Cybersecurity

How Safe Is Public Wi-Fi?

The real risks are more nuanced than “never use airport Wi-Fi.” Here is how to use shared networks with better judgment and a few sensible safeguards.

Thumbnail for public Wi-Fi cybersecurity videoWatch the original conversation ↗

Public Wi-Fi is part of modern life. Airports, hotels, cafés, conference centres, libraries, and transit hubs all make connectivity easy. The security advice around these networks, however, is often reduced to one dramatic rule: public Wi-Fi is dangerous. That is too simplistic to be useful.

Start with the threat you are actually managing

A shared network means you have less control over the infrastructure and less certainty about who else is using it. The risks include connecting to a fake hotspot, sending traffic through a poorly secured network, exposing local device services, or being tricked into visiting a malicious site.

At the same time, the web has changed. HTTPS now protects the content of most mainstream web sessions in transit. That significantly reduces the old-style risk of someone simply sitting nearby and reading every page or password sent over the network. It does not eliminate phishing, malware, credential theft, fake access points, or unsafe device configuration.

The fake-hotspot problem

One of the simplest attacks is social rather than technical: create a network name that looks legitimate and wait for people to connect. “Airport_Free_WiFi” and “Hotel_Guest” are easy names to imitate.

Before connecting, confirm the network name with signage or staff where practical. Be particularly cautious when several similarly named networks appear.

HTTPS helps, but it is not a trust badge

HTTPS encrypts the connection between your browser and the website. That matters. But a malicious website can also use HTTPS. The padlock tells you the connection is encrypted; it does not tell you the person or organization behind the site is trustworthy.

Check the domain carefully before entering credentials, especially when a captive portal or unexpected login page appears.

A better rule than “never use public Wi-Fi”:

Treat public networks as untrusted infrastructure. Keep your device hardened, verify where you are connecting, and use stronger controls for sensitive activity.

Practical steps that reduce risk

  • Prefer your mobile connection for highly sensitive activity when it is available and practical.
  • Keep your operating system, browser, and applications updated.
  • Disable automatic Wi-Fi joining so your device does not connect to remembered or open networks without your attention.
  • Turn off unnecessary sharing and discovery features on laptops when using public networks.
  • Use MFA on important accounts so a stolen password is less useful to an attacker.
  • Use a reputable VPN when your threat model calls for it, especially when you need additional protection for network traffic or are working under organizational policy.
  • Do not ignore certificate or browser security warnings.

What about banking?

A legitimate banking app or properly configured HTTPS banking site provides strong encryption, but context still matters. If you have a trusted mobile connection available, using it for banking or other highly sensitive tasks is a simple way to reduce dependence on an unknown network.

The same reasoning applies to administrative consoles, privileged corporate access, or anything where compromise would have unusually high impact.

Organizations have a role too

Public Wi-Fi safety is not only an individual responsibility. Employers with travelling or hybrid staff should provide clear guidance, phishing-resistant MFA where possible, managed devices, endpoint protections, secure remote access, and sensible policies for high-risk administrative activity.

Security works better when we reduce the number of decisions employees have to improvise under pressure.

The bottom line

Public Wi-Fi is not automatically unsafe, and avoiding it entirely is not realistic for everyone. The better approach is layered security: updated devices, encrypted services, verified networks, MFA, cautious browsing, and stronger connectivity choices when the sensitivity of the activity warrants them.

Continue the conversation

Want the fuller discussion?

This guide was developed from the themes explored in Is Public Wi-Fi Safe? The Real Cyber Security Risks & Mitigation Strategies.

Watch on YouTube ↗