Forum Discussion
rwbradley
May 24, 2016Explorer
Gdetrailer wrote:rwbradley wrote:
Unfortunately there are a lot of opinions on this topic and not a lot of expert advice. As a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker (CEH), I can say, the best advice posted so far is buy a MIFI hotspot and do not use public WIFI for anything sensitive like banking.
Unfortunately where opinion seems to get in the way of reality is regarding advice on WHEN public WIFI can be safe. Public WIFI can NEVER be trusted to do sensitive things like banking. The problem with public WIFI is that you can never be sure that the Starbucks WIFI that your phone sees is truly put up by Starbucks even when you are parked outside Starbucks. I can easily create a WIFI network called Starbucks and then I can watch every packet of data pass thru my "fake" Starbucks network on its way to the bank. HTTPS will not even protect you as it is easy to generate a fake Certificate and most users do not realize that a certificate does two things, one is to encrypt the data and the other is to prove the owner. Most users would never know that they are getting a fake certificate from a fake Starbucks network and that their data is being decrypted, thus being able to steal their password and then re-encrypting it and forwarding it on to the proper destination (your bank).
Yes it is unlikely to happen to you, but it is easy to do, high school kid easy. Do you want to risk someone getting your banking information or other sensitive info and putting a mortgage on your home and then transferring the money to the Grand Caymans? Don't ever risk using public WIFI for anything sensitive without using a VPN to secure your traffic, it is just not worth the risk to be "that guy" who got hacked.
I did a write up on my blog on Internet Safety while RVing. Part 3 addresses WIFI security and Part 4 addresses VPN's.
Link
Post some real life PROOF of REAL folks who have been CERTIFIED BY A THIRD PARTY that they got hacked by using a public wifi..
Many people YACK that it is not safe, but yet they (and you) offer no real life CERTIFIED EXAMPLES as proof.
Is it possible? Sure, but in real life, since you are an "expert" on the subject you should be able to offer real examples and even numbers on how many have been hacked..
I would bet, that if you could even offer proof, most of those folks would have already been hacked via Malware BEFORE hopping on a free wifi..
OK I will take the troll bait.
Normally if you go to your Doctor and he tells you that you have cancer, you assume that he is the expert and take his expert opinion in making future decisions, you may ask for a second opinion to be sure. In the legal world people bring experts to court, not so they can teach the judge and jury how to be an expert in their field or to bore them with case studies to prove the causal link of something, the expert simply proves they are an expert in the field and the court will take their testimony as expert fact.
For this reason if you would like to contact a Mod and ask them to PM me I would be glad to provide (privately) proof of my (I guess it was your comment) "expertise". I would also gladly accept any expert opinion you can bring forth to refute anything I have said.
However just as your Doctor or Lawyer would laugh you out of their office if you asked for certified proof, I am bound by both moral and professional obligations along with privacy laws that do not allow to discuss any examples I may or may not be aware of or involved in.
I am however not interested in trying to change any opinion, we are all entitled to our opinion, but as the OP asked for advice, this is mine.
I suggest if anyone wants to learn more of the risks of public WIFI, I would open up google and search "man in the middle attack" you will find more than enough proof. With that said, the best way to be safe on the internet is to not be the low hanging fruit, the low hanging fruit always get picked first. Just because you don't think you have been hacked today does not mean you have not been hacked thru your healthcare insurance provider, Home Depot, Target, LinkedIn, Evernote etc... It also does not mean you will not be hacked later. Why hope for the best when a little amount of protection can go a long way to helping prevent it one day?
Public WIFI is the low hanging fruit, and if you think RV'rs are safe, think about this for a moment... In Florida, Arizona, and Texas in the winter, RV parks are filled with hundreds of thousands of retired, possibly less tech savvy home owners with their mortgage paid off all crammed together in small RV parks not much bigger than a Walmart parking lot. In each park that is hundreds or thousands of middle class computer users in easy range of a single hacker, that is what I call low hanging fruit. The banks may be somewhat safe as they have a team of IT security people, but an RV park in the south in winter would be the first place I would go as opposed to a Starbucks or McDonalds to harvest huge amounts of credentials from lots of people who have enough money to have paid off their house, have credit cards and lines of credit, and own several iPhones, iPads and Laptops and use them regularly on public WIFI to do their banking, Facebook etc all with the same password, so all I need to do is get their password off of one less secure site to get access to everything, all because they think they will never get hacked in an RV park!
About RV Must Haves
Have a product you cannot live without? Share it with the community!8,801 PostsLatest Activity: Jul 05, 2025