\
**Post date:** [May 6, 2010, 6:41pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/4 "2010-05-06T18:41:39Z")

</div>

If you don’t have a VPN server to connect to, but you do have an SSH server, then there’s also a pretty cool way you can set up a SOCKS proxy that causes all of your browser’s traffic to be encrypted between your PC and your SSH server, and then it goes unencrypted to the internet from there. This is perfect for an untrusted local network if you don’t want to go full-blown VPN, which is a lot more work to set up. The ‘PuTTY’ SSH client has this functionality on Windows.

If you have access to an SSH server and want to try setting this up, let me know and I’ll post more info.

---

<div class="post-metadata">

**Author:** ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)\
**Post date:** [May 6, 2010, 6:48pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/5 "2010-05-06T18:48:17Z")

</div>

> [@Musicat](#):
>
> The question isn’t how to administer stuff remotely (I do that all the time), but how to be sure that existing administration is not compromised by going thru a public connection.
> 
> I can’t set up VPN on a specialty server or an email server for shared accounts, anyway.

I think you misunderstand the suggestion. He’s not suggesting you use the VPN to connect directly to the server you want to administer, he’s suggesting you use VPN to connect to a network you trust, and then remotely administer the email/whatever server the normal way, as if you were physically sitting on the trusted network (e.g. the network back at the office). You’d use all the same potentially-unencrypted protocols, but the traffic is first sent to the trusted network over an encrypted tunnel, then from there to the server, it’s regular unencrypted traffic.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2010, 6:51pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/6 "2010-05-06T18:51:39Z")

</div>

> [@ntucker](#):
>
> I think you misunderstand the suggestion. He’s not suggesting you use the VPN to connect directly to the server you want to administer, he’s suggesting you use VPN to connect to a network you trust, and then remotely administer the email/whatever server the normal way, as if you were physically sitting on the trusted network (e.g. the network back at the office). You’d use all the same potentially-unencrypted protocols, but the traffic is first sent to the trusted network over an encrypted tunnel, then from there to the server, it’s regular unencrypted traffic.

Well, I get what you are saying, but that seems like an extra layer of complexity and data forwarding to slow things down. Surely that’s not what everyone does just to connect to email while traveling?

---

<div class="post-metadata">

**Author:** ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)\
**Post date:** [May 6, 2010, 6:55pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/7 "2010-05-06T18:55:35Z")

</div>

> [@Musicat](#):
>
> Well, I get what you are saying, but that seems like an extra layer of complexity and data forwarding to slow things down. Surely that’s not what everyone does just to connect to email while traveling?

No, most people probably just do it insecurely. 🙂 The VPN is the right solution, and in my experience, the lousy speed on hotel networks is a much bigger hindrance than the overhead of VPN.

---

<div class="post-metadata">

**Author:** ![lazybratsche](https://avatars.discourse-cdn.com/v4/letter/l/ba8739/32.png) [@lazybratsche](https://boards.straightdope.com/u/lazybratsche)\
**Post date:** [May 6, 2010, 7:15pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/8 "2010-05-06T19:15:21Z")

</div>

What **ntucker** said.

You won’t see a noticeable performance hit with a VPN connection. It uses a bit of processor time, and adds a bit of data overhead, but it’s a pretty trivial difference. I often use a VPN on this very computer, a not-very-powerful netbook like yours, and I never notice a performance hit. The bottleneck will be your internet connection, even if it’s a _really_ fast connection.

In my case, I often VPN from one academic institution’s network to my “home” academic network, so that I can transfer large files from my lab’s file server as if I was on the same LAN. Both institutions are connected via the amazingly fast Internet2 network, so the bottleneck is the 100mbit ethernet connection on this computer. Even at that speed, the VPN doesn’t cause a big performance hit.

If your employer can give you a client, setting it up is really easy. They should simply give you a VPN client to install. Then, when you want to connect to the VPN, you just run the client and give sign-in information. Presto, all the data moving between you and your employer’s network is now secure. You can now do anything that you’d be willing to do with a wired connection to your employer’s network.

---

<div class="post-metadata">

**Author:** ![Voyager](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voyager/32/133_2.png) [@Voyager](https://boards.straightdope.com/u/Voyager)\
**Post date:** [May 6, 2010, 7:39pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/9 "2010-05-06T19:39:21Z")

</div>

> [@Musicat](#):
>
> Well, I get what you are saying, but that seems like an extra layer of complexity and data forwarding to slow things down. Surely that’s not what everyone does just to connect to email while traveling?

We use an SSH connection for email, and VPN for anything else, such as browsing our intranet or getting to files. My new company has a web based mail also, but I have to VPN to get to that. If you are only as secure as Yahoo you are asking for trouble - remember Sarah Palin.

---

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [May 6, 2010, 7:48pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/10 "2010-05-06T19:48:47Z")

</div>

[The Idiot-Proof Way To Securely Use Public Wi-Fi](http://consumerist.com/2008/10/the-idiot-proof-way-to-securely-use-public-wi-fi.html) from the Consumer Reports blog site.

As the article says, VPN. Just in case you haven’t heard that before.

---

<div class="post-metadata">

**Author:** ![BrotherCadfael](https://avatars.discourse-cdn.com/v4/letter/b/977dab/32.png) [@BrotherCadfael](https://boards.straightdope.com/u/BrotherCadfael)\
**Post date:** [May 6, 2010, 8:22pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/11 "2010-05-06T20:22:07Z")

</div>

You can also use a tool like GoToMyPC, which sets up a secure connection to your desktop. This link is encrypted and otherwise protected, so it doesn’t compromise your network, and all that travels over the connection are screen images, keystrokes, and mouse movements.

