Shared Security Podcast

Hotel Wi‑Fi is not automatically unsafe, but Microsoft’s CaptiveCrunch reporting shows how a routine captive-portal connection can be manipulated into credential theft or malware delivery.

Show Notes

Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware delivery.

They cover what HTTPS and VPNs actually protect, why a lock icon does not prove a page is legitimate, the warning signs that should make travelers disconnect, and when a cellular hotspot is the better choice. Scott also shares an update on his Digital Legacy Tree book and tools.

** Links mentioned on the show **

Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/

FBI hotel Wi‑Fi guidance https://watech.wa.gov/fbi-warns-cyber-risks-when-telecommuters-use-hotel-wi-fi

FCC — Cybersecurity Tips for International Travelers https://www.fcc.gov/consumers/guides/cybersecurity-tips-international-travelers

Scott Wright — Digital Legacy Tree book and tools https://securityperspectives.com/digital-legacy-tools

** Watch this episode on YouTube **

https://youtu.be/TBqKfiGayfo

** Become a Shared Security Supporter **

Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join

** Thank you to our sponsors! **

SLNT

Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".

** Subscribe and follow the podcast **

Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast

Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social

Follow us on Mastodon: https://infosec.exchange/@sharedsecurity

Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/

Visit our website: https://sharedsecurity.net

Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe

Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe

Leave us a rating and review: https://ratethispodcast.com/sharedsecurity

Contact us: https://sharedsecurity.net/contact

What is Shared Security Podcast?

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Welcome to the Shared Security Podcast, the longest running cyber security and privacy

show for actual humans.

No jargon, no hype, just honest analysis from industry veterans who've seen everything

and survived it.

Each week we break down the stories that matter, expose the nonsense that doesn't, and give

you the tools to stay safe in a world where everything is connected and nothing is guaranteed.

This is Shared Security.

This week on Shared Security we're talking about hotel wifi, and is it actually safe?

Well, the answer isn't never use hotel wifi, but the moment your phone or laptop throws

up a hotel login page is exactly when you should slow down and pay attention.

So we're talking about the captive crunch malware campaign where attackers turn that

ordinary wifi connection step into a chance to steal credentials or deliver malware.

So we'll cover the right flags that should make you stop.

We'll talk about a VPN and what that does and doesn't do, and the simple habits that

keep a hotel connection from turning into an account takeover.

And joining me for this conversation is the one and only Scott Wright.

Oh there, hello from Canada.

Hello from Canada.

How's it going up in Canada?

Oh, not too bad.

We're under attack by Canada geese that have machine guns and weird looking hairdos, but

yeah.

Yeah, that's awful.

I'm sorry you're going through that.

We have Canada geese here too, and they are invasive, but you know, I mean you guys

have invaded the United States at one point before.

Not before, we'll do it again if we have to.

You'll do it again if you've got to burn the White House down again.

You've got to do it.

I know.

I know.

Yeah.

Besides all that, we're here to talk about wifi.

You know, it's fascinating to me, we were just talking about this before the podcast

is that the threats around wifi haven't really changed over the years.

We're talking way back, right?

We've been always having this conversation about wifi on the show, and if you look

back on our previous episodes, you'll see we're kind of talking about the same thing.

Even though there's new attacks and there's kind of new methods, but the end of the day,

the same advice still applies that we're going to talk about on this podcast today.

It's because it's not all technology that has the risks.

That's right.

Yeah.

That's right.

So just to kind of frame everything, so I was kind of inspired by a couple of weeks

ago, Microsoft released some details about an attack that they've been seeing more focused

on Entra ID, which is kind of the central authentication system for Microsoft products.

And there is a dub this attack called captive crunch, not captain crunch, like the cereal.

I mean, a little confusing there, but captive crunch.

And this malware campaign is essentially pretty widespread according to Microsoft.

So this has been affecting hotel chains, large conference centers, you know, things like that.

And what they found was that, you know, these are mostly state sponsored threat actors that

are doing these things.

But what happens is you'll be just like you normally do connect to the hotel wifi

and you get this thing called a captive portal, which is, you know, some type of

login or authentication to, you know, so not everybody can access the wifi network, but

hotel guests specifically.

