6. Safe browsing and public Wi-Fi
How to Tell a Safe Website from a Dangerous One
Before you type a password or pay online, always check these three things in your browser:
1. Look for HTTPS — not HTTP
The address bar at the top of your browser shows the website address. A safe website starts with https:// — the 's' stands for 'secure'. An older or unsafe site starts with http:// (no 's'). When a site is HTTPS, the connection between your phone and the website is encrypted, meaning no one in the middle can read what you send.
2. Check the padlock icon
Next to the address, most browsers show a small padlock icon when HTTPS is active. Tap or click it to see the site's security certificate. If you see a warning triangle or 'Not Secure', stop — do not enter any information.
3. Read the domain name carefully
Criminals create fake websites that look exactly like real ones but have a slightly different address. Look very carefully at the full domain name:
• Legitimate: www.ethiotelecom.et
• Fake: www.eth1otelecom.et (a '1' instead of the letter 'i')
• Legitimate: www.telebirr.com
• Fake: www.telebir.com (one 'r' missing)
Always type addresses yourself rather than clicking links in SMS or email messages.
Public Wi-Fi — Convenient but Risky
Free Wi-Fi hotspots in cafés, hotels, hospitals, universities, and Ethio Telecom shops across Addis Ababa and other cities are extremely convenient. But they come with serious risks that most people do not realise.
Why public Wi-Fi is dangerous
When many people share the same Wi-Fi network, a skilled attacker on that network can use tools to intercept (read) the data being sent by other users. This is called a 'man-in-the-middle' attack. If you log in to your email or bank while on public Wi-Fi without protection, your username and password can be captured.
The 'evil twin' hotspot
Another common trick is for a criminal to set up a fake Wi-Fi hotspot with a name almost identical to a legitimate one:
• Real network: 'Bole Airport Free WiFi'
• Fake network: 'Bole Airport Free WiFi2'
Once you connect to the fake network, the criminal can see everything you send and receive.
What you CAN safely do on public Wi-Fi
• Read news articles and watch public videos.
• Use apps that use HTTPS (most modern apps do).
• Make voice or video calls on WhatsApp or Telegram (these are end-to-end encrypted).
What you should AVOID on public Wi-Fi without a VPN
• Logging in to your bank app or TeleBirr.
• Entering your passwords or PINs.
• Shopping online with your bank card.
• Opening work email or important documents.
What Is a VPN and When Do You Need One?
A VPN (Virtual Private Network) is an app that creates an encrypted tunnel between your phone and a server elsewhere on the internet. All your internet traffic passes through this tunnel, so even if someone is spying on your Wi-Fi, they see only scrambled, unreadable data.
Think of it like this: imagine you are sending a private letter in a sealed envelope, instead of a postcard that anyone can read. The VPN is the sealed envelope.
When a VPN is especially useful:
• Any time you use public Wi-Fi (cafés, hotels, airports, hospitals).
• When accessing sensitive accounts away from home.
• When you want extra privacy on your browsing history.
How to choose a safe VPN:
• Use a paid, reputable VPN service — free VPNs are often the product: they sell your data.
• Look for VPNs with a 'no-logs' policy, meaning they do not record your browsing history.
• Trusted options available in Ethiopia include ProtonVPN (has a genuinely free tier), Mullvad, and ExpressVPN.
• Avoid VPNs whose privacy policies are unclear, or that are made by companies with no reputation.
Using a VPN does not make you completely invisible online — your VPN provider can see your traffic. Choose a trustworthy provider.
Scenario
Sara is sitting in a café near Meskel Square in Addis Ababa, using their free Wi-Fi. She wants to pay her electricity bill via her bank's website. She notices the bank website address shows http:// (not https://) and there is a 'Not Secure' warning in her browser. What should Sara do?
Safer Browsing Habits and Browser Settings
Beyond checking website addresses, a few simple habits and settings will dramatically improve your safety while browsing:
Keep your browser updated
Your browser (Chrome, Firefox, Samsung Internet, Safari) receives regular security updates. Enable automatic updates or manually update your browser when prompted. Outdated browsers have known vulnerabilities that criminals actively exploit.
Enable 'Safe Browsing' in Chrome
Google Chrome has a feature called Safe Browsing (Settings → Privacy and Security → Safe Browsing → select 'Enhanced Protection'). When you visit a dangerous or deceptive site, Chrome warns you before the page loads.
Be careful with browser extensions
Extensions (or add-ons) added to your browser can have access to everything you do — every page you visit, every password you type. Only install extensions from trusted sources, and delete any you no longer use. Criminals sometimes buy old extensions and inject malware into them via updates.
Clear your browser history and cookies on shared devices
If you ever use a shared computer (like in a school or internet café), always sign out of all accounts and clear the browser history, cookies, and saved passwords when you are done (Settings → Privacy → Clear browsing data).
Do not save passwords in the browser on shared or public devices
Most browsers offer to save your passwords. This is convenient on your personal phone, but never allow it on a shared or public computer — the next user could access your saved accounts.
Check your understanding
1/7 · 80 XPAlmaz opens a website to pay her water bill. The address bar shows 'http://waterauthority-pay.et'. What should concern her most?