Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Public Wi-Fi: check the network and destination

Separate network risk from fake-website risk and choose a connection for sensitive tasks.

Users of online and financial servicesAbout 5 minutes of reading + 3 questions
Start with the example Need help now?

What you will learn

  • An encrypted connection does not establish that a website is trustworthy.
  • Check the network and official destination before entering information.
  • For sensitive tasks on an unverified network, use mobile data or wait.

Practice example

Wi-Fi asks for a banking password

Wi-Fi asks for a banking password

At a hotel, you join a network with a familiar name. An HTTPS page opens and asks you to sign in to your bank account to get free internet.

A familiar name is not verificationThe request does not fit network accessHTTPS has a limited role
Fictional training scenario.
Show the example explanation
A familiar name is not verification
A network name can be copied. Check with staff, but also examine what the page asks you to do.
The request does not fit network access
Your banking password is not information to give to a Wi-Fi portal.
HTTPS has a limited role
It encrypts data sent to the website; it does not check the operator’s intentions.

The network, connection and website are different

On a public network, you may not know who runs the equipment. However, public Wi-Fi does not automatically mean other users can see all your information: HTTPS encrypts the connection between the browser and website.

HTTPS does not establish that a website is honest. A fraudulent site can have an encrypted connection too. Check the address and whether the request makes sense, as well as the connection’s protection; our domain-checking guide provides detailed steps.

Before entering information

  1. Check the exact network name with staff. A similar or familiar name alone does not establish who runs it.
  2. For banking, use the official app or known bank address. If you cannot verify the network, switch to mobile data or postpone the sensitive task.
  3. Do not bypass browser certificate warnings. Do not install unfamiliar programs or profiles to get Wi-Fi access.
  4. Disable unnecessary file sharing and keep the system, apps and browser updated.

What a VPN and 2FA can add

A VPN encrypts traffic between your device and the VPN service. It does not make a fake website trustworthy or stop its operator reading information you submit. For a work device, follow your organisation’s network and VPN requirements.

Two-factor authentication adds protection for account access. It does not protect card details you enter on a fake site.

If you have already shared information

Stop using the suspicious page. From a trusted device and connection, change an exposed password and check the account using the recovery guide. If you entered banking information or approved a suspicious payment, call your bank immediately on an official number.

If you installed unfamiliar software or allowed device access, follow device recovery steps. Record the time, network name and page address without reopening suspicious content.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A public network portal uses HTTPS and asks for your banking password. What should you do?

Why does this matter? Encryption protects the journey to a website, but its operator receives what you submit. A banking password is not for accessing hotel Wi-Fi, so HTTPS or a VPN does not make that request appropriate.

  1. Enter it because the connection is encrypted.

    HTTPS does not make the portal’s request legitimate. You may deliver information to the wrong person over an encrypted connection; transmission protection does not change the recipient.

  2. Do not enter information, disconnect and check the network with staff.Correct answer

    The unexpected banking request is a reason to stop. You stop disclosure while checking the network rather than trying to make an inappropriate request safe.

  3. Turn on a VPN, then enter the password.

    A VPN cannot stop you handing information to a fake website’s operator. The tunnel protects part of the transmission path, but does not take back information you willingly enter into a fake site.

You need to make a payment but cannot verify the Wi-Fi network. What is the better choice?

Why does this matter? A sensitive task depends both on the connection you use and where you enter information. Changing networks does not verify a website for you, and payment urgency is no reason to ignore a browser warning.

  1. Use mobile data and the official banking app, or postpone the payment.Correct answer

    This avoids the unverified network; you still need the genuine app or website. You reduce uncertainty about the network while choosing a known destination; neither check replaces the other.

  2. Open the first search result for your bank.

    A result may lead to a fake website; use a known official destination. Search provides results, not approval to entrust the first one with banking information.

  3. Accept a certificate warning to continue.

    Do not bypass the warning for a sensitive task. Bypassing the warning continues despite the browser being unable to establish the expected connection protection.

You use a VPN. What does it not address?

Why does this matter? A VPN can protect part of the transmission, but does not verify every website’s business identity. If a scammer controls the destination, an encrypted route there does not prevent them reading the submitted form.

  1. Encryption of traffic to the VPN service.

    That is a core function of a VPN connection. The question asks for a VPN’s limitation; describing encryption identifies a function rather than the unresolved problem.

  2. Extra protection for traffic across the local network.

    A VPN can help protect that part of the journey. This is part of the protection a tunnel may provide, while the final site’s trustworthiness remains a separate question.

  3. Giving information to a fake website you opened.Correct answer

    A fake website’s operator receives information you submit, even through a VPN. The address, identity and reason for the request therefore still need checking while a VPN is active.

No registration. Your answers are not sent; the result is just for you.

Remember

An encrypted connection does not establish that a website is trustworthy.

Recognise fake websites and messages

References

Sources and further reading

The recommendation to use public networks cautiously and avoid exposing sensitive information appears in Serbian National CERT publications. The FTC explanation of public Wi-Fi and HTTPS (United States) supplements the technical distinction between the network, encrypted connection and trustworthiness of a website; US reporting routes are not part of this lesson.

Content last reviewed