Is Public Wi-Fi Safe? What HTTPS Protects and What It Does Not

Public Wi-Fi at cafes, airports and hotels used to deserve its alarming reputation. Years ago, many websites sent traffic without encryption, so someone on the same network could potentially read usernames, passwords or messages. The web has changed: today, most websites and apps use HTTPS/TLS, which encrypts the contents of the connection between your device and the service.

That means public Wi-Fi is usually safe for ordinary web use when the site or app is using a valid encrypted connection. Someone operating the hotspot may still learn some network-level information, but they should not be able to read the contents of a properly protected HTTPS session simply because you share the same Wi-Fi.

The risks that still matter:

  • Fake or “evil twin” hotspots: A scammer can create a network with a convincing name such as “Airport Free WiFi.” Connecting does not automatically expose your encrypted passwords, but a malicious hotspot can try to steer you toward fake login pages or captive portals. Verify the official network name when possible.
  • Fake websites are still fake: HTTPS protects data in transit; it does not prove that the website itself is trustworthy. A phishing site can have a valid certificate and a padlock. Check the domain before entering credentials. Our fake-website guide explains what to look for.
  • Certificate warnings: Never click through a browser warning about an invalid or untrusted certificate just because you are trying to get online. A warning can indicate that the connection is being interfered with.
  • Device exposure: Keep your operating system and browser updated, turn off unnecessary file sharing, and use your device's “Public network” profile where available.
  • Privacy from the hotspot operator: HTTPS encrypts page contents, but the network provider can still observe some connection metadata. A VPN can reduce what the local network can see by putting your traffic inside an encrypted tunnel to the VPN provider.

Do you need a VPN on public Wi-Fi? Not for every login or purchase. A properly encrypted banking or shopping site does not become unsafe merely because the Wi-Fi is public. A VPN is still useful when you want additional privacy from the local network, when you do not trust the hotspot operator, or when an employer requires one for access to work systems. Remember that a VPN does not make a fraudulent website legitimate.

Practical checklist:

  • Confirm the official network name when you can.
  • Use sites and apps that establish a normal HTTPS/TLS connection, and do not bypass certificate warnings.
  • Keep automatic updates enabled and disable unnecessary sharing.
  • Use multi-factor authentication on important accounts.
  • If a network feels suspicious or you cannot verify it, switch to mobile data or a trusted hotspot.
  • Use a reputable VPN when you want an extra privacy layer on a network you do not control.

The key distinction is simple: public Wi-Fi is not automatically unsafe, and HTTPS is doing most of the heavy lifting for confidentiality. The remaining risks are mainly about connecting to the wrong network, trusting the wrong website, ignoring security warnings, or exposing more metadata than you want.

We use cookies to improve your experience. Learn more.