Skip to content
Guide

Public Wi-Fi safety: how to stay safe on cafe, hotel and airport networks

Public Wi-Fi is far safer than it was ten years ago, mostly because nearly every site now uses HTTPS. It is not risk-free, though. This guide explains what someone on the same network can and cannot see, the tricks that still work, and the habits that keep you safe.

7 min read

What can actually go wrong

On an open network, everyone connected shares the same airwaves, and the owner of the hotspot, or anyone who set up a fake one, sits between you and the internet. That position allows a handful of attacks.

  • Fake hotspots, also called evil twins. Someone creates a network named Airport Free WiFi or copies the name of the cafe's real network. Your device may join it by itself if it has joined a network with that name before.
  • Snooping on unencrypted traffic. Anything sent without encryption, such as old apps, plain HTTP pages or some smart devices, can be read by whoever controls the hotspot.
  • DNS tampering. A malicious hotspot can answer your device's DNS lookups with addresses of its own choosing and send you to a copy of a login page.
  • Fake sign-in pages. The page a hotel or airport shows before you get online can be faked, and a fake one may ask for card details, your email password or an app install.
  • Attacks on your device. Open file sharing, unpatched software and devices that accept connections from the local network are exposed to everyone on the same Wi-Fi.
  • Tracking. Even when content is encrypted, the network sees which sites you connect to and when, and some free hotspots log it for analytics or marketing.

What HTTPS already protects, and what it does not

When your browser shows a secure connection, the content of the page, your passwords and your card numbers are encrypted between your browser and the website. A hotspot owner can neither read nor change them. This is the main reason public Wi-Fi is safer today than it used to be.

HTTPS leaves some things exposed, and a VPN does not fix everything either:

What is at stakeWithout a VPNWith a VPN
Page content, passwords and card numbers on HTTPS sitesEncrypted by HTTPSEncrypted by HTTPS, inside the encrypted tunnel
Which sites you visitUsually visible to the hotspot through DNS lookups and connection detailsHidden from the hotspot; the VPN server handles them instead
Apps and devices that do not encrypt their trafficReadable by the hotspotEncrypted inside the tunnel
Your device on the local network (sharing, open ports)Exposed to other usersStill exposed: a VPN is not a firewall for your device
A fake login page you type your password intoNot protectedNot protected

The last two rows matter. A VPN encrypts traffic leaving your device, but it does not make you immune to phishing or to attacks on a device that accepts incoming connections. You still need the habits below.

Before you connect

  1. Confirm the network name with staff or on a printed sign. Be wary of near-duplicates with an extra word such as Free or Guest, and of an open network when the real one has a password.
  2. Prefer networks with a password. With WPA3, other guests cannot decrypt your traffic even though they know the password. With older WPA2, a determined guest who knows the password can. Either way, a password stops casual snooping, but it does not stop a fake copy of the network.
  3. Turn off auto-join for public networks. Tell your phone or laptop to forget a hotspot when you leave, so it does not silently join a network with the same name somewhere else.
  4. Mark the network as public. On Windows, choose Public network when asked; it turns off network discovery and file sharing on that network. On a Mac, switch on the firewall in System Settings.
  5. Update first. Install pending system and browser updates at home. Many attacks on local networks rely on old, already fixed bugs.

Captive portals and when to switch the VPN on

Hotels, airports and trains often show a sign-in page before they let you online. This page is called a captive portal, and it clashes with VPNs: the VPN cannot connect until you have signed in, and the portal cannot load while a kill switch blocks traffic outside the tunnel.

  1. Join the Wi-Fi with the VPN off, or with the kill switch paused for a moment.
  2. Let the sign-in page appear. If it does not, open a plain site such as neverssl.com, which exists to trigger portals.
  3. Check the page before you type anything. It should ask for a room number, a voucher or an email address. It should never ask for your email password, and it should ask for a card only when you knowingly pay for access.
  4. Once you are online, switch the VPN on and turn the kill switch back on.

Some hotel, train and conference networks only let web traffic through and block the ports VPNs normally use, often by accident rather than by policy. If WireGuard will not connect after the portal, try OpenVPN over TCP port 8080, which BoltVeil calls firewall mode. If the network's terms say that VPNs are not allowed, respect them and use mobile data instead.

Where a VPN helps on public Wi-Fi

A VPN creates an encrypted tunnel from your device to a VPN server. On public Wi-Fi that has three concrete benefits: the hotspot cannot see which sites you visit, it cannot read traffic from apps that skip encryption, and it cannot tamper with your DNS lookups, because those travel through the tunnel too.

For that to work, the VPN has to be on before anything sensitive happens, and it has to stay on. Use the platform kill switch where there is one (our WireGuard setup guide shows where), and set your phone to start the VPN automatically on Wi-Fi you do not trust.

BoltVeil works with the free VPNClient app and the official WireGuard and OpenVPN apps on every major platform. Plans start at $4.99 a month on the pricing page, or you can earn premium days without paying, as explained on the free VPN page.

Habits that matter more than any tool

  • Use two-factor authentication on email, banking and social accounts. A stolen password is far less useful without the second factor.
  • Take certificate warnings seriously. If your browser warns that a connection to a well-known site is not private, stop. On public Wi-Fi that warning can mean someone is intercepting the connection.
  • Never install anything a hotspot asks for. No cafe, hotel or airport hotspot needs you to install an app, a certificate or a profile to get online.
  • Keep banking for mobile data if you are not using a VPN. Your carrier's connection is much harder to impersonate than a Wi-Fi name.
  • Log out and forget the network when you leave, especially on shared or borrowed computers.
  • Limit what you share nearby. Turn off Bluetooth when you do not need it, and on iPhone set AirDrop to Receiving Off or Contacts Only.

A quick checklist

  1. Network name confirmed with staff.
  2. Network marked as public, sharing off.
  3. Signed in to the portal, then VPN on with the kill switch.
  4. A secure connection on every page where you type something.
  5. Network forgotten when you leave.

Frequently asked questions

Is public Wi-Fi safe for online banking?

Banking sites and apps use strong encryption, so the risk is lower than it used to be. What remains is a fake login page or a fake hotspot. With a VPN on and two-factor authentication it is reasonably safe; without them, mobile data is the safer choice.

Can someone on the same Wi-Fi see my passwords?

Not on sites that use HTTPS, which is nearly all of them. They can see passwords sent to old sites or apps without encryption, and they can trick you into typing a password into a fake page. A VPN solves the first problem; checking the address bar solves the second.

Does a VPN protect me from an evil twin hotspot?

Largely, yes. With the VPN on, the fake hotspot only sees encrypted traffic to the VPN server and cannot tamper with your DNS. It can still show you a fake sign-in page before the VPN connects, so check what that page asks for.

Is hotel Wi-Fi safer than cafe Wi-Fi?

Not necessarily. Hotel networks often put many guests on one shared network behind a sign-in page that can be faked. Treat both the same way.

Should I use a VPN on my home Wi-Fi too?

It matters less at home because you control the network. People still use one there to keep their internet provider from seeing which sites they visit. Our VPN vs proxy guide explains what each tool actually hides.

Your IP, hidden in minutes.

Create your account, pick a country and connect. Pay less, or earn it free.