You’re sitting in a coffee shop, opening your laptop, tapping “Free Wi-Fi” – and you hesitate for a second. Is that safe? Is someone watching? Could a hacker on the same network drain your bank account?

The answer is less dramatic than many security guides suggest – but there’s a catch.

Where the fear comes from

Warnings about public Wi-Fi are as old as Wi-Fi itself. And they used to be justified: ten years ago, most websites transmitted data unencrypted. Anyone on the same network could use freely available tools to actually eavesdrop – emails, passwords, search queries. That wasn’t theory; it was a routine demo at security conferences.

Since then, the internet has fundamentally changed. Only the warnings haven’t.

What changed since then: HTTPS

The most important change has five letters: HTTPS. The lock icon in your browser’s address bar means the connection between your device and the website is encrypted – regardless of whether you’re at home, in a hotel or on a train.

And HTTPS is no longer the exception; it’s the norm. According to Google’s Transparency Report, over 95% of all Chrome page loads now use HTTPS. Your bank, your email provider, your favorite news site, your online store – they all encrypt automatically.

That means: even on an open Wi-Fi network, an attacker on the same network cannot simply read your passwords, your emails or your bank details. The encryption happens between your browser and the website’s server – the Wi-Fi in between is just the delivery route, and on that route all an eavesdropper sees is encrypted gibberish.

What an attacker can still see

Does that mean public Wi-Fi is completely risk-free? Not quite. Even with HTTPS, a few things remain visible:

  • Which websites you visit – not what you do there, but the fact that you’re connecting to, say, chase.com, nytimes.com or tinder.com. The domain is briefly visible during the connection setup (through DNS queries and the so-called SNI header).
  • How much traffic you generate – an attacker could tell whether you’re streaming a movie or just checking email.
  • When you’re online – timestamps of your connections.

That’s not access to your data, but it is a glimpse at your browsing habits. Whether that matters to you depends on your personal threat model. For the vast majority of people going about their day: probably not.

The real dangers – and they have little to do with the Wi-Fi

The risks lurking on public Wi-Fi are usually the same ones lurking at home – you just think about them more carefully when you’re at a coffee shop.

Fake networks: An attacker can set up a Wi-Fi network called “Hilton Lobby Free WiFi” that looks just like the real hotel network. Anyone who connects routes all their traffic through the attacker’s device. HTTPS still protects the content here too – but the attacker sees your DNS queries and can try to redirect you to manipulated websites.

Captive portals with a phishing flavor: Some public Wi-Fi networks require you to log in through a web page. Occasionally these ask for more information than necessary – email address, name, room number. That’s less of a technical attack and more of a data-harvesting operation.

Shoulder surfing: The most trivial and at the same time most underestimated danger in a coffee shop is the person at the next table looking at your screen. No VPN in the world helps against that – only a privacy screen on your display or a seat with your back to the wall.

Do I need a VPN at the coffee shop?

Let me be honest here – including about our own VPN article from April. There we wrote that public Wi-Fi networks are “the classic and strongest use case” for a VPN. That’s true in principle – but it deserves some context.

A VPN does add an extra layer of encryption and hides the domains you visit from eavesdroppers on the network. That’s real. But: HTTPS already does the heavy lifting. The contents of your communication – passwords, message text, account details – are encrypted even without a VPN, as long as the website uses HTTPS. What the VPN additionally protects is essentially the information about which websites you visit.

Whether that’s worth the effort depends on your situation:

  • You’re quickly checking the news on airport Wi-Fi? HTTPS is enough.
  • You regularly work with confidential company data at a coworking space? A VPN makes sense – and your employer probably provides one anyway.
  • You’re traveling to countries with internet censorship? A VPN is essential – but for entirely different reasons.

The VPN industry makes billions by painting the dangers of public Wi-Fi as more dramatic than they actually are today. That doesn’t mean VPNs are useless – we covered the real benefits in detail in our VPN article. But the line “Without a VPN at the coffee shop you’re defenseless” was accurate in 2012 and is overblown in 2026.

What actually helps: five rules for when you’re out and about

Instead of a VPN, most people on public Wi-Fi mainly need common sense and a few simple habits:

1. Check the network name. Ask at the front desk or the staff for the exact Wi-Fi name. Don’t blindly connect to the strongest open signal.

2. Look for HTTPS. Before you enter a password anywhere, check for the lock icon in the address bar. No lock? No login.

3. Forget the network afterward. Most devices remember Wi-Fi networks and reconnect automatically. In your Wi-Fi settings, you can delete saved networks – or turn off auto-connect.

