Skip to main content

Morning Overview

The NSA still tells every phone owner to switch off one common wireless setting

Government cybersecurity guidance for mobile devices has stayed remarkably consistent for years on one specific point: switching off wireless radios that are not actively in use closes off an entire category of attack that most phone owners never think about. The advice sounds almost too simple to matter, yet it keeps reappearing in official best-practices documents because the underlying vulnerability has never really gone away.

Why an Always-On Radio Is a Standing Invitation

Every wireless radio on a phone, whether it handles Wi-Fi, Bluetooth, or near-field communication, is constantly listening for nearby networks and devices even when nothing is actively connected. That listening behavior is what makes convenience features work, letting a phone automatically rejoin a home network or pair with a car’s audio system without any manual steps. It also means the radio is broadcasting and receiving signals in public spaces around the clock, giving a nearby attacker a live target to probe rather than a closed system that only opens when someone chooses to use it.

Wi-Fi Auto-Connect Is the Specific Feature Under Fire

The setting most frequently singled out in agency guidance is automatic Wi-Fi connection to previously used or open networks. A phone configured to auto-join any available network will, in unfamiliar territory, sometimes connect to a network with a name matching one it has seen before, even if that network is actually a lookalike set up by someone nearby. This technique, sometimes called an evil-twin network, exploits the fact that Wi-Fi devices generally trust a familiar network name without verifying the identity of whoever is actually operating it. Once connected, traffic can be intercepted, redirected, or manipulated before the phone’s owner realizes the connection was never with the network they intended to use.

Bluetooth Discoverability Carries a Similar Risk

Leaving Bluetooth in a discoverable state broadcasts a device’s presence to anything scanning nearby, which is useful for pairing a new accessory but otherwise serves little purpose most of the day. Security researchers have repeatedly demonstrated attacks against Bluetooth connections that exploit older pairing protocols or known implementation flaws in specific chipsets, and a phone sitting in discoverable mode for extended periods gives an attacker more opportunity to attempt one of those exploits. Turning the radio off entirely, rather than merely leaving it non-discoverable, removes the exposure altogether since a disabled radio cannot be scanned, probed, or connected to at all.

Location and Tracking Add a Second Motive

Beyond the direct hacking risk, active wireless radios can be used to approximate a device’s location by triangulating the signal strength picked up by multiple receivers, a technique unrelated to GPS entirely. Retailers, transit systems, and other organizations have used Wi-Fi and Bluetooth signals from phones to track foot traffic patterns without ever needing the device to actually connect to anything. Disabling radios that are not needed limits how much passive tracking data a phone leaks simply by existing in a public space, independent of whatever security risk the connection itself might carry.

What the Broader Guidance Actually Recommends

Formal mobile security guidance from government and standards bodies typically frames this as part of a broader “reduce attack surface” principle: any feature, service, or radio that is not actively needed should be disabled, because every enabled feature is a potential entry point regardless of how unlikely a specific exploit might seem. That principle extends beyond wireless radios to things like unused apps with broad permissions and location services that run continuously in the background, but wireless radios draw particular attention because they operate passively and are so rarely switched off by habit.

Turning It Off Costs Little in Practice

Modern operating systems make disabling Wi-Fi and Bluetooth from a lock screen or control panel a one-tap action, and most phones reconnect instantly once a radio is switched back on, so the convenience tradeoff is minor compared with leaving both running continuously in public. Airplane mode offers an even broader version of the same idea, cutting every radio at once in situations, like an unfamiliar transit hub or a crowded public event, where the exposure is highest. None of this requires new software or a security subscription; it is simply a habit of switching a radio off once its immediate job is done rather than leaving it running by default.

Near-Field Communication and Other Overlooked Radios

Wi-Fi and Bluetooth draw most of the attention in mobile security guidance, but near-field communication, the short-range radio used for contactless payments and quick data transfers, carries its own narrower but real exposure. Because NFC only works at a range of a few inches, the practical risk is smaller than with Wi-Fi or Bluetooth, but security researchers have still demonstrated proof-of-concept attacks that read or manipulate NFC transactions when a device is left active and unattended in close proximity to a compromised reader. Disabling NFC when it is not being used for a payment or transfer follows the same reduce-the-attack-surface logic applied to the other radios, even though the realistic threat window is much narrower.

Guidance documents also tend to bundle radio management together with related habits, such as reviewing which apps hold Bluetooth or Wi-Fi permissions in the background and periodically clearing out saved network profiles for networks a person no longer uses. A phone that still remembers dozens of old Wi-Fi networks from hotels, airports, and former workplaces carries a longer list of names it might automatically trust, which is part of why some guidance recommends periodically pruning that saved list rather than only worrying about whether a radio is currently switched on.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview