How Safe are Public Wi-Fi Networks (Hotspots) in Costa Rica?

Share this article

Public WiFi Networks in Costa RicaNot too many years ago, public Wi-Fi hotspots were a rarity. As the market shifted to mobile devices, the demand for public Wi-Fi hotspots increased exponentially. Airports, hotels, coffee shops, restaurants, and bars quickly jumped on the band wagon to gain a competitive advantage. With our mobile devices, we look for public Wi-Fi hotspots. Mobile users rarely consider the dangers of a public Wi-Fi hotspot, and mobile devices lack the basic tools required to insure a save connection. This void created a whole new criminal culture aimed at collecting personal information. Through understanding the dangers of public Wi-Fi networks, we can take the steps needed to safely use our mobile devices on public Wi-Fi networks.

Rule number one is to never connect to a public Wi-Fi network without a firewall and anti-virus protection. When using a public Wi-Fi network, you should assume that there is no network security. Ideally, a public Wi-Fi hotspot does not allow devices on the network to see each other. The Wi-Fi router should block any attempt to discover any other devices on the network. However, you cannot assume that this is the case. With one minor error in router configuration, the public Wi-Fi network looks like a local network, where all device can communicate with each other.

Rule number two is to use a VPN service for all sensitive information. There are just too many ways to decode normal browser traffic and collect personal information. With VPN, all information is encrypted, at a higher level of security.

Rule number three is to turn off the Wi-Fi feature that automatically connects your mobile device to the Wi-Fi hot spot with the strongest signal. With automatic connections, you may be connecting to a rogue public Wi-Fi hotspot. A rogue public Wi-Fi hotspot (also called “Man in The Middle”) connects to a legitimate Internet connection, and captures traffic as it passes through the rogue hotspot. This traffic is then decoded to collect account names, passwords, and credit card numbers. Even VPN encoded traffic is not immune to this attack, it just takes a lot more work to decode it.

Rule number four is to not ignore the untrusted certificate messages issued by the browser. When connecting to a secure Web site, your browser receives a certificate for verification. The browser compares the certificate with its database of Trusted Certificate Authorities. If there is a problem with the certificate, you get the untrusted certificate message. You should always view the certificate in question. In some cases, the certificate is valid for the domain to which you are connecting, but they failed to certify the full URL. These certificates are usually OK. You should always be wary of certificates from untrusted certificate authorities. Never accept a certificate from DigiNotar. Both Google and Firefox removed DigiNotar from the list of Trust Certificate Authorities due its certificates being used in rogue Wi-Fi hotspot attacks. Be extremely aware of self-signed digital certificates.

Rule number five is to check the trusted certificates on your browser, and remove DigiNotar as a Trusted Certificate Authority. You will not be able to do this on iPhones, iPads, or Android versions before Ice Cream Sandwich (ICS). ICS added the capability to audit your certificate database.

Rule number six is to remember that firewalls and anti-virus programs do nothing to protect you from rogue public Wi-Fi hotspots. On Android devices you can install Wifi Protector to automatically detect, protect and defend against most rogue Wi-Fi hotspots. I was unable to find an equivalent app for iPhones, or iPads.

Rule number seven only applies to Windows 7, and to businesses and homes with a secure internal network. Windows 7 introduced Wireless Hosted Network. If a Windows 7 computer is connected to a wired LAN, and has SoftAP certified Wi-Fi adapter, it can act as a public Wi-Fi hotspot. It is imperative that the virtual Wi-Fi feature be disabled. You may accidentally become the man in the middle in a public area. You should only enable this feature, when you are using your Windows 7 laptop to tether other devices to the Internet.

By following the above rules, we can use a public Wi-Fi hotspot with a higher degree of confidence that our personal information is secure from unwanted intrusion. As I have said before, it is extremely difficult to stop a professional thief, but we can protect against the common thief.

Print Friendly, PDF & Email

Comments