Hotel Wi‑Fi is not automatically unsafe, but Microsoft’s CaptiveCrunch reporting shows how a routine captive-portal connection can be manipulated into credential theft or malware delivery.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security Podcast, the longest running cyber security and privacy
show for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing is guaranteed.
This is Shared Security.
This week on Shared Security we're talking about hotel wifi, and is it actually safe?
Well, the answer isn't never use hotel wifi, but the moment your phone or laptop throws
up a hotel login page is exactly when you should slow down and pay attention.
So we're talking about the captive crunch malware campaign where attackers turn that
ordinary wifi connection step into a chance to steal credentials or deliver malware.
So we'll cover the right flags that should make you stop.
We'll talk about a VPN and what that does and doesn't do, and the simple habits that
keep a hotel connection from turning into an account takeover.
And joining me for this conversation is the one and only Scott Wright.
Oh there, hello from Canada.
Hello from Canada.
How's it going up in Canada?
Oh, not too bad.
We're under attack by Canada geese that have machine guns and weird looking hairdos, but
yeah.
Yeah, that's awful.
I'm sorry you're going through that.
We have Canada geese here too, and they are invasive, but you know, I mean you guys
have invaded the United States at one point before.
Not before, we'll do it again if we have to.
You'll do it again if you've got to burn the White House down again.
You've got to do it.
I know.
I know.
Yeah.
Besides all that, we're here to talk about wifi.
You know, it's fascinating to me, we were just talking about this before the podcast
is that the threats around wifi haven't really changed over the years.
We're talking way back, right?
We've been always having this conversation about wifi on the show, and if you look
back on our previous episodes, you'll see we're kind of talking about the same thing.
Even though there's new attacks and there's kind of new methods, but the end of the day,
the same advice still applies that we're going to talk about on this podcast today.
It's because it's not all technology that has the risks.
That's right.
Yeah.
That's right.
So just to kind of frame everything, so I was kind of inspired by a couple of weeks
ago, Microsoft released some details about an attack that they've been seeing more focused
on Entra ID, which is kind of the central authentication system for Microsoft products.
And there is a dub this attack called captive crunch, not captain crunch, like the cereal.
I mean, a little confusing there, but captive crunch.
And this malware campaign is essentially pretty widespread according to Microsoft.
So this has been affecting hotel chains, large conference centers, you know, things like that.
And what they found was that, you know, these are mostly state sponsored threat actors that
are doing these things.
But what happens is you'll be just like you normally do connect to the hotel wifi
and you get this thing called a captive portal, which is, you know, some type of
login or authentication to, you know, so not everybody can access the wifi network, but
hotel guests specifically.
And these vary by hotel chain, by the systems that they're using.
But what's happening is that users will get this pop up for, hey, Microsoft found malware
on your machine, you need to click here, or they'll be a prompt for your user credentials,
like for your Microsoft login credentials with something saying, hey, you know, this is Microsoft
tech support.
We found this thing on your computer, you need to follow these instructions and all these
things kind of vary, but it's one of those things of if you're not aware during that
login process of something weird like, why is the hotel asking me to scan my computer
or why am I getting this Microsoft login prompt?
It definitely is out of the ordinary.
And I think that's the one trigger for a user, right?
Is you're not seeing a hotel login page.
That should be your first warning sign that something else is going on here.
Yeah, it's an interesting problem.
And as I was saying to you earlier, I started looking at this about 10 years ago
after the Honey Stick project where I was dropping USB drives.
I started exploring the possibility of doing a project called the Honey Point project where
we would set up some rogue, but not malicious access points with free Wi-Fi, capture some
data and just sort of see what was exposed and do a little experiment and report on that.
And it turned out that technologically it was actually kind of hard to, you know,
actually see anything because even 10 years ago, most important data streams were being
encrypted and a lot of people using VPNs even then.
So you couldn't really see much.
It doesn't mean that we couldn't have done something, but I decided not to go forward
with that one just because there wasn't a lot of free data available.
We could have though, as you suggested, done something a little more on the social
engineering side because when you set up one of these access points, you can
create, as you said, a captive portal that can collect any information you want.
You could, you know, you could typically, hotels always ask for your room number in
your name or something, but there are other free Wi-Fi portals where they just
ask for an email address and, you know, it seems like a fair exchange.
I'll give you my email address and you can be free Wi-Fi, right?
But you may immediately get an email, you know, that is a phishing email and
trying to social engineer you from that point of view, but you could also get,
as you said, those pop-ups that could try to download malware right to your computer.
So it's more of a social engineering risk, really, than the technology risks
that we all sort of assumed it would be.
Yeah, you're exactly right.
And the other thing I wanted to bring up is that a lot of people think
that if I'm using a VPN, that's going to protect me.
And that isn't always the case, right?
Because a VPN is used for really hiding the web traffic that you are sending
across the ISP that the hotel is using.
Or even if you're using a VPN at home, your, your internet access provider,
right, is they're unable to see your queries and what your, what websites
you're going to and things like that.
Now VPNs is a bigger issue altogether because there's been issues
with some VPN providers are able actually to see what you're doing.
And there's been court subpoenas and all these things of how much is logged,
right, with these VPN providers.
But it's really not protecting you from a malware type of attack where,
like in this case, with the captive crunch malware, like you're still
going to get a pop-up, like you're still going to get, if someone has
attacked the actual hotel network in that captive portal system,
turning your VPN on before that isn't really going to help you at all.
