Working From Bali, Lisbon or Medellín? The 5-Minute Security Checklist for Coworking Wi-Fi

Shared Wi-Fi is safer than it was a decade ago, but a coworking network still puts your laptop on the same network as dozens of strangers, and the bigger threat in most nomad hubs walks in through the front door. Here is the routine that covers both.

By NetWorthy Editors · · 10 min read · 19 sources

Person in a beige wrap writing in a notebook with a pen
Photo: IqbalStock on Pixabay

Key takeaways

  • The FTC says connecting through public Wi-Fi is usually safe today because most sites encrypt traffic, but shared networks still expose your device to fake hotspots and other users on the same network.
  • Australian police charged a man in 2024 for running fake 'evil twin' Wi-Fi networks at Perth, Melbourne and Adelaide airports and on domestic flights, and harvesting login credentials.
  • Five settings do most of the work: VPN on, Wi-Fi auto-join off, firewall on with sharing off, automatic updates on, and a password manager with passkeys for your important accounts.
  • Physical theft is the bigger day-to-day risk in nomad hubs: Portugal logged 7,443 pickpocket thefts in 2025 with 46% in the Lisbon district, and Bali police are warning about motorbike phone snatching.
  • Turn on device-level theft protection (such as Apple's Stolen Device Protection) and full-disk encryption before you travel, so a stolen laptop or phone doesn't become a stolen bank account.

How risky is coworking or café Wi-Fi in 2026?

For ordinary browsing, less risky than its reputation: the U.S. Federal Trade Commission now says "connecting through a public Wi-Fi network is usually safe" because most websites encrypt the traffic between your device and the site. The problem is what encryption doesn't cover. On a shared network in a Canggu coworking space, a Lisbon café or a Medellín Airbnb, your laptop sits on the same local network as everyone else, the network name can be faked, and a login page can be a trap.

The fake-network risk isn't theoretical. In 2024 the Australian Federal Police charged a man accused of running "evil twin" Wi-Fi networks at airports in Perth, Melbourne and Adelaide and on domestic flights. The fake hotspots mimicked legitimate ones and sent people to fraudulent login pages that harvested email and social media credentials. The AFP's advice afterwards was the same short list security agencies keep repeating: use a VPN, turn off file sharing, don't enter credentials on suspicious access points, and forget networks you no longer use.

The FTC also flags the gap that HTTPS can't close: "if you visit a scammer's website, your data may be encrypted...but it won't be safe from scammers." The padlock tells you the connection is encrypted, not that the site is real. That's why the checklist below leans on settings that work even when you click the wrong thing.

What's on the 5-minute checklist?

Seven settings and habits, each under a minute, cover the realistic risks of working on shared Wi-Fi. Do the first five once per device and the last two whenever you sit down somewhere new.

  1. VPN on, set to connect automatically on untrusted networks.
  2. Wi-Fi auto-join off for café and coworking networks, and forget the ones you're done with.
  3. Firewall on, sharing off, and the network set to Public on Windows.
  4. Automatic OS and browser updates on.
  5. Password manager plus passkeys on email, banking and work accounts, with two-factor authentication everywhere else.
  6. Confirm the network name with staff before you join, and ignore lookalikes.
  7. Physical setup: back to a wall, screen away from the room, bag strapped to the chair, phone off the table edge.
In a coworking space you share the network, and the room, with dozens of strangers, which is why the checklist covers both. Video: Life-Of-Vids on Pixabay

Do you actually need a VPN on coworking Wi-Fi?

Yes, if you're logging into anything that matters. When the NSA published its 2021 guidance on securing wireless devices in public, it told staff that work on public Wi-Fi "should be conducted over a corporate-provided virtual private network", or else over a personal hotspot rather than an open one. The same guidance said to disable Bluetooth discoverability in public and never accept pairing requests you didn't start. The FTC also suggests a VPN if you regularly access accounts over public networks.

