Metlivi Blog

How can you reduce account and data risk when using companion apps on public networks?

Using a companion app on airport or café Wi-Fi is not automatically a security failure. The FTC notes that encryption is now widespread and public Wi-Fi is usually safe, a useful correction to advice that treats every hotspot as hostile. Still, you do not control the venue's access point, nearby people, captive portal, or saved-network behavior. A companion session may also expose more than network traffic: message previews can be seen over your shoulder, an app may be open on a shared laptop, and a login can persist after you leave. A proportionate routine checks four boundaries—the network name, the encrypted route, the device and surroundings, and the account state after disconnection.

August 30, 20268 min readHome, Safety, Pets & Sustainable LivingBy Metlivi Editorial Team
Section 1

Decide whether this session belongs on this connection

Reading a low-sensitivity conversation is different from changing a password, exporting an archive, adding a payment method, or reviewing recovery codes. If cellular data or a personal hotspot is practical, reserve especially consequential account changes for that connection; CISA guidance recommends moving sensitive personal activity away from open public Wi-Fi. Otherwise, verify the public Wi-Fi name and sign-in procedure with a sign or staff member rather than choosing the strongest signal or a familiar-looking “Free” name. Disable automatic joining for unknown networks so the phone does not silently reconnect later. This is a risk-based choice, not a claim that a named venue network is guaranteed to be trustworthy.

Section 2

Inspect the captive portal before entering any account secret

A legitimate venue portal may ask you to accept terms, enter a room code, or provide an email, but it should not need your companion-app password or one-time authentication code. Check the full domain, not just the page logo. If the device asks you to install a certificate, configuration profile, remote-management tool, or unknown app simply to browse, stop and confirm with the provider. Do not override a certificate warning to make the companion app or web session load. HTTPS protects the connection to the domain shown; it does not prove that a look-alike domain is the service you intended. Open the official app or a saved, verified address after the portal step is complete.

Section 3

Reduce local sharing and observation routes

Turn off file sharing, nearby sharing, AirDrop visibility, or local-network permissions that are not needed for the session. Keep the operating system, browser, and companion app updated before travel rather than accepting an unexpected update prompt from the portal. Use a screen angle and notification setting that fit the public setting, and use headphones if audio would reveal conversation content—while remembering that a microphone may still capture the room. On a shared computer, avoid the session if possible; if it is necessary, do not save the password, recovery code, downloaded archive, or browser profile. Network encryption cannot prevent a person beside you from reading the screen or a public machine from retaining local data.

Section 4

Use authentication and VPN tools for their actual scope

Two-factor authentication can make a stolen password less useful, but an approval prompt can still authorize a login you did not initiate. Read the device and location shown and reject unexpected prompts. A reputable VPN can encrypt traffic from your device to the VPN provider, which can be useful on a network you do not manage; it does not validate a fraudulent website, protect an unlocked screen, erase app logs, or make a compromised endpoint trustworthy. NCCoE materials present VPN and HTTPS as layers, not magic switches. Use a service you already selected and configured, not an unknown “free VPN” advertised by the captive portal.

Section 5

Close the connection and account deliberately

When finished, stop media uploads, sign out of a web session on any nonpersonal device, close downloaded files, and disconnect from the network. Use the operating system's “forget this network” control if you do not want automatic reconnection. Re-enable sharing features only when you need them. In the companion account, check the recent session list after consequential activity and revoke anything unfamiliar; there is no need to rotate a unique password merely because a normal encrypted session used public Wi-Fi. Save a security-alert email only if it corresponds to a real event. This calibrated cleanup avoids both complacency and disruptive changes unsupported by evidence.

Section 6

Record anomalies with enough context to investigate

If you saw a certificate warning, unexpected login, changed recovery address, unexplained export, or app behavior that began only on one network, record the time, venue, network name, device, app version, and exact warning. Switch to a connection you trust before changing credentials or contacting support. Separate the network observation from the account event: correlation does not prove the hotspot caused it. Use the companion service's official security channel and preserve receipts. Public-network controls reduce exposure but cannot promise a particular outcome, and interfaces change across operating-system versions; verify current menu names in the device maker's documentation when a setting differs from this checklist.

Related questions

Common questions

Is public Wi-Fi always unsafe for a companion app?

No. The FTC notes that widespread encryption makes public Wi-Fi usually safe, but you should still verify the network, use the correct encrypted service, and protect the device and session.

Do I need a VPN every time?

Not necessarily. A trusted VPN can protect the path to the VPN provider, but it does not verify websites, secure an unlocked device, or replace HTTPS and account controls.

Should I change my password after using café Wi-Fi?

Not automatically. Change it if it was reused, exposed, entered into a suspicious page, or accompanied by verified account anomalies; otherwise review the session and keep a unique password.

Related reading

Keep exploring this topic