• United States




Free Wi-Fi is not free from cyber security threats

Jan 27, 20164 mins
InternetInternet of ThingsIT Skills

The list of topics to cover in awareness training programs continues to grow with the expansion of free Wi-Fi across major cities.

From San Francisco to New York, cities across the country are giving makeovers to old phone booths. This month New York City began replacing thousands of pay phones with free Wi-Fi hot spots. According to The Wall Street Journal, “The city expects to have 500 hot spots installed by July, and eventually, about 7,500 units will be replaced.” While this 21st century technological upgrade is great for consumers, it poses security risks for the enterprise.

Tyler Cohen Wood, cyber security adviser to Inspired eLearning, said there are several reasons for concern. In addition to Wi-Fi hotspots opening up the possibility of hackers stealing valuable information, the city will also have the ability to collect information. Each booth will be equipped with a tablet for free calls and web browsing, but this opens the doors for complete strangers to access information and receive passwords if not protected. 

Cohen Wood warned, “It is possible a hacker could put key loggers on tablets, so be cognizant, and don’t enter private info onto the tablets provided.”

As more cities hop on board with these implementations, enterprises could fall victim to even more human error if security teams don’t educate their employees on how to secure their devices and their sensitive information. More than ever, security awareness training for end users is critical to securing the extended network of the enterprise. What people don’t know can hurt them and result in a breach.

Here are some tips Cohen Wood recommends including in an awareness training program:

  1. If people are going to use these hotspots, make sure they are using a virtual private network (VPN), and encrypting what they are sending. 
  2. Make sure users understand that what they’re sending or putting on a tablet could be viewed by anyone else on the network if it is not secured, which means it could be viewable by the next person who comes along, viewable by Google, or viewable by the city of New York or whoever else is watching.
  3. If not secured, people can sniff your traffic.
  4. Don’t do anything that is company business or includes private information, unless using secured things like VPN, (still not recommended). 
  5. If users have their phone set up to automatically connect to Wi-Fi, they may think they’re on secure network — but they’are not.
  6. Do not access bank information, company information, or other private/sensitive data unless they have manually disconnected from the free network.

Security professionals need to make sure that end users understand the implications and risks involved in sending a work email through a public network, so don’t underestimate the power of continuously educating all employees from entry-level folks all the way up to executives.

Cohen Wood said,New York is not the only city that is putting in Wi-Fi, and what has been said in the privacy policy is that the consortium behind LinkNYC might share anonymized data with third parties but nothing personal.”

The reality, Cohen Wood noted, is that “If you’re using this network and encryption, they have the keys to view the traffic. If you have sensitive info or work info, I would highly recommend that you use your own encryption.  Even if they were able to pull out metadata, if you’re using a VPN through your company, they can’t get anything.” 

In today’s world where we are relying more and more on these devices and IoT is coming out faster, Cohen Wood said, “The best way to protect yourself is by having an education program in place. I’m not talking about learning about all the bits and bytes about what is going on, but what you can do to protect yourself, your company, and your family.”


Kacy Zurkus is a freelance writer for CSO and has contributed to several other publications including The Parallax, and K12 Tech Decisions. She covers a variety of security and risk topics as well as technology in education, privacy and dating. She has also self-published a memoir, Finding My Way Home: A Memoir about Life, Love, and Family under the pseudonym "C.K. O'Neil."

Zurkus has nearly 20 years experience as a high school teacher on English and holds an MFA in Creative Writing from Lesley University (2011). She earned a Master's in Education from University of Massachusetts (1999) and a BA in English from Regis College (1996). Recently, The University of Southern California invited Zurkus to give a guest lecture on social engineering.

The opinions expressed in this blog are those of Kacy Zurkus and do not necessarily represent those of IDG Communications, Inc., its parent, subsidiary or affiliated companies.

More from this author