Skip to content
VaultPass

Fundamentals

Public Wi-Fi: which risks are real and which are out of date

The VaultPass desk5 min read
A radio antenna tower against the sky

For years the advice was that connecting to a café's Wi-Fi amounted to giving away your passwords. That advice described the internet of 2012 well and describes today's badly. The risks still exist, but they are different ones and they are defended differently.

The advice “do not use public Wi-Fi” was born in an era when most of the web travelled unencrypted. Back then, anyone on the same network with a free program could read your email or steal an open session.

That changed. Today practically all traffic goes over HTTPS: the content travels encrypted between your browser and the server, and anyone in the middle sees little more than which domain you connected to.

The advice deserves updating, because repeating an obsolete fear makes people ignore the risks that remain.

What is no longer a problem

Passwords being read in transit. When you sign in to your bank or your email, the connection is encrypted end to end. Someone on the same network sees that you connected to your bank, not what you typed.

The classic session hijack. The tools that years ago let people take over other users’ sessions on a shared network worked on unencrypted traffic. Against HTTPS they do nothing.

The browser’s generic warning. If a site has no padlock, the browser now tells you conspicuously, and practically no serious service runs unencrypted any more.

What is still a risk

1. The fake network

This is the main one. Setting up an access point called Airport_Free_WiFi costs very little. Your phone connects — especially if it remembers a network with that name from a previous time — and the attacker controls the path.

With that control they cannot decrypt HTTPS, but they can:

  • Send you to a fake sign-in page when you type an address.
  • Manipulate the captive portal — that screen where you accept the terms — to ask for details or get you to install something.
  • See which domains you connect to.

The defence is not technical, it is judgement: be suspicious of any screen asking for a password right after you connect to a new network. No legitimate Wi-Fi needs your Google account or your card to grant access.

2. The captive portal with a catch

Some portals ask you to register with an email, or offer “install our app to browse faster”. Do not install anything that comes from a network you met thirty seconds ago.

If the portal asks for an email, use an alias, not your main address.

3. Someone knowing where you go

Even though the content is encrypted, the network’s owner sees the domains you visit. In a hotel or an airport that usually does not matter. If it does matter to you — and there are legitimate reasons — that is where a VPN earns its place.

4. Your own device being exposed

On a shared network, other machines can try to reach yours. Windows handles this with the network type: marking the connection as a public network disables discovery and file sharing. It is one click and it removes the whole problem.

Do you need a VPN?

It depends what you expect from it, and there is a lot of marketing here.

What a VPN actually does: encrypts your traffic as far as the VPN’s server. The Wi-Fi owner stops seeing which domains you connect to. It also lets you appear to be in another country.

What it does not do: it does not protect you from phishing, from malware, or from handing your password to a fake site. It does not make you anonymous.

The uncomfortable detail: a VPN does not remove trust, it moves it. You stop trusting the hotel’s Wi-Fi and start trusting the VPN company, which sees all your traffic. With a paid, audited provider that is a reasonable trade. With a free VPN it is often a bad deal: you are the product.

The practical conclusion: for most people on a café’s Wi-Fi, HTTPS already covers the essentials. A VPN adds privacy from the network’s owner and is genuinely useful in countries with censorship or filtering. It is not a security obligation.

An alternative almost nobody considers and which is usually better: tethering from your own phone. It is your network, nobody else’s, and modern data plans make it painless.

What to do in practice

Before connecting:

  • Ask for the exact network name at the counter. This one gesture disarms the evil twin.
  • Turn off automatic connection to open networks in your phone’s settings. It stops your device latching onto a fake network with a familiar name.

While connected:

  • Mark the network as public on Windows.
  • Do not install anything the portal offers.
  • Check the padlock and the domain before typing a password, especially at the bank.
  • Leave sensitive business for later if you can. Not because of the encryption, but because in a public place there is a very analogue threat: someone looking at your screen and your keyboard.

When you finish:

  • Forget the network so your device does not reconnect to it automatically in future.

What actually protects your accounts away from home

Wi-Fi ends up being a minor worry next to the same two measures as always:

Two-factor authentication. Even if someone gets your password, they do not get in.

A password manager. It will not fill credentials into a domain it does not recognise, so it protects you from precisely the attack that is real on a hostile network: the fake page.

In short

  • HTTPS has removed the classic risk of your traffic being read.
  • The real danger today is the fake network and fraudulent sign-in pages.
  • Ask for the exact network name and disable automatic connection.
  • A VPN gives privacy from the Wi-Fi owner, not immunity; free ones rarely pay off.
  • Tethering from your phone is usually the simplest and safest option.

Frequently asked

The questions that keep coming up

Is public Wi-Fi dangerous?

Far less than a decade ago, because almost all traffic is now encrypted with HTTPS. The main risk is no longer someone reading your data, but connecting to a fake network built to redirect you to phishing pages.

Do I need a VPN on airport Wi-Fi?

It is not essential for most people, because HTTPS already encrypts the content. A VPN hides which sites you connect to from the network's owner, which may matter to you for privacy more than for security.

Can someone steal my banking password on a public network?

Not by reading the traffic, which is encrypted end to end. They can get it if they lead you to a fake site and you type it in yourself, which is how it happens in practice.

What is an evil twin network?

It is an access point created by an attacker using the same name as a legitimate network, so devices connect without suspicion and the attacker can manipulate what users see.

Keep reading