Resource icon

Use a public Wi-Fi login page without trusting a fake hotspot

A captive portal asks you to accept terms or sign in before a hotel, airport or café Wi-Fi grants internet access. The page may belong to the real venue, but a nearby attacker can create a similar-looking network name. A portal password prompt is not proof that the network itself is private.

Before you start​

If you have a reliable cellular connection, use it for sensitive tasks. Ask staff or an official sign what exact Wi-Fi network name the venue provides.

Do it step by step​

  1. Select the verified network name from your device's Wi-Fi list. Avoid automatic connection to a familiar name that you did not check in the current location.
  2. Read the captive portal's address and request. Supplying an email address for terms may be normal; entering your bank password or Apple/Google account password is not.
  3. Complete only the venue's necessary access step. If the portal redirects to an unexpected payment or identity page, stop and confirm with staff using a known contact channel.
  4. After access, open important websites by their known address or bookmarked app and verify HTTPS. A lock means the connection to that site is encrypted, not that a lookalike domain is legitimate.
  5. Turn off unnecessary local sharing and use the device's Public network profile where available. Forget the network when you leave if you do not want future automatic reconnection.

Check the result​

The expected service should load through HTTPS without repeated credential requests from unrelated pages. Check the selected Wi-Fi name one more time after the portal closes.

If something goes wrong​

If a device cannot open the portal, use its normal network login prompt or ask the venue. Do not install a browser extension, root certificate or management profile suggested by an unknown portal.

Know the limit​

FTC says modern HTTPS makes many public Wi-Fi sessions safer, while fake networks and wrong-site sign-ins remain risks. Microsoft notes that a captive portal itself is not proof of network security. FTC's public Wi-Fi guidance Microsoft's captive-portal caution
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack