I keep seeing security advice begin with “use a VPN on public Wi‑Fi,” while spending less time on the software and people already trusted with the endpoint. That feels like a threat-modeling question worth asking before reaching for a network fix: which browser extensions, synced accounts, notifications, and other users can already see or influence what happens here?
Public networks can still matter, and I’m not arguing that they never do. But a browser extension with broad permissions, a lock-screen notification preview, a synced clipboard, or an active session left on a shared computer seems like a more immediate path to an authentication code or session than the café router in some situations. I’ve started reconsidering the habit of copying one-time codes into a clipboard that syncs across devices.
Which everyday access path do you think is most underestimated? Counterexamples and disagreement welcome.