Public Wi-Fi is not automatically dangerous, and modern HTTPS encrypts the content of most web traffic. The bigger everyday risks are connecting to an impersonated network, entering information into a fake captive portal, ignoring browser warnings, exposing local sharing services, or using an unpatched device.
Before connecting
- Ask staff for the exact network name when possible.
- Avoid networks with confusing duplicates such as “Hotel Guest Free” and “Hotel_Guest_Free_5G” unless the venue confirms the correct one.
- Turn off automatic connection to open networks.
- Install system and browser updates before traveling.
While connected
- Use websites and apps that show a valid HTTPS connection. Do not bypass certificate warnings.
- Be cautious when a captive portal asks for more than basic access information.
- Disable file sharing, network discovery, printer sharing, and AirDrop sharing with everyone.
- Use your cellular connection for highly sensitive activity when practical.
- A trustworthy VPN can reduce what the local network and internet provider can observe, but it does not make a fake website trustworthy or stop you from entering information into a scam page.
After leaving
- Disconnect from the network.
- Forget it if you do not expect to use it again.
- Turn off auto-join for hotel, airport, conference, and store networks.
- Review any unexpected login alerts that appeared during the trip.
HTTPS is necessary, not a guarantee of honestyEncryption protects the connection to the site you reached. A scam website can also use HTTPS. Verify the domain and the request, not just the padlock.
