Public Wi-Fi risk today is more nuanced than the old warnings suggest
Older security advice painted every coffee-shop network as an active hacker trap. Modern websites and apps almost universally encrypt traffic with HTTPS by default, which closes off much of the classic 'someone reading your traffic on the same network' attack. That does not mean public Wi-Fi is risk-free, but the specific risks worth worrying about have shifted.
What is genuinely still risky
A smaller set of real risks remain relevant even with widespread HTTPS adoption.
- Fake 'evil twin' hotspots that mimic a legitimate network name (like 'Airport_WiFi_Free') to intercept connections before HTTPS protections apply
- Networks that don't require authentication, making it easier for anyone nearby to be on the same local network as you
- Sites or apps that still don't enforce HTTPS properly, which is rare today but not impossible
- Shoulder surfing and physical device theft, an underrated risk in busy public spaces
- Auto-connect settings that silently join your device to previously used or spoofed network names
What matters less than people think
Some long-standing warnings are less relevant to how most people actually use public Wi-Fi today.
- Casually browsing news sites or checking non-sensitive apps over public Wi-Fi carries limited practical risk today, since the traffic is encrypted regardless of the network
- A VPN is a reasonable extra layer but is not a magic fix; it protects the connection, not you from a phishing link or a weak password
Practical habits that actually reduce risk
A short list of habits covers most of the real remaining risk without requiring constant vigilance.
- Turn off Wi-Fi auto-connect for open networks so your device does not silently join unfamiliar hotspots
- Confirm the exact network name with staff before connecting at a cafe, hotel, or airport
- Avoid entering banking credentials or sensitive logins on public Wi-Fi when a cellular connection is available instead
- Keep your device's operating system updated, since many public-network exploits target outdated software
- Use a VPN for an extra layer when accessing sensitive work systems from an untrusted network
For small business owners specifically
If staff regularly work from cafes, co-working spaces, or client sites, set a simple written expectation: sensitive systems require MFA regardless of network, and a VPN or cellular hotspot is preferred for anything involving client data or payments. This removes ambiguity without requiring a full VPN rollout.
Frequently asked questions
Is hotel Wi-Fi safer than a coffee shop's?
Not meaningfully. Both are shared, semi-open networks with unknown other users, and both carry similar evil-twin and interception risks. Treat any network you do not control the same way, regardless of the venue's reputation.
Does a password-protected public Wi-Fi network solve the risk?
It reduces the risk of a completely open network but does not eliminate evil-twin or shared-network risks, since the password is often posted publicly or shared with every customer, meaning many strangers still share the same network.
Is my phone's cellular hotspot always safer than public Wi-Fi?
Generally yes, since it is a private connection only you use, making evil-twin and shared-network risks irrelevant. It is a good default for anything sensitive when travelling or working outside the office.