Public Wi-Fi Safety 2026: How to Use Airport and Cafe Wi-Fi Without Getting Hacked
Public Wi-Fi safety in 2026: what HTTPS already protects, the real risks like evil twin hotspots, where a VPN helps and the settings to change before you travel.

Public Wi-Fi safety advice has aged badly. Most of what circulates online still describes a world where anyone in the café could read your emails as they flew past, and that stopped being broadly true once the web moved to HTTPS. The genuine risks in 2026 are narrower, stranger and easier to defend against, but they have not disappeared, and airports, hotels, railway stations and cafés remain the places where people make their worst decisions with their phones.
This guide separates what the encryption already handles from what it does not, explains the attacks that still work on an open network, and gives you a short list of settings that removes most of the residual risk. At TechLein we would rather you understood the threat model than followed a rule you cannot explain, because the “never use public Wi-Fi” advice is both impractical and slightly wrong.
Key takeaways
- HTTPS already encrypts the content of nearly everything you do, so passive eavesdropping is largely solved.
- The live risks are fake hotspots, manipulated captive portals and hostile devices sharing the network with you.
- A VPN hides which sites you visit from the network operator. It does not make a malicious website safe.
- Do not do banking or UPI transactions on an unknown network. Use mobile data instead; it costs almost nothing.
What HTTPS already protects
When your browser shows a secure connection, the traffic between your device and that website is encrypted end to end. Someone sitting on the same Wi-Fi cannot read your passwords, your messages, your card details or the page content. They also cannot modify what you see, because any tampering breaks the connection’s integrity checks and your browser refuses to load the page.
Since virtually every serious site and app now uses HTTPS by default, and browsers warn loudly when a site does not, the classic image of a hacker in the corner reading your Gmail over café Wi-Fi is essentially obsolete. Your banking app, your messaging apps and your email are all encrypted in transit regardless of the network.
What still leaks
Encryption protects content, not metadata. Whoever runs the network can generally see which sites and services you connect to, how much data you exchange and when. Domain name lookups often travel unencrypted unless you have enabled encrypted DNS. On a hotel or corporate network, that is a privacy question rather than a security one, but it is real, and it is the main thing a VPN fixes.
The risks that still work
Evil twin hotspots
Anyone can broadcast a network called “Airport Free WiFi” or a name matching the café you are sitting in. Your phone cannot tell the difference between the real one and an impostor, because network names are not authenticated. Once you connect to the attacker’s access point, they control your DNS, your gateway and your captive portal, which is enough to run everything below.
Captive portal tricks
The sign-in page that appears when you join a public network is an ideal place to run a scam, because people expect it to ask for something. Watch for portals that ask for your email password rather than just an email address, that request card details for a “free” connection, that push you to install an app or a configuration profile, or that display a certificate warning you are invited to ignore. Installing a profile or a certificate hands the network the ability to inspect your encrypted traffic. That is the one action that genuinely breaks HTTPS, and it requires you to agree to it.
Hostile devices on the same network
On an open network you share a local segment with strangers. If your laptop has file sharing, network discovery or a media server switched on, those services are visible to everyone else connected. Old, unpatched devices are also scanned automatically by anything malicious already on the network. This is why marking the network as public on Windows matters: it changes the firewall profile and hides you from discovery.
Shoulder surfing and left-behind sessions
The least technical risk is the most common. Someone reading your screen in an airport queue, or a device left logged in on a hotel business-centre PC, defeats every layer of encryption you have. Treat a shared computer as compromised by default and never sign into anything important on one.
Where a VPN helps and where it does not
| Situation | Does a VPN help? | Why |
|---|---|---|
| Network operator seeing which sites you visit | Yes | Traffic and DNS are tunnelled to the VPN provider instead |
| Connected to an evil twin hotspot | Largely | The fake access point sees only encrypted tunnel traffic |
| Other devices scanning yours on the local network | Partly | A VPN does not close open ports; your firewall settings do |
| A phishing site asking for your password | No | The tunnel delivers your data to the scammer perfectly securely |
| Malware you download and run | No | Encryption in transit says nothing about what you install |
| A captive portal you gave real credentials to | No | You handed the information over voluntarily |
| Hiding activity from your VPN provider | No | You have moved trust from the café to the provider, not removed it |
That last row deserves emphasis. A VPN relocates trust rather than eliminating it, which is why free VPN apps funded by advertising are a poor trade: you are paying with exactly the browsing data you were trying to protect. If you use one, use a reputable paid service, and understand what it does and does not cover. The broader picture is in our notes on how to protect your privacy online.
Settings to change once, before you travel
- Turn off automatic connection to open networks. Both Android and iOS have a setting for auto-joining networks; disable it so your phone never silently attaches to an impostor named like one you used before.
- Forget public networks after use, so your device does not advertise for them or rejoin them later.
- Mark the network as public on Windows when prompted, and keep the firewall on. On a Mac, ensure file sharing is off.
