Skip to Main Content
Privacy

Are public Wi-Fi networks safe? What actually matters in 2026

The old warning was that anyone on the cafe network could read your traffic. Encryption largely ended that, and the FTC now says connecting through public Wi-Fi is usually safe. The risks that remain are different ones, and worth knowing precisely.

Subash Poudel6 min read

The short answer

  1. Public Wi-Fi is much safer than it used to be. Because nearly all web traffic is encrypted, the FTC's guidance is that connecting through a public network is usually safe.
  2. The real risks moved. Fake networks, fake sign-in pages and your own device settings now matter more than anyone eavesdropping on the air.
  3. Encryption protects data in transit, not from the site receiving it. A scam site with a padlock is still a scam site.
  4. A VPN is useful for hiding which sites you visit from the network operator. It does not make a phishing page safe.
  5. The highest-value settings are free - turn off automatic joining of open networks and file sharing before you travel.

The advice about public Wi-Fi has not caught up with the web. Most of what people repeat describes a threat that was real in 2012 and is now marginal — while the things that actually go wrong on a cafe network get almost no attention.

Quick answer

Public Wi-Fi is usually safe now. The FTC's own guidance says so directly: "Because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe."

The reason is that almost every website and app now encrypts its traffic. Even if someone captures your data off the air, they get scrambled output rather than your messages, passwords or bank details.

What remains worth caring about is a different list:

  • Fake networks set up to look like the venue's
  • Fake sign-in pages, served through a captive portal
  • Your own device settings — automatic joining, file sharing, outdated software
  • Being watched rather than read — the network operator can see which sites you visit
  • Everything that is not the network at all — phishing, malware, weak passwords

What encryption changed

When you see https and a padlock, the connection between your device and the site is encrypted. Someone on the same network sees that a connection happened and roughly where to, but not what was in it.

That was not always true. In the early 2010s a large share of the web ran unencrypted, and reading other people's traffic in a coffee shop was genuinely easy. The shift to HTTPS across almost the entire web removed that.

The risks that are real

1. Fake networks

An attacker sets up a hotspot named like the venue's — Hotel_Guest_WiFi, Airport_Free_WiFi, Starbucks WiFi 2. Devices show it alongside the genuine one, and nothing distinguishes them visually. This is often called an evil twin.

Connecting routes your traffic through their equipment. Encryption still protects the contents, so this is not the disaster it is sometimes described as — but it gives them two useful things: a list of the sites you connect to, and the ability to show you any page they like when you first join.

What to do: ask the venue for the exact network name. Do not guess from the list, and be suspicious of near-duplicates.

2. The sign-in page

The captive portal — the page that appears when you join and asks you to accept terms or log in — is the most abused part of public Wi-Fi, because people expect it to ask for something.

A genuine portal may want an email address or a room number. It never needs:

  • Your password for another service, especially a social or email account
  • Card details for free Wi-Fi
  • A software download, app install, or security certificate
  • A Social Security number, date of birth or ID document

What to do: if a portal asks for any of that, disconnect. Nothing about joining a network requires credentials to an unrelated account.

3. Your device announcing itself

Two default settings cause more trouble than the network ever does:

  • Automatically joining open networks. Your phone reconnects to anything with a familiar name, without asking, including a fake one.
  • File and printer sharing, or AirDrop set to receive from everyone. Fine on your home network, not on a shared one.

4. Everything that has nothing to do with Wi-Fi

Most bad outcomes on a hotel network would have happened at home too: a phishing email, a fake support call, a malicious download, a reused password turning up in credential stuffing. The network gets blamed because it is the unfamiliar thing in the room.

Do you need a VPN?

A VPN encrypts all of your traffic and routes it through a server run by the VPN provider. On a network you do not trust, it hides which sites you are visiting from the network operator.

That is genuinely useful, and it is also narrower than the marketing suggests.

A VPN doesA VPN does not
Hide which sites you visit from the network operatorMake a phishing site safe
Protect the small share of traffic still unencryptedStop malware you install yourself
Prevent the network injecting content into pagesMake you anonymous
Let you reach your work networkProtect a weak or reused password

What to do before you travel

A five-minute setup that covers most of it:

  1. Turn off automatic joining of open networks. iPhone: Settings → Wi-Fi → Ask to Join Networks → Ask, and Auto-Join Hotspot → Ask to Join. Android: Settings → Network & internet → Wi-Fi → Wi-Fi preferences, and turn off connecting to open networks automatically.
  2. Forget networks you no longer use. Your device advertises for saved names; an old airport network is a name someone can impersonate.
  3. Turn off file sharing — Windows sharing, macOS file sharing, AirDrop set to Contacts Only or Receiving Off.
  4. Update the operating system, browser and apps before you leave. Updates are the single most effective security step on this page.
  5. Turn on two-factor authentication for email and banking, so an intercepted password alone is not enough. Which second factor to use compares them.
  6. Know your mobile hotspot works. Your own data connection is the simplest answer for anything sensitive.