Basically, it is secure remote control of your workstation. Works like a charm for me.

---

<div class="post-metadata">

**Author:** ![Hari\_Seldon](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hari_seldon/32/5173_2.png) [@Hari\_Seldon](https://boards.straightdope.com/u/Hari_Seldon)\
**Post date:** [May 6, 2010, 10:20pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/12 "2010-05-06T22:20:54Z")

</div>

I have one question. In order to set up a VPN connection to my host, I have to enter a UID and password. Can these be intercepted? Also, the host claims (or used to) that the number of simultaneous VPN connections they can host is limited and want us to limit our usage. Is this an outdated problem?

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [May 6, 2010, 10:26pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/13 "2010-05-06T22:26:11Z")

</div>

> [@Musicat](#):
>
> Well, I get what you are saying, but that seems like an extra layer of complexity and data forwarding to slow things down. Surely that’s not what everyone does just to connect to email while traveling?

I suspect that is exactly how most most business travelers get their business email while on travel. It is how things are done at my company and a lot of others.

---

<div class="post-metadata">

**Author:** ![ZenBeam](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@ZenBeam](https://boards.straightdope.com/u/ZenBeam)\
**Post date:** [May 6, 2010, 11:24pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/14 "2010-05-06T23:24:39Z")

</div>

> [@Duckster](#):
>
> [The Idiot-Proof Way To Securely Use Public Wi-Fi](http://consumerist.com/2008/10/the-idiot-proof-way-to-securely-use-public-wi-fi.html) from the Consumer Reports blog site.
> 
> As the article says, VPN. Just in case you haven’t heard that before.

I don’t understand how this works. It’s encrypted from my PC to… where, exactly? Doesn’t there need to be another end running the same software?

---

<div class="post-metadata">

**Author:** ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)\
**Post date:** [May 6, 2010, 11:54pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/15 "2010-05-06T23:54:37Z")

</div>

> [@ZenBeam](#):
>
> I don’t understand how this works. It’s encrypted from my PC to… where, exactly? Doesn’t there need to be another end running the same software?

It doesn’t really sound like the author of that article knows what he’s talking about. Some of the solutions he mention are VPN services you need to subscribe to, and he mentions OpenVPN, which is free and allows you to set up the server end of the VPN yourself (I have done this – it’s not for the faint of heart), but some of the things he mentions don’t make any sense. There’s no way plugging an IronKey USB drive into your computer magically encrypts all your network traffic unless there’s a corresponding service you’re connecting to, as you mentioned.

**Hari** , a secure channel will be negotiated before your username and password are sent, so that is safe. Otherwise the whole system would fail to work. And regarding the number of connections, it’s possible that’s just a software licensing issue, like the VPN server software they bought only allows them a certain number of connections at once and they have to pay for more, so they only want you using it when necessary.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [May 6, 2010, 11:57pm UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/16 "2010-05-06T23:57:40Z")

</div>

> [@ZenBeam](#):
>
> I don’t understand how this works. It’s encrypted from my PC to… where, exactly? Doesn’t there need to be another end running the same software?

It sure looks like those VPNs in the article allow you to connect to that companies computer securely then they send encrypted traffic to your PC. One is ad supported the others have a monthly or yearly fee.

---

<div class="post-metadata">

**Author:** ![Voyager](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voyager/32/133_2.png) [@Voyager](https://boards.straightdope.com/u/Voyager)\
**Post date:** [May 7, 2010, 12:17am UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/17 "2010-05-07T00:17:04Z")

</div>

> [@Hari\_Seldon](#):
>
> I have one question. In order to set up a VPN connection to my host, I have to enter a UID and password. Can these be intercepted? Also, the host claims (or used to) that the number of simultaneous VPN connections they can host is limited and want us to limit our usage. Is this an outdated problem?

The VPN we have uses a token card which generates a one time password for the tunnel. Someone intercepting it and reusing it would be out of luck.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [May 7, 2010, 3:50am UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/18 "2010-05-07T03:50:08Z")

</div>

> [@Voyager](#):
>
> The VPN we have uses a token card which generates a one time password for the tunnel. Someone intercepting it and reusing it would be out of luck.

The token card is for authentication not encryption. Encryption is set up with some sort of public key exchange. A VPN that sends passwords in the clear is so poorly implemented that most right thinking people would consider the software as basically fraudulent if it sends anything in the clear after the public key exchange.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 7, 2010, 11:39am UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/19 "2010-05-07T11:39:10Z")

</div>

So everyone I see at Starbucks, the library and airports is using a version of VPN? Or is every 2nd person sniffing every 1st and stealing passwords?

---

<div class="post-metadata">

**Author:** ![kferr](https://avatars.discourse-cdn.com/v4/letter/k/71e660/32.png) [@kferr](https://boards.straightdope.com/u/kferr)\
**Post date:** [May 7, 2010, 11:51am UTC](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519/20 "2010-05-07T11:51:54Z")

</div>

> [@Musicat](#):
>
> So everyone I see at Starbucks, the library and airports is using a version of VPN? Or is every 2nd person sniffing every 1st and stealing passwords?

If they’re doing real work then they should be using a VPN. My company’s security policy says that even if I just want to do some casual browsing I’m required to vpn into the corporate network to do so.

[Next page](https://boards.straightdope.com/t/pc-use-in-large-hotel-what-security-protection-is-needed/538519.md?page=2)
