Public Wi‑Fi security: what a VPN actually protects
How to use Wi‑Fi at an airport, hotel, or café: HTTPS, VPNs, captive portals, auto-connect, and checks before opening an important account.
Updated:
Using public Wi‑Fi at an airport, hotel, or café does not mean that your data will automatically be stolen. Most current websites and apps use HTTPS, so content is already encrypted between the device and the service. An unfamiliar network still deserves care because you do not control the access point or know who configured it.
A practical rule: verify the network name, keep the device updated, use HTTPS, and connect through a VPN you trust. For a particularly sensitive task, switch to mobile data when in doubt.
What can still go wrong on an unfamiliar network?
The network operator or an attacker may try to:
- create an access point with a name similar to the hotel’s Wi‑Fi;
- redirect users to a fake sign-in page;
- observe unencrypted requests and connection metadata;
- reach file-sharing services left open on a laptop;
- attack an old, unpatched device;
- convince the user to install a profile, certificate, or app.
HTTPS and a VPN reduce some network risks, but they do not fix phishing, malicious files, or an insecure device.
HTTPS already makes public Wi‑Fi safer
HTTPS encrypts traffic between the browser and a website. Someone nearby should not see a password or page content simply because they share the network. The US Federal Trade Commission notes that widespread encryption has made public Wi‑Fi generally safer than it was in the past.
HTTPS still has limits:
- a padlock does not prove that the website is genuine;
- a look-alike domain can also use HTTPS;
- an old app may handle some data differently;
- unprotected DNS or metadata can reveal information about connections;
- a malicious extension sees data on the device itself.
Never ignore a browser certificate warning on a banking, email, or government page.
What a VPN adds
A VPN creates an encrypted connection from the device to a VPN server. The local network sees communication with that server rather than every request as it would on a direct route. This is useful when you do not trust the network.
A VPN can:
- protect traffic between the device and the VPN server;
- carry DNS through a correctly configured tunnel;
- replace the local network’s public IP for websites;
- reduce the information visible to the Wi‑Fi operator;
- maintain a consistent route while changing networks when the client supports it.
A VPN cannot protect a password deliberately entered on a fake site, remove a malicious app, or cancel approval of an attacker’s sign-in request. The VPN provider also becomes part of the route, so use a service you trust.
Connect through a captive portal safely
A captive portal is the page that asks you to accept terms, enter a room number, or receive a code before internet access is enabled. A VPN can prevent this page from loading because the network has not yet allowed a connection to the VPN server.
Use this order:
- Confirm the exact network name with staff or an official sign.
- Connect and wait for the network sign-in page.
- Do not enter an email, banking, Apple, or Google password. The portal should request only information related to the network itself.
- Complete network access.
- Turn on the VPN immediately and confirm that it is connected.
- Only then open the sites and apps you need.
Do not install an unknown root certificate or device-management profile just to get Wi‑Fi. Such configuration can be legitimate on a company network, but it should come from your administrator through a verified channel.
Phone and laptop settings
Before traveling:
- enable automatic updates;
- disable automatic joining of open networks;
- turn on the laptop firewall;
- disable file and printer sharing for public networks;
- configure screen lock and device finding;
- update the VPN app and sign in before the trip;
- save a backup way to contact banks and essential services.
After using a network, disconnect and choose Forget this network if you do not plan to return. This reduces the chance of automatically joining another access point with the same name.
Is it safe to use a banking app on hotel Wi‑Fi?
A current official banking app should encrypt its connection regardless of the Wi‑Fi. The consequences of a mistake are still high. If the network looks suspicious, use mobile data. It does not eliminate phishing, but it removes the unknown local access point from the route.
When mobile data is unavailable:
- Verify the network name.
- Connect the VPN after the captive portal.
- Open the official banking app instead of a message link.
- Do not perform a transaction while an unknown caller is directing you.
- Stop if you see a certificate warning or an unusual request.
If the VPN will not connect
- Complete the captive portal first.
- Check whether a normal HTTPS page works without the VPN.
- Disable another VPN, proxy, or Private DNS configuration.
- Reconnect to Wi‑Fi, then restart the VPN client.
- Try another location or the profile recommended by your service.
- If the network blocks the VPN entirely, use mobile data or another trusted network.
Do not disable browser security or install unknown certificates to “fix” the connection.
Quick checklist
Before connecting
- Confirm the exact network name.
- Update the system and VPN client.
- Disable auto-connect and sharing.
After joining
- Complete the captive portal without an important account password.
- Turn on the VPN.
- Use HTTPS and official apps.
Afterward
- Disconnect and forget the network.
- Review important accounts if suspicious prompts appeared.
- Change a password only when there are signs of compromise, not merely because public Wi‑Fi was used.