Wi-Fi público

Redes

Qué amenaza de verdad en una cafetería o un aeropuerto, qué historias están desfasadas y las tres reglas que bastan.

“Never use open networks — they will steal all your passwords” has been repeated for fifteen years. The internet has changed a great deal since, and half of the old scare stories no longer apply. Here is what genuinely remains dangerous.

Qué ha cambiado

Traffic used to travel in the clear, and the person at the next table could read your mail and pick passwords out of the air. Today the vast majority of sites run over HTTPS: the connection is encrypted between your browser and the server, and the network owner sees only domain names, not page contents or what you type.

So the classic password sniff from the next table is now largely historical. The padlock does its job here: it does not say the site is honest, but it does say the channel is encrypted.

Qué sigue siendo peligroso

A fake access point. The main real threat. Someone runs a network called “Airport_Free_WiFi” or exactly like the café’s, you connect, and all traffic passes through their device. They cannot read encrypted content, but they can serve fake login pages and “update your app” prompts.

The captive portal. Many public networks greet you with a sign-in form. That is a perfect place for a fake: the user is already expecting an unfamiliar page and is not surprised by a request for an email, a phone number or, in the bolder version, card details “for verification”.

Sites without HTTPS. Few remain, but on an open network entering anything on them is genuinely risky.

Your own device rather than the network. Open shares and network discovery are convenient at home and unnecessary at an airport.

Tres reglas que bastan

1. Do not enter anything important where the address looks doubtful. Reach your bank and email from bookmarks rather than a page you were redirected to. The advice matches the anti-phishing one because the threat is the same.

2. Enable a second factor before the trip rather than during it. Then an intercepted password is useless on its own.

3. Turn off auto-connect to open networks. A phone that latches onto “free Wi-Fi” by itself will latch onto a fake one too, in your pocket and without your knowledge.

¿Hace falta una VPN?

An honest answer: less than VPN advertising suggests. HTTPS already encrypts the contents, and a VPN adds little beyond hiding which domains you visit from the network owner.

Meanwhile all your traffic starts flowing through the VPN provider’s server, so the question of trust simply moves: instead of a café you now trust a company you know even less about. Free VPNs live on selling traffic data — precisely what you were hiding from.

If you have a corporate VPN, use it: trust there is defined by contract. Buying one solely for cafés makes little sense; the three rules above deliver more.

Copiado