Reviewed by the Foxmole editorial team · 2026-07-29
Key takeaways
- HTTPS has made open Wi-Fi far less risky than it used to be.
- Confirm the network name and turn off auto-join.
- A VPN is a nice-to-have, not a must, for everyday browsing.
Public Wi-Fi has a scary reputation, but the real risks have shifted. Because most sites now use HTTPS encryption, the classic “someone reading your traffic at the café” attack is far less effective than it used to be. That doesn’t mean open networks are risk-free, it means knowing where the real risks are.
The genuine risks
- Fake hotspots. An attacker sets up a network named like the venue’s (“Airport_Free_WiFi”) to get you to connect through them. Confirm the exact network name with staff.
- Sites without HTTPS. On the rare page still served over plain HTTP, data can be read on a shared network. Modern browsers warn you, heed the “Not secure” label.
- Auto-connect. Your device silently rejoining open networks you don’t control.
Simple habits that cover most of it
- Stick to HTTPS sites (the default now) and don’t dismiss “Not secure” warnings.
- Turn off auto-join for open networks.
- Save sensitive logins (banking) for a network you trust, or use mobile data.
- Keep your device and browser updated, patched software resists most opportunistic attacks.
Do you need a VPN on public Wi-Fi?
A reputable VPN encrypts all your traffic, which adds protection on untrusted networks and hides which sites you visit from the network operator. It’s a reasonable extra layer if you use open Wi-Fi often, but it’s not the necessity it once was for basic browsing, thanks to HTTPS. Choose a provider you trust, since a VPN can see your traffic itself.
The short version
Confirm the network is real, keep HTTPS on and software updated, don’t auto-join, and save the most sensitive tasks for a network you control. A VPN is a nice-to-have, not a must, for most everyday use.