Knowledge · Check before you click or pay · 7 minutes

Is