Public Wi-Fi: What’s Actually At Risk
The scary version of this advice is fifteen years out of date. Here is what someone on the café network can genuinely do to you in 2026 — and the two things that still go badly wrong, neither of which encryption can save you from.
“Never use public Wi-Fi” is advice from a different internet, and it gets repeated with a confidence that is now roughly fifteen years out of date.
It comes from an era when most of the web was unencrypted and your login session travelled across the café in plain view. In 2010 someone released a browser add-on called Firesheep that made hijacking the logged-in Facebook session of anyone in the room a two-click operation. Not a skilled attack. A toy. It was built specifically to embarrass the industry into fixing things, and — credit where it’s due — it worked.
That era is over. Essentially all meaningful web traffic is encrypted by default, browsers make a scene about plain HTTP, and apps often refuse to talk to anything but their own known server. The single attack that made public Wi-Fi genuinely frightening has been engineered out of existence.
Which does not mean the risk is zero. It means it moved, and almost nobody updated the advice to match. Let’s fix that.
What someone on your network can actually do
Step 1 of 5
They join the same network as you
No skill involved. The password is chalked on a board next to the cake stand, or there is no password at all. Everyone in the room is on one shared segment, and on plenty of consumer access points every device can talk directly to every other device.
Step 2 of 5
They wedge themselves in the middle
Two cheap tricks. One: quietly tell your laptop that they are the router. Two — even lazier — broadcast a network with the same name and a stronger signal, and let your phone walk over on its own. Your phone remembers network names, not hardware, which is a design decision worth thinking about.
Step 3 of 5
They watch the envelopes go past
Everything you send now flows through their machine. The contents stay sealed — but the addresses do not. Which bank. Which messaging app. Which employer’s VPN. Which dating site, at 11pm, for forty minutes. They cannot read the letters. They can absolutely read the postmarks.
Step 4 of 5
So they try to get you to open the envelope yourself
They cannot break the encryption, so the goal becomes stopping it from happening. A sign-in page that never quite finishes loading. A "certificate problem — tap to continue anyway" that you have been trained by years of minor glitches to accept without reading.
Step 5 of 5
Or they skip the technology entirely
The most reliable attack on public Wi-Fi involves no hacking at all: a fake "sign in to get online" page asking for your email password, or somebody reading your screen from the next table while you complain about your manager. Both work perfectly regardless of how good the encryption is.
What they can’t get (and it’s a lot)
Let’s be specific about what encryption buys you, because it’s genuinely most of the battle:
The contents of everything. Your emails, messages, passwords, documents, card numbers. Someone watching the network sees an unreadable stream of noise. Not “hard to read”. Noise.
Your logged-in session. The Firesheep attack simply does not function against an HTTPS site. The cookie that keeps you signed in isn’t visible on the wire.
Anything in an app that pins its certificate. Your banking app doesn’t just check the certificate is valid — it checks it’s the specific one it expects. Interception doesn’t produce a warning there; it produces an app that flatly refuses to work.
What they can still get
Where you go. The hostname of most sites is still visible while the connection is being set up, and DNS lookups are frequently unencrypted. So they learn: this person banks with X, uses messaging app Y, connects to employer Z’s VPN. That’s a profile. Depending on who you are, that profile is the whole risk — a journalist, an activist, or someone leaving an abusive relationship may care far more about “who I talk to” than “what I said”.
Traffic patterns. When you’re active, how much you move, how long you stay. Enough to infer a video call, a big upload, your working hours.
Anything genuinely unencrypted. Increasingly rare on the web. Considerably less rare in older desktop software, smart devices, and internal company tools that were never designed to leave the office.
Whatever you hand over yourself. Which brings us to the important part.
The two things that actually go wrong
Nearly every real compromise on public Wi-Fi comes down to one of these two. Note that encryption doesn’t help with either, because in both cases you are the one opening the door.
1. The fake sign-in page
You connect. A page pops up. It asks you to sign in with your email, or your Google account, or “your room number and surname” to get online.
Here is the rule, and it is absolute:
A real captive portal never needs your email password. Ever. Not once. Not for any reason.
A legitimate one might want a room number, a voucher code, or a tick-box saying you won’t torrent anything. If a network’s sign-in page asks for credentials to a service that is not the network — Google, Microsoft, Facebook, your work account — it is harvesting them, and you have just typed your password into a laptop in a rucksack.
This works brilliantly in airports and hotels, because in those places you’re tired, you’re in a hurry, and you half-expect a faff.
2. Clicking through a certificate warning
When your browser says the certificate is invalid, that is not bureaucratic throat-clearing. That is the exact alarm that fires when someone is trying to sit in the middle of your connection. It is the system working perfectly, and it has one job.
On your home network it’s usually a misconfigured server. On public Wi-Fi you should treat it as an attack in progress until proven otherwise.
Never tap through it in a café. Not to check one email. Not because it did the same thing yesterday. If a site throws a certificate warning on a public network, close it and use mobile data.
What to actually do
Turn off auto-connect, and forget networks you’ve left. This is the easiest
win available and virtually nobody does it. Your phone will cheerfully rejoin
anything called Free_Airport_WiFi for the rest of its natural life — including
a laptop in a bag on a train that happens to be broadcasting that name. Settings
→ Wi-Fi → tap the network → Forget. Takes ten seconds.
Use your phone’s hotspot for anything that matters. Mobile data is encrypted to the carrier and has no strangers sharing the segment. For banking, work systems, or anything you’d rather not have profiled, tethering is simpler and stronger than any of the alternatives — and it removes the decision entirely, which is worth more than it sounds.
Understand what a VPN actually does here, because the marketing is enthusiastic and largely nonsense. A VPN does not add encryption you were otherwise missing — HTTPS already gave you that. What it does is move the person who can see your metadata, from “whoever is in this café” to “whoever runs the VPN”. On a hostile network that’s a real improvement. But it’s a transfer of trust, not a magic shield, and a free VPN funded by nothing in particular is a worse custodian than the café. Use a reputable paid one or your employer’s, or don’t bother.
Keep HTTPS-only mode on, so any attempt to downgrade you to plain HTTP becomes a visible refusal rather than a silent success.
Watch the room, not just the network. Shoulder-surfing is real and undefeated. So is walking off with a laptop that someone left to go and collect their flat white. The most effective attack in the café may involve no packets at all.
The one thing to take away
The modern risk of public Wi-Fi isn’t that someone plucks your password out of the air. Encryption fixed that, quietly, years ago.
The modern risk is that someone gets you to hand it over — through a fake sign-in page, or a certificate warning you waved past on autopilot — and that everything you do is visible as a pattern even when the contents aren’t.
So: forget networks when you leave, never type a password into a captive portal, and never click through a certificate error on a network you don’t control.
And if what you’re about to do genuinely matters, just use your own mobile data and stop thinking about it. The best security decision is usually the one you only have to make once.