Skip to content
Amrani Academy

2. Devices on the move

Public Wi-Fi, VPNs, and your phone's hotspot

Free Wi-Fi in cafes, hotels, airports, and trains is convenient, but you have no idea who runs it, how it is configured, or who else is on it. Treat every public network as untrusted.

What can go wrong

Anyone can set up a hotspot named "Free_Cafe_WiFi" and wait for people to connect. On a hostile or compromised network, an attacker may be able to observe your traffic, redirect you to fake login pages, or probe your device directly. Modern websites encrypt most traffic with HTTPS, which helps a great deal, but it does not make an untrusted network safe, and it does nothing for apps or services that connect insecurely.

Prefer your phone's hotspot

The simplest strong option is often to skip public Wi-Fi entirely and tether to your own phone. A personal hotspot over 4G or 5G is a network you control, with no strangers on it. For short sessions, checking email or joining a call, it is usually the best choice. Just set a strong hotspot password and watch your data allowance.

Use the VPN when you do use public Wi-Fi

If your organisation provides a VPN, use it whenever you work over a network you don't control. A VPN wraps all your traffic in an encrypted tunnel back to a trusted endpoint, so even a malicious network operator sees only encrypted data. If the VPN won't connect, that is a reason to stop and switch to your hotspot, not to carry on without it.

A few extra precautions

Tell your device to forget public networks after use so it doesn't reconnect automatically, and turn off Wi-Fi when you're not using it. Avoid doing highly sensitive work, payroll, client personal data, anything privileged, over public Wi-Fi at all if you can wait until you're on a trusted connection.

The rule of thumb: hotspot first, VPN if you must use public Wi-Fi, and never sensitive work on an untrusted network without protection.

Course contents