What Are the Real Risks of Public Wi-Fi?

Short answer

Public Wi-Fi is neither as simple a danger as it was in the early web nor free of risk. Most legitimate websites and apps now use HTTPS encryption, so a nearby person generally cannot read page contents and passwords as easily as was once possible. More realistic risks include joining a lookalike hotspot, entering credentials into a false captive portal, ignoring certificate warnings, leaving file sharing enabled, using unpatched software, and conducting a high-consequence task over a network you do not control. Risk comes from the combination of device, connection, destination and action, not from the word “free”.

HTTPS changed the structure of the risk

Early web traffic often used unencrypted HTTP, allowing someone on the same network to observe or alter data directly. HTTPS now encrypts content between the device and website and authenticates the domain through certificates. Even if the café's wireless link is open, correctly operating HTTPS protects page contents, passwords and form data against ordinary local eavesdropping.

The US Federal Trade Commission's updated consumer guidance says that public Wi-Fi is usually safe because encryption is now widespread. It still recommends checking for HTTPS or the lock indicator and keeping systems and browsers current. FTC: Are Public Wi-Fi Networks Safe?

This makes the claim that every public hotspot can simply steal every password an outdated simplification. HTTPS protects the channel to a destination; it does not prove that the destination is honest or stop a person from voluntarily giving a password to an impostor. The practical threat has shifted away from routine plaintext interception towards identity deception, endpoint weakness and poor decisions.

A false hotspot deserves more attention than an open one

Wi-Fi names are not unique identities. An attacker can create “Airport_Free_WiFi”, “Hotel Guest”, or a name differing from the café's network by one character. After a connection, the hotspot may display a false portal asking for email, social credentials, card details or “verification”. It may encourage installation of a certificate, profile or application.

The Australian Cyber Security Centre advises confirming the official name from staff or signage, disabling automatic connection, and forgetting the network afterwards. If uncertain, use a trusted home, office or mobile connection. Cyber.gov.au: Connecting to public Wi-Fi and hotspots

A publicly displayed Wi-Fi password does not establish trust. Every hotel guest may share it, and a false access point can imitate the login. A password may protect part of the wireless link to the access point, but it does not authenticate the operator or every subsequent path.

Captive portals create a confusing transition

Airports, hotels and cafés often use a captive portal to show terms, request a room number or grant access. Before normal internet use, the device may make an unencrypted request and be redirected. A legitimate portal is not inherently malicious, but it teaches users to accept that “Wi-Fi sends me to a different page”, creating an opportunity for imitation.

If a portal requests an email address, consider whether the venue genuinely needs it. If it asks for the password to your main mailbox, banking information, installation of a root certificate, an unknown configuration profile or disabled security controls, stop. A network operator rarely needs the password to an unrelated email account. Do not bypass a browser certificate error merely because the connection belongs to a hotel.

Exposure of the device on a shared network

A computer may classify a new network as private or home and enable file sharing, printing, discovery or remote services. On public Wi-Fi, select the public-network profile, disable unnecessary sharing and open receiving, enable the firewall, and install security updates. Cyber.gov.au likewise recommends disabling file sharing on public hotspots.

Not every exposure travels through network packets. A crowded terminal creates shoulder-surfing, theft, notification and unattended-session risks. Someone can read client data over your shoulder even when HTTPS is flawless. Network protection cannot substitute for physical and screen privacy.

A VPN is useful, not proof of trust

A VPN creates an encrypted tunnel between the device and a VPN server. It can reduce what the local hotspot and network operator observe and changes the exit IP address visible to websites. It is useful for frequent public-network use, controlled remote access to an organisation, or a threat model involving local monitoring.

It also transfers some trust to the VPN provider. The operator may observe connection metadata, its application requires updates, and a poor or malicious free service may collect information. A VPN does not recognise a fake bank, stop a user typing into a phishing page, repair an infected device or make an identified login anonymous. Select one by examining the operator, privacy policy, credible independent assessment, maintenance history and business model.

My assessment: reduce the trust level rather than imposing a universal ban

A network is one layer in a transaction. Secure use also depends on the correct domain, valid certificate, updated endpoint, trustworthy application, account protection and human judgement. Calling every public hotspot categorically unsafe can mislead in two directions: people may experience unnecessary fear, or assume that changing to mobile data makes phishing and weak credentials disappear.

A better rule is to lower the trust level. Reading ordinary pages, maps and low-sensitivity information is usually lower risk on an updated device using HTTPS. A bank transfer, identity-document upload, change to main-email security, enterprise administration or client-confidential task should wait for a mobile hotspot or trusted network where practical. The greater the consequence, the less one should depend on a single control.

Before, during and after connection

Before joining, confirm the network name with staff, disable automatic joining, and prefer personal mobile data where convenient. During use, inspect addresses and certificate warnings, refuse unknown profiles, and do not enter a primary account password into an unusual portal. Use multifactor authentication and keep the operating system, browser and apps updated.

After leaving, forget the network so that the device does not later join an attacker using the same name. If credentials were entered into a suspicious portal, use a trusted connection to replace that password and every reused version, review account activity and revoke unfamiliar sessions.

One-minute checklist

  • Was the hotspot name confirmed by staff or official signage?
  • Is automatic joining disabled and the network classified as public?
  • Does the browser show the correct domain and HTTPS without a certificate warning?
  • Is the portal requesting an unreasonable password, payment or installation?
  • Are file sharing, discovery and open receiving disabled?
  • Is the task sensitive enough to justify a mobile hotspot instead?
  • Are the system, browser, apps and VPN current?
  • Will I forget the network and review suspicious account activity afterwards?

Conclusion

Modern public-Wi-Fi risk should not be described through the decade-old assumption that all web traffic is plaintext. Nor should widespread HTTPS cause complacency. Treat a hotspot as a lower-trust network: authenticate its name, rely on correct HTTPS rather than emotional reassurance from a lock icon, protect the device, postpone high-consequence tasks, and use mobile data or a reputable VPN where the threat warrants it. Security comes from layered judgement, not from one network label.

Related reading

Continue reading: All articles in How Digital Life Actually Works


Discover more from Geoffrey Chen

Subscribe to get the latest posts sent to your email.