And these vary by hotel chain, by the systems that they're using.

But what's happening is that users will get this pop up for, hey, Microsoft found malware

on your machine, you need to click here, or they'll be a prompt for your user credentials,

like for your Microsoft login credentials with something saying, hey, you know, this is Microsoft

tech support.

We found this thing on your computer, you need to follow these instructions and all these

things kind of vary, but it's one of those things of if you're not aware during that

login process of something weird like, why is the hotel asking me to scan my computer

or why am I getting this Microsoft login prompt?

It definitely is out of the ordinary.

And I think that's the one trigger for a user, right?

Is you're not seeing a hotel login page.

That should be your first warning sign that something else is going on here.

Yeah, it's an interesting problem.

And as I was saying to you earlier, I started looking at this about 10 years ago

after the Honey Stick project where I was dropping USB drives.

I started exploring the possibility of doing a project called the Honey Point project where

we would set up some rogue, but not malicious access points with free Wi-Fi, capture some

data and just sort of see what was exposed and do a little experiment and report on that.

And it turned out that technologically it was actually kind of hard to, you know,

actually see anything because even 10 years ago, most important data streams were being

encrypted and a lot of people using VPNs even then.

So you couldn't really see much.

It doesn't mean that we couldn't have done something, but I decided not to go forward

with that one just because there wasn't a lot of free data available.

We could have though, as you suggested, done something a little more on the social

engineering side because when you set up one of these access points, you can

create, as you said, a captive portal that can collect any information you want.

You could, you know, you could typically, hotels always ask for your room number in

your name or something, but there are other free Wi-Fi portals where they just

ask for an email address and, you know, it seems like a fair exchange.

I'll give you my email address and you can be free Wi-Fi, right?

But you may immediately get an email, you know, that is a phishing email and

trying to social engineer you from that point of view, but you could also get,

as you said, those pop-ups that could try to download malware right to your computer.

So it's more of a social engineering risk, really, than the technology risks

that we all sort of assumed it would be.

Yeah, you're exactly right.

And the other thing I wanted to bring up is that a lot of people think

that if I'm using a VPN, that's going to protect me.

And that isn't always the case, right?

Because a VPN is used for really hiding the web traffic that you are sending

across the ISP that the hotel is using.

Or even if you're using a VPN at home, your, your internet access provider,

right, is they're unable to see your queries and what your, what websites

you're going to and things like that.

Now VPNs is a bigger issue altogether because there's been issues

with some VPN providers are able actually to see what you're doing.

And there's been court subpoenas and all these things of how much is logged,

right, with these VPN providers.

But it's really not protecting you from a malware type of attack where,

like in this case, with the captive crunch malware, like you're still

going to get a pop-up, like you're still going to get, if someone has

attacked the actual hotel network in that captive portal system,

turning your VPN on before that isn't really going to help you at all.

Cause that's just protecting the information that you're sending.

And by the way, that is still all encrypted through the use of HTTPS,

which I know we've talked about that in the past where before, way back

in the day, because Scott and I are old, we remember where you could

use a tool called SSL strip, which would basically force a captive

portal or, you know, another system into plain text, essentially.

So then you could intercept what people were doing on a hotel network

very easily.

And today that is much harder to do from an attacker perspective.

Yeah.

And you probably have seen, I've seen this many times, you go to a hotel

and there'd be four or five Wi-Fi hotspots, right?

And one of them will say, you know, Hilton guests or whatever.

And then you'll see one that's saying, Hilton free Wi-Fi.

And what are you going to pick?

Right.

If you're cheap, you're going to pick the free one because it doesn't

have any codes needed to get in.

And that sounds like a pretty good, you know, scenario for attacking somebody.

Yeah.

So that's, that's a great point, Scott, is, you know, be aware

of the hotel network you are connecting to because, yeah,

somebody could easily put up a fake portal or a fake access

point and redirect traffic through, through them.

That is totally plausible.

Now, the biggest thing I hear from a lot of people is like, Oh my gosh,

should we even use hotel Wi-Fi?

And like we always talk about this goes back to your threat model, right?

