Every hotel, clinic, senior living community, retailer, and conference center offers guest Wi-Fi. Most of those networks share the same design: an open SSID with no encryption, and maybe a splash page asking visitors to accept terms. It's familiar, it's easy, and it's the weakest link in a lot of otherwise well-run networks.

Here's what actually goes wrong on public and guest Wi-Fi — and what venue operators can do about it today.

Why open Wi-Fi is risky

An open network has no encryption over the air. Anything a device sends that isn't separately protected can be observed by someone nearby. Networks that “protect” guests with a passphrase printed on a table tent aren't much better: when everyone knows the password, the password isn't protecting anyone from anyone else. On WPA2-Personal, someone who knows that shared passphrase can decrypt other users' traffic.

The Wireless Broadband Alliance's 2026 Wi-Fi Security FAQ lists the most common risks of unsecured Wi-Fi:

  • Data interception — passwords, emails, messages, and browsing activity.
  • Man-in-the-middle attacks, where an attacker reads or alters traffic in transit.
  • Evil twin hotspots — fake networks set up to impersonate a real one.
  • Malware injection through downloads, ads, or unsecured websites.

How an evil twin attack works

An evil twin is a rogue access point broadcasting the same network name as a legitimate one — “Hotel_Guest” or “Clinic-WiFi.” Devices can't tell the difference between two open networks with the same name, so users connect to whichever signal is stronger. Once connected, the attacker can watch traffic, inject content, or present a fake captive portal that harvests names, emails, room numbers, or credentials.

The uncomfortable part for venue operators: on an open network, there's nothing built into the connection that proves the network is really yours. That protection has to come from somewhere else.

The trouble with captive portals

Captive portals — the login or “accept terms” pages that pop up after you join — are everywhere. They're also, as the WBA notes, complex to configure and maintain, and many administrators are actively looking for something better. From a security standpoint, they have three problems:

  1. They don't encrypt anything. A portal sits on top of an open network; the radio link underneath is still unprotected.
  2. They train users to type information into pop-ups on networks they can't verify — exactly the behavior an evil twin exploits.
  3. They break things. Smart TVs, medical devices, voice assistants, and many IoT devices can't complete a portal flow at all, which leads to workarounds that weaken the network further.

Better options, from good to best

Good: Opportunistic Wireless Encryption (OWE)

OWE (marketed as Wi-Fi Enhanced Open) gives each device its own encryption keys on an open network using a Diffie-Hellman key exchange — no password and no user action required. It stops passive eavesdropping, which is a real improvement. But it has limits: client support isn't universal, it doesn't prove the network's identity, and so it doesn't stop evil twins.

Better: segmentation and client isolation

Whatever authentication you use, guest traffic should live on its own VLAN, be isolated from staff and operational systems, and have client-to-client isolation turned on so guests can't reach each other's devices. This doesn't make the radio link private, but it sharply limits what an attacker can reach.

Best: Passpoint and OpenRoaming

Passpoint (also called Hotspot 2.0) and the OpenRoaming federation built on it solve the problem at the root. Devices authenticate automatically using a trusted credential — a carrier SIM, a corporate identity, or a federated account — and every session is encrypted from the moment of connection. Crucially, the authentication only succeeds if the network can establish a secure signaling connection with the user's credential provider. An evil twin can't do that, so the device refuses to connect.

No splash page. No guessing which network is real. And for users, it simply works — the same way their phone joins a cellular network.

For venue operators: you don't have to choose one approach. A common modern design runs Passpoint/OpenRoaming for devices that support it, an OWE or segmented guest SSID for everything else, and retires the open captive-portal network over time.

What visitors should do in the meantime

If you're the one connecting rather than running the network, the WBA's practical advice holds up: prefer Passpoint/OpenRoaming networks when available, avoid fully open or suspicious hotspots, keep devices updated, rely on HTTPS for anything sensitive, and use a trusted VPN on networks you can't verify.

The bottom line

Guest Wi-Fi is part of the experience you deliver. An open network with a captive portal was a reasonable compromise a decade ago. Today, the tools exist to give guests a connection that's both easier and genuinely secure — and to take your venue's name out of the evil twin playbook.

Source material: Wireless Broadband Alliance, Wi-Fi Security – General Audience FAQ, v1.0.0 (April 2026).