Public Wi-Fi carries real risks — but understanding which threats are genuine helps you use it safely rather than avoiding it entirely. In 2025, most web traffic uses HTTPS, which significantly changes the threat landscape compared to a decade ago.
The Real Risks vs What Is Overblown
⚠️ Genuine Threats
- Evil twin / rogue access points — Attackers create a hotspot named identically to the legitimate network. Your device connects to theirs instead.
- Unencrypted HTTP traffic — Any site using HTTP (not HTTPS) can have its content read by others on the same network.
- Malware via compromised networks — Some routers can inject malicious code into unencrypted downloads.
✅ Less Risky Than Many Think
- HTTPS-encrypted sites — Over 95% of web traffic now uses HTTPS. Content is encrypted end-to-end even on public Wi-Fi.
- Banking apps — Major banking apps use certificate pinning, making interception nearly impossible even on hostile networks.
- Encrypted messaging — Signal, iMessage, and WhatsApp encrypt messages end-to-end regardless of the network.
Five Rules for Public Wi-Fi Safety
1. Verify the Network Name
Ask a staff member for the exact Wi-Fi name before connecting. Attackers set up “Starbucks_WiFi” next to the legitimate “Starbucks” network. A character difference is enough to redirect your traffic.
2. Check for HTTPS on Every Site
Look for the padlock icon and https:// in your browser address bar. If a site shows http:// (no S), do not enter any login credentials or personal information.
3. Use a VPN on Untrusted Networks
A VPN encrypts all traffic from your device, including DNS lookups, before it leaves your machine. Essential for hotel and airport Wi-Fi. See our Tool Directory for reviewed options — Proton VPN has a strong free tier.
4. Use Your Phone Hotspot for Sensitive Tasks
For online banking or accessing sensitive work systems, switch to your mobile data connection. It is significantly more secure than any public Wi-Fi network.
5. Keep Your Device Firewall Active
Windows Defender Firewall and macOS Firewall should be enabled. On Windows: Settings → Privacy & Security → Windows Security → Firewall. On Mac: System Settings → Privacy & Security → Firewall.