Cause that's just protecting the information that you're sending.
And by the way, that is still all encrypted through the use of HTTPS,
which I know we've talked about that in the past where before, way back
in the day, because Scott and I are old, we remember where you could
use a tool called SSL strip, which would basically force a captive
portal or, you know, another system into plain text, essentially.
So then you could intercept what people were doing on a hotel network
very easily.
And today that is much harder to do from an attacker perspective.
Yeah.
And you probably have seen, I've seen this many times, you go to a hotel
and there'd be four or five Wi-Fi hotspots, right?
And one of them will say, you know, Hilton guests or whatever.
And then you'll see one that's saying, Hilton free Wi-Fi.
And what are you going to pick?
Right.
If you're cheap, you're going to pick the free one because it doesn't
have any codes needed to get in.
And that sounds like a pretty good, you know, scenario for attacking somebody.
Yeah.
So that's, that's a great point, Scott, is, you know, be aware
of the hotel network you are connecting to because, yeah,
somebody could easily put up a fake portal or a fake access
point and redirect traffic through, through them.
That is totally plausible.
Now, the biggest thing I hear from a lot of people is like, Oh my gosh,
should we even use hotel Wi-Fi?
And like we always talk about this goes back to your threat model, right?
Depending on who you are and what you do and what types of
activities you're using the internet for, you may want to, you
know, purchase one of those hotspot devices or what, like what I do
when I travel, I use my phones built in personal hotspot.
Not that I don't trust the Wi-Fi network, but I actually find that
the speed and the quality of that connection over my mobile phone
is actually better than a lot of these crappy Wi-Fi networks.
I mean, it was a thing that a lot of people were scared to do
just because of the cost of mobile data years ago, but now
it's pretty much, you know, included in every plan.
So the cost shouldn't really be an issue anymore.
I do the same thing.
And the only time I would use a free one is if, you know, the
mobile data coverage is really weak.
And, you know, you can get something stronger locally, but
then I would use a VPN and I would also double check, you
know, any important portals or you're going to enter
information on because you can still see an, you know, a
TLS encryption logon icon or whatever it is, right, that
they show you when you're on a secured page, but that
doesn't mean you're on the legitimate page.
It only means that you've got SSL or TLS turned on.
I mean, I think the biggest piece of advice too is if you just
see anything strange, like, you know, popups or certificate
warnings or these types of things on a hotel network, you
should probably disconnect as soon as possible, right?
Like, because that is not normal.
You should not be seeing certificate errors.
You should not be seeing popups saying, this is
Microsoft support, install this thing, right?
Or like your point, Scott, about if you're, if you put in an
email address into a portal and then all of a sudden you're
getting these weird email messages, this happens at
airports too, right?
If that system was compromised, you need to be aware of that.
So again, I think the message is just being more aware
of anything strange that happens during that login
process and obviously you're not going to get, you
know, Microsoft scan malware requests.
As soon as you log into a hotel network, that is not normal.
So yeah, really important information, I think, for
being able to know.
Just something to be aware of.
I mean, I know we're coming towards the end of travel
season, you know, the end of summer is here.
I know we've got Labor Day this weekend or by the time
you listen to this episode, it will be Labor Day when
this episode is released in the US, but it's always
good to have kind of these travel tips around how
tell you how to use Wi-Fi more securely, hotel
network or not.
All right.
So I think that's all we have time for today, but Scott,
I wanted to give you a chance to plug the book again.
The book.
Yes.
Yeah.
Cool.
Let me just see.
How's that look there?
Oh, there we go.
Very nice.
It's a little bit cropped, but yeah, there's my, my
first version of the cover and title, the digital
legacy tree, ensuring your loved ones can access the
digital accounts they need after you die.
The title may actually change a little bit based
on feedback.
I have quite a few people doing reviews now, but
I'm really interested, especially in, you know,
security experts or financial planners, estate planners
who have, you know, a lot of experience in these
areas.
I'd really love to get more stories and feedback on
that, but a couple of interesting, you know, quotes
I just love to relay from early beta readers saying
things like, this is a remarkable resource.
I've recommended all my family members to get
a copy of it for their use.
Looking forward to seeing you get this published.
Also, I keep getting, keep being impressed with your
detail, which is very nice to hear.
So yeah, so yeah, if you're interested, Tom, I'll put
the link in the, in the show notes, but it's
securityperspectives.com.
You go there, you can find the link to the
digital legacy tree, a book and tools.
And yeah, congratulations on that.
It's great.
I love seeing it take off and you've been getting
good feedback and that's great.
So we'll continue to give that.
Hope to publish this in the next month or two.
Um, it's, it's going to be self published and you know,
it's, I think it'll be pretty straightforward.
In fact, I'm going to be probably offering free
versions of the, the Kindle version for a while
until I get some reviews.
So stay tuned for how you can get that.
All right, everyone.
Well, thank you again for listening and
subscribing and sharing the podcast with your
friends and colleagues.
It's much appreciated.
We love getting feedback by the way.
If you have feedback about this episode, you
can drop a comment in our YouTube video for
this, or you can send us an email at feedback
at shared security.net.
So until next time, stay safe, stay secure
and stay private.
Thank you for listening or watching.
If you liked this episode, hit subscribe, share
it with your friends and colleagues or jump
into our community at shared security.net
slash supporter to keep the conversation going.
Thanks again, and we'll see you next week
for another episode of shared security.