Free Wi-Fi in a café, airport or hotel is convenient. But you are joining a network you don't control, possibly shared with strangers. Here is what the real risks are and which simple habits keep your data safe.
Why public Wi-Fi is risky
Fake hotspots
An attacker can create a network with a believable name — "Cafe_Free_WiFi" next to the real "Cafe WiFi", say. Join it, and all your traffic goes through their device.
Open networks without a password
On a network with no password, traffic between your device and the router isn't encrypted. Anything sent without HTTPS can be seen by others within range.
Websites without encryption
If a website's address starts with http:// rather than https://, everything you type — logins, passwords, messages — travels in plain text. On a public network that is especially risky.
Where you go is visible
Even when page content is encrypted, the network's owner, or an attacker running a fake hotspot, can see which websites you visit.
Auto-connect and file sharing
Your phone may join a Wi-Fi network just because it recognises the name, and file sharing left on exposes your folders to other devices on the network.
What HTTPS protects and what it doesn't
Most websites now use HTTPS — the padlock in the address bar. That cuts the risks a lot: page content, passwords and messages are encrypted between your browser and the website, so a stranger on the network can't read them.
But HTTPS doesn't hide which websites you visit, and it won't save you if you click through a browser warning about an "insecure certificate" — that is exactly how an attacker tries to get in the middle. On a public network, such a warning is a reason to disconnect at once.
How to protect yourself: simple rules
- Ask staff for the network name and join exactly that one.
- Open only HTTPS websites. Don't enter passwords on pages without a padlock.
- Never click through certificate warnings.
- Use a VPN — it encrypts all your device's traffic up to its server, so strangers on the network can't even see where you go. How a VPN differs from a proxy is covered in "Proxy vs VPN vs Tor".
- Turn off auto-connect to open networks and file sharing.
- Turn on two-factor authentication for important accounts: even if a password leaks, nobody gets in without the second factor.
- Keep your system and browser updated — updates close security holes.
- Use mobile data for important things — tether it from your phone; that is safer than any stranger's network.
- "Forget" the network afterwards in your settings so the device doesn't rejoin it by itself.
If you work through a proxy
A proxy protects only the programs it is set up in. Its protocol matters too: SOCKS5 doesn't encrypt the connection to the proxy, so on a public network a stranger could see your proxy login and password. An HTTPS proxy encrypts that connection — choose it on networks you don't trust. More in "HTTP, HTTPS or SOCKS5".
FAQ
Is password-protected Wi-Fi, like in a hotel, safe?
Safer than an open network, but every guest knows the password, so you can't trust it like your home network. The rules above still apply.
Can I use online banking on public Wi-Fi?
Better to use mobile data. If there is no other option, only through the bank's official app or an HTTPS website — ideally with a VPN on.
Does incognito mode help?
No: incognito doesn't save history on your device, but it does nothing to protect your traffic on the network.