Why Shared Computers Are a Different Kind of Risk
When you use a library terminal, a hotel business center computer, or a workplace machine you share with colleagues, you're stepping into a device with an unknown history. Previous users may have left behind browser cookies, saved credentials, or even malicious software. Unlike your personal phone or laptop — where you control what's installed and who has access — a shared computer is a shared environment in every sense.
The core risk isn't that someone will sit down and immediately hack you. It's more mundane: a browser that remembers your login, an autofilled email address, or a session that didn't properly close. These are the gaps that expose accounts. If you're newer to these concepts, our grounded introduction to personal computing covers the foundational ideas that make these risks easier to understand.
Best Practices for Staying Secure
The following practices are organized from most to least critical. Use them as a checklist any time you sit down at a device that isn't yours.
Always open a private or incognito browsing window before doing anything on a shared computer.
Private browsing mode prevents the browser from saving your history, cookies, or form data to the device. When you close the window, that session data is discarded automatically, significantly reducing what you leave behind.
Log out of every account explicitly — don't just close the tab or window.
Many websites keep you logged in via a browser cookie that persists even after a tab is closed. The next person to visit that site on the same browser may find themselves automatically signed in as you.
Decline every prompt to save passwords or autofill information.
Browsers offer to save credentials as a convenience, but on a shared machine that convenience becomes a liability for every future user of that device. Even a saved username can expose which services you use.
Avoid logging into financial, medical, or other highly sensitive accounts on public computers.
Some public computers may have keyloggers — software that silently records everything typed — installed either maliciously or through prior compromise. High-stakes accounts deserve extra caution because the consequences of exposure are greater.
Manually clear the browser's cache, cookies, and history before leaving, even after an incognito session.
If you used a regular (non-private) session for any reason, leftover cookies and cache entries can expose your account state to the next user. A manual clear adds a safety net.
Quick Steps You Can Take Right Now
If you're preparing to use — or have already used — a public computer, these immediate actions reduce your exposure with minimal effort.
Use Your Phone Instead When It Matters
For anything sensitive — banking, healthcare portals, or government accounts — your personal smartphone on its own mobile data connection is almost always a safer choice than a public computer. You control the device, the software, and the session. If your phone is unavailable, weigh whether the task can wait until you're back on a trusted device.
What the Numbers Tell Us
Data on credential theft and session hijacking underscores why these precautions aren't overcautious — they're proportionate to real, documented risks.
80%+
Of data breaches involve compromised credentials
According to Verizon's Data Breach Investigations Report, the majority of breaches trace back to stolen or misused login credentials — the exact risk a shared-computer session can create.
1 in 3
Public Wi-Fi users unaware of session risks
Surveys by cybersecurity awareness organizations consistently find that a large share of users don't realize browser sessions can persist after a tab is closed on shared devices.
“The weakest point in any security system is usually the human element — not the software. Habits matter more than tools.”
— Bruce Schneier, Security technologist and author on cryptography and cybersecurity
For broader context on how device security extends into your home environment, see our article on home network security habits — many of the same principles apply across contexts.
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.

