Russians were told about the risks of connecting to public Wi-Fi
Using public Wi-Fi in cafes, airports, hotels, and shopping malls can pose a risk if personal, banking, or work data is transmitted over an unsecured network. Denis Sinyukov, a Full Stack engineer, application architect, specialist in corporate IT systems, fintech development and automation of business processes, told Izvestia on July 22.
According to the expert, the main risk of an open network is that the user does not control which infrastructure his data passes through and who else is connected to the same access point.
"An open network is like a conversation in a crowded room: your interlocutor can be anywhere, and anyone can eavesdrop. Technically, an attacker connected to the same network can intercept everything that is transmitted in the clear," Sinyukov explained.
It is especially dangerous to use public Wi-Fi when entering passwords, bank data, passport information, as well as when working with corporate documents. The risk is higher if the operating system and applications on the phone or laptop have not been updated for a long time: in this case, fraudsters can exploit already known vulnerabilities.
The IT specialist noted that even ordinary website browsing can be dangerous if the user is connected to a fake Wi-Fi network. According to him, many applications continue to exchange service data in the background: mail services check new messages, social networks update sessions, and various platforms transfer digital authorization keys. The expert explained that hackers, having intercepted such a key, are able to gain access to an account without entering a password, so even watching a news feed does not guarantee security when connecting to a fake access point.
He called the creation of Wi-Fi networks with names similar to the real ones one of the common schemes. For example, scammers may use almost the same name as that of a cafe or hotel chain. If automatic connection is enabled on the device, the phone or laptop can connect to a fake network without warning.
According to Sinyukov, after that, all user traffic passes through the attacker's device. In dangerous cases, fraudsters can not only see the pages they visit, but also substitute sites by showing a fake page of a bank or other data theft service.
The expert recommended that you do not enter passwords, pay for purchases, or open your work email via public Wi-Fi. If you need to connect, you should use a reliable VPN and disable automatic network connectivity.
"Paying for purchases through an open network is the maximum risk. It's also better not to open your work email: corporate correspondence may contain secret documents and links to the company's internal systems," he said.
To reduce the risks, Sinyukov advised using the mobile Internet whenever possible, checking for HTTPS and the lock icon in the address bar, regularly updating the system and applications, and disabling automatic Wi-Fi connectivity in advance.
Experts from the Roskachestvo Center for Digital Expertise said on July 16 that many users are in no hurry to delete the old one after installing the new version of the banking application, but such a habit can cost not only free space in their phone's memory, but also money in their accounts. It was noted that the main danger of the old versions is the lack of up—to-date security updates.
Переведено сервисом «Яндекс Переводчик»