
Public WiFi is riskier than your home network, but the old "never use public WiFi" advice is outdated. Most sites and apps use HTTPS encryption automatically now, which protects the content of your traffic even on an open network. The two risks that are still real are man-in-the-middle attacks on poorly configured networks, and evil-twin hotspots, fake networks set up to look like a legitimate one so your device connects to an attacker instead. A VPN protects against both by encrypting your traffic end to end, but it doesn't protect you from malware already on your device or from phishing pages that trick you into typing a password directly. Everyday browsing, reading news, checking sports scores, is low risk on public WiFi. Banking and anything with a saved payment method is where you should use a VPN or switch to mobile data instead.
Airport, cafe, and hotel WiFi warnings have been repeated for so long that most people either ignore them completely or avoid public WiFi altogether out of vague fear. Neither reaction is quite right, because the actual risk profile has changed a lot in the last several years, mostly for the better.
The biggest shift is HTTPS becoming the default almost everywhere. When you see a lock icon in your browser's address bar, the connection between your device and that website is encrypted, which means someone else on the same WiFi network cannot simply read your traffic in plain text the way they could a decade ago. Most major websites, banking apps, and messaging apps use this by default now.
What's still genuinely risky:
An evil twin is a fake WiFi network set up with a name that looks identical, or almost identical, to a real one nearby. Think "Airport_Free_WiFi" next to the real "Airport-Free-WiFi," or a hotspot broadcasting the exact same name as your hotel's real network from a laptop two tables away. Devices that have connected to a similarly named network before will sometimes auto-connect to the fake one without asking.
Once you're connected to the attacker's hotspot, they control the connection, which means they can see unencrypted traffic, redirect you to fake login pages, or simply slow things down while collecting whatever data passes through in the clear.
Practical defenses:
We connect remotely, check your device for anything suspicious picked up on public WiFi, help you secure accounts if a session or password may have been exposed, and set up your VPN correctly for future travel. Flat $79.99 USD, any time zone, No Fix No Fee.
Get help now – $79.99A VPN creates an encrypted tunnel between your device and the VPN provider's server, so anyone on the local network, including an evil twin operator, sees only encrypted traffic instead of your actual browsing.
| A VPN protects against | A VPN does not protect against |
|---|---|
| Local network snooping on an evil-twin or open hotspot | Malware or spyware already installed on your device |
| Your ISP or hotspot operator logging your browsing | Phishing pages that trick you into typing a password directly |
| Traffic interception between you and the VPN server | A weak or reused password on the account you're logging into |
| Basic geographic content restrictions | A dishonest or poorly secured VPN provider itself |
In short, a VPN is a real and useful layer specifically for the "someone on this network can see my traffic" problem. It isn't a general safety switch that makes every other kind of risk disappear. If you travel a lot and your VPN connection itself is unreliable on the road, our guide on VPN connections dropping abroad covers the most common causes.
A practical way to think about it: how bad would it be if this specific traffic were read by a stranger right now?
If you're regularly working from cafes, coworking spaces, or hotel business centers, our VPN and remote work support service can set up a properly configured VPN once, so you're not making these judgment calls every single time you connect.
We help remote workers and travelers with this from wherever you are:
The risk is real but narrower than it used to be. Most websites and apps now use HTTPS encryption by default, which already protects the content of your traffic even on open WiFi. The remaining real risks are man-in-the-middle attacks on networks with weak or no encryption setup, and fake hotspots (evil twins) set up to imitate a real network's name so your device connects to the attacker instead. Both are avoidable with basic precautions, so public WiFi is riskier than home WiFi, but not the guaranteed disaster older warnings suggested.
An evil twin is a fake WiFi hotspot set up with the same or a very similar name as a legitimate network, like a cafe's real WiFi name, placed nearby so devices connect to it automatically or by mistake. Once connected, the attacker controlling that hotspot can see and sometimes modify your traffic. The best defense is confirming the exact network name and password with staff before connecting, and never connecting to an open network with no password at all in a place that would normally require one.
No. A VPN encrypts your traffic between your device and the VPN server, which protects you from the local network operator or an attacker on the same WiFi snooping on your data. It does not protect you from malware already on your device, from phishing sites that trick you into typing your password directly, or from a compromised VPN provider itself. A VPN is a strong layer of protection for public WiFi specifically, not a general safety guarantee.
Browsing news sites, reading email through a proper HTTPS webmail site, checking sports scores, or using well-known apps with built-in encryption is generally low risk on public WiFi because the connection to those sites is already encrypted end to end. Riskier activities are online banking, entering credit card numbers on unfamiliar sites, or logging into accounts on any site that still loads as plain HTTP without a lock icon in the address bar. When in doubt, use a VPN or your phone's mobile data for anything involving money or sensitive logins.