Skip to main content
FixMyTech

Is Public Wi-Fi Still Dangerous in 2026

By

Published

8 min read

Share

Short answer

Far less than the warnings suggest. Nearly all web traffic is now encrypted, so someone on the same network cannot read your passwords or messages. They can see which domains you visit. The one rule that still matters: never click through a certificate warning, and treat any network asking you to install something as hostile.

On this page

“Never use public Wi-Fi” is some of the most durable security advice in circulation, and it describes a web that largely stopped existing around 2015. The warnings were accurate when most sites sent logged-in sessions over plain HTTP and session cookies could be picked out of the air with a browser extension. That era produced a genuine, widely demonstrated problem, and it ended.

What fixed it was not better Wi-Fi. It was HTTPS becoming the default everywhere, browsers marking plain HTTP as not secure, and certificates becoming free and automatic. The attack did not get harder; the thing it targeted stopped being available.

The remaining risks are real but narrow, and the useful version of this advice is much shorter than the one you have heard.

What is actually exposed now

Someone on the same network can Yes or no
Read your passwords as you type them No
Read your messages, emails, documents No
See which domains you connect to Often yes
See how much data and when Yes
Redirect you to a fake site without a warning No
Serve a fake site if you ignore the warning Yes
Read your traffic if you installed their certificate Yes

Only the metadata rows are routinely true. Someone watching can often tell you connected to your bank, because the destination address and parts of the name lookup remain visible even when contents are not. They cannot tell what you did there, and they cannot see the credential.

Encrypted DNS, which Chrome, Firefox and both mobile platforms now support, hides part of that too. The connection destination still leaks, so the picture is blurred rather than erased.

Why interception fails

When your browser connects to a site over HTTPS, it demands a certificate proving the responder genuinely controls that domain, signed by an authority your device trusts. Those certificates are only issued to someone who can demonstrate control of the domain.

An interceptor cannot produce one. The relay works fine right up to the identity check, where the browser throws a full-page warning instead of connecting.

That warning is the defence, and it is the reason this attack has become impractical rather than impossible. The mechanism in more detail is in what a man-in-the-middle attack actually is.

The three things that still matter

Never click through a certificate warning. A full-page browser warning saying the connection is not private should end the session on that network. On your own network it is usually a clock problem or an expired certificate; on café Wi-Fi it is a reason to stop. The small “proceed anyway” link is the single way to manually disable the protection described above.

Never install anything a network asks you to. A sign-in page that wants a certificate, a profile, a VPN configuration or an app is not a normal captive portal. That is the one action that genuinely removes the defence, because a device that trusts the interceptor’s certificate stops warning you. Legitimate hotel Wi-Fi needs a room number, not software.

Watch what the sign-in page asks for. Captive portals legitimately intercept your first request — that is how the page appears — but they ask for a room number, an email address or a terms checkbox. A portal asking for your email password, your card details for “verification”, or your date of birth is not running the network’s sign-in.

Evil twin networks, in proportion

Someone sets up an access point named like the venue’s. Your phone, which remembers networks by name, joins automatically. This part is genuinely easy and genuinely happens.

What follows is less dramatic than the name suggests. The attacker now relays encrypted traffic they cannot read, sees which domains you visit, and triggers certificate warnings if they attempt more. The realistic yield is metadata and the chance you ignore a warning.

If you want to reduce even that: turn off automatic joining for public networks you used once. On iPhone, Settings → Wi-Fi → the i next to a network → Auto-Join off. On Android, the saved network’s settings offer the equivalent. Forgetting networks you will not use again is the tidier version.

The risks that are not about the network at all

Worth more attention than the encryption question, because these have not been solved by anything.

Someone reading your screen. Trains, planes and café tables. Unglamorous, effective, and completely unaffected by a VPN. A privacy filter costs less than a month of VPN subscription.

Leaving the laptop unattended. Physical access to an unlocked machine is the end of the conversation.

Phishing, which does not care where you are. The connection to the fake bank page is perfectly encrypted with a valid certificate and a padlock. All of that is true and none of it helps.

Sharing settings left on. When Windows asks public or private, answer public. It blocks local network discovery and file sharing. macOS equivalents sit under Sharing in System Settings, and turning the firewall on is a reasonable default for a laptop that travels.

Where a VPN genuinely helps

Not nowhere, just not where the advertising claims.

It hides which sites you visit from the local network and the venue, which is a privacy benefit rather than a security one. It bypasses network-level blocking. It gives you a consistent apparent location. On a conference or hotel network with an operator you have no reason to trust, those are reasonable things to want.

What it does not do is add encryption to sites that already have it, which is essentially all of them. Your traffic is encrypted between your device and the VPN server, and then it continues to the site exactly as it would have. You have changed who can see the metadata — from the café to the VPN provider — which is only an improvement if you trust the provider more, and free VPN providers have a poor record on exactly that point.

“Military-grade encryption” in VPN marketing means AES, which is what your browser already uses for every HTTPS connection. It is a phrase, not a feature.

Realistic expectations

Using public Wi-Fi on a current, updated device, through apps and websites you reached normally, is a low-risk activity. Checking your bank balance in a café is fine. The warnings you have absorbed over the years were correct once and have not been retired because frightening advice circulates well.

The residual risk sits in two human decisions and one physical one: clicking through a certificate warning, installing something a network asked for, and the person sitting behind you. None of those is fixed by a subscription, and all three are entirely within your control.

Frequently asked questions

Can someone on the same Wi-Fi see what I am browsing?
They can often see which domains you connect to, from name lookups and connection metadata. They cannot see the pages, the contents or anything you type, because that is encrypted between your device and the site.
Do I need a VPN on public Wi-Fi?
It is a reasonable precaution and not the necessity the advertising implies. It mainly hides which sites you visit from the local network, moving that visibility to the VPN provider instead. It adds nothing to a site that already uses HTTPS.
Is banking on public Wi-Fi safe?
Technically yes, on a current device through the bank's own app or website. The realistic risks are someone watching your screen and the possibility you joined a network you did not check, not interception of the connection itself.
What about networks with no password at all?
An open network means the radio traffic is not encrypted at the Wi-Fi layer, so nearby devices can see more metadata. The HTTPS layer still protects contents, so the exposure is which sites you visit rather than what you did there.
Can I be hacked just by connecting?
Very unlikely on an updated device. That would need an unpatched flaw in your operating system's network handling. Turning off file sharing and marking the network as Public closes the ordinary local exposure.

All Security guides