Home / Guides / VPN Basics
Is Public Wi-Fi Safe? What a VPN Changes
Public Wi-Fi is safer than it used to be, but it is still a network you do not control. Here is what the real risks are and what actually reduces them.
What has improved
Most websites and apps now use HTTPS, which encrypts the content between your device and the site. On a normal HTTPS site, another person on the cafe Wi-Fi cannot read your messages or passwords by just watching the network.
What can still go wrong
- Fake hotspots ("evil twins"). Someone sets up a network named like the real one, such as "Airport_Free_WiFi". If you join it, that person controls your connection and can try to redirect you to fake login pages.
- Captive portals. The login page that asks for your email or room number is a normal thing, but it can also be a place where you are asked for more than you should give.
- Unencrypted traffic. Some apps, old devices and smart gadgets still send data without encryption.
- Metadata. Even with HTTPS, the network operator can often see which domains you visit.
- Outdated devices. Unpatched software can be attacked over a shared network.
What a VPN adds
A VPN encrypts everything between your device and the VPN server, including the domains you look up. On a public network, that:
- hides which sites you visit from the network operator and other people on the network,
- adds protection for apps that do not use HTTPS,
- makes some on-path tampering harder.
A VPN does not fix a fake hotspot problem if you accept a certificate warning, and it does not stop you from typing a password into a phishing page.
Habits that matter more than any tool
- Confirm the network name with staff before joining, and avoid networks that need no verification when a trusted alternative exists.
- Use your phone's hotspot for anything sensitive, like banking or work logins. Your phone's cellular connection is usually safer than shared Wi-Fi.
- Turn off auto-join for open networks and turn off file sharing.
- Never click through certificate warnings. A warning on a site that normally works is a red flag.
- Use two-factor authentication on important accounts so a stolen password alone is not enough.
- Keep your device updated and use the built-in firewall.
- Log out and forget the network when you are done.
A reasonable rule
For casual browsing on a well-known hotel or airport network, HTTPS plus updated software is fairly safe. For work logins, banking or anything sensitive, use your phone's hotspot, or a VPN from a provider you have researched, or both. See how to set up a VPN.