All articles

Practical privacy

Public Wi-Fi Is Usually Safer Than It Used to Be—Still Check the Connection

By Joseph Sides · September 12, 2026

A measured guide to HTTPS, hotspot names, device settings, VPN choices, and the privacy checks that matter on a shared network.

An unbranded laptop and phone beneath translucent network rings on a burgundy café table.
Original AI-generated editorial illustration.

Public Wi-Fi advice often sounds as if connecting at an airport or café immediately exposes every password on a device. That picture is outdated. Encryption is now built into most ordinary web connections, so using a public network is generally safer than it was in the early internet. The more useful question is not whether every hotspot is dangerous, but what the network can still reveal, whether the destination is genuine, and what choices reduce avoidable risk.

HTTPS changed the baseline

The Federal Trade Commission’s current public Wi-Fi guidance explains that widespread website encryption makes connecting through a public hotspot usually safe. In a browser, “https” and the connection indicator show that data moving between the browser and that website is encrypted. Someone operating or observing the local network should not be able to read that encrypted page content as if it were plain text.

That protection has limits. HTTPS secures the connection to a destination; it does not prove that the destination deserves your trust. The FTC notes that a fraudulent website can also use encryption. A convincing imitation may protect the transmission while still delivering the information directly to a scammer. Check the full domain name, use saved bookmarks for sensitive accounts, and treat unexpected sign-in links as a phishing question rather than a Wi-Fi question.

Confirm which network you joined

A familiar-looking network name is not proof that it belongs to the hotel, café, conference, or airport around you. If several similar names appear, ask staff for the exact network name and normal sign-in process. Avoid joining a network simply because its name includes words such as “guest” or “free.” A password supplied by the venue may restrict access, but it does not turn every other person on that shared network into a trusted participant.

Disable automatic connection to open or previously used networks when the feature is not needed. After leaving, forget the hotspot if you have no reason to reconnect. The National Security Agency’s public wireless guidance, written for government and defense users but shared broadly, recommends turning off Wi-Fi, Bluetooth, and near-field communication when they are not in use. That is especially sensible for higher-risk work, although ordinary users can apply the simpler principle: do not leave radios and sharing features available by default when you are finished with them.

Harden the device, not only the connection

Use the device’s “public network” setting when one is offered. Turn off local file sharing, nearby discovery, and printer sharing unless you intentionally need them. Keep the operating system, browser, and security software current; the FTC recommends automatic updates as part of protecting personal information regardless of how a person connects. A hotspot is only one layer. An outdated device, reused password, deceptive prompt, or unattended unlocked screen can matter more than the network itself.

Use multi-factor authentication on important accounts, and pause if an unexpected approval request appears. A connection can be technically encrypted while a person is socially engineered into approving access. For sensitive work, follow the employer’s rules about approved devices, hotspots, and remote-access tools. Personal judgment should not override an organization’s security policy.

A VPN is a tool, not a trust eraser

A reputable virtual private network can encrypt traffic between the device and the VPN provider, which can reduce what the local hotspot can observe and may be required for work. The NSA recommends a personal or organization-provided VPN when its higher-risk audience must use public Wi-Fi. But a VPN shifts part of the trust relationship to the VPN service; it does not make a fraudulent website legitimate, fix a compromised device, or prevent a person from voluntarily disclosing information.

If you choose a consumer VPN, investigate it before installing it. The FTC’s VPN guidance recommends reviewing permissions, confirming that the product encrypts information, and checking whether it shares information with third parties. Avoid treating a dramatic privacy claim or a free download as evidence of good practices.

Match the connection to the task

For routine browsing over verified HTTPS, a legitimate public network may be a reasonable choice. For financial transactions, confidential client work, health information, account recovery, or other high-consequence activity, waiting for a trusted connection or using cellular data or a personal hotspot can reduce uncertainty. The right decision depends on the sensitivity of the task, the device, and the alternatives available.

A calm checklist is more useful than panic: verify the hotspot, inspect the destination, keep software current, limit sharing, use stronger authentication, and disconnect when finished. Public Wi-Fi is not automatically private or automatically catastrophic. It is a shared connection that deserves proportionate attention.

General educational information, not legal or security advice. Sources checked September 12, 2026.