By Eric L.
09/08/2026 · 7 MIN READ

Public Wi-Fi is safe enough for reading the news and dangerous enough that you shouldn't log into your bank on it without precautions.

The reason for both halves: HTTPS now encrypts the content of nearly every site, so the person at the next table can't read your messages or steal your password; but the network still sees which sites you visit, your device still announces itself, and a fake hotspot with the coffee shop's name takes minutes to set up. What follows is what is actually visible, the four real risks, and six rules that take care of most of it.

ON PUBLIC WI-FI THE NETWORK SEESFIG. 01
which sites you open    ✓
when and how long       ✓
page contents           ✗
your messages           ✗
    └─ a VPN removes the first line
WHAT THE NETWORK OWNER SEESFIG. 02
which sites you open  yes
timing and volume     yes
your device name      yes
page contents         no
your passwords        no
None of this needs special software: a normal router logs it by default.

What public Wi-Fi can see

Everyone on the same network shares the same path to the router, and the network's owner sees everything that passes through it. Visible:

  • Which domains you connect to. DNS queries and the server name in the TLS handshake (SNI) are usually sent in plain text.
  • When and how much. Timing and volume of every connection. A video call looks different from email.
  • Your device: its name, manufacturer, and the background requests apps make.
  • Anything unencrypted: old apps, some smart devices, and the occasional site still on plain HTTP.

Not visible, on HTTPS sites: page content, forms, passwords, messages. This part works, and it's why public Wi-Fi is no longer the disaster it was ten years ago.

WHAT A FAKE HOTSPOT LOOKS LIKEFIG. 03
real   Cafe_Guest   password on till
fake   Cafe_Guest   no password
           └─ same name, stronger
              signal, easier to join
the phone picks whichever is easier

Does HTTPS make public Wi-Fi safe?

Mostly, with three gaps. DNS: the "where is this site" question is usually unencrypted, so the network keeps a list of everywhere you went, and a malicious network can answer with the wrong address. The captive portal: the "accept terms" page you see on connecting sometimes loads over plain HTTP, and what you type into it, phone number, email, room number, is unprotected. And apps: not every app uses HTTPS as strictly as a browser does.

WHAT HTTPS STILL LEAVES VISIBLEFIG. 04
page content          not visible
passwords, messages   not visible
which sites you open  visible
timing and volume     visible
The two rows that stayed visible are exactly the two a VPN encrypts next.

Public Wi-Fi dangers: the four real risks

Evil twin. Someone broadcasts a network called "Airport_Free_WiFi" from a laptop. Devices pick the strongest signal, you join, and your traffic passes through their machine. HTTPS still protects content, but DNS and the captive portal are theirs.

Auto-join. Your phone remembers network names and reconnects to any network with the same name, no questions asked. This is what the evil twin relies on.

HOW AN EVIL TWIN GETS YOUYour phoneauto-join is onjoins, no questionsTheir laptopnamed Airport_Free_WiFiThe siteWHAT PASSES THROUGH THEIR MACHINEDNS answerstheirsThe captive portaltheirsHTTPS contentstill sealed
Auto-join puts you on the twin: your DNS and the portal become theirs, while HTTPS content stays sealed.

Open sharing. File sharing, AirDrop set to Everyone, printer sharing, a media server: all of it stays on when you join a stranger's network, and anyone on that network can see your device and try.

Portal forms. Hotels ask for a last name and room number, airports for a phone number. Where that data goes and how long it's kept is rarely stated.

WHAT A TUNNEL SOLVES HEREFIG. 05
eavesdropping on the network     solved
a fake hotspot                   solved
DNS substitution by the network  solved
phishing on the sign-in page     no
malware you download             no
The two rows marked no are still up to you: no tunnel can fix a click.

Six rules for using public Wi-Fi safely

  1. Ask which network is real. One question to staff removes most evil twins. At airports, use the name on official signage.
  2. Turn off auto-join. On iPhone, tap the (i) next to the network and disable Auto-Join; on Android, open the network details and disable auto-connect.
  3. Clear the captive portal, then start working. Never enter card details or account passwords into a portal page. No coffee shop needs them.
  4. Turn off sharing. Set AirDrop to Contacts Only, mark the network as Public on Windows, disable file and printer sharing.
  5. Use mobile data for anything sensitive. The carrier link is encrypted and other subscribers can't see your traffic. Banking on mobile data, videos on Wi-Fi.
  6. Turn on the VPN before you do anything else. Why is the next section.

After connecting, the Privacy Checker shows what your device reveals to websites on its own, and What Is My IP shows the address you're currently using.

SIX RULES BEFORE YOU CONNECTFIG. 06
[ ] ask staff for the exact name
[ ] turn off auto-join
[ ] connect the tunnel first
[ ] type nothing extra on sign-in
[ ] forget the network afterwards
[ ] banking on mobile data only
Skip the third box and the other five stop mattering, since they all assume the tunnel is already up.

If a network already made you uneasy, the order of actions matters more than panic.

Prompt for an AI
Help me work out what I risked on an untrusted
network.

Where: (café / hotel / airport / coworking).
Network: (open / password / sign-in page).
What I did: (list it: checked mail, logged into
a bank, just read news).
Tunnel was on: (yes / no / cannot remember).
Was I asked to install a certificate or profile:
(yes / no).

Say what here is genuinely risky and what is not,
and what to do now, in order.
If the risk is minimal, say so plainly instead of
alarming me.

Is public Wi-Fi safe with a VPN?

With the VPN on, everything your device sends, including DNS, goes through an encrypted tunnel to the VPN server. The coffee shop's router and the person running an evil twin see one encrypted connection to one address: no domain list, no DNS, no app traffic. That closes every gap HTTPS leaves.

What it doesn't do: protect what you typed into the captive portal (that happens before the tunnel), close the sharing services on your device, or cover the seconds when the tunnel drops. For the last one, the VPN's kill switch must be on; it blocks traffic until the tunnel is back rather than letting it fall to the open network. What the network sees with and without a tunnel is laid out in what can my ISP see, and the same logic applies to a coffee shop.

WITH THE VPN ON, MOMENT BY MOMENT1. Join Wi-Fino tunnel yet2. Captive portaltyped before the tunnel3. Tunnel upDNS included4. Tunnel dropsfor a few secondsKill switch onblocks until it is backKill switch offfalls to the open networkSharing services stay onthe tunnel does not close them: turn them off yourselfThe router and an evil twin see one encryptedconnection to one address while the tunnel is up.
The portal comes before the tunnel and sharing stays on, so those two are still yours to handle.

In short: on public Wi-Fi, HTTPS protects the content and a VPN protects everything else, which is where you went and when. Together they make a hotel or airport network about as private as your own.

404 VPN runs VLESS in its apps and gives WireGuard configs for Istanbul and Marseille from the dashboard; either way DNS stays inside the tunnel, and the Android app's kill switch blocks traffic during reconnects. Details on the security page; set it up before your next trip.