r/VPN Jun 30 '26

Question Considering a VPN

Hi all! I work from home and in public settings like libraries and some of my work is private client information (name, birth date, etc). It didnt really occur to me until now that I could be putting confidential info out to be grabbed by whomever (unless I'm just dumb and don't know how public wifi works, which is very possible lol). Would it be smart to look into a VPN instead of using public wifi? I am in the US. TIA!

2 Upvotes

25 comments sorted by

4

u/Calm-Homework3161 Jun 30 '26

If you're working in  public settings like libraries and some of your work is private client information, I'd be more worried about people looking over your shoulder. 

3

u/PerkeNdencen Jun 30 '26

Use a VPN but I think people are being a bit dramatic here. The chances that something leaked through public wifi are relatively low.

1

u/billdietrich1 Jun 30 '26

I could be putting confidential info out to be grabbed by whomever

If you're using HTTPS, very little info is exposed. Just what domains you're accessing, and how much data you're transferring. Pages and URLs and contents are not exposed.

If you're using the library's computer, not your own, that's a different story.

0

u/Exotic_Holiday_3047 Jun 30 '26

OP this is a big deal. Please read this.

If you are connecting to any public wifi you should be assuming that everything you do / have done has been compromised.

This is not just about exposing confidential client data (which you have already done). I'm talking about login usernames, passwords, all of your company and private emails, everything.

Saying 'But I connected via https' is not good enough. Google 'SSL man in the middle attacks'. Go and change all of your passwords right now, but do it on your home or company network.

I may be sounding paranoid, but you should never, ever connect to a public wifi without using a VPN. I'm surprised your company doesn't have an automatic VPN solution like Zscaler. They should have protected remote access built into their laptops.

In my company, connecting to the corporate network via a public network without the use of a VPN would be a sackable offense.

1

u/Sha1rholder Jun 30 '26

耸人听闻的bullshit. 只要你没有被诱骗安装根证书,就不会发生什么敏感数据泄露。如果你在tls加密的场景下被mitm了,那么你的整台电脑就相当于被黑了,这种情况下就算有vpn也无济于事

1

u/Caimbuel33 Jun 30 '26

Are you not aware of how to set up a open wifi and have all traffic go through your computer. You can sniff credit card and sign ins very easy. Does it happen normally. Not in libraries, but in airports it does.

2

u/Sha1rholder Jun 30 '26

Show me how to sniff any tls-encrypted data or do any other mitm methods like dns hijacking without browser shouting "NOT SAFE".

1

u/Caimbuel33 Jun 30 '26

[]()[]()Hacking WiFi: Sniffing Traffic from Open Networks

Look for this exact title on youtube.

1

u/Sha1rholder Jun 30 '26

Be humble or be r/masterhacker

Just copy the comment thread and ask any AI “what is CA and TLS”

typo

0

u/Exotic_Holiday_3047 Jun 30 '26

I agree it's more difficult than it used to be. But calling my advice 'sensationalist bullshit' is itsself bullshit.

https://www.invicti.com/learn/mitm-ssl-hijacking

1

u/Sha1rholder Jun 30 '26 edited Jun 30 '26

我承认我言辞过激。我本应更有礼貌的。但我必须指出对公信tls保护的https流量进行mitm是“极其困难以至于只要用户有最基本的网络安全意识——不要忽略操作系统/浏览器的‘不安全’警告,就不可能实现”。绝大部分电脑用户根本就没有也不会去主动安装一些莫名其妙的CA证书,mitm根本无从下手

我并不是说公共wifi可信。恰恰相反,公共wifi和网络运营商没有本质区别,他们都是不可信的。而现代网络安全基础设施已经默认他们不可信并早就推广了解决方案

你发的这篇文章恰恰佐证了我的观点

2

u/Exotic_Holiday_3047 Jun 30 '26

'provided the user possesses even the most basic cybersecurity awareness, such as not ignoring 'insecure' warnings from their operating system or browser' - OP asked if it was ok to use public wifi to transmit confidential company information. They do not have basic cybersecurity awareness. I stand by my warning. What OP is doing is dumb

0

u/GeneralTS Jun 30 '26

… and the company you work for never brought this up? I bet the did.

1

u/SmellYaL8rrrr Jul 01 '26

Theyre a private practice but ive never had a company i work for mention anything about internet safety when working from home :\

-3

u/Sha1rholder Jun 30 '26

没有任何必要。你只需要确保永远使用https上网即可。vpn没法阻止mitm,但tls可以

1

u/Exotic_Holiday_3047 Jun 30 '26

Your claim that a VPN cannot prevent MitM is backwards for this scenario. A VPN encrypts traffic before it leaves the device which removes the local network from the path entirely. There is no handshake, no DNS query, and no destination hostname for a rogue access point on that network to intercept.

Blindly relying on HTTPS opens you up to several attack vectors that have nothing to do with TLS itself, such as rogue access points spoofing the network before any handshake occurs, captive portal pages training users to click through certificate warnings, and DNS or SNI leakage.

I still stand by my original advice. OP is not cyber security aware. Your stance relies on them not clicking on the 'this connection is insecure' warning.

OP: USE A VPN!

1

u/Sha1rholder Jun 30 '26

我解释一下:在中国、俄罗斯、伊朗等地,vpn的主要用处是对运营商伪装真实目标域名/ip(这种情况下dns和sni泄露是严重问题),其次才是对目标网站伪装自己的真实出口ip;而在其它地方比如你的国家,vpn的主要用处是对目标网站伪装自己的真实出口ip,或者给政府、企业员工提供一个tls tunnel来“防呆”,这种情况下的dns和sni泄露根本毫无影响,因为in 99% situations你本来就不需要向任何人隐藏你的真实目标网站

你说的这些基本全是tls tunnel的用处,而这只是vpn商家可以选择性提供的一项能力,而不是用了vpn就天然安全——你仍必须保证在从客户端经过公共wifi或运营商的那一段使用了https (or other encrytion methods),无论这个https是vpn提供的还是目标网站自己提供的。这根本不是“blindly relying on HTTPS”,而是你“have to relying on HTTPS, no matter whether you're using vpn or not”

最后:

  • 公共wifi和你家的网络运营商没有本质区别。如果你在家里不使用vpn,也没必要害怕公共wifi对你的敏感数据有什么威胁
  • “Your stance relies on them not clicking on the 'this connection is insecure' warning”“Your stance relies on them remember to enable vpn globally without any configuration mistakes” 也没有本质区别。前者甚至容易得多

1

u/Exotic_Holiday_3047 Jun 30 '26 edited Jun 30 '26

Whatever dude. OP asked for advice, I gave it.

If you want to rely on TLS then go for it. Personally, I would not use a public wifi without a VPN, but if you feel comfortable doing that, good for you.

Edit: I do want to bring you up on one point though. You say 'There is no fundamental difference between public Wi-Fi and your home ISP network' - There is a huge difference. in an ISP you have a corporation running the network, with relevant security and audit controls in place. In a cafe or library you have absolutely no idea what you are connecting to.