What to do while connected

  • Confirm the network name with staff. The one useful question to ask.
  • Use apps rather than browsers for banking and email. An app checks it is talking to the right server and cannot be redirected to a lookalike.
  • Look for the padlock, and treat its absence on any page asking for information as a stop signal.
  • Do not install anything a network asks you to install. No certificate, no app, no "connection helper".
  • Prefer mobile data for anything financial. Free, and removes a variable.
  • Sign out of shared accounts when you finish, and lock your screen when you step away — shoulder surfing in an airport is a more realistic threat than packet capture.
  • Turn Wi-Fi off when you are not using it, which also cuts the location tracking that happens through network scanning.

What about hotel and airport networks specifically?

They deserve slightly more caution, for a mundane reason: they are the places people expect to see an unusual sign-in page, so a fake one attracts less suspicion. A hotel portal asking for your room number and surname is normal. A hotel portal asking for a card number "to verify identity" is not.

The same applies to conference and event networks, where attendees expect to register and are primed to hand over details.

Key takeaways

  • Encryption solved the original problem — the FTC says public Wi-Fi is usually safe.
  • The remaining risks are fake networks, fake sign-in pages, and your own device settings.
  • A padlock protects the journey, not the destination.
  • A VPN hides your browsing from the network operator; it does not neutralise phishing or malware.
  • Turn off automatic joining and file sharing, keep software updated, and use mobile data for anything sensitive.

For the wider picture of who collects what about you online, online privacy is the place to start, and how to protect your personal information covers the habits that matter most.

Build the habits that travel with you

SafeSurf IQ teaches the checks that work on any network - reading a sign-in page, spotting a fake portal, and knowing what a padlock really means.

Try it free

Frequently asked questions

Is public Wi-Fi safe to use?
Usually, yes. The FTC's guidance states that because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe. Nearly all websites and apps now encrypt their traffic, so someone else on the same network cannot read what you send. The remaining risks are fake networks, fake sign-in pages, and device settings that expose you - not eavesdropping.
Do I need a VPN on public Wi-Fi?
Not for the reason most people think. Encryption already protects the contents of what you send. A VPN adds two things - it hides which sites you visit from the network operator, and it protects the small amount of traffic that is still unencrypted. That is worthwhile if you value privacy from the network, or you handle sensitive work, but it is not the difference between safe and unsafe.
Can someone steal my passwords on public Wi-Fi?
Not by watching the network, in almost all cases - a password sent to an encrypted site is unreadable in transit. Passwords are lost on public Wi-Fi the same way they are lost anywhere else - a phishing page, a fake sign-in portal, or malware. That is why unique passwords and two-factor authentication matter more here than any network setting.
Is it safe to do online banking on public Wi-Fi?
Technically yes, since banking apps and sites use strong encryption. The practical advice is still to prefer your mobile data for anything financial, because it removes one variable entirely at no cost. If you do use public Wi-Fi, use the bank's own app rather than a browser, and never reach the bank through a link or a captive portal page.
What is an evil twin network?
An evil twin is a fake Wi-Fi hotspot named to look like a real one - for example a network called Airport_Free_WiFi next to the genuine one. Connecting sends your traffic through equipment the attacker controls, which lets them serve fake sign-in pages and see which sites you visit. Encryption still protects the contents, but the fake pages are the point.
How can I tell if a public Wi-Fi network is real?
Ask the venue for the exact network name rather than guessing from the list. Be suspicious of duplicates, near-identical names, and open networks that require personal details or a payment to join. A genuine hotspot never asks for a password to another service, a card number for free access, or permission to install a certificate or an app.

Sources

  1. Are Public Wi-Fi Networks Safe? What You Need To Know Federal Trade Commission, 2023
  2. Public Wi-Fi Networks Federal Trade Commission, 2026
  3. Using public Wi-Fi hotspots UK National Cyber Security Centre, 2025
  4. How to Protect Yourself Online Federal Communications Commission, 2025
  5. HTTPS encryption on the web Google, 2026

About the author

Subash Poudel

Cybersecurity & Digital Literacy

Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.

  • Founder and engineer, SafeSurf IQ
  • Writes and reviews the platform's phishing, scam and privacy curriculum
  • Works from primary incident and fraud reporting, cited on every article

Last reviewed . Figures are checked against the primary sources listed above at each review.