Account Security · Global
Public Wi-Fi & VPN
Is public Wi-Fi actually dangerous? The honest answer: less than it used to be — but a few real risks remain. Here’s what genuinely protects you, and where a VPN honestly helps.
Updated Aug 2026 · 6 min read
Wi-Fi · open network
Connected to “Airport_Free_WiFi” — a lookalike network set up to watch your traffic
You’ll see a lot of scary advice about public Wi-Fi — much of it written to sell you something. So let’s be straight: the web is mostly encrypted now (HTTPS), which quietly killed the old “anyone can read your password on café Wi-Fi” threat. But a few genuine risks remain, and they’re worth understanding before you decide what protection you actually need.
The Real Risks
Fake “evil twin” hotspots
An attacker sets up a hotspot named to look legit — “Airport_Free_WiFi”, “Starbucks_Guest” — so you connect to them instead of the real network. Now they sit between you and the internet. This is the biggest real risk.
Fake login (captive-portal) pages
The “sign in to use this Wi-Fi” page can be faked to phish your email password or card details. It’s phishing wearing a Wi-Fi costume.
Snooping on unencrypted connections
Anything not sent over HTTPS can, in theory, be read on a shared network. In practice most sites are HTTPS now — but not all traffic is.
What Actually Protects You
- Stick to HTTPS. Look for the padlock and the correct web address; never dismiss a browser security warning on public Wi-Fi.
- Use two-factor authentication, so a stolen password alone can’t open your accounts.
- Keep your phone, laptop, and apps updated — most real attacks exploit old software.
- For anything sensitive (banking, big payments), prefer your mobile data over an unknown network.
- Turn off auto-connect to open networks, and “forget” networks you won’t use again, to avoid silently joining an evil twin.
- Check the exact network name with staff before connecting — attackers rely on you guessing.
Where a VPN Genuinely Helps
A VPN routes your traffic through an encrypted tunnel to a server you choose. On a public or untrusted network, that’s a real, useful upgrade:
- It encrypts ALL your traffic to a trusted server, so the local network — real or fake — can’t read or tamper with what you do. That’s the main win on an untrusted or public network.
- It hides your browsing from the network owner and your ISP.
- It’s a solid defence-in-depth layer if you travel a lot or often must use sensitive services on public Wi-Fi.
But be honest about the limits:
- It does NOT stop phishing, malware, or you typing a password into a fake site — a VPN protects the pipe, not your decisions.
- Free VPNs often make money by logging or selling your data, which defeats the point. Choose a reputable, independently-audited, no-logs provider.
Bottom line: you don’t need a VPN to use public Wi-Fi safely if you stick to HTTPS and use two-factor authentication. But a reputable, no-logs VPN is a worthwhile layer if you travel often or regularly handle sensitive things away from home — just don’t treat it as a cure-all, and never use a “free” one that pays for itself with your data.
VPNs we recommend
Want a no-logs VPN for public Wi-Fi and travel? Two budget-friendly options, both with apps for all your devices: FastestVPN and iProVPN.
Partner links — they may earn us a commission at no cost to you. Learn how we make money.
If You Used Public Wi-Fi and Are Worried
- 1
Once you’re on a network you trust, change the passwords for anything sensitive you accessed, and make each unique.
- 2
Turn on two-factor authentication where you haven’t already.
- 3
Update your device and apps, and review recent account activity for anything unfamiliar.
- 4
If you entered details on a Wi-Fi “login” page, treat that as a possible phishing page and change that password too.
Frequently Asked Questions
Is public Wi-Fi safe to use?
Safer than it used to be, thanks to HTTPS encryption on most sites — but not risk-free. The real dangers are fake “evil twin” hotspots and fake Wi-Fi login pages, not the network itself. Stick to HTTPS, use 2FA, and keep sensitive tasks for a network you trust.
Do I really need a VPN on public Wi-Fi?
Not strictly, if you stay on HTTPS and use 2FA. But a reputable VPN is a genuinely useful extra layer — especially on untrusted networks, when travelling, or if you regularly do sensitive things away from home. It’s protection in depth, not a magic shield.
Are free VPNs okay?
Be careful. Running a VPN costs money, so many free ones monetise by logging or selling your data — the exact opposite of what you wanted. Prefer a reputable paid, no-logs, independently-audited provider.
What is an “evil twin” Wi-Fi network?
A fake hotspot named to look like a real one (e.g. “Airport_Free_WiFi”) that an attacker sets up to intercept your traffic. Verify the exact network name with staff, and turn off auto-connect so your device doesn’t join one on its own.
Can someone really steal my bank password on public Wi-Fi?
It’s much harder than people fear, because banking sites use HTTPS the network can’t read. The bigger risks are a fake login page (phishing) or a fake hotspot — which is why checking the address bar and using 2FA matter more than the network itself.
Related reading: passwords & 2FA, check a suspicious link, or browse all our scam guides.
Informational only — not security advice for a specific situation. Sources: UK NCSC and US CISA / FTC guidance on public Wi-Fi and VPNs, and current HTTPS-adoption data. Verify against primary sources.