How to use public Wi-Fi safely

    Public Wi-Fi is not automatically dangerous, but you do not control the router, other users or the login portal. Modern HTTPS blocks much passive snooping; careful network selection and account security address the risks it does not solve.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    Confirm the network name

    Ask staff for the exact network name rather than choosing the strongest open signal. Attackers can create a lookalike hotspot using the venue's name.

    Disable automatic connection to open networks and forget the network when finished. If a captive portal requests unusual personal, payment or account credentials, use mobile data instead.

    Understand what HTTPS protects

    HTTPS encrypts the content exchanged with a correctly validated website, which prevents nearby users from simply reading passwords or messages in transit. Current browsers warn when a certificate is invalid; do not bypass that warning.

    A network operator may still see connection metadata such as domain lookups in some configurations, and phishing pages can also use HTTPS.

    What a VPN adds

    A trustworthy VPN encrypts traffic between the device and VPN server, reducing visibility for the hotspot operator and protecting protocols that may not otherwise be safely configured. It also hides the public IP address from destination sites.

    A VPN does not make a fake website genuine, remove malware or hide activity from the VPN provider. Choose based on audits, leak protection and policy—not a claim of total anonymity.

    Secure the device before connecting

    Install operating-system and browser updates, enable the firewall and turn off file sharing or local discovery when not needed. Keep device encryption and a strong screen lock enabled.

    Use multifactor authentication and a password manager. These measures limit the impact if a login page is imitated or a credential has already leaked.

    Prefer mobile data for sensitive actions

    Banking applications generally use strong transport security, but mobile data removes the untrusted local network from the path. Delay unusually sensitive administration or financial changes when a trusted connection is available soon.

    If tethering your own phone, use WPA2 or WPA3, a strong hotspot password and turn the hotspot off afterwards.

    After using a shared network

    Disconnect, forget the network and close any account sessions you no longer need. Investigate browser certificate warnings, unexpected multifactor prompts or login alerts rather than assuming they are unrelated.

    Changing every password after normal public Wi-Fi use is unnecessary. Change credentials if you entered them into a suspicious page, ignored a certificate warning or receive evidence of unauthorised access.

    What has actually changed since the old advice

    Much of the warning material still circulating online dates from a period when a large share of websites sent data unencrypted. In that era, a laptop on a café network really could read a neighbour's email or session cookie with freely available tools. Browsers now default to encrypted connections and warn loudly about invalid certificates, so straightforward eavesdropping on web traffic is no longer the everyday threat it once was.

    The risks that remain are different in character. A hostile hotspot can redirect unencrypted name lookups, push a captive portal designed to harvest credentials, or simply record which services you connect to and when. Devices that expose file sharing, printing or local discovery can also be probed by anyone else on the same network, which is why turning those services off travels further than any single product recommendation.

    The honest summary is that public Wi-Fi is usually fine for ordinary browsing on an updated device, and that the strongest protections are unglamorous: current software, unique passwords, multifactor authentication and scepticism toward login pages that appear unprompted.

    Travel, hotels and shared devices

    Hotel and conference networks deserve extra care because they combine long stays, many strangers and captive portals that normalise entering personal details. Give only what the portal genuinely needs, never reuse an account password to access Wi-Fi, and decline any portal that asks to install a certificate or profile unless a trusted employer requires it.

    Public charging points and shared computers introduce separate problems. Use a plain power adapter or a charge-only cable rather than an unknown USB port, and treat any shared or business-centre computer as untrusted: do not sign in to email or banking, and assume anything typed could be recorded.

    If you travel often, an eSIM or a local data plan is usually cheaper and safer than depending on venue networks, and tethering from your own phone keeps you on a connection whose password only you know.

    • Give portals minimal personal data
    • Never install a requested certificate or profile
    • Use charge-only cables or your own adapter
    • Avoid signing in on shared computers
    • Prefer tethering or a local data plan

    Choosing a VPN for public networks

    If you decide a VPN is worthwhile, judge it on evidence rather than marketing. Look for an independently audited no-logs policy, a clearly stated corporate owner and jurisdiction, modern protocols such as WireGuard, a kill switch that is on by default and verified protection against DNS and IPv6 leaks. Applications for every device you own matter more than an enormous server count.

    Be sceptical of free VPN applications. Running a global network is expensive, and services that charge nothing frequently monetise through advertising identifiers, data sharing or aggressive upsells; several have shipped serious security flaws. A reputable paid service or the free tier of an established provider with a published business model is a safer compromise.

    Remember what a VPN cannot do. It will not stop you from typing a password into a convincing fake login page, it will not remove malware already present, and it does not make you anonymous, since your provider and the sites you sign in to still identify you.

    Frequently asked questions

    Is hotel Wi-Fi safe for banking?

    The official bank app or a correctly validated HTTPS site provides strong encryption, but mobile data is a sensible extra precaution for high-impact transactions.

    Do I always need a VPN on public Wi-Fi?

    Not always, because HTTPS protects most modern web traffic. A reputable VPN adds privacy and covers more traffic, especially on networks you do not trust.

    Can the Wi-Fi owner see my passwords?

    Not when they are sent through a correctly validated encrypted connection. They may still see metadata, and a fake site can capture anything you enter.

    Are free VPN apps safe for public Wi-Fi?

    Often not. Running a VPN network costs money, and free services frequently fund themselves through advertising data or weak engineering. A reputable paid provider, or the free tier of an established audited one, is a better trade-off.

    Is mobile data genuinely safer than public Wi-Fi?

    For most people, yes, because the network is operated by a licensed carrier and no stranger nearby controls it. It does not protect against phishing or malware, so account security still matters.