What's Actually Changed Since Public Wi-Fi Fears Began
A lot of commonly repeated public Wi-Fi advice dates back to a time when much of the web wasn't encrypted by default. Today, the overwhelming majority of websites and apps use HTTPS, which encrypts traffic between your device and the website itself, regardless of the network carrying it. This significantly reduces — though doesn't eliminate — the risk of someone on the same network simply reading your traffic in plain text.
Risks That Are Still Real
Encryption at the website level doesn't protect everything. Risks that remain relevant on public networks include: connecting to a fake network set up to impersonate a legitimate one, malware distributed through a compromised network's login or "captive portal" page, and older devices or apps that still use unencrypted connections for some background traffic. Network operators (and anyone who has compromised the network) can also still see which domains you're connecting to, even if they can't read the encrypted content itself.
The Role of HTTPS
HTTPS uses encryption to protect the content of your connection to a specific website, and most browsers now visually flag connections that aren't using it. This matters most for exactly the kind of activity people worry about on public Wi-Fi — logging in, entering payment details, or reading personal messages — since that's precisely the traffic HTTPS is designed to protect. It's worth noting HTTPS confirms the connection is encrypted and reaching the domain shown in the address bar; it doesn't independently verify that the organization behind that domain is trustworthy.
Evil Twin and Rogue Hotspots
An "evil twin" is a fake Wi-Fi network set up with a name deliberately similar to a legitimate one — for example, mimicking a café's real network name closely enough that a phone might connect automatically or a person might not notice the difference. Once connected, an attacker controlling that network has a better vantage point to attempt the network-level attacks described above. Confirming the exact network name with staff, rather than guessing from a list of similarly named options, is a simple and effective precaution.
Where a VPN Genuinely Helps
A VPN encrypts your device's traffic through a tunnel to the VPN provider's own servers, which hides your browsing from the local network operator and reduces the value of certain network-level attacks. It's a genuinely useful tool for the specific concern of "what can this particular Wi-Fi network operator see," but it doesn't replace other precautions — you're placing a similar degree of trust in the VPN provider instead, which is worth choosing carefully, and a VPN doesn't protect against phishing, malware, or a compromised device.
Practical Steps for Safer Public Wi-Fi Use
- Confirm the exact network name with staff rather than guessing from similarly named options.
- Prefer networks that require a password over fully open ones where possible.
- Keep your device's software updated, since public networks are one place unpatched vulnerabilities could be exploited.
- Avoid installing anything prompted by a network's login page.
- Use a VPN if you want an added layer of privacy from the network operator specifically, particularly for sensitive activity like banking.
Using a Phone Hotspot Instead
When it's available and affordable, using your phone's personal hotspot avoids public Wi-Fi risk categories entirely, since you control the network and its password. This is a reasonable default for sensitive tasks — like banking or entering payment details — when you're away from a network you fully trust.
Frequently Asked Questions
Is it still dangerous to check email on coffee shop Wi-Fi?
Checking email over HTTPS on a legitimate, password-protected coffee shop network carries meaningfully lower risk than it did years ago, since encryption is now the default for nearly all sign-in and email traffic. The bigger remaining risks are connecting to a fake network with a similar name, or using a network entirely without any password.
Does a VPN make public Wi-Fi completely safe?
A VPN encrypts your traffic between your device and the VPN provider, which is genuinely useful against certain network-level risks, but it shifts trust to the VPN provider itself rather than eliminating the need for other precautions like avoiding suspicious networks or keeping software updated.
Are Wi-Fi networks without a password always risky?
Open networks (no password at all) are generally considered higher risk than password-protected ones, since anyone nearby can potentially observe unencrypted traffic. This is a good reason to prefer networks with a password, even a shared, publicly posted one at a business, over fully open ones.