How Public WiFi Exposes Your Data and What a VPN Actually Protects
Patrick Bushe
December 3, 2024 · 5 min read
Public Wi-Fi in cafes, airports and hotels used to be genuinely dangerous: most websites didn't encrypt traffic, so anyone nearby could read it. Today most sites use HTTPS, which changes the risk. Here's what's still exposed, and what a VPN does about it.
What HTTPS already protects
When a site uses HTTPS, the content you send and receive, such as passwords, messages and card numbers, is encrypted between your browser and the site. Someone on the same Wi-Fi can't read it. Most major sites use HTTPS everywhere.
What's still exposed on public Wi-Fi
- Which sites you visit: the network operator and others can usually see the website names you connect to, even if they can't see the pages.
- Unencrypted sites and apps: anything still using plain HTTP can be read or altered.
- Fake hotspots: an attacker can set up a network called "Airport Free WiFi" (an "evil twin") and see or redirect your traffic.
- Fake sign-in pages: some hotspots show a login page; a fake one may ask for an email password or card details.
- Your device: if file sharing is on, other people on the network may be able to see it.
What a VPN adds
- Encrypts all your traffic between your device and the VPN server, so the local network sees only that you're connected to a VPN.
- Hides which sites you visit from the Wi-Fi operator.
- Protects apps and sites that don't use HTTPS.
- Makes evil twin hotspots much less useful to an attacker.
What a VPN doesn't protect
- Phishing: if you type your password into a fake site, a VPN won't stop it.
- Malware on your device.
- Tracking by websites through cookies and accounts.
- The VPN company itself, which can see your traffic instead of the Wi-Fi operator. Choose one you trust.
Safe habits on public Wi-Fi
- Confirm the network's exact name with staff.
- Check for HTTPS before entering anything private.
- Turn off file sharing and set the network to "Public."
- Use your phone's hotspot for banking if you're unsure.
- Forget the network when you leave.
Close the WebRTC gap
Browsers use WebRTC for video calls, and it can reveal your IP address around a VPN. WebRTC Privacy Shield sets Chrome's WebRTC policy so calls go through your VPN. It isn't a VPN itself. See checking for VPN leaks and spotting fake websites.