Public Wi-Fi Security: What Actually Keeps You Safe

Cafés, airports and hotels all offer free Wi-Fi. Here’s what the real risk is today, and what actually reduces it.

What’s actually risky about public Wi-Fi

Open or poorly secured wireless networks make it easier for another device on the same network to intercept traffic that isn’t independently encrypted, and for attackers to set up a fake hotspot with a convincing name to lure people into connecting. The UK NCSC’s guidance on Wi-Fi vulnerabilities such as KRACK covers exactly this class of risk at the protocol level — weaknesses in how devices and access points negotiate a secure connection, which is one reason keeping router and device firmware updated matters as much as the network you choose to join.

The good news: most of your traffic is already encrypted

The picture has genuinely improved. The large majority of websites now use HTTPS by default, which encrypts the content of your connection to that site regardless of the network you’re on. EFF’s guidance notes that public Wi-Fi protection “isn’t as necessary for everyone anymore because the majority of web traffic is now encrypted using HTTPS”. That doesn’t mean public Wi-Fi is risk-free — it means the biggest risk has shifted from someone reading your traffic to things HTTPS doesn’t cover: which sites you’re visiting at all (visible to the network operator), fake hotspots, and any app or site that still doesn’t use HTTPS properly.

What actually reduces the risk

  • Confirm the network name with staff. The FCC’s traveller guidance specifically recommends confirming the exact network name and login process before connecting at an airport, hotel or café — fake hotspots with near-identical names are a documented tactic.
  • Check for the padlock / HTTPS. Your browser shows a padlock icon and “https://” for encrypted sites. Avoid entering passwords or payment details on any site that doesn’t show it.
  • Turn off Wi-Fi auto-join. Prevents your device from silently connecting to unfamiliar or spoofed networks with a recognised-looking name.
  • Avoid public or shared computers for anything sensitive. Guidance from the FCC and equivalent government travel-security resources consistently flags hotel business-centre and internet café computers as unsuitable for banking or entering payment information, since you can’t verify what’s installed on them.
  • Keep 2-Step Verification on. If a password is intercepted or guessed despite everything else, 2SV is what stops it being enough on its own — see our online privacy basics guide.
  • Use a VPN as an added layer, not a fix-all. A VPN hides which sites you’re visiting from the local network operator and encrypts the small amount of traffic that still isn’t HTTPS-protected. It’s genuinely useful on networks you don’t trust, but it doesn’t protect a compromised device or make a fake hotspot safe to use for banking. See What a VPN Actually Protects You From.

A note on mobile data as the simplest alternative

If you have a reasonable mobile data allowance, using your phone’s own connection (or tethering from it) sidesteps most public Wi-Fi risk entirely, since it isn’t a shared network. It isn’t always practical — data costs and coverage vary, especially when travelling internationally — but it’s worth defaulting to for anything sensitive when it’s available, rather than automatically reaching for the nearest free hotspot.

FAQ

Is public Wi-Fi still dangerous now that most sites use HTTPS?

Less dangerous than it used to be, but not risk-free. The content of most individual site connections is encrypted regardless of the network, but the network operator can still see which sites you connect to, and fake hotspots remain a real tactic.

Do I need a VPN for public Wi-Fi specifically?

It’s a genuinely useful added layer, especially on networks you don’t control, but it isn’t the only thing that matters — checking for HTTPS, avoiding shared computers and keeping 2-step verification on all do real work too.

What’s the single biggest mistake people make on public Wi-Fi?

Entering payment details or logging into sensitive accounts on a public or shared computer they don’t control, rather than their own device. A VPN on your own phone or laptop doesn’t help if the risk is the computer itself.

Compare VPN providers for travel and everyday use

Compare VPN options →

Sources: UK NCSC – Wi-Fi (KRACK) security guidance; EFF Surveillance Self-Defense – VPN glossary; FCC – Cybersecurity Tips for International Travelers.