Confirm the network name
Ask staff for the exact network name rather than choosing the strongest open signal. Attackers can create a lookalike hotspot using the venue's name.
Disable automatic connection to open networks and forget the network when finished. If a captive portal requests unusual personal, payment or account credentials, use mobile data instead.
Understand what HTTPS protects
HTTPS encrypts the content exchanged with a correctly validated website, which prevents nearby users from simply reading passwords or messages in transit. Current browsers warn when a certificate is invalid; do not bypass that warning.
A network operator may still see connection metadata such as domain lookups in some configurations, and phishing pages can also use HTTPS.
What a VPN adds
A trustworthy VPN encrypts traffic between the device and VPN server, reducing visibility for the hotspot operator and protecting protocols that may not otherwise be safely configured. It also hides the public IP address from destination sites.
A VPN does not make a fake website genuine, remove malware or hide activity from the VPN provider. Choose based on audits, leak protection and policy—not a claim of total anonymity.
Secure the device before connecting
Install operating-system and browser updates, enable the firewall and turn off file sharing or local discovery when not needed. Keep device encryption and a strong screen lock enabled.
Use multifactor authentication and a password manager. These measures limit the impact if a login page is imitated or a credential has already leaked.
Prefer mobile data for sensitive actions
Banking applications generally use strong transport security, but mobile data removes the untrusted local network from the path. Delay unusually sensitive administration or financial changes when a trusted connection is available soon.
If tethering your own phone, use WPA2 or WPA3, a strong hotspot password and turn the hotspot off afterwards.
After using a shared network
Disconnect, forget the network and close any account sessions you no longer need. Investigate browser certificate warnings, unexpected multifactor prompts or login alerts rather than assuming they are unrelated.
Changing every password after normal public Wi-Fi use is unnecessary. Change credentials if you entered them into a suspicious page, ignored a certificate warning or receive evidence of unauthorised access.
What has actually changed since the old advice
Much of the warning material still circulating online dates from a period when a large share of websites sent data unencrypted. In that era, a laptop on a café network really could read a neighbour's email or session cookie with freely available tools. Browsers now default to encrypted connections and warn loudly about invalid certificates, so straightforward eavesdropping on web traffic is no longer the everyday threat it once was.
The risks that remain are different in character. A hostile hotspot can redirect unencrypted name lookups, push a captive portal designed to harvest credentials, or simply record which services you connect to and when. Devices that expose file sharing, printing or local discovery can also be probed by anyone else on the same network, which is why turning those services off travels further than any single product recommendation.
The honest summary is that public Wi-Fi is usually fine for ordinary browsing on an updated device, and that the strongest protections are unglamorous: current software, unique passwords, multifactor authentication and scepticism toward login pages that appear unprompted.
Travel, hotels and shared devices
Hotel and conference networks deserve extra care because they combine long stays, many strangers and captive portals that normalise entering personal details. Give only what the portal genuinely needs, never reuse an account password to access Wi-Fi, and decline any portal that asks to install a certificate or profile unless a trusted employer requires it.
Public charging points and shared computers introduce separate problems. Use a plain power adapter or a charge-only cable rather than an unknown USB port, and treat any shared or business-centre computer as untrusted: do not sign in to email or banking, and assume anything typed could be recorded.
If you travel often, an eSIM or a local data plan is usually cheaper and safer than depending on venue networks, and tethering from your own phone keeps you on a connection whose password only you know.
- Give portals minimal personal data
- Never install a requested certificate or profile
- Use charge-only cables or your own adapter
- Avoid signing in on shared computers
- Prefer tethering or a local data plan
Choosing a VPN for public networks
If you decide a VPN is worthwhile, judge it on evidence rather than marketing. Look for an independently audited no-logs policy, a clearly stated corporate owner and jurisdiction, modern protocols such as WireGuard, a kill switch that is on by default and verified protection against DNS and IPv6 leaks. Applications for every device you own matter more than an enormous server count.
Be sceptical of free VPN applications. Running a global network is expensive, and services that charge nothing frequently monetise through advertising identifiers, data sharing or aggressive upsells; several have shipped serious security flaws. A reputable paid service or the free tier of an established provider with a published business model is a safer compromise.
Remember what a VPN cannot do. It will not stop you from typing a password into a convincing fake login page, it will not remove malware already present, and it does not make you anonymous, since your provider and the sites you sign in to still identify you.
