Network sniffing — also called packet capture or packet analysis — is intercepting and reading the traffic passing across a network. The same tools that let an engineer diagnose a broken connection let an attacker watch what you’re doing.
The honest headline: encryption has already solved most of this. The classic image of someone in a café harvesting your banking password is largely obsolete. What sniffing still reveals is metadata — which sites you visit, when, and how much — and that turns out to be plenty.
Key Takeaway:
A sniffer on your network can no longer read what you send. It can still see where you’re sending it. Content is protected; the pattern of your behaviour usually isn’t.
How Sniffing Actually Works
A network card normally ignores traffic addressed to other machines. Put it in promiscuous mode and it accepts everything it can see, handing each packet to software like Wireshark for inspection.
The critical question is what the card can see, and that depends on the network:
- Wired, modern switch: the switch sends traffic only to the port it’s addressed to. You see your own traffic and broadcasts — not your neighbour’s. To capture someone else’s, an attacker has to actively interfere, typically with ARP spoofing to make traffic route through their machine first.
- Open Wi-Fi (no password): everything travels through the air unencrypted at the wireless layer. Anyone in range with the right adapter can capture all of it, passively and undetectably.
- WPA2 Wi-Fi with a shared password: traffic is encrypted, but anyone who knows the password and captures your device joining the network can potentially decrypt your session. A café that prints the password on the wall offers less protection than it appears.
- WPA3: materially better — each session gets its own keys, so knowing the password no longer lets someone decrypt other people’s traffic.
This is why “sniffing” is far harder on a switched office network than on shared Wi-Fi. The physical medium matters more than the tool.
What a Sniffer Can and Can’t See Today
| Data | Visible? |
|---|---|
| Page content over HTTPS | ✅ Protected — encrypted |
| Passwords on HTTPS sites | ✅ Protected |
| Anything over plain HTTP | ❌ Fully readable |
| Which domains you visit | ❌ Usually visible |
| Your DNS lookups | ❌ Visible unless encrypted |
| IP addresses you connect to | ❌ Always visible |
| Timing and volume of traffic | ❌ Always visible |
Two things keep leaking the domain even under HTTPS. Your DNS lookups are sent in plain text by default, announcing each site before you visit it. And the TLS handshake itself has historically carried the hostname unencrypted so the server knows which site to serve. Encrypted Client Hello is fixing that, but it isn’t universal yet.
The Public Wi-Fi Story, Honestly
“Hackers on public Wi-Fi will steal your bank details” sold a lot of VPN subscriptions, and it’s now mostly out of date. The overwhelming majority of web traffic is HTTPS, so the interesting content is encrypted before it reaches the air.
What someone on the same network genuinely gets is a list of the sites you visited and when. That’s not nothing — it’s the same information your ISP monetises — but it’s a privacy exposure, not an account takeover.
The real remaining risks on public networks are a malicious hotspot that manipulates your traffic rather than merely observing it, and the handful of apps still doing something careless over plain HTTP.
Who Can Sniff Your Traffic
- Anyone on the same Wi-Fi — most feasible on open networks, harder on WPA3.
- Whoever runs the network — café, hotel, airport, or whoever controls the router.
- Your ISP — sees everything leaving your home, and doesn’t need to sniff anything to do it. See what your ISP can see.
- Your employer — corporate networks routinely inspect traffic, often with an installed certificate that lets them decrypt HTTPS legitimately.
- Anyone who has compromised your router — which is why default router passwords matter.
Wireshark and Legitimate Uses
Wireshark is the standard packet analyser, and the overwhelming majority of its use is entirely ordinary: engineers diagnosing latency, developers debugging an API that won’t connect, security teams investigating an incident, students learning how protocols actually behave.
Capturing traffic on your own network, or one you’re authorised to test, is completely legal and genuinely educational — watching a DNS query and a TLS handshake unfold teaches more than any diagram.
Intercepting communications you are not party to is a different matter entirely, and is a criminal offence in most countries — including under wiretapping and computer misuse laws. The tool is neutral; the authorisation is what matters.
How to Protect Yourself
- Insist on HTTPS. Already the default nearly everywhere, and it’s the single biggest reason sniffing is far less dangerous than it was. See what SSL/TLS does.
- Encrypt your DNS. DNS over HTTPS closes the biggest remaining metadata leak.
- Use a VPN on untrusted networks. A local sniffer then sees a single encrypted stream to one address, with no visible destinations at all.
- Secure your own network. WPA3 where available, a strong password, and a changed router admin password — the full checklist.
- Treat shared networks as observed. Not dangerous, but not private.
🔒 VPNs That Close the Metadata Gap
On a hostile or shared network, a VPN is the one measure that hides destinations as well as content:
- PureVPN — own DNS resolvers, so lookups stay inside the tunnel
- IPVanish — strong speeds, unlimited devices
Worth remembering that this moves the observation point rather than removing it — your VPN provider now sees what the network used to. That’s why the provider’s logging policy matters: Are Free VPNs Safe?
Frequently Asked Questions
Can someone steal my password by sniffing?
Not on an HTTPS site, which is essentially all of them now — the password is encrypted before it leaves your device. On a plain HTTP site, yes, trivially. Check for the padlock before typing anything sensitive.
Can they see which sites I visit?
Usually yes. DNS lookups and the TLS handshake tend to reveal the hostname even when the content is encrypted. Encrypted DNS and a VPN both close this.
Is sniffing illegal?
Capturing traffic on your own network, or one you have permission to test, is legal. Intercepting other people’s communications without authorisation is a crime in most jurisdictions. The distinction is consent, not the software.
Would I know if I was being sniffed?
Passive capture leaves no trace and cannot be detected from your side. Active interception like ARP spoofing sometimes causes odd symptoms, but you should assume shared networks are observable rather than expecting a warning.
Does a VPN stop sniffing?
It defeats local sniffing effectively — an observer sees one encrypted connection to one address. The visibility shifts to your VPN provider, which is why choosing a trustworthy one matters.
Is home Wi-Fi safe from this?
Largely, provided it’s WPA2 or WPA3 with a password only you know. The risks are a compromised router or someone who has your Wi-Fi password.
Can my employer read my traffic?
On company equipment and networks, often yes — including HTTPS, via a certificate installed on the device that permits inspection. It’s usually disclosed in the acceptable use policy.
Should I learn Wireshark?
If networking interests you, absolutely. Capturing your own traffic and watching a page load — DNS, handshake, transfer — makes abstract concepts concrete. Just keep it to networks you own or are authorised to test.