Security of HTTPS websites while on Wi-Fi while traveling

I don’t like to do financial stuff using my MacBook or iPads over WiFi connections in motels; I just use my phone over cellular to check balances and if there is a problem I call them.

1 Like

I don’t even check my email on bare public WiFi or in hotels. I use a VPN to prevent the ViFi contractor from siphoning off any information they can sell, such as, email addresses, email contents.
If you use Google, however, it captures everything. It is the end-point of your connection, of course.
When I was recently in a hotel in Tokyo, Google news headlines insisted on showing me the headlines for Asian news outlets, even though location services were OFF.
So, yes, be careful about checking your financial accounts on the road.

Financial accounts and email (and most website traffic) is encrypted, so someone on a public WiFi network can’t see any of your data. The fact you got local headlines is because the IP address you were connecting from is in that location. It doesn’t require inspection of the data you’re sending/receiving.

5 Likes

For many years I have been using an iPad with a Gigsky mobile data subscription when travelling. It works well in Japan. I Hotspot this to my iPhone and Macbook instead of using hotel wifi.
The latest iPads have e-SIMs for this but I use an Apple SIM card with my ancient device.

Actually I was connecting through a VPN, so it shouldn’t necessarily be a Tokyo IP address. Maybe the VPN automatically used a local server? I’ll have to check.

When you log in to an email provider, the login information isn’t necessarily all encrypted. It depends on the protocol used by your email host. For many years my home ISP (Spectrum) used a simple, unencrypted login - no TLS! Recently it was upgraded, but you have to re-initiate the account to set the updated protocol.

OK, I’m paranoid! :smiley: Be careful, everyone!

1 Like

I won’t try to convince you otherwise, but IMO, as long as the bank’s site use HTTPS with a strong cipher (as most should, these days), the fact that the Wi-Fi network might not be secure should be irrelevant.

Someone snooping the Wi-Fi may see that there is traffic from your computer to the bank, but they shouldn’t be able to get anything beyond that. With most sites, including search engines, using HTTPS, I think the dangers of public Wi-Fi are not nearly as bad as they were in the past.

This shouldn’t be possible if the sites you visit use HTTPS connections. You definitely want to make sure the site is adequately secure, and you want to look for security alerts that may indicate a compromised network, but unless you’re visiting sites using unencrypted links, someone snooping the network should only be able to see the IP addresses of the sites you’re visiting (and maybe their hostnames). The content of your session shouldn’t not be available.

4 Likes

I don’t disagree that it would take more than one compromise to get past the protection of HTTPS.
I admit I’m a person who worries excessively. :slightly_smiling_face:

That isn’t good! I wouldn’t be comfortable using an email provider that was still using plaintext passwords, whether or not I’m on public WiFi (but, yes, in that case public WiFi could be risky).

1 Like

While use of https is a basic requirement for privacy and security on any type of connection to the Internet, wired and wireless, using public Wi-Fi still requires caution. Why? Because it is difficult for most users to ensure all components of a webpage and a website use encryption. Something as simple as a session ID embedded into a URL can give criminals information to exploit. Further, commercial websites have become very complex, with multiple teams and companies involved in coding, data storage, and functionality.

So, I think the safest practice is to avoid doing anything sensitive or private on public Wi-Fi if possible. If that isn’t possible, use a Wi-FI network security scanning app before logging in to websites (such as https://www.sophos.com/en-us/products/mobile-control/intercept-x) and a trustworthy VPN.

3 Likes

But don’t modern browsers (e.g., Safari and Firefox) warn you when they detect an unencrypted element on a page?

Not always because of the sheer number and diversity of components, delivered by servers both controlled and not controlled by the site owner, on most webpages and because browsers typically do not inspect address bar text for security and privacy vulnerabilities.

Mixed content handling is an area where there has been a lot of progress in recent years. Browsers are now very aggressive at either automatically converting them into secure (https) requests, or blocking them entirely. (Safari is particularly stubborn about simply refusing to load content rather than forcing it through a secure channel.)

You generally won’t even see a warning like you did in the MSIE days – browsers either “upgrade” the connection before it starts, or it skips the insecure connection entirely. (The warnings pile up the browser console, for web developers.)

As for “text in the address bar” – URL paths and query parameters – that has always been sent encrypted in HTTPS requests. It may not look like it, since it’s displayed as part of the “address” along with the server name (which is exposed) but everything beginning with the first slash occurs “inside” the encryption as part of the request

3 Likes

I’ve always been suspicious of hotel networks, and business travel is an essential part of my job. So my solution is to use a travel router that has built-in VPN support. My current travel router is a GL-iNet Slate Plus and configured it to connect to my PIA VPN account. The router connects to the hotel’s Wi-Fi (it has captive portal support), and once that is set, I flip a switch that turns on the VPN (which tunnels through the hotel network to a point of presence that I pre-selected).

My devices all know the travel router and just connect to it (ignoring the hotel’s network), so all my devices are on my own (secure) LAN and isolated from the hotel; I travel with my own “bubble of security.”

4 Likes

It’s cool, and if it makes you happy I wouldn’t take that away. OTOH, that is a very particular use case, made more prescient by stupid Wi-Fi policies that allow only one (or a small number of) devices to connect. A VPN protects the metadata (i.e. who you are connected to), and not just the data (the content of the communication itself). I do have a NordVPN subscription but I rarely use it because I only really need it when doing geoblock circumvention; realistically I just don’t care that much if people know I use Apple devices, bank at NatWest, and have overwhelmingly left politics. It’s nice to know it’s there, I guess. But if your circumstances are very different, maybe that VPN does matter. I also dream of the day that an open Wi-Fi network somewhere actually works and is free; my experience is that if they aren’t managed by your cell or broadband provider, and aren’t otherwise paid commercial services, they’re also never worth having.

2 Likes

You wrote, “A VPN protects the metadata (i.e. who you are connected to), not the data (the content of the communication itself).” That’s actually untrue. A VPN creates an encrypted tunnel through all the intervening networks (from the endpoint to the VPN Point of Presence) and all packets traversing through the tunnel are opaque to the intervening networks. VPNs protect the communications and the metadata (whereas HTTPS only protects the data).

1 Like

Pha, thanks! I have clarified my post. It is, of course, what I meant to say—that the VPN is giving you additional protection, that a lot of people including me simply feel we can live without.

Yes, but you have to trust the VPN provider to not record, sell or otherwise distribute that data. Not all are trustworthy, and most will surrender records to a government request. So do your homework and see if you can only use those that don’t retain records of customer activity - they can’t surrender data that doesn’t exist.

1 Like

I’ve been using Mullvad, partly because on ios it includes some content/tracking blocking (basically easylist) at the dns level, so it helps protect privacy in all apps. They also have a free-to-everyone encrypted DNS service (also diskless) that includes DNS blocking outside of the VPN that I’ll probably install one of these days since it allows reasonably quick switching between blocklists, and blocks with the vpn turned off.

The Mullvad apps work well on macs and ios, they have regular audits, and the VPN is entirely RAM based now. They have an excellent blog that includes the audits, notices of problems on assorted platforms, new features and at least one somewhat entertaining report of an attempt to look at their logs last year.

They also don’t keep credit card information if that’s how you you pay. You pay for any number of months in advance, and that’s it. Add more money when it runs out if you want to. [I stopped using proton because they insisted that I have a credit card on file so they could auto renew me whether I wanted that or not. The only way to stop renewal was to cancel the account, and since that cancels the service immediately, you have to time it right.]

For anybody interested, Mullvad is also the pick of Wirecutter:

Another happy Mullvad user here.