Suitcase TheoryA working theory of travelling light

Travel Routine

Public wifi abroad is an authentication problem

The risk on open networks is less about traffic being read and more about captive portals, lookalike networks and accounts being accessed while credentials are in use.

Passengers silhouetted against sunset light at an airport terminal, showcasing travel anticipation.
Photograph by K via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Open wireless networks are treated as a general danger. The actual risks are narrower and specific, and most of them concern identity rather than the contents of traffic.

Encryption has changed what is exposed

Almost all web and app traffic is now encrypted in transit, so another user on the same network cannot simply read the contents of a session.

What remains visible is metadata: which servers are being contacted and how much data flows. That is a privacy question rather than an account security one.

The practical consequence is that the old advice about avoiding banking on public wifi addresses a risk that has largely been engineered away.

Lookalike networks are the live problem

Anyone can broadcast a network with a plausible name resembling a hotel or a café. Devices joining it route their traffic through equipment controlled by a stranger.

Encryption still protects the traffic, but the operator can serve a convincing login page and capture whatever is typed into it.

Confirming the exact network name with staff, rather than choosing the most plausible one on the list, removes this at the point where it matters.

Captive portals train bad habits

Hotel and airport portals ask for personal details, room numbers and sometimes social logins, in an interface that cannot be verified and looks different everywhere.

Because travellers encounter dozens of these, they become accustomed to entering credentials into unfamiliar pages, which is the behaviour an attacker relies on.

Portals also frequently break certificate warnings by design, training users to dismiss exactly the alert that would indicate something genuinely wrong with a connection.

Using a throwaway detail where a portal asks for an email, and never a password reused elsewhere, contains the damage without preventing the connection.

Devices leak by trying to reconnect

Phones remember networks and search for them automatically, announcing the names of places they have previously connected to.

Turning off automatic joining for open networks, and removing saved public networks after a trip, reduces both the tracking and the chance of joining an impostor.

Widely used network names make this worse, because a device that once joined a common café or airport name will rejoin anything broadcasting it anywhere in the world.

What actually protects an account

Second-factor authentication protects an account even when a password is captured, which makes it more valuable than any network-level precaution.

A mobile data connection avoids the shared network entirely, and where roaming or a local plan is affordable, it is the simpler answer to the whole category of problem.

Questions readers ask

What do people lose most often when travelling?

Phones, chargers, passports and glasses, overwhelmingly at security, in seat pockets and in accommodation. All are transition points rather than random events.

Is a checklist worth it for regular travellers?

More so, not less. Frequent travellers pack on autopilot, which is exactly the mode in which a single item is quietly omitted.

Travel Routineroutinecheckliststransithabits
Nadia Halloran
Editor, Suitcase Theory

Nadia edits Suitcase Theory and has been running the same 34-litre bag since 2018.

Also by Nadia Halloran