Security

How safe is public Wi-Fi

Today's internet is far safer than the era when plenty of sites sent data unencrypted: HTTPS now protects the content of most web connections. Public Wi-Fi still is not an environment you should fully trust, though — the real risks have moved to fake networks, phishing, outdated devices and the network metadata that stays visible.

In short

  • HTTPS already encrypts the content of the connection between your browser and a site.
  • Simply joining a public network does not mean the person at the next table can read your passwords.
  • Fake access points and phishing pages are still a genuine threat.
  • Outdated apps and devices tend to be less well protected.
  • A VPN adds a separate protected layer between your device and the VPN infrastructure.

What HTTPS changed

When a site uses HTTPS, data between browser and server travels over a protected connection. Someone merely watching traffic on the same Wi-Fi network should not see the page content, the password you typed or the text of your messages in the clear.

That is a fundamental difference between today's web and the early internet, where unencrypted HTTP was far more common.

Browsers also warn about certificate problems. If a protected connection to the real site cannot be verified, you will normally get a prominent warning.

So the picture of "anyone in the café joins the Wi-Fi and immediately reads everyone's passwords" no longer reflects how modern HTTPS services work.

But HTTPS does not solve every security problem.

A fake network can fool you before you open a single site

One of the practical risks of public Wi-Fi is an access point that merely looks official.

Next to a network called `Hotel_Guest`, for example, a `Hotel_Free_WiFi` may appear. You join it believing it belongs to the hotel, when in fact a stranger set it up.

HTTPS still protects your data once you open the real site. But whoever runs the fake network can try to redirect you to a phishing page, show a counterfeit sign-in window, or talk you into installing an unfamiliar app or certificate.

So it is worth watching more than the padlock in the browser: check which network you joined and which address is open before you type a password.

Wi-Fi sign-in pages deserve attention too

In airports, hotels and cafés a captive portal often appears once you connect. It may ask you to accept terms, give a room number, an email address or a phone number.

Pages like that are perfectly normal in themselves, but the same visual pattern is convenient for phishing.

Do not enter your email, banking or social network password just because a Wi-Fi page asks for it. Network access does not normally require anything of the sort.

If a portal offers you an unfamiliar app, configuration profile or certificate to download, check with the network's owner whether that really is the official way in.

When you are done, it is worth turning off automatic reconnection to a network you do not plan to use again.

What can stay visible at the network level

HTTPS protects the content of a connection, but it does not hide the fact that network activity is happening.

The network operator can see that your device is connected, roughly how much data it is moving and which network addresses it talks to. Depending on the DNS technology in use and the particular app, some additional network information may also be available to the network's infrastructure.

None of that amounts to the contents of your messages or your passwords, but it can still matter for privacy.

On top of that, not all of a device's traffic necessarily goes through a modern browser. Older apps, poorly configured software and specialised devices may rely on weaker mechanisms.

It is sensible, then, to treat a public network as infrastructure you do not control and are not obliged to trust more than necessary.

A VPN adds a separate layer of protection

With a VPN, your device establishes a protected connection to the VPN infrastructure. Traffic that goes through it travels inside an encrypted channel.

For whoever runs the public Wi-Fi, that reduces how much they learn about your onward internet connections. The network still sees the device and the fact that data is moving, but it does not get the usual overview of the traffic carried inside the VPN connection.

A VPN does not make a phishing page safe, though. If you opened a counterfeit site yourself and typed a password into it, protected delivery does not undo the wrong choice of recipient.

The same goes for malicious apps and a compromised device. A VPN protects the network connection; it does not replace system updates, attention and your other layers of security.

Practical rules for public networks

Check the Wi-Fi name before connecting, especially when several similar options are in range. In a hotel, office or café, staff can confirm it.

Take browser certificate warnings seriously and do not click past them without a good reason. A modern browser shows those warnings precisely because the authenticity of the protected connection could not be confirmed.

Do not install unfamiliar certificates or apps just to get onto ordinary public Wi-Fi.

Keep your operating system, browser and apps current. Security fixes matter especially on networks you do not trust.

For an extra layer of connection protection you can use MaskNet or another VPN service, particularly if public Wi-Fi is part of your routine.

What to remember

  • HTTPS already protects the content of most modern web connections.
  • The main risks on public Wi-Fi today are not "password sniffing" but fake networks, phishing, user mistakes and outdated software.
  • Network metadata can stay visible to whoever runs the infrastructure, even with HTTPS.
  • A VPN adds a protected layer for internet traffic, but does not replace attention, updates and account security.
Connect MaskNet