guide
What Can Actually Happen on Public Wi-Fi (2026 Reality Check)
Published Aug 3, 2026 · Last updated Aug 3, 2026
A decade ago, coffee-shop Wi-Fi meant anyone could read your email. HTTPS everywhere ended that era — so is public Wi-Fi safe now? Mostly, with three real exceptions.
Risk 1: The network sees your destinations
Even with HTTPS, the network operator (and whoever runs the captive portal) sees every domain you visit via DNS and connection metadata. Hotel and airport networks monetize exactly this. An encrypted VPN tunnel removes it — the network sees one connection to one server and nothing else.
Risk 2: Evil twin hotspots
Anyone can broadcast 'Airport_Free_WiFi'. Connect and they control your DNS, your captive portal, and any unencrypted request. Modern browsers limit the damage, but a fake portal harvesting the email+password combo you reuse everywhere doesn't need to break TLS.
Risk 3: The long tail of unencrypted apps
Smart-TV apps, older mail clients on plain IMAP, IoT gadgets, some corporate tools — the traffic that still isn't encrypted is exactly the traffic you don't monitor. A device-level VPN wraps all of it.
The two-minute defense
Use your phone's hotspot for anything sensitive when possible; otherwise connect a VPN before doing anything that involves a login. A no-card free plan from a verifiable provider is genuinely sufficient for travel Wi-Fi — unlimited-data free tiers like Proton's or hide.me's exist precisely for this. Turn on your VPN's auto-connect-on-untrusted-Wi-Fi setting and the whole problem disappears from your attention.
What NOT to do
Don't install a random 'free WiFi security' app from an unknown developer — unverifiable free VPNs are a bigger threat than the coffee shop.