Is Hotel Wi-Fi Safe? Here’s What Cybersecurity Experts Say You Need to Know Before You Log In | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Key Points

  • Two cybersecurity experts say hotel Wi-Fi is generally low risk, but fake networks and poor security habits can still expose travelers.

  • Travelers should verify the hotel’s official Wi-Fi network, keep devices updated, and enable multi-factor authentication before a trip.

  • For banking, work accounts, and other sensitive activities, both experts recommend using a mobile hotspot instead of hotel Wi-Fi.

What’s the first thing you do when you check into a hotel? For many travelers, it’s asking for the Wi-Fi password. And while some people log into their bank accounts without a second thought, others won’t even check their email unless they’re connected to a VPN.

So, who’s right? Is hotel Wi-Fi actually safe, or should you avoid accessing sensitive information altogether? To find out, we interviewed two cybersecurity experts—and, it turns out, the answer falls somewhere in the middle. Hotel Wi-Fi does come with risks, but in many cases, the biggest vulnerability isn’t the network itself; it’s how travelers use it.

Here’s what you need to know about hotel Wi-Fi before your next trip.

The Network Isn’t the Main Problem

Connecting to Wi-Fi in a hotel room.Credit: Luis Alvarez/Getty Images

Security analyst Udaya Vemuri says hotel Wi-Fi is convenient but not something he fully trusts. One mistake he sees often is travelers joining a network simply because it carries the hotel’s name. 

“Attackers can create fake networks with very similar names,” Vemuri says. When connecting to the Wi-Fi, he recommends confirming that you’re on the correct network with the front desk first.

The fake network tactic was even flagged by the FBI’s Internet Crime Complaint Center. A 2020 advisory on hotel Wi-Fi warned that criminals can set up a so-called “evil twin network” with a name nearly identical to the hotel’s own, tricking guests into connecting directly to an attacker-controlled connection. The bureau also noted that hotel network infrastructure is largely outside a guest’s control and “often built favoring guest convenience over robust security practices.” 

Translation: the network isn’t always the most secure. 

Dahvid Schloss, chief operating officer of cybersecurity firm Suzu Labs, offers a different take. A former government hacker who has security-tested hotel chains directly, Schloss compares hotel Wi-Fi to the network at a local coffee shop. They’re both loosely controlled public connections with some inherent risk but not the danger many travelers imagine.

“Your likelihood of getting attacked just by connecting to a hotel network is genuinely low,” Schloss says. He adds that much of the fear around public Wi-Fi comes from a misunderstanding of how hacking actually works, and that simply sharing a network with a bad actor is not enough to get compromised.

How to Protect Yourself

A person using their cell phone and computer.Credit: iStockphoto/Getty Images

A person using their cell phone and computer.Credit: iStockphoto/Getty Images

Despite their different comfort levels, Vemuri and Schloss have similar practical advice. User behavior, not the network, is the bigger factor for an individual traveler. Schloss recommends keeping devices updated and paying attention to browser warnings to lower your risk of being hacked or exposing sensitive information. Most incidents he sees are self-inflicted rather than the result of an active attack. In his experience, laptops are more vulnerable to poor habits than phones, since phone ecosystems tend to be harder to breach even when travelers aren’t especially careful.

Vemuri takes a more cautious approach in practice. When he needs to check his bank account, log in to work systems, or handle anything sensitive, he uses his mobile hotspot instead of hotel Wi-Fi. When he does have to use hotel Wi-Fi, he makes sure his devices are updated, turns on multi-factor authentication, and completely avoids sensitive tasks.

Turning on multifactor authentication for any account you may access while traveling adds another layer of protection, and it’s worth doing so before a trip rather than scrambling to set it up from a hotel room. For anything sensitive—your bank accounts, your work email, or any other private accounts you wouldn’t want exposed—both experts recommend switching to a mobile hotspot instead of relying on hotel Wi-Fi.

Read the original article on Travel & Leisure

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW