Is Public Wi-Fi Still Dangerous in 2026
Short answer
Far less than the warnings suggest. Nearly all web traffic is now encrypted, so someone on the same network cannot read your passwords or messages. They can see which domains you visit. The one rule that still matters: never click through a certificate warning, and treat any network asking you to install something as hostile.
On this page
“Never use public Wi-Fi” is some of the most durable security advice in circulation, and it describes a web that largely stopped existing around 2015. The warnings were accurate when most sites sent logged-in sessions over plain HTTP and session cookies could be picked out of the air with a browser extension. That era produced a genuine, widely demonstrated problem, and it ended.
What fixed it was not better Wi-Fi. It was HTTPS becoming the default everywhere, browsers marking plain HTTP as not secure, and certificates becoming free and automatic. The attack did not get harder; the thing it targeted stopped being available.
The remaining risks are real but narrow, and the useful version of this advice is much shorter than the one you have heard.
What is actually exposed now
| Someone on the same network can | Yes or no |
|---|---|
| Read your passwords as you type them | No |
| Read your messages, emails, documents | No |
| See which domains you connect to | Often yes |
| See how much data and when | Yes |
| Redirect you to a fake site without a warning | No |
| Serve a fake site if you ignore the warning | Yes |
| Read your traffic if you installed their certificate | Yes |
Only the metadata rows are routinely true. Someone watching can often tell you connected to your bank, because the destination address and parts of the name lookup remain visible even when contents are not. They cannot tell what you did there, and they cannot see the credential.
Encrypted DNS, which Chrome, Firefox and both mobile platforms now support, hides part of that too. The connection destination still leaks, so the picture is blurred rather than erased.
Why interception fails
When your browser connects to a site over HTTPS, it demands a certificate proving the responder genuinely controls that domain, signed by an authority your device trusts. Those certificates are only issued to someone who can demonstrate control of the domain.
An interceptor cannot produce one. The relay works fine right up to the identity check, where the browser throws a full-page warning instead of connecting.
That warning is the defence, and it is the reason this attack has become impractical rather than impossible. The mechanism in more detail is in what a man-in-the-middle attack actually is.
The three things that still matter
Never click through a certificate warning. A full-page browser warning saying the connection is not private should end the session on that network. On your own network it is usually a clock problem or an expired certificate; on café Wi-Fi it is a reason to stop. The small “proceed anyway” link is the single way to manually disable the protection described above.
Never install anything a network asks you to. A sign-in page that wants a certificate, a profile, a VPN configuration or an app is not a normal captive portal. That is the one action that genuinely removes the defence, because a device that trusts the interceptor’s certificate stops warning you. Legitimate hotel Wi-Fi needs a room number, not software.
Watch what the sign-in page asks for. Captive portals legitimately intercept your first request — that is how the page appears — but they ask for a room number, an email address or a terms checkbox. A portal asking for your email password, your card details for “verification”, or your date of birth is not running the network’s sign-in.
Evil twin networks, in proportion
Someone sets up an access point named like the venue’s. Your phone, which remembers networks by name, joins automatically. This part is genuinely easy and genuinely happens.
What follows is less dramatic than the name suggests. The attacker now relays encrypted traffic they cannot read, sees which domains you visit, and triggers certificate warnings if they attempt more. The realistic yield is metadata and the chance you ignore a warning.
If you want to reduce even that: turn off automatic joining for public networks you used once. On iPhone, Settings → Wi-Fi → the i next to a network → Auto-Join off. On Android, the saved network’s settings offer the equivalent. Forgetting networks you will not use again is the tidier version.
The risks that are not about the network at all
Worth more attention than the encryption question, because these have not been solved by anything.
Someone reading your screen. Trains, planes and café tables. Unglamorous, effective, and completely unaffected by a VPN. A privacy filter costs less than a month of VPN subscription.
Leaving the laptop unattended. Physical access to an unlocked machine is the end of the conversation.
Phishing, which does not care where you are. The connection to the fake bank page is perfectly encrypted with a valid certificate and a padlock. All of that is true and none of it helps.
Sharing settings left on. When Windows asks public or private, answer public. It blocks local network discovery and file sharing. macOS equivalents sit under Sharing in System Settings, and turning the firewall on is a reasonable default for a laptop that travels.
Where a VPN genuinely helps
Not nowhere, just not where the advertising claims.
It hides which sites you visit from the local network and the venue, which is a privacy benefit rather than a security one. It bypasses network-level blocking. It gives you a consistent apparent location. On a conference or hotel network with an operator you have no reason to trust, those are reasonable things to want.
What it does not do is add encryption to sites that already have it, which is essentially all of them. Your traffic is encrypted between your device and the VPN server, and then it continues to the site exactly as it would have. You have changed who can see the metadata — from the café to the VPN provider — which is only an improvement if you trust the provider more, and free VPN providers have a poor record on exactly that point.
“Military-grade encryption” in VPN marketing means AES, which is what your browser already uses for every HTTPS connection. It is a phrase, not a feature.
Realistic expectations
Using public Wi-Fi on a current, updated device, through apps and websites you reached normally, is a low-risk activity. Checking your bank balance in a café is fine. The warnings you have absorbed over the years were correct once and have not been retired because frightening advice circulates well.
The residual risk sits in two human decisions and one physical one: clicking through a certificate warning, installing something a network asked for, and the person sitting behind you. None of those is fixed by a subscription, and all three are entirely within your control.