A VPN encrypts everything leaving your device, not just the websites that use HTTPS. That covers background app traffic and DNS lookups that can reveal which services you use, and it means a fake hotspot sees only encrypted traffic to the VPN server. If you're unsure how that tunnel works, start with what a VPN is and isn't.

Three settings make the difference between having a VPN and actually using one:

  • Auto-connect on untrusted networks. Most major VPN apps can switch on whenever you join a network you haven't marked as trusted. Turn it on so you never browse "just for a second" without it.
  • Kill switch on. This blocks traffic if the VPN drops, which happens on flaky café connections.
  • Every device covered. Your phone joins the same network as your laptop. See setting up a VPN on every device.

If you haven't picked a provider, our best VPN comparison ranks the options on speed and app quality, and VPN free trials lists the ones you can test on your actual coworking connection before paying. A VPN won't stop you typing a password into a phishing page, though. That's what the password manager and passkeys in step five are for.

Why turn off Wi-Fi auto-join?

Because an evil twin works by reusing a name your device already trusts. If your phone remembers "Dojo_Guest" or "Cafe_Free_WiFi", it may join any network broadcasting that name, anywhere, without asking you. Turning off auto-join, or forgetting the network entirely, closes that door.

  • iPhone and iPad: Settings, Wi-Fi, tap the More Info button next to the network, then turn off Auto-Join or tap Forget This Network. Apple's support page explains that turning off Auto-Join keeps the password but stops automatic reconnection, while forgetting removes both.
  • Mac: System Settings, Wi-Fi, click the More Options button next to the network, then turn off Auto-Join or choose Remove From List.
  • Windows: when you join a café or coworking network, leave "Connect automatically" unticked, and remove old networks from the known-networks list.

Before joining at all, confirm the exact network name and login procedure with staff. Two networks with nearly identical names in the same café is your cue to ask, and the AFP's advice after the airport case was simply not to enter credentials on access points that look suspicious.

Which firewall and sharing settings matter on shared networks?

The ones that make your laptop invisible to everyone else on the network. A VPN protects traffic leaving your device, but other users on the same coworking LAN can still try to reach your device directly, through file sharing, printer sharing or a service you forgot was running.

  • Windows: set the network profile to Public. Microsoft's network settings guide recommends Public for networks at home, work or in public places. Under that profile your PC stays hidden from other devices on the network, which blocks file and printer sharing. Private makes your PC discoverable and should only be used where you trust every person and device.
  • Mac: System Settings, Network, Firewall, toggle it on. Apple's firewall guide covers the Options button for per-app rules. Then open your Sharing settings and switch off anything you don't need on the road, such as file sharing and screen sharing.
  • Everyone: The NSA's public Wi-Fi guidance specifically says to turn off file and printer sharing on laptops connected to public networks. If you share files with a colleague, use a cloud link instead of an open folder.
Desktop monitor, laptop and smartphone on a white desk with a potted plant
Firewall on and sharing off takes under a minute and closes the door other users on the network could knock on. Photo: Artist_atsite on Pixabay

Do OS updates really matter for Wi-Fi security?

Yes, because attackers on a shared network go after known, unpatched flaws. As CISA puts it, "many software updates are created to fix security risks." The FTC's public Wi-Fi guidance makes the same point and says to turn on automatic updates for your operating system, browser and security software.

Nomads often put updates off because they eat data or need a restart before a client call. Fix that with timing rather than skipping: let updates install overnight on your accommodation Wi-Fi with the VPN on, and check on the first day in a new city that nothing is waiting. The same goes for your router-style gadgets, such as a travel router or portable hotspot.

How do a password manager and passkeys protect you on public Wi-Fi?

They stop the attack that HTTPS and VPNs can't: you handing your password to a fake page. A password manager only autofills on the real domain it saved, so a lookalike login page on an evil twin network gets nothing. CISA calls a password manager "an easy-to-use program that generates, stores and even fills in all your passwords".

Passkeys go a step further. The FIDO Alliance describes a passkey as a credential stored on your phone, computer or hardware key that you unlock with the same biometric or PIN you use to unlock the device, and it is bound to the real site, so it can't be phished onto a fake one. In a 2024 survey commissioned by FIDO, 53% of people said they had enabled passkeys on at least one account. Set them up first on the accounts that unlock everything else: your main email, your bank and your work login.

