Wi-Fi security · Plain-English answer
An evil twin is a fake Wi-Fi hotspot that copies the name of a legitimate network, such as a cafe or airport, to trick devices into connecting. Once connected, the attacker controls the network and can watch unencrypted traffic, serve fake login pages, or redirect you to malicious sites.
Wi-Fi networks are identified by name, and names can be copied by anyone with cheap hardware. An attacker sits in a public place broadcasting a network called something plausible, often the exact name of the venue's real Wi-Fi with a stronger signal. Phones and laptops that have joined the real network before may even reconnect to the imposter automatically.
Once you are on it, every request flows through the attacker's equipment. HTTPS still protects page contents, so the practical attacks are fake portal pages harvesting emails and passwords, and nudging victims towards lookalike sites.
Be suspicious of duplicate network names, networks that drop their usual password requirement, and portal pages demanding more information than usual. Asking staff for the exact network name defeats most casual imposters, and turning off auto join for public networks stops silent reconnections.
Because you cannot reliably spot a good fake, defence in depth matters: a VPN encrypts your traffic before the network sees it, so even a successful evil twin captures little of value. Combined with checking for HTTPS before entering credentials, that removes most of the attack's payoff.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free