Is public wifi really unsafe, or is that just fearmongering?
The warnings you hear about coffee shop, airport, and hotel wifi do sound a bit alarmist. But the risks underneath them are real and well documented by security researchers — they’ve just gotten less severe over the past decade as more of the web started encrypting by default.
Quick Answer
| Risk on Public Wi-Fi | Does a VPN Protect You? |
|---|---|
| Packet sniffing on unencrypted traffic | Yes |
| Rogue or fake access points (“evil twins”) | Yes — traffic stays encrypted regardless of the network |
| Phishing sites or fake login pages | No — a VPN doesn’t verify what you’re logging into |
| Malware already on your device | No |
| Session hijacking via stolen cookies | Yes — encrypted traffic is far harder to intercept |
What actually made public wifi risky in the first place
Open networks — no password, or a password everyone in the building knows — don’t encrypt the traffic between your device and the router the way your home network’s WPA2/WPA3 setup does. Anyone else on that same network can grab freely available tools and potentially intercept unencrypted traffic as it passes by. It’s called packet sniffing, and it’s not exactly hard to do.
Why it’s less dangerous than it used to be, but not zero-risk
Most of the web runs on HTTPS now, that padlock icon in your browser, which encrypts your traffic’s content even on an unsecured wifi network. That alone shuts down a lot of the easy attacks that were common ten years ago, like someone just reading your login credentials as they crossed the network in plain text.
Still, real risks remain:
- Rogue access points — an attacker sets up a network with a name close enough to fool you, something like “Airport_Free_WiFi,” and once you connect they’ve got a front-row seat to your traffic before it even leaves the local network
- DNS spoofing — redirecting you to fake versions of real sites, sometimes built specifically to steal your login
- Unencrypted apps and services — not everything uses HTTPS correctly, and some older or just poorly built software still sends data in the clear
- Session hijacking — stealing session cookies to pose as a user who’s already logged in
What a VPN actually protects against here
A VPN encrypts everything leaving your device, not just the parts that were already going to be encrypted anyway. So even if you connect to a rogue access point, or the whole network is compromised, whoever’s watching only sees encrypted VPN traffic, not the content underneath, no matter whether the site you’re visiting handles HTTPS properly or not.
What a VPN doesn’t protect against
A VPN won’t stop you from installing malware. It won’t save you if you type your password into a phishing page that isn’t actually your bank. And it does nothing for a device that’s already compromised. It protects your network traffic — that’s the whole job, nothing more.
Practical takeaway
A few habits cut your risk regardless of whether you’re running a VPN: don’t enter sensitive information on any site without HTTPS (check for the padlock), turn off auto-connect on your devices so they don’t quietly join a spoofed network with a familiar name, and treat any surprise login prompt or certificate warning on public wifi as your cue to disconnect, not click through.
How to spot a genuinely dangerous network
Not all public wifi is equally risky. The nastiest setups are “evil twin” networks — a rogue access point with a name deliberately close to the real one (think “Airport_WiFi_Free” instead of the venue’s actual network) built to trick you into connecting so the attacker sits right between you and the internet. Before you connect anywhere, it’s worth just asking staff for the exact network name instead of guessing which open network looks legit, and being suspicious of any network that wants you to install a certificate or an app just to get online.
Public wifi is safer than it was ten years ago, mostly thanks to HTTPS becoming the default, but rogue access points and network-level attacks are still real and still hard to spot from a regular user’s perspective. If you’re regularly connecting to networks you don’t control — hotel wifi, airport lounges, coffee shops — a VPN knocks out an entire category of risk for very little effort on your part. See our Best VPN for Privacy & Security picks if you’re choosing one specifically for this.
