The WiFi Password on the Chalkboard
A shared WiFi password feels friendly. It is also the easiest route from a guest phone onto your till, your camera recorder and your office PC.
Walk into a South African venue and there is a good chance the WiFi password is on a chalkboard, on a laminated card at the till, or, our personal favourite, written in koki directly onto the wall behind the espresso machine.
It feels friendly. It’s also, quietly, one of the worst security decisions a business makes.
This isn’t a scare piece. No-one’s hacking the café next door for the thrill of it. But the way WiFi access is typically handed out in SA hospitality gives every guest, every delivery driver, every random person taking a phone call outside the same level of network access as the owner. And when something does go wrong, the blast radius is the entire business.
What’s actually on that network?
Every small venue we audit has more than the owner realises plugged into the “guest” WiFi:
- The POS terminal (Pilot / GAAP / SkyTab / Yoco)
- The card machine gateway
- The office PC with the accounting software
- The printer that prints the supplier invoices
- The CCTV DVR with 30 days of footage
- The staff WhatsApp Web laptop in the back office
- The manager’s phone with the banking app
- The supplier portals saved in someone’s browser
All of those are sharing a flat network with every guest’s phone. Because the network was set up once, by whoever installed the router, and nobody’s thought about it since.
The three things that actually go wrong
We’re not going to pretend a casual guest is going to hack your POS. That’s not the real risk. The real risks are much more boring, much more common, and much more damaging.
1. A compromised guest device pivots onto your stuff
Most people don’t patch their Android phones. Most people don’t update their laptops. A decent slice of the devices that connect to your WiFi have at least one known vulnerability that’s been public for a year or more.
When a compromised phone joins your network, it does not need anyone to be “hacking”. The malware on it scans the local network automatically. It finds the POS. It finds the camera DVR with default credentials. It quietly catalogues what’s there, waiting for instructions. That’s how small businesses get ransomwared: not a targeted attack, just a drive-by from a guest’s infected phone.
2. The password walks out
The chalkboard password never changes, because changing it means re-telling every regular. So it ends up:
- Screenshotted by guests and shared in WhatsApp groups
- Saved permanently on every phone that’s ever connected
- Visible from the street through the window (we’ve seen this)
- Known to every ex-employee who ever worked there
Once the password is “out,” your network is effectively open to the suburb. People camp in your parking lot to use your bandwidth. Your speeds tank. The next morning, you’re phoning the ISP complaining about “slow internet.”
3. POPIA exposure you didn’t know you had
Here’s the part most owners miss. When a guest connects to a shared-password network, you are still handling their personal data: their MAC address, their traffic metadata, their device name (“Sarah’s iPhone 13”). You just have no record of consent for it.
If the Information Regulator receives a complaint and asks how you’re processing guest data lawfully, “there’s a password on the chalkboard” is not an answer. You don’t have a consent record, you don’t have a privacy notice, you don’t have a data-retention policy. Everything you’re doing is technically outside the POPIA framework.
A captive portal fixes this because every guest actively opts in on a splash page. That opt-in is your lawful basis. (More on that in the POPIA guide.)
”But my guests want a password”
Some do. Most don’t. What guests actually want is to get on the WiFi in under 30 seconds without faff. The chalkboard is one way to deliver that. A captive portal with a one-tap “Connect” button is another, and it is usually faster, because they don’t have to type CappuccinoLover!2021 on a phone keyboard.
The few venues that really do need a password (high-end hotels, boardroom WiFi, tenant-access buildings) can still have one, issued per guest, from the captive portal, valid for a set time. You can even print it on the room key card or email it on check-in. That’s not the same thing as writing it on a wall.
What actually good-looking WiFi security looks like
You don’t need enterprise gear. You need the following, and most SA venues are missing at least three of these:
Network segmentation
The guest WiFi and the business network are kept separate from each other. A guest device has no route to the till, the camera recorder, or anything else on the business side. On most decent routers this is a short change to make, but it is surprising how often it is skipped.
If you can plug your laptop into the same WiFi as a guest and then ping your POS from it, your network has no segmentation. Fix this first.
A captive portal for guests
Not a shared password. An individualised session per guest, with consent capture, session time limits, and per-user bandwidth caps. This gives you a log: who connected, when, for how long, from what device. If something goes wrong, you can trace it. If POPIA asks, you have an answer.
Per-user rate limiting
The one guest streaming Netflix at 4K on your WiFi shouldn’t be allowed to slow down every other guest. A captive portal enforces a fair-share cap per device, typically 5–10 Mbps each, so everyone gets a good experience and no-one can saturate the pipe.
Password hygiene for the business network
The business-side WiFi (POS, office PC, CCTV) should have a strong password that changes when staff change. Not the chalkboard password. Not “password123”. Something random, stored in a password manager, rotated when someone leaves.
Firmware updates
This is the least glamorous and most important item on the list. The router running your whole network has had multiple security patches released in the last year. If nobody’s logged into it since it was installed, it’s running firmware with known holes. Ten minutes every few months fixes this.
What we actually look for when we audit an SA venue
This is the checklist, in the order we work through it. Run it on your own venue and see how many you can tick:
- Has the shared guest WiFi password been changed in the last year?
- Are the POS, the office PC and the guest WiFi on separate networks, or one flat one?
- When was the router firmware last updated?
- Are the default credentials still active on any device, especially the CCTV DVR?
- Is there a privacy notice and a consent mechanism, or no POPIA artefact at all?
- If a captive portal is already in place, is it actually segmenting guest traffic, or just showing a splash page?
Most of the fixes are quick. None of them need new hardware. All of them reduce the risk that one compromised guest device turns into a business-wide incident.
The short version
- The chalkboard password is friendly, fast, and dangerous.
- The real risk is not guests hacking you. It is compromised guest devices pivoting onto your POS and cameras.
- A shared password with no consent mechanism is also a quiet POPIA problem.
- Fix it by separating the guest network from the business network, and putting a login page in front of guests.
- Update your router firmware. Change default credentials on every device.
None of this is expensive. All of it sleeps better at night.
Want us to do a free security audit on your WiFi setup? We’ll tell you what we find, with no obligation to sign anything. Take the next step.