Wi-Fi Security at Hotels, Airports, and Coffee Shops: Real Risks and Practical Protection

The Risk That’s Real and the Risk That’s Overstated

Public Wi-Fi security risks are simultaneously overstated by VPN marketing and understated by users who connect to every available network without any protection. The reality is more specific than either narrative: some public Wi-Fi risks are genuine and require protection, others have been largely addressed by the HTTPS ubiquity that now characterises the modern web, and the most dangerous public Wi-Fi scenarios are ones that most users never encounter.

Understanding the specific, current risk profile of public Wi-Fi in 2026 — rather than the risk profile that existed when public Wi-Fi security advice was originally written in the early 2010s, before HTTPS was near-universal — produces protection decisions that are calibrated to actual risk rather than to marketing imperatives.

What HTTPS Changes About Public Wi-Fi Risk

The primary public Wi-Fi risk in the pre-HTTPS era was that a network attacker could intercept the content of web traffic as it passed through shared network infrastructure. An attacker on the same coffee shop Wi-Fi as you could see the websites you visited, the content you viewed, and the credentials you submitted to unencrypted login forms. This was a genuine and significant risk when most websites used HTTP rather than HTTPS.

In 2026, approximately 95% of web traffic is HTTPS-encrypted, and major browsers flag HTTP sites as ‘Not Secure’ prominently. An attacker on the same public Wi-Fi can still see which websites you visit (the domain name — google.com, your bank’s domain — is visible in DNS queries and TLS handshakes even over HTTPS) but cannot see the content of HTTPS-encrypted communications. The credential theft from unencrypted login forms that was the most immediate historical public Wi-Fi risk has been largely addressed by HTTPS adoption.

The Risks That Remain Genuine

Evil twin attacks — creating a Wi-Fi access point with the same name as a legitimate network (Airport_Free_WiFi, Hotel_Guest_Internet) to intercept connections — can capture traffic from devices that automatically connect to familiar-named networks. In this scenario, the attacker controls the network infrastructure and can potentially intercept traffic before HTTPS encryption is established, redirect DNS queries to malicious destinations, or harvest authentication credentials from HTTPS stripping attacks if the victim doesn’t notice the missing secure connection indicator.

Unpatched device vulnerabilities are exploitable over shared networks: devices on the same network can potentially access services running on other devices if those services have known vulnerabilities and the devices haven’t been updated. A laptop with an unpatched Windows vulnerability that’s firewalled at home may be exposed on a public network where the network provides no equivalent protection. Keeping devices updated and enabling the operating system firewall (on by default in Windows 11 and macOS) provides protection against this attack surface.

Practical Protection That’s Actually Necessary

The protections with genuine benefit on public Wi-Fi: ensure HTTPS is active for any site where you enter credentials (the padlock in the browser address bar) — use HTTPS Everywhere browser extension or ensure the browser is configured to upgrade to HTTPS automatically; use a VPN specifically for non-HTTPS traffic (which is primarily now DNS queries and application traffic outside the browser) rather than assuming all traffic is at risk; and disable automatic network connection to saved networks in public spaces by using specific saved networks rather than auto-connecting to any open network.

The protection with the most consistent benefit across all scenarios: MFA on accounts. Even if an attacker on public Wi-Fi somehow intercepts a username and password, an account protected by MFA can’t be accessed with the credential alone. MFA is the protection that works regardless of the network security situation — it limits the damage from credential theft regardless of the interception method.

The Scenarios Where Extra Caution Is Justified

The public Wi-Fi situations where elevated caution is appropriate: hotel networks where you’ve been assigned a room number and a password that might be shared with many other rooms simultaneously (the shared credentials create a shared network segment where other guests can potentially see your traffic), airports and transit hubs where large numbers of people use the same SSID and the legitimacy of the specific access point is hard to verify, and any situation where sensitive work is being done remotely on confidential information.

For sensitive work in public spaces, the protection combination that addresses the legitimate risks: a VPN from a trusted provider (to encrypt DNS queries and non-browser traffic), confirmed HTTPS for all browser sessions, and the consideration that some sensitive work — accessing confidential client files, submitting financial information, performing administrative operations on production systems — is better deferred until a more trusted network connection is available. The cellular data connection from a phone hotspot provides a more private network than public Wi-Fi and is worth using when the information sensitivity justifies it.

Related articles

Share article

Latest articles