For accounts without passkey support, turn on two-factor authentication, prefer an authenticator app over SMS when you're swapping SIMs, and use a different password everywhere. If a banking app locks you out after you sign in from a new country, see our guide on why banking apps stop working abroad.

Is laptop and phone theft a bigger risk than hackers in Bali, Lisbon and Medellín?

For most nomads, yes. Local reporting from all three hubs points to street theft, not Wi-Fi hacking, as the everyday threat.

Bali

Australian outlets reported in July 2026 that Bali is seeing a wave of snatch-and-grab thefts, mostly by thieves on motorbikes targeting exposed phones, jewellery and bags in Seminyak, Kuta, Canggu, Legian and Uluwatu, particularly after dark. In June 2026 a New Zealand tourist had her iPhone snatched near Kuta while riding as a motorbike passenger and checking directions. Police advised not holding your phone openly near the road edge and using a phone holder or voice directions instead. Badung police ask victims to report to the nearest station or call 110.

Lisbon

Portugal's 2025 Annual Internal Security Report recorded 7,443 pickpocket thefts, up 7.7% on 2024, with 46% in the Lisbon district and roughly three-quarters of those in the capital itself. The classic hotspot is the crowded tram.

“Before we had managed to say a very few words, one of the policemen said: “Tram number 28?””

— yamey, Adam Yamey Writes (blog) · Travel blogger describing being pickpocketed getting off Lisbon's 28 tram, July 2019

Medellín

In February 2026 more than 400 police officers raided the El Opera sector of downtown Medellín, recovering 150 stolen phones and finding a workshop where stolen devices were reset for resale. A year earlier police arrested a woman accused of drugging foreign visitors she met through dating apps, mainly in El Poblado and Itagüí, and stealing phones, cards and electronics. The nomad advice on laptops in Medellín cafés has been consistent for years:

“they spot you in a cafe, then they’ll wait till you leave, follow you, put a gun on your head”

— @levelsio, Nomads.com forum · Nomad List founder relaying what locals told him about working in Medellín cafés, March 2016

“lots of people working on their laptop, on a terras, in Medellin (El Poblado)… But do not try that in the sketchier areas.”

— @giovanni, Nomads.com forum · Nomad replying in the same thread, March 2016

The physical checklist

  • Sit with your back to a wall and your screen facing it, which also stops shoulder surfing of passwords and client documents. A privacy screen filter helps on trains and in open-plan coworking.
  • Loop a bag strap around a chair leg, and never leave a laptop or phone unattended for a coffee refill.
  • Keep your phone off the table edge nearest the street, and off your lap on a scooter.
  • Pack away before you leave, not on the pavement outside.
  • Turn on full-disk encryption (FileVault on Mac, BitLocker or Device Encryption on Windows) and a short auto-lock time.

On iPhone, turn on Stolen Device Protection, which adds extra security when your phone is away from familiar locations such as home or work. It requires iOS 17.3 or later, two-factor authentication on your Apple Account, a passcode, Face ID or Touch ID, Significant Locations and Find My. That combination means a thief who watched you type your passcode still can't immediately change your Apple Account password or reach saved passwords.

Canvas backpack laid out with a notebook, watch, coins and a travel guide on a dark surface
Looping a strap around a chair leg is low-tech, but it defeats the grab-and-run. Photo: Pexels on Pixabay

What should you do if your device is stolen or you joined a fake network?

Act in the first hour, and in this order: lock and locate, change passwords, then report.

  1. Lock or wipe the device from Find My (Apple) or Find My Device (Google or Microsoft) on a friend's phone or a laptop.
  2. Change your main email password first, then banking and work accounts, from a trusted device. A password manager makes this a 10-minute job instead of an afternoon.
  3. Call your bank's international line to freeze cards and alert them to the theft. Our guide to getting locked out of your U.S. bank as an expat covers how to avoid a second crisis when they re-verify you.
  4. Report it locally: 110 in Indonesia, 123 in Colombia, or the PSP tourist police in Lisbon. You'll need a report for insurance claims, and Medellín police say recovered phones can be returned to owners who filed one.
  5. If you entered a password on a suspicious network, change that password, sign out of all sessions and check your account's recent sign-in activity.