Depending on who you are and what you do and what types of

activities you're using the internet for, you may want to, you

know, purchase one of those hotspot devices or what, like what I do

when I travel, I use my phones built in personal hotspot.

Not that I don't trust the Wi-Fi network, but I actually find that

the speed and the quality of that connection over my mobile phone

is actually better than a lot of these crappy Wi-Fi networks.

I mean, it was a thing that a lot of people were scared to do

just because of the cost of mobile data years ago, but now

it's pretty much, you know, included in every plan.

So the cost shouldn't really be an issue anymore.

I do the same thing.

And the only time I would use a free one is if, you know, the

mobile data coverage is really weak.

And, you know, you can get something stronger locally, but

then I would use a VPN and I would also double check, you

know, any important portals or you're going to enter

information on because you can still see an, you know, a

TLS encryption logon icon or whatever it is, right, that

they show you when you're on a secured page, but that

doesn't mean you're on the legitimate page.

It only means that you've got SSL or TLS turned on.

I mean, I think the biggest piece of advice too is if you just

see anything strange, like, you know, popups or certificate

warnings or these types of things on a hotel network, you

should probably disconnect as soon as possible, right?

Like, because that is not normal.

You should not be seeing certificate errors.

You should not be seeing popups saying, this is

Microsoft support, install this thing, right?

Or like your point, Scott, about if you're, if you put in an

email address into a portal and then all of a sudden you're

getting these weird email messages, this happens at

airports too, right?

If that system was compromised, you need to be aware of that.

So again, I think the message is just being more aware

of anything strange that happens during that login

process and obviously you're not going to get, you

know, Microsoft scan malware requests.

As soon as you log into a hotel network, that is not normal.

So yeah, really important information, I think, for

being able to know.

Just something to be aware of.

I mean, I know we're coming towards the end of travel

season, you know, the end of summer is here.

I know we've got Labor Day this weekend or by the time

you listen to this episode, it will be Labor Day when

this episode is released in the US, but it's always

good to have kind of these travel tips around how

tell you how to use Wi-Fi more securely, hotel

network or not.

All right.

So I think that's all we have time for today, but Scott,

I wanted to give you a chance to plug the book again.

The book.

Yes.

Yeah.

Cool.

Let me just see.

How's that look there?

Oh, there we go.

Very nice.

It's a little bit cropped, but yeah, there's my, my

first version of the cover and title, the digital

legacy tree, ensuring your loved ones can access the

digital accounts they need after you die.

The title may actually change a little bit based

on feedback.

I have quite a few people doing reviews now, but

I'm really interested, especially in, you know,

security experts or financial planners, estate planners

who have, you know, a lot of experience in these

areas.

I'd really love to get more stories and feedback on

that, but a couple of interesting, you know, quotes

I just love to relay from early beta readers saying

things like, this is a remarkable resource.

I've recommended all my family members to get

a copy of it for their use.

Looking forward to seeing you get this published.

Also, I keep getting, keep being impressed with your

detail, which is very nice to hear.

So yeah, so yeah, if you're interested, Tom, I'll put

the link in the, in the show notes, but it's

securityperspectives.com.

You go there, you can find the link to the

digital legacy tree, a book and tools.

And yeah, congratulations on that.

It's great.

I love seeing it take off and you've been getting

good feedback and that's great.

So we'll continue to give that.

Hope to publish this in the next month or two.

Um, it's, it's going to be self published and you know,

it's, I think it'll be pretty straightforward.

In fact, I'm going to be probably offering free

versions of the, the Kindle version for a while

until I get some reviews.

So stay tuned for how you can get that.

All right, everyone.

Well, thank you again for listening and

subscribing and sharing the podcast with your

friends and colleagues.

It's much appreciated.

We love getting feedback by the way.

If you have feedback about this episode, you

can drop a comment in our YouTube video for

this, or you can send us an email at feedback

at shared security.net.

So until next time, stay safe, stay secure

and stay private.

Thank you for listening or watching.

If you liked this episode, hit subscribe, share

it with your friends and colleagues or jump

into our community at shared security.net

slash supporter to keep the conversation going.

Thanks again, and we'll see you next week

for another episode of shared security.