How do I use public wifi safely?
What is actually risky now that most traffic is encrypted, the fake-hotspot problem, and the one setting that matters most.
- Difficulty
- beginner
- Time
- 15 min
- Read
- 4 min
- Safety
- warning
Short answer
Most of the old advice is out of date because almost all web traffic is encrypted now. The real risks are fake hotspots imitating the venue and your device auto-joining networks. Use mobile data or a phone hotspot for anything financial, turn off auto-join, and check the network name with staff.
Public wifi used to be genuinely dangerous because traffic was unencrypted and could simply be read. Widespread encryption has changed that substantially. What has not changed is that you do not know who is running the network.
Safety
Step by step
- Understand what encryption already protects.Almost every site now uses HTTPS, so the contents of what you send are encrypted between your device and the site. Someone on the same network cannot read it. That covers most of what people worry about.
- Understand what it does not hide.The network operator can still see which sites you connect to, when, and how much. The contents are protected; the pattern is not.
- Treat fake hotspots as the main risk.Anyone can create a network called 'Airport Free WiFi' or something close to the café's real name. Connect to that and the operator controls your connection. Ask staff for the exact network name rather than guessing.
- Turn off automatic joining.Phones remember networks and rejoin anything with a matching name. A device that auto-joins an unknown network in a station has connected before you have decided anything. This is the single most valuable setting here.
- Forget networks after using them.One-off hotel, café and airport networks accumulate in the saved list and get rejoined automatically for years. Clear them out periodically.
- Use mobile data for anything financial.Banking, payments, entering card details. Mobile data is a network you have a relationship with, and the extra cost is negligible against the alternative.
- Use a phone hotspot instead where you can.Tethering a laptop to your own phone avoids the public network entirely and is usually faster. This is the practical answer for working away from home.
- Consider a VPN for the pattern rather than the contents.A VPN hides which sites you visit from the network operator. It does not make an insecure site secure, and it moves your trust to the VPN provider — which is a real consideration.
- Be wary of captive portals asking for too much.A sign-in page wanting a password, a date of birth or a card number for free wifi is not normal. An email address is the usual maximum, and a disposable one is fine.
- Turn off sharing on a laptop.File and printer sharing set up for a home network should not be active on a public one. Both systems ask whether a network is public or private — answer public.
- Keep the device updated.The attacks that still work against modern devices rely on unpatched flaws. An up-to-date device on public wifi is in a considerably better position than an old one behind a VPN.
- Check for a padlock and the right address.A browser warning about a certificate on a public network is a reason to stop, not to click through. That is the signal that something is interfering with the connection.
Tips
- The advice to avoid public wifi entirely is out of date for ordinary browsing. Reserve the caution for financial activity and for networks you cannot verify.
- Ask the venue for the network name and password. A network with no password at all is not necessarily unsafe now, but it is easier to imitate.
- Hotel and conference networks are no more trustworthy than café ones — the guest network is separate from anything the venue actually secures.
Common mistakes
- Leaving automatic wifi joining on — The device connects to anything with a familiar name before you have decided to. Turning it off is the single most useful change.
- Clicking through a certificate warning to get online — That warning is exactly what appears when something is intercepting the connection. It is the one warning worth taking seriously.
If it doesn't work
Two networks with almost the same name
Cause: Possible fake hotspot imitating the venue — Fix: Ask staff which is correct. Do not guess, and do not pick the one with the stronger signal.
Certificate warning on a public network
Cause: Something interfering with the connection, or a broken captive portal — Fix: Do not proceed. Disconnect and use mobile data instead.
Captive portal will not load
Cause: The sign-in page is not being triggered — Fix: Open a plain HTTP address, which forces the portal to appear. Do not enter credentials for anything else while trying.
Phone joins a network you did not choose
Cause: Auto-join and a remembered network name — Fix: Turn auto-join off and clear old saved networks from the list.
Questions people ask
Is public wifi still dangerous?
Much less than it was, because almost all web traffic is now encrypted. The real risks are fake hotspots imitating the venue and your device auto-joining unknown networks. Use mobile data for anything financial.
Do I need a VPN on public wifi?
It hides which sites you visit from the network operator, which is a real benefit. It does not make an insecure site secure, and it moves your trust to the VPN provider. For banking, mobile data is simpler.