Public Wi-Fi is safe enough for reading the news and dangerous enough that you shouldn't log into your bank on it without precautions.
The reason for both halves: HTTPS now encrypts the content of nearly every site, so the person at the next table can't read your messages or steal your password; but the network still sees which sites you visit, your device still announces itself, and a fake hotspot with the coffee shop's name takes minutes to set up. What follows is what is actually visible, the four real risks, and six rules that take care of most of it.
which sites you open ✓
when and how long ✓
page contents ✗
your messages ✗
└─ a VPN removes the first linewhich sites you open yes timing and volume yes your device name yes page contents no your passwords no
What public Wi-Fi can see
Everyone on the same network shares the same path to the router, and the network's owner sees everything that passes through it. Visible:
- Which domains you connect to. DNS queries and the server name in the TLS handshake (SNI) are usually sent in plain text.
- When and how much. Timing and volume of every connection. A video call looks different from email.
- Your device: its name, manufacturer, and the background requests apps make.
- Anything unencrypted: old apps, some smart devices, and the occasional site still on plain HTTP.
Not visible, on HTTPS sites: page content, forms, passwords, messages. This part works, and it's why public Wi-Fi is no longer the disaster it was ten years ago.
real Cafe_Guest password on till
fake Cafe_Guest no password
└─ same name, stronger
signal, easier to join
the phone picks whichever is easierDoes HTTPS make public Wi-Fi safe?
Mostly, with three gaps. DNS: the "where is this site" question is usually unencrypted, so the network keeps a list of everywhere you went, and a malicious network can answer with the wrong address. The captive portal: the "accept terms" page you see on connecting sometimes loads over plain HTTP, and what you type into it, phone number, email, room number, is unprotected. And apps: not every app uses HTTPS as strictly as a browser does.
page content not visible passwords, messages not visible which sites you open visible timing and volume visible
Public Wi-Fi dangers: the four real risks
Evil twin. Someone broadcasts a network called "Airport_Free_WiFi" from a laptop. Devices pick the strongest signal, you join, and your traffic passes through their machine. HTTPS still protects content, but DNS and the captive portal are theirs.
Auto-join. Your phone remembers network names and reconnects to any network with the same name, no questions asked. This is what the evil twin relies on.
Open sharing. File sharing, AirDrop set to Everyone, printer sharing, a media server: all of it stays on when you join a stranger's network, and anyone on that network can see your device and try.
Portal forms. Hotels ask for a last name and room number, airports for a phone number. Where that data goes and how long it's kept is rarely stated.
eavesdropping on the network solved a fake hotspot solved DNS substitution by the network solved phishing on the sign-in page no malware you download no
Six rules for using public Wi-Fi safely
- Ask which network is real. One question to staff removes most evil twins. At airports, use the name on official signage.
- Turn off auto-join. On iPhone, tap the (i) next to the network and disable Auto-Join; on Android, open the network details and disable auto-connect.
- Clear the captive portal, then start working. Never enter card details or account passwords into a portal page. No coffee shop needs them.
- Turn off sharing. Set AirDrop to Contacts Only, mark the network as Public on Windows, disable file and printer sharing.
- Use mobile data for anything sensitive. The carrier link is encrypted and other subscribers can't see your traffic. Banking on mobile data, videos on Wi-Fi.
- Turn on the VPN before you do anything else. Why is the next section.
After connecting, the Privacy Checker shows what your device reveals to websites on its own, and What Is My IP shows the address you're currently using.
[ ] ask staff for the exact name [ ] turn off auto-join [ ] connect the tunnel first [ ] type nothing extra on sign-in [ ] forget the network afterwards [ ] banking on mobile data only
If a network already made you uneasy, the order of actions matters more than panic.
Help me work out what I risked on an untrusted
network.
Where: (café / hotel / airport / coworking).
Network: (open / password / sign-in page).
What I did: (list it: checked mail, logged into
a bank, just read news).
Tunnel was on: (yes / no / cannot remember).
Was I asked to install a certificate or profile:
(yes / no).
Say what here is genuinely risky and what is not,
and what to do now, in order.
If the risk is minimal, say so plainly instead of
alarming me.
Is public Wi-Fi safe with a VPN?
With the VPN on, everything your device sends, including DNS, goes through an encrypted tunnel to the VPN server. The coffee shop's router and the person running an evil twin see one encrypted connection to one address: no domain list, no DNS, no app traffic. That closes every gap HTTPS leaves.
What it doesn't do: protect what you typed into the captive portal (that happens before the tunnel), close the sharing services on your device, or cover the seconds when the tunnel drops. For the last one, the VPN's kill switch must be on; it blocks traffic until the tunnel is back rather than letting it fall to the open network. What the network sees with and without a tunnel is laid out in what can my ISP see, and the same logic applies to a coffee shop.
In short: on public Wi-Fi, HTTPS protects the content and a VPN protects everything else, which is where you went and when. Together they make a hotel or airport network about as private as your own.
404 VPN runs VLESS in its apps and gives WireGuard configs for Istanbul and Marseille from the dashboard; either way DNS stays inside the tunnel, and the Android app's kill switch blocks traffic during reconnects. Details on the security page; set it up before your next trip.