Public Wi-Fi Is Not Safe Until Your VPN Is Connected

Business traveler uses a laptop aboard an airplane while a blue encrypted tunnel bypasses a rogue red wireless hotspot and connects to a secure firewall.

Public Wi-Fi Is Not Safe Until Your VPN Is Connected

Business traveler uses a laptop aboard an airplane while a blue encrypted tunnel bypasses a rogue red wireless hotspot and connects to a secure firewall.

Click here to view/listen to our blogcast.

Public Wi-Fi is convenient, but it is built on trust. You see a network name that appears to belong to an airline, hotel, coffee shop, or conference center, and you connect. Unfortunately, that name does not prove who operates the network.

Passengers aboard a recent Delta flight from Las Vegas to Atlanta received a dramatic reminder of that risk. Following the DEF CON cybersecurity conference, an unauthorized wireless network reportedly appeared with a name resembling Delta’s legitimate service. The aircraft’s Wi-Fi was temporarily disabled while the incident was investigated.

Delta said its aircraft operating systems and corporate systems were not compromised. Nevertheless, the incident demonstrates how easily someone can create a wireless network that looks trustworthy. The same technique can be used anywhere people expect public Wi-Fi.

The Network Name Proves Nothing

This type of setup is commonly called an “evil twin” network. An attacker creates a hotspot using a name that resembles a legitimate network. The fake network may even have a stronger signal than the real one or appear after users are unexpectedly disconnected.

Once someone connects, the attacker may attempt to:

  • Display a fake sign-in or payment page
  • Steal email, Microsoft 365, banking, or social media credentials
  • Redirect the user to a fraudulent website
  • Collect information about the connected device
  • Encourage the user to install an application, certificate, browser extension, or device profile

Modern website encryption has reduced some public Wi-Fi risks, but it has not made fake networks harmless. A fraudulent website can also use HTTPS. The connection may be encrypted while securely delivering your password to the criminal operating the site. The Federal Trade Commission warns that the padlock symbol does not mean the organization behind a website is legitimate.

Use the VPN Your Organization Controls

Employees should treat every public network as untrusted, including Wi-Fi offered by airports, airplanes, hotels, restaurants, conference centers, waiting rooms, and shared offices.

CDML encourages clients to use the secure VPN provided through their organization’s SonicWall firewall. SonicWall NetExtender or Mobile Connect creates an encrypted tunnel between the remote device and the firewall. Someone monitoring the public network may see that a VPN connection exists, but the information inside the tunnel is protected from ordinary local interception.

Unlike an unfamiliar consumer VPN, an organization-managed VPN is configured and supported by the organization’s technology provider. Access can be limited to authorized users, protected with multifactor authentication, monitored, and removed when an employee leaves.

VPN Configuration Matters

Having VPN software installed does not guarantee that all Internet traffic uses it. Some VPNs only provide access to internal resources. Other traffic may continue directly through the public network.

SonicWall’s Tunnel All Mode can route all user traffic through the SSL VPN and the organization’s firewall. Whether this is appropriate depends on security requirements, Internet capacity, remote-work needs, and firewall configuration. The organization’s technology provider should evaluate and configure it.

Employees do not need to understand routing tables, but they should receive a simple procedure for working safely:

  1. Confirm the official Wi-Fi name with the location providing it.
  2. Disable automatic connections to unknown or previously used public networks.
  3. Complete the legitimate network access page, if one is required.
  4. Connect to the organization’s SonicWall VPN before opening email, cloud applications, financial information, patient records, or other sensitive data.
  5. Verify that the VPN reports a successful connection.
  6. Never ignore certificate warnings or install anything requested by a public hotspot.
  7. Use a cellular hotspot or postpone sensitive work if the VPN will not connect.

A VPN cannot stop someone from entering a password into a convincing phishing page before the tunnel is established. Multifactor authentication, endpoint protection, web filtering, security training, device updates, and strong access policies must work alongside it.

How CDML Can Help

CDML Computer Services can review how employees connect while traveling or working remotely. This can include:

  • Configuring and maintaining SonicWall VPN access
  • Installing and testing NetExtender or Mobile Connect
  • Enabling multifactor authentication
  • Evaluating full-tunnel and split-tunnel requirements
  • Applying device and wireless policies through management tools
  • Creating practical remote-work and travel-security procedures
  • Training employees to recognize fake hotspots and login pages

The goal is to give employees a reliable, repeatable way to work safely wherever they are.

Final Thoughts

Public Wi-Fi should never be trusted because its name looks right. Before accessing organizational information, connect through your organization’s secure VPN and confirm that it is working.

If your employees work from airports, hotels, client locations, conferences, or other public spaces, contact CDML Computer Services to review your remote-access security and help configure a properly protected SonicWall VPN solution. You can also call 718-393-5343 to start the conversation.

Icon

Elevating Customer Experience.