Guides

Public Wi-Fi: what actually threatens you

The classic scare story — someone in a café stealing your password out of the air — is mostly obsolete, because HTTPS already encrypts the content of nearly all your connections. What remains on public Wi-Fi is subtler: visible metadata like domain names, fake access points, captive portals, and other devices sharing the network with you.

🛡️

HTTPS already protects content

Almost every serious website and app encrypts its traffic end to end. Passwords, messages and card numbers travel inside TLS, so a snooper on café Wi-Fi sees ciphertext, not your data. That part of the old threat is largely gone.

🌍

Metadata still leaks

Encryption hides what you say, not whom you talk to. DNS lookups and the server names in TLS handshakes reveal which sites and services you use, and the network operator or anyone positioned on it can collect that list.

🔑

The network itself can lie

Anyone can broadcast a hotspot named after the café or airport. Your device joins the strongest familiar-looking signal, and from then on the attacker is your gateway. This, not password sniffing, is the realistic modern attack.

Is public Wi-Fi still dangerous

Less than the folklore says, more than zero. A decade ago much of the web ran unencrypted, and a laptop in the corner really could capture logins from the air. Today nearly all meaningful traffic is wrapped in TLS: banking, mail, messengers and shops encrypt content between your device and their servers regardless of the network you sit on.

What survives is a different set of risks: metadata that encryption does not cover, access points that are not what they claim to be, portal pages that ask for personal data, and the simple fact that you share a local network with strangers.

What the network still sees: DNS and SNI

TLS hides the content of your traffic but not its destinations. When your device looks up a hostname, that DNS query is often readable by the network, and when it opens a TLS connection, the server name usually appears in plaintext in the handshake — the SNI field. Whoever runs or watches the hotspot can build a tidy list of every site and app you touched, timestamped.

For most people this is a privacy issue rather than an emergency: the list of domains you visit says a lot about you, and on a public network you have no idea who collects it or why. Encrypted DNS narrows the leak but does not remove SNI.

This is the one gap a VPN closes completely on hostile networks: inside the tunnel, DNS and handshakes are invisible to the hotspot, which sees only that you are connected to a VPN server.

Fake hotspots and lookalike networks

Nothing stops anyone from broadcasting a Wi-Fi network named after the café, hotel or airport you are in. Devices happily join the strongest signal with a familiar name, and phones that remember old networks will reconnect to a lookalike automatically, without you touching anything.

Once you are on an attacker's access point, they are your gateway: they assign your DNS, route every packet and can try to redirect you to convincing fake pages. TLS still protects properly secured sites — your browser will warn loudly if someone impersonates them — but anything unencrypted, any app that ignores certificate errors, and anything you type into a page the attacker serves is exposed.

The practical defenses are unglamorous: turn off auto-join for public networks, forget hotspots you no longer use, and never ignore a certificate warning while you are on one.

Captive portals and login pages

The page that greets you on hotel or airport Wi-Fi — asking for a room number, an email address or a social login — is itself worth treating with suspicion. It runs with the network operator's privileges, it is trivial to imitate on a fake hotspot.

Give portals the minimum: a throwaway email if a field is mandatory, never a password you use anywhere else, and never card details. A portal has no legitimate reason to ask for payment credentials to give you free Wi-Fi.

One practical note: VPN apps usually cannot connect until the portal is completed, because the network blocks everything else. Finish the portal, then confirm the tunnel is up before doing anything sensitive. Aurora's apps reconnect automatically once the network starts passing traffic.

What a VPN does and does not do here

On public Wi-Fi a VPN does one job extremely well: it makes the local network irrelevant. The hotspot, its operator and anyone else on it see a single encrypted stream to a VPN server — no DNS queries, no SNI, no destinations, nothing to redirect. Protocols like WireGuard do this with little battery or speed cost, so leaving it on is realistic.

What a VPN does not do also matters. It does not vet the portal page you type into, does not protect a device with file sharing exposed to the local subnet, and does not make a phishing site legitimate. It moves your trust from an unknown hotspot to your chosen provider — a good trade, not a magic one.

Practical habits for public networks

Most of the real protection comes from a handful of settings you configure once, plus two habits you keep. None of this requires expertise.

The settings matter because attacks on public Wi-Fi are opportunistic: they harvest whatever the careless majority exposes. A patched device that joins nothing automatically, shares nothing locally and tunnels its traffic is simply not a worthwhile target.

  • Keep the OS and browser updated — most real-world compromises exploit known, already-patched bugs
  • Turn off auto-join for open networks and periodically forget old saved hotspots
  • Disable file, printer and AirDrop-style sharing when on networks you do not control
  • Never click through certificate warnings on a public network
  • Give captive portals minimal data and never reused passwords or card numbers
  • Turn the VPN on after the portal and leave it on for the whole session

Frequently asked questions

Can someone steal my password on café Wi-Fi?
On a properly secured site, realistically no: HTTPS encrypts your login between the browser and the server, so a snooper captures ciphertext. The realistic risks are different — a fake page you are redirected to, a certificate warning you click through, or an unencrypted app. Treat browser security warnings on public networks as hard stops.
If HTTPS protects me, why use a VPN on public Wi-Fi?
Because HTTPS hides content, not destinations. The hotspot still sees every domain you resolve and connect to via DNS and SNI, and a malicious gateway can manipulate anything unencrypted. A VPN wraps all of it into one opaque stream, so the local network learns nothing and can redirect nothing.
What is a fake hotspot and how do I recognize one?
It is a network broadcast by an attacker using a trusted-sounding name — the café, the airport, the hotel. You often cannot distinguish it by looking, which is the point. Defend structurally instead: disable auto-join, forget old networks, never bypass certificate warnings, and keep a VPN on so a hostile gateway sees only tunnel traffic.
Is hotel Wi-Fi safer than an open café network?
Not meaningfully. A password on the wall changes little: everyone in the building shares the same network, the operator still sees your metadata, and lookalike hotspots are just as easy to run. Apply the same rules everywhere — updates, sharing off, minimal data into portals, VPN on for the session.
Should I avoid banking on public Wi-Fi?
Banking apps and sites use strong TLS plus their own protections, so the connection itself is well defended. The risks are around it: fake portal pages, lookalike networks, shoulder surfing. With an updated device and a VPN on, checking your bank on public Wi-Fi is a reasonable thing to do.
Does a VPN protect me from other devices on the same Wi-Fi?
Partly. It hides your traffic from them completely, which removes the main exposure. But if your device itself exposes services to the local subnet — file sharing, an open debug port — neighbors may still reach those directly. That is why disabling sharing on untrusted networks belongs alongside the VPN, not instead of it.

Keep reading

Try Aurora

14-day money-back guarantee. Up to 7 devices on one subscription.

Protect my devices