What public Wi-Fi actually exposes, and what it does not

Most advice about hotel and airport Wi-Fi was written for an internet that no longer exists. Here is what changed, and what still deserves your caution.

eSIM Net Editorial

4 min read

A laptop open in a cafe showing the list of available wireless networks, including several open ones named after hotels and airports.

Public Wi-Fi advice has aged badly. A decade ago much of the web travelled unencrypted, and anyone sharing a café network could read a surprising amount of what you were doing. That was a genuine emergency, and it produced a generation of warnings that are still repeated.

The web changed underneath the advice. The overwhelming majority of traffic is now encrypted end to end by default, and browsers actively warn about anything that is not. Most of the old attack simply does not work any more.

That is not the same as "public Wi-Fi is safe". It means the risks moved.

What is mostly solved

Old riskStatus
Reading your passwords in transitEncrypted. Login forms are HTTPS everywhere.
Reading your email and messagesEncrypted, and messaging apps add their own layer.
Session hijacking from the next tableLargely closed by HTTPS and modern cookie handling.
Injecting content into pages you visitBlocked on encrypted connections.

The thing to check is the padlock, which your browser now shows by default and complains loudly about when it is missing.

What is still real

Networks that are not what they claim to be

Anyone can name a wireless network anything. "Airport_Free_WiFi" in an airport is trivially easy to run from a bag. Joining one does not hand over your encrypted traffic, but it does let the operator see which services you connect to, and it puts a convincing sign-in page in front of you.

Check the network name against official signage. When there are two plausible options, ask someone who works there.

Captive portals that ask for too much

A sign-in page is the one part of the experience the network operator fully controls, and some collect far more than a Wi-Fi session needs. A portal asking for your name, date of birth, passport number or card details is collecting data, not authenticating you.

Never enter payment details on a captive portal. If a network genuinely requires payment, pay through the provider's own site, not the intercept page.

Metadata

Even when content is encrypted, whoever runs the network sees which services you contacted and when. A hotel cannot read your messages; it can see that you use a particular messaging service, a particular bank, a particular dating app. In some countries that log is retained, and in a few it is accessible to more people than you would expect.

The device, not the network

File sharing left switched on, an unlocked laptop at a café table, a shoulder looking at a screen in a departure lounge. These are the ones that still work, and none of them are fixed by a VPN.

Where a VPN genuinely helps

A VPN hides your traffic metadata from the local network and moves the point of visibility to the VPN provider. That is a real benefit if you do not want a hotel or a country's public network logging which services you use — and it is a transfer of trust, not an elimination of it.

It is worth having. It is not the difference between safe and compromised that the marketing implies, because HTTPS already does the heavy lifting.

A short, honest list of habits

  1. Verify the network name against official signage before joining.
  2. Turn off automatic joining of open networks — it is how phones end up on networks nobody chose.
  3. Never enter payment or passport details on a captive portal.
  4. Turn off file sharing and set the firewall to public on a laptop.
  5. Use two-factor authentication everywhere. It is worth more than any network precaution.
  6. For anything sensitive, use your own mobile data instead.

The simplest answer

Your own connection removes the entire category. A mobile data connection is not shared with the room, has no captive portal, and does not need to be identified correctly before you trust it. That is a side benefit of a travel eSIM rather than the reason to buy one, but it is a genuine one — and it is why the useful version of "avoid public Wi-Fi" is "have an alternative".

Key takeaways

  • The classic "someone on the café Wi-Fi is reading your email" attack is largely solved by universal HTTPS.
  • What remains: fake networks, captive portals asking for too much, and the traffic metadata a network operator can still see.
  • A VPN is useful, but it is no longer the emergency it was sold as.
  • Your own mobile data sidesteps the whole category.

Get online the moment you land

Pick a destination, pay, and the eSIM arrives by email. Plans from $2.99.

Use your own connection instead

Refunds on unused eSIMs · Works on iPhone and Android

Frequently asked questions

Is public Wi-Fi safe in 2026?

Much safer than it was, because almost all web traffic is encrypted by default. The remaining risks are fake networks, over-collecting sign-in pages, and the metadata the network operator can still see.

Do I need a VPN on hotel Wi-Fi?

It helps by hiding which services you use from the network, and it shifts that visibility to the VPN provider. It is a reasonable precaution rather than a necessity.

Can someone steal my password on public Wi-Fi?

Not by intercepting an encrypted connection, which is now the default. The realistic routes are a phishing page, a fake network, or someone watching you type.

Is it safe to do online banking on public Wi-Fi?

Banking apps and sites use strong encryption, so the connection itself is protected. Using your own mobile data is still the lower-risk option, mainly because it removes any doubt about the network.

Should I let my phone join open networks automatically?

No. Turn that off. It is the main way phones end up connected to networks nobody deliberately chose.

Written by

eSIM Net Editorial

Editorial team

We build and run eSIM Net, which means we spend our days inside the unglamorous details of travel connectivity: why a profile will not install, what a carrier really charges per megabyte, which settings break data the moment you land. These guides are the version of that we wish someone had written for us.