Why Public Wi-Fi Deserves More Caution

Most people treat public Wi-Fi the way they treat a public water fountain — available, convenient, and probably fine. In practice, the risks are more specific and more concrete than the general anxiety around them suggests. Understanding exactly what can go wrong helps you make better decisions rather than simply avoiding public networks altogether.

The core problem is that public networks are shared environments. Unlike your home router — where you control who connects — a café or airport network may have dozens or hundreds of simultaneous users, some of whom are paying attention to the traffic around them. For a deeper look at how home networks compare, see our guide on securing your home network.

Below are the specific risks most users overlook, and what you can realistically do about each one.

1

Man-in-the-Middle Attacks

A man-in-the-middle (MITM) attack occurs when someone positions themselves between your device and the network, intercepting the data passing between them. On an open or poorly secured public network, this is technically feasible with widely available software. The attacker doesn't need physical access to your device — just to be on the same network.

What's at risk: login credentials sent over unencrypted connections, session cookies that can be used to impersonate you on websites, and form data you submit. Sites using HTTPS encrypt traffic in transit, which significantly raises the bar for this attack — but not all sites or apps use it consistently for every request.

An attacker on the same network can intercept traffic without ever touching your device.

2

Rogue Hotspots (Evil Twin Networks)

This is one of the most underestimated threats. An attacker creates a Wi-Fi network with a name nearly identical to a legitimate one — "Airport_WiFi_Free" instead of "Airport Free WiFi" — and waits for devices to connect. Once connected, all your traffic flows through their equipment.

Your device has no reliable way to tell the difference. The fake network may even load websites normally by forwarding your traffic through a real connection. The attacker simply logs what passes through. This is why verifying the exact network name with a staff member before connecting matters more than it seems.

Fake networks that mimic real ones are simple to create and hard for devices to detect.

3

Auto-Connect Behavior

Most smartphones and laptops are set to automatically reconnect to networks they've joined before. This convenience feature becomes a liability when a rogue hotspot uses the same name as a network you've previously used — your device may join it without any prompt.

The fix is straightforward: disable auto-connect for public networks in your device's Wi-Fi settings. On most operating systems, you can tell your device to "forget" a public network after you leave, preventing future automatic connections. This is a low-effort habit that removes an entire class of risk.

Devices that auto-connect can silently join rogue networks using familiar names.

4

Unencrypted Traffic From Apps

Even when a website uses HTTPS, the apps on your phone don't always follow suit. Some apps — particularly older or less-maintained ones — transmit data over unencrypted connections, or use a mix of encrypted and unencrypted requests. This means that even if your browser traffic is protected, a background app could be leaking account tokens or personal data.

You generally can't audit this yourself without technical tools. The practical mitigation is to use a VPN on public networks, which encrypts all traffic leaving your device regardless of what the individual app does. This is one of the genuinely useful protections a VPN provides in this context.

Apps can leak data over unencrypted connections even when your browser is fully protected.

5

Captive Portal Risks

Captive portals are the login pages that appear when you first join a public network — the screen asking you to accept terms or enter an email address. While they're standard, they also represent a moment of reduced security. Before you authenticate, your device's connection is open, and the portal page itself may not be fully encrypted.

More importantly, captive portals can be spoofed. A rogue hotspot can serve a fake portal that mimics a real one, collecting whatever information you submit — including email addresses or, in some setups, payment details. Enter only the minimum information required, and never submit a password on a captive portal page.

Fake captive portals can harvest the information you submit before you even browse.

6

Passive Network Monitoring

Even without active interception, simply being on a public network exposes metadata. The network operator — or anyone monitoring the network — can see which domains you're connecting to, how often, and for how long, even if the content of those connections is encrypted. This is sometimes called traffic analysis.

For most casual browsing, this level of observation is low-stakes. But if you're accessing sensitive accounts, conducting business, or handling personal information, that metadata can reveal more than you'd expect. A VPN routes your traffic through an encrypted tunnel, making traffic analysis significantly harder for passive observers on the same network.

Even encrypted traffic reveals which sites you visit — metadata that can be observed passively.

What You Can Actually Do About It

None of these risks require you to swear off public Wi-Fi. They require you to be deliberate. Turning off auto-connect, using a VPN, and sticking to HTTPS sites covers the majority of everyday exposure. If you travel frequently, the stakes are higher — our article on digital security while travelling covers the additional threats you face abroad.

Three Habits That Cover Most of Your Risk

First, disable auto-connect for all public Wi-Fi networks and forget them when you leave. Second, use a reputable VPN whenever you connect to a network you don't control — it encrypts all traffic from your device, including from apps. Third, confirm the correct network name with staff before connecting, especially in airports, hotels, and transit hubs where fake hotspots are most commonly reported.

For a nuanced breakdown of what VPNs actually protect versus what they don't, see our VPN explainer. And if you're curious how public risk compares to using your home connection, this balanced breakdown puts both in perspective.

Share

Technology & Connection Editorial Team · Contributor

Technology & Connection Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.