- Turn off file sharing, printer sharing and network discovery before joining. Also switch off AirDrop or Nearby Share when you are not actively using them.
- Enable HTTPS-only mode in your browser so it refuses unencrypted connections rather than quietly loading them.
- Enable encrypted DNS (private DNS on Android, or the equivalent browser or system setting) so your lookups are not readable by the network.
- Keep the operating system and browser updated. Most local network attacks target known, patched flaws.
- Use unique passwords and two-factor authentication, so a single credential leak on the road cannot cascade. A password manager handles the first part and our two-factor authentication setup guide the second.
What to do at the airport or café
- Ask a staff member for the exact network name and password. Do not guess from the list, and be suspicious of an open network with the same name as a password-protected one.
- Prefer the network that has a password, even a shared one, over a completely open network. It gives each client a distinct encryption key.
- Connect, and let the captive portal open on its own. If it does not appear, do not go hunting for it on random sites.
- Give the portal only what is unavoidable, typically an email address or a phone number for a one-time code. Never an account password, never card details for free access.
- Refuse any request to install an app, a certificate or a configuration profile. Walk away from the network instead.
- Stop immediately if you see a certificate or privacy warning in your browser. That warning on a public network is a strong signal something is intercepting traffic.
- Do your browsing, but keep banking, UPI payments and anything involving identity documents off the network entirely.
- When you finish, disconnect, tell the device to forget the network, and turn Wi-Fi off until you need it again.
Just use your mobile hotspot
Mobile data in India is cheap enough that the security calculation is straightforward: for anything that matters, tether to your own phone. A personal hotspot gives you a network with exactly one operator, you, and it removes evil twins, captive portals and hostile neighbours in a single step. Give it a strong password and WPA3 or WPA2 encryption, and it is comfortably the safest option in any public place.
Reserve public Wi-Fi for bulk, low-sensitivity traffic: large downloads, streaming, software updates. Reserve your own connection for banking, payments and account logins. This one habit replaces most of the rest of this article.
Why banking and UPI deserve a hard rule
The technical case for avoiding banking on public Wi-Fi is weaker than it used to be, since the app’s encryption holds regardless. The practical case is still strong. You are in a distracting environment where shoulder surfing is easy, where you are more likely to accept a warning to make something work, and where a manipulated portal or DNS can steer you to a convincing lookalike site. Banking mistakes are also expensive and slow to unwind, as the recovery processes in our guide to UPI payment fraud protection make clear.
The rule is easy to follow: if the screen involves money or an identity document, switch to mobile data first. If your phone is compromised in some other way, none of this helps, which is why the basics in our guide to securing your Android phone come first.
Frequently asked questions
Is hotel Wi-Fi safer than airport Wi-Fi?
Only slightly. A per-room password is better than a fully open network, but hotel networks are often old, poorly maintained and shared with every other guest. Treat them the same way.
Do I really need a VPN on public Wi-Fi?
It is useful for privacy from the network operator and for reducing what a fake hotspot can observe. It is not essential for security on a modern, fully HTTPS site, and it does nothing against phishing or malware.
Is it safe to use my banking app, as opposed to a browser?
Apps generally pin their connections and are harder to spoof than a browser session. It is still better to switch to mobile data, because the surrounding risks such as shoulder surfing do not change.
What should I do if I already entered a password on a suspicious portal?
Change that password immediately from a trusted connection, sign out all other sessions, and enable two-factor authentication on the account. Then check whether that password was reused anywhere, using the methods in our guide to checking whether your data leaked in a breach.
Can someone hack my phone just because we are on the same Wi-Fi?
Not on a patched device with sharing disabled. The risk comes from open services, outdated software, or something you were persuaded to install. Keep updates current and decline installation requests from networks.
The bottom line
Public Wi-Fi is not the danger zone it was a decade ago, because HTTPS removed the easiest attack. What remains is a set of tricks that need your cooperation: connecting to a network that only looks familiar, typing a real password into a captive portal, installing a profile so a page will load, clicking through a certificate warning. Every one of those is a decision you can decline.
Set auto-connect off, turn sharing off, keep your devices updated, and move anything involving money to your own mobile hotspot. Do that and airport and café Wi-Fi become what they should be: a convenience for browsing and downloads, with none of your important accounts riding on the goodwill of whoever is running the access point.
Tags:
More from TechLein Editorial Team
View all articles →
FASTag Annual Pass 2026: Price, Eligibility and How to Apply
Everything about the FASTag Annual Pass in 2026: who is eligible, how trips are counted, how to activate it via Rajmarg Yatra and what it does not cover.

ABHA Health ID Card 2026: How to Create and Use Your Digital Health Account
How to create and use an ABHA health ID card in 2026: Aadhaar and driving licence routes, ABHA address, linking records and consent-based sharing.

How to Compare Mobile Recharge Plans in India (2026 Value-for-Money Guide)
How to compare mobile recharge plans in India using cost per GB and cost per day, daily-limit versus total-data packs, OTT bundles and unlimited-call fine print.