4. Keep your system up to date. The biggest danger on public Wi-Fi isn’t the eavesdropper – it’s an outdated operating system with known security holes. Updates are your first line of defense.

5. Use two-factor authentication. Even if someone could somehow intercept your password (which is extremely unlikely with HTTPS) – with a second factor, they still can’t get into your account.

Bottom line: less panic, more awareness

Public Wi-Fi today is significantly safer than its reputation suggests. HTTPS has fundamentally changed the rules. The horror stories about intercepted passwords date back to a time when most websites were still unencrypted – and that era is over.

That doesn’t mean you should carelessly use every open network you find. It means the danger lies somewhere different than most people think: not in the encrypted data stream, but in fake networks, in careless habits and in the simple fact that someone at the coffee shop can look over your shoulder.

Last week I was sitting in a hotel lobby on their Wi-Fi and hesitated for a moment before logging in. Old habit. Then I checked the lock icon in the address bar, read my emails – and closed the laptop. Not out of fear, but because I’d run out of coffee.

How do you handle public Wi-Fi? Cautious, relaxed or somewhere in between? Let us know in the comments – we’d love to hear your take.

Comments

4
OS1
1 month ago
Excellent article
Like Like like love care 12 Reply
3
swarfendor437
1 month ago
I don't have a notebook, but a smartphone. I always use my data plan. I don't use free WiFi.
Like Like like 6 Reply
1
Susie
1 month ago
A really useful updated article for Wifi & more.
Thank you :)
Like Like like 7 Reply
4
Boby
1 month ago
Okay, but what about when we use a dedicated application, e.g. a bank, and not a browser?
Like Like like 3 Reply
1
readingisfundamental
1 month ago
The article was SPECIFICALLY about PUBLIC WI-FI. Look elsewhere
Like Like angry 1 Reply
3
Mark
1 month ago
It doesn’t matter app or browser , you use the same connection
Like Like like 1 Reply
3
Harry
1 month ago
Yes, but, can one see the protocol being used as easily as when using a browser? Unless the OS blocks apps from using insecure transports, you'd have to place a greater degree of trust in the app authors.
Like Like Reply
1
Marilyn
1 month ago
The article states that HTTPS encrypts that data on both sides, so even accessing a bank would be safe. But it also says that you should use two factor authentication to be completely safe. That way anyone spying can't even see what sites you're accessing. So make sure to use two factor authentication.
I always logout of each site when I'm finished, and I completely close the browser after accessing a site that I'm particularly sensitive about.
Like Like like 6 Reply
2
jena
1 month ago
Your bank has better security than average browser, usually. The WiFi has not much to do with that. Not to mention my bank uses two-factor confirmation for all transactions, so there is little risk of abuse.
Like Like like 1 Reply
0
Phil
1 month ago
Another good article which is easily digestable by those of us habitually using technology but may not keep up to date with latest developments.

A message which needs to be repeated so this awareness becomes embedded more cuturally rather than simply learning by rote.
Like Like like 2 Reply
3
EWS
1 month ago
This is a great article. It clearly demonstrates the unfounded fears surrounding the use of social media. However, I would add that the biggest threat posed by free Wi-Fi is the service provider—the one offering the service. Because security protocols are useless if security is only superficial. If we go on a trip to a foreign country and our device connects to a street network while sightseeing, we have practically no idea who is operating it. The average user knows almost nothing about security. For them, security means a strong password—and that’s about it. People need to be educated about networks in much greater depth so they can better protect their data.
Like Like like 3 Reply
2
Mockingbird
1 month ago
A strong password is the stumbling block. Most folks like a short password for convenience. Two factor is important then. Search for the 500 most common passwords to make sure your password is not among them. Hackers can try all these passwords in a few minutes. Length is more important than complexity. Try a passphrase that's easy to remember but hard to guess.
Like Like Reply
1
Erika
1 month ago
Thanks for the article!
Like Like Reply
2
Nil
1 month ago
You're missing a crucial aspect. Your device itself is now on a public network!!
Subject to an 0-day or other operating system vulnerabilities.
Like Like like 1 Reply
2
Pentata
1 month ago
I use open WiFi networks at coffee shops, but always with VPN on my tablet. The article is really interesting and helpful. Thank you.
Like Like like 2 Reply
1
Anna
1 month ago
I love these chats. Thank you for them.
Like Like Reply
2
Keith
1 month ago
Yeah sure, https does most of the lifting for website visits. But some one did mean apps, and the consequences of some apps involve live transport via internet, which likely has nothing to do with https. You expect security on some famous messaging apps, but what about the others? Please write an article about app security on non-home WiFi! Thanks, good article overall.
Like Like Reply
2
Joe
1 month ago
I am sorry but for last few years I no longer see the lock symbol, seems the address line cuts it off or hide it.
Like Like Reply
1
nestoribio
1 month ago
It should be selected on your browser settings. You should block non HTTPS connections!
Like Like Reply
1
Peter
1 month ago
Great article. I Did not know about HTTPS
THANK YOU.
Like Like like 1 Reply
1
Luigi
1 month ago
The Friday Chat is establishing itself as a very useful informative avenue on the ways we connect these days , keep up the good work.
Like Like like 1 Reply
1
ian4238
1 month ago
On recent overseas trip, I had very limited 'roaming' on my phone, so used hotel WiFi, very carefully. I feel much better informed after reading this article.
Like Like Reply
1
Marc
1 month ago
If you use secure DNS available with some browsers, and https, it sounds like VPN is not even needed.

