Why open networks were a risk
Open Wi-Fi at the airport, the coffee shop, the hotel lobby or the mall used to be a real danger. On a network with no password, or with a password posted on the wall, someone else connected nearby could watch traffic and, in the worst cases, read what you typed on sites without proper protection.
Read also: Two-factor authentication: why to turn it on for every important account and How to spot a fake website before you type your password.
What has changed
The Federal Trade Commission explains that the picture has improved a lot: most websites now use encrypted connections, which stops someone on the same network from reading what you send. An address starting with https and the padlock in the browser show that.
So the old fear of someone grabbing your bank password out of the air is much smaller. The risks that remain are different: fake networks with names that imitate the venue, cloned login pages and devices that have not been updated.
Source: Federal Trade Commission, Are Public Wi-Fi Networks Safe? What You Need To Know.
When to avoid a network completely
Be extra careful with networks that have generic names and no confirmation that they belong to the place, such as "Free Airport WiFi" or "Starbucks Guest 2." Scammers sometimes set up their own hotspots with names close to the official one, and anything you do on them passes through their equipment.
What actually helps
- Ask staff for the exact network name. Fake networks usually copy the venue name.
- Only enter data on https pages, and do not click through certificate warnings.
- Keep your phone, laptop and browser updated, since many attacks exploit old flaws.
- Turn off auto-join for open networks on your phone and laptop.
- Use your phone's personal hotspot for banking or anything sensitive.
- Turn on two-factor authentication on important accounts, so a leaked password does not become a hacked account.
Do you need a VPN?
A VPN protects you from snoops on the same network, but the VPN company itself can then see your traffic. If you use one, pick a well-known paid service with a clear privacy policy, and be wary of free VPN apps, which often make money from your data. For most people, https plus updated devices plus 2FA already covers the main risks.
Sources
- Federal Trade Commission. Are Public Wi-Fi Networks Safe? What You Need To Know. https://consumer.ftc.gov/articles/are-public-wi-fi-networks-safe-what-you-need-know
Frequently asked questions
Is public Wi-Fi still dangerous?
Less than before, because most sites use encrypted connections. The bigger risks today are fake networks and cloned login pages.
Do I need a VPN on public Wi-Fi?
It is not required. It helps against snoops on the network, but the VPN provider can see your traffic, so avoid unknown free services.
Is it safe to use my banking app on public Wi-Fi?
Banking apps use encryption, but the safest choice for sensitive tasks is your own cellular data or personal hotspot.
Does turning off auto-join help?
Yes. It keeps your phone from connecting on its own to open or look-alike networks without you noticing.