Internet & Web
How to Use Public Wi-Fi Safely Wherever You Are
Public Wi-Fi is convenient but not always private. Here is a calm, practical set of habits that keep your accounts and data safe on any open network.
Internet & Web
Public Wi-Fi is convenient but not always private. Here is a calm, practical set of habits that keep your accounts and data safe on any open network.
The short version: on an open network your two real risks are connecting to a fake hotspot and sending data over an unencrypted (http) connection, not a stranger silently reading your bank password out of thin air. Because roughly 95 percent of web traffic now travels over HTTPS encryption, much of the old "hackers can steal everything on public Wi-Fi" advice is a decade out of date. What still matters is knowing which network you are actually on, keeping your traffic encrypted, and locking a few device settings so your phone stops making connection decisions for you.
An open network has no password, which means there is no encryption at the Wi-Fi link layer. Anyone nearby with a laptop and free software like Wireshark can capture the raw packets moving through the air in that cafe. The crucial detail: what they capture is almost always HTTPS traffic, encrypted end to end between your device and the website, so they see the destination but not the contents, not your messages and not your passwords.
Two things break that protection, and these are the risks worth caring about:
A newer wrinkle worth knowing: some venues now run WPA3 Enhanced Open (also called OWE, Opportunistic Wireless Encryption), which encrypts each device's link even with no password. It is a genuine upgrade, but you cannot count on it being present, so your habits should not change.
The classic attack is the "evil twin": an attacker broadcasts a network with a trustworthy-looking name like "Airport_Free_WiFi," or copies the exact SSID of the real cafe network. Your phone, recognizing a familiar name, may join it on its own. From there the attacker sits between you and the internet.
The defense is unglamorous and effective. Confirm the exact network name with staff, and never let convenience pick the network for you. If you see two networks with nearly identical names, treat that as a warning sign, not a coincidence.
The sign-in page that pops up at hotels and airports, the captive portal, is where people get careless. Never type a real password into it. Legitimate portals ask for a room number, an email address, or a simple checkbox; they never need your Google or bank password. If a portal pushes you to "log in with Facebook" and the page looks even slightly off, close it.
Glance at the address bar. "https://" with the padlock (or simply no "Not Secure" warning) means the connection is encrypted with TLS. You can turn that habit into a guarantee: both Chrome and Safari offer an HTTPS-First mode that warns before loading any http page.
DNS, the lookups that turn a domain name into an address, historically traveled in plaintext, letting a rogue network see and redirect where you were going. Encrypted DNS closes that gap:
Apple's iCloud Private Relay (bundled with iCloud+) does something similar for Safari, encrypting requests and hiding your IP address behind two separate relays. It is not a full VPN, but on open Wi-Fi it meaningfully shrinks what the local network can observe.
A VPN wraps all of your device's traffic in an encrypted tunnel to the provider's server, so the local network sees a single opaque stream. Given how much HTTPS already covers, a VPN's real value on public Wi-Fi is filling the gaps: unencrypted apps, DNS leaks, and metadata about which sites you visit.
What to look for:
Skip the VPN for quick, casual browsing on a network you trust. Use one when you travel often, work from cafes with confidential material, or genuinely must handle something sensitive while away from home.
These take about five minutes and then work silently in the background.
On every device, keep the OS and browser updated, and protect key accounts with two-factor authentication, ideally a passkey or an authenticator app (TOTP) rather than SMS, since text codes can be intercepted. If a password ever does leak, that second factor is what stops the account takeover.
Only if you send it over an unencrypted (http) connection or into a page an attacker controls. Traffic to normal HTTPS sites and reputable apps is encrypted end to end, so a snooper on the network sees scrambled data rather than your credentials. The realistic threat is a fake page, not raw eavesdropping.
Generally yes. Cellular connections over LTE or 5G are encrypted between your phone and the carrier and are not shared with strangers in the room, so for a quick sensitive task, switching to mobile data is often simpler than trusting an open network.
Not for casual browsing. A VPN mainly helps by covering DNS leaks, poorly built apps, and hiding which sites you visit, which matters most for frequent travelers and confidential work. For checking the news or maps, it is optional.
They are fine for ordinary browsing as long as you confirm the official network name and stay on HTTPS. Treat their captive portals with suspicion, never enter real account passwords there, and save banking or large purchases for a trusted network or your mobile data.
Keep reading
A crowded inbox drains attention all day. Here is a calm, repeatable system to clear the backlog and keep your email tidy without living inside it.
Forgotten subscriptions quietly drain money every month. Here is a calm, practical way to find every one of them, cancel cleanly, and keep the list short.