If you're heading out on a new visa, pair this routine with our pre-flight checklist for approved digital nomad visas. If you also travel for work and stay in hotels, read how attackers are targeting hotel Wi-Fi to steal Microsoft 365 logins and our 2026 business traveler's security guide.

Frequently asked questions

Is coworking Wi-Fi safe to use for online banking?

It's usually workable because banking sites and apps encrypt your connection, and the FTC says public Wi-Fi is usually safe today for that reason. Add a VPN, confirm the network name with staff, and use passkeys or app-based two-factor authentication so a fake login page can't capture your credentials.

What is an evil twin Wi-Fi network?

It's a fake hotspot that copies the name of a real one so devices join it, often showing a fake login page to capture passwords. Australian police charged a man in 2024 for running evil twin networks at airports and on flights. Turning off auto-join and confirming network names with staff are the main defences.

Does a VPN protect my laptop from theft or phishing?

No. A VPN encrypts your internet traffic on shared networks, but it won't stop someone grabbing your laptop or stop you typing a password into a convincing fake page. You need full-disk encryption and theft protection for the first, and a password manager plus passkeys for the second.

Should I set coworking Wi-Fi to Public or Private on Windows?

Public. Microsoft recommends the Public profile for networks at home, work or in public places, because it hides your PC from other devices on the network and blocks file and printer sharing. Only use Private on a network where you trust every person and device.

Is it safe to work on a laptop in Medellín cafés?

Many nomads do, mostly in busier areas like El Poblado, but locals and long-time visitors warn about being followed after leaving a café with a laptop. Keep your setup discreet, pack up before you leave, avoid flashing devices in quieter streets, and make sure the laptop is encrypted and backed up.

Sources

  1. Are Public Wi-Fi Networks Safe? What You Need To Know — Federal Trade Commission
  2. NSA Releases Guidance on Securing Wireless Devices While in Public — CISA, 2021-07-30
  3. NSA to National Security Employees: Avoid Working on Public Wi-Fi — Nextgov/FCW, 2021-07-30
  4. Australian charged for 'Evil Twin' WiFi attack on plane — BleepingComputer, 2024-07-01
  5. Forget a Wi-Fi network or prevent your device from automatically joining it — Apple Support
  6. Block connections to your Mac with a firewall — Apple Support
  7. Essential network settings and tasks in Windows — Microsoft Support
  8. Update Software — CISA (Secure Our World)
  9. Use Strong Passwords — CISA (Secure Our World)
  10. Passkeys — FIDO Alliance
  11. About Stolen Device Protection for iPhone — Apple Support
  12. 'Really bad': Warning for Aussies headed to Bali — InDaily, 2026-07-09
  13. Kuta Police Investigate Tourist iPhone Theft — Bali Live, 2026-06-18
  14. Furtos por carteiristas aumentaram em 2025 — DNoticias.pt, 2026-03-31
  15. Si le robaron el celular hace poco en Medellín, así lo puede recuperar: encuentran 150 aparatos en mega operativo en El Opera — Publimetro Colombia, 2026-02-06
  16. Capturan a mujer que usaba sustancias tóxicas para poder robar extranjeros en Medellín — Publimetro Colombia, 2025-02-13
  17. Is it safe to work with your laptop from coffee shops in South/Central America? — Nomads.com forum, 2016-03
  18. Tram number 28 — Adam Yamey Writes, 2019-07-17
  19. Secure, Sync and Share Passkeys Across Devices with Keeper — Keeper Security

Quotes from social posts are reproduced verbatim from public posts and linked to the original. Read our editorial standards.

From Rotation

Every story, one email, 8am daily.

Subscribe at the bottom of this page.

More travel guides