Secure DNS uses encryption (like DoH or DoT) and cryptographic authentication (DNSSEC) to protect your internet traffic
Like Like like 1 Reply
1
gwyz
1 month ago
makes a lot of sense.
Like Like Reply
1
Nil
1 month ago
Marc, secure DNS is only for site lookup (the IP address) - it's not related actual site traffic encryption.
Like Like Reply
1
Richard
1 month ago
Is it impossible un eavesdroper, or hacker, can add HIS locksign just before the URL addresse?
Like Like Reply
1
nestoribio
1 month ago
The DNS isn't a problem anymore!
Use a secure DNS or DNSS server. There are plenty of them, many free to use!
The other day I was at my dentist and have troble browsing. I just for curiosity found that the problem was my secure DNS. I left a note to the secretary telling not to block secure DNS and next visit that block was over...
On my first visit I used my data plan.
Like Like like 1 Reply
1
nestoribio
1 month ago
Something not mentioned is the importance of a good firewall.
For Android users that have no root access a no root firewall could be good for normal browsing, specially if you use another browser, not the default one (mostly Chrome or Samsung Internet).
But if you're using a laptop (I don't have a clue about Chromebooks) a good firewall is mandatory not matter which OS you use!
Note that most of them, even if there is a native firewall it isn't on by default.
Like Like Reply
1
Thierry
1 month ago
Personnellement, je serai plus nuancé. Si vous êtes sur WIFI WPA2, un attaquant connecté au même réseau et équipé d'un logiciel d'analyse (comme Wireshark) peut intercepter les ondes. S'il a capturé le moment où votre appareil s'est connecté au Wi-Fi, il peut déchiffrer la couche Wi-Fi de vos paquets de données. Sans VPN, seul le HTTPS protège vos données. En WPA3, on utilise une technologie appelée SAE (Simultaneous Authentication of Equals). Même si le réseau est public et sans mot de passe, chaque connexion entre un appareil et la borne est chiffrée de manière unique ; le WPA3 bloque l'interception passive des données par les ondes. Néanmoins, HTTPS n'est pas inviolable et peut être contourné par : une attaque "Man-in-the-Middle", le stripping SSL / HTTPS, le pishing local avec de faux sites. Au final, un VPN crée un tunnel chiffré de bout en bout. Même si le Wi-Fi est piraté ou corrompu, personne ne peut voir ce que vous faites". Donc à mon avis, sur un WIFI, et plus particulièrement un réseau WIFI public, un VPN reste indispensable. Mais ce n'est que mon avis.
Like Like love 1 Reply
1
Joc
1 month ago
Très bonne remarque. Il est toujours nécessaire d'utiliser son gros bon sens. Si vous demandez au comptoir (hôtel ou resto) le niveau de WPA utilisé du WIFI, j'ai constaté qu'aucun des employés n'a pu me répondre et m'ont surement pris pour un extra-terrestre. Alors j'utilise toujours un navigateur tel Opera pour avoir autant un VPN actif que la recherche du site HTTPS de ma destination. A+ pour votre commentaire.
Like Like Reply
1
Wolfman
1 month ago
Useful info. Thanks :-)
Like Like Reply

Add comment

Submit