Privacy & Security 8 min readBy Mehadi ShawonPublished Updated

Public WiFi Myths: What Actually Puts You at Risk (and What Doesn't)

Is public WiFi dangerous in 2026? Most public wifi safety myths are outdated. Here is what really puts you at risk on an open network, and what does not.

Cafe WiFi symbol split between a glowing red risk zone and a blue protected zone, representing public WiFi myths versus real risk
Quick answer

Public WiFi Myths: What Actually Puts You at Risk (and What Doesn't)

Public WiFi is far less dangerous than it was a decade ago, because nearly all web traffic is now encrypted with HTTPS end to end. The real remaining risks are fake 'evil twin' hotspots and the sites you visit, not passive eavesdropping. The Australian Federal Police charged a man in June 2024 over evil-twin WiFi networks at airports and on flights.

Is public WiFi dangerous? Much less than the warnings suggest. The scenario most people picture — a stranger in the corner quietly reading your banking session — has been largely closed off by the shift to HTTPS on essentially every site that matters.

That does not make coffee-shop WiFi risk-free. It means the risks moved. Sorting the outdated myths from the live problems is the difference between useful caution and pointless anxiety.

Myth: anyone on the network can read what you are doing

This was substantially true in the era of unencrypted HTTP, when session cookies travelled in the clear and tools existed purely to harvest them from shared networks. It is no longer the normal case.

Traffic to an HTTPS site is encrypted between your browser and the server. Google's Transparency Report tracks HTTPS adoption across Chrome platforms and shows the overwhelming majority of page loads are now encrypted; browsers actively warn on the exceptions. Someone capturing packets on the same WiFi sees ciphertext.

What they do still see is metadata: the domain names you resolve and connect to, roughly when, and how much data moved. That is meaningful privacy leakage — it is just not the same as reading your messages. If you are curious what a network can already infer about you, our post on browser fingerprinting covers the tracking that happens regardless of the connection.

Two overlapping wireless access point icons on a dark grid, one genuine and one cloned, illustrating an evil twin hotspot on public WiFi

Fact: fake hotspots are the real attack

The credible threat is that the network itself is the attacker. An 'evil twin' is a hotspot broadcasting a familiar-looking name — the airport's, the airline's, the hotel's — so devices and people connect to it by habit.

This is not theoretical. In a media release dated 28 June 2024, the Australian Federal Police announced charges against a Perth man accused of setting up evil-twin free WiFi access points on domestic flights and at Perth, Melbourne and Adelaide airports to capture personal credentials.

Once you are on an attacker-run network they control the captive portal and DNS resolution. They cannot break HTTPS, but they can present a convincing sign-in page asking for an email password, or push a fake 'certificate update' or app installer. Every successful version of this attack ends with the victim typing or installing something voluntarily.

Myth: a VPN makes public WiFi safe

A VPN does one clear job well: it encrypts everything between your device and the VPN server, so the local network sees only an encrypted tunnel rather than your list of destinations. On a network you do not trust, that is genuinely worth having.

What it does not do is make a malicious website harmless, stop you entering credentials on a fake portal, or protect you from software you chose to install. It moves the point of trust from the café to your VPN provider — which is exactly why provider choice matters, as we set out in what a VPN actually is and whether you need one and the more specific best VPNs for public WiFi in 2026.

Nor does a VPN hide you from the sites themselves. If you want to see what your connection currently reveals, check the IP lookup tool with and without your VPN running.

What actually deserves your caution

  • Captive portals asking for account passwords. A guest network needs a room number or an email address, never your webmail password.
  • Any prompt to install software, a profile, or a certificate in order to browse. Refuse and leave.
  • Networks with names that are almost right — an extra word, a hyphen, a missing letter. Confirm the exact name with staff.
  • Auto-join on your device, which will silently reconnect to a name you used once. Turn it off for public networks and forget them afterwards.
  • File sharing and network discovery left enabled from your home setup.
  • Sites where the browser warns the connection is not private. On a shared network, treat that warning as final.

A practical routine for untrusted networks

  1. Disable auto-join for public networks and forget them after use.
  2. Turn on your operating system's firewall and mark the network as public, not private.
  3. Prefer mobile tethering for banking and anything involving payment details.
  4. Run a VPN if you do not want the operator profiling your destinations.
  5. Keep the browser and operating system patched, since browser warnings are doing most of the defensive work.
  6. Never install anything a network asks you to install.

Two adjacent fears are worth separating out. Charging your phone at a public USB port is a different mechanism entirely, and the evidence for it is weaker than the headlines imply — we go through it in what juice jacking is and whether to worry.

And private browsing mode does nothing for network-level privacy, whatever hotel WiFi advice suggests. Our breakdown of what incognito mode actually hides explains why local history and network visibility are separate things.

Public WiFi in 2026 is broadly usable. Watch which network you join, refuse anything it asks you to install or sign into, and reserve your real caution for the fake hotspot rather than the imaginary eavesdropper.

A realistic risk ranking for a coffee-shop session

Not all public-network risks are equal, and treating them as one undifferentiated threat leads to the wrong precautions. Ordered by how likely they are to affect an ordinary visitor:

  1. Being tricked by a captive portal or fake login page — high likelihood, and it depends on you typing something rather than on any interception.
  2. Connecting to a rogue access point with a plausible name, which is the technique behind the Australian Federal Police case.
  3. Traffic analysis: whoever runs the network sees which domains you connect to even when the content is encrypted.
  4. Attacks on an unpatched device from another machine on the same network — low, but the reason updates matter.
  5. Reading the contents of an encrypted session — very low against a properly configured modern site.

Notice that the top two require your participation, which is why habit changes outperform tooling here.

What is worth doing, in order of effect

  • Keep the device and browser updated, which closes the only realistic path to a silent compromise.
  • Turn off automatic connection to open networks so your phone stops rejoining anything with a familiar name.
  • Treat any captive portal that asks for an account password or payment details as fake and leave.
  • Use mobile data or a personal hotspot for banking if you have signal to spare.
  • Use a reputable VPN when you want to hide destinations from the network operator, and understand it shifts trust to the provider rather than removing it.

Frequently Asked Questions

Is public WiFi dangerous in 2026?+

Far less than it used to be. Because nearly all web traffic is encrypted with HTTPS, someone on the same network cannot read the contents of your sessions. The remaining risks are fake hotspots, malicious captive portals and software you are persuaded to install.

Can someone see my passwords on public WiFi?+

Not from passive monitoring of an HTTPS connection. They can obtain a password if you type it into a fake sign-in portal they control, which is how evil-twin hotspot attacks actually succeed.

What is an evil twin WiFi network?+

It is a hotspot deliberately named to look like a legitimate one, such as an airport or hotel network, so people connect out of habit. The Australian Federal Police charged a man in June 2024 over evil-twin networks set up at airports and on flights.

Do I need a VPN on public WiFi?+

A VPN is useful because it hides which sites you visit from the network operator, but it does not make a malicious site safe or stop you entering details on a fake portal. It shifts trust from the venue to your VPN provider.

Is it safe to do online banking on public WiFi?+

It is usually safe over HTTPS in the bank's own app, but mobile data or tethering removes the uncertainty entirely. If you do use public WiFi, never sign in through a link from a captive portal and never install anything the network requests.

Ad Space

Try the related free tools

Hands-on utilities from DigiMetrics Hub that go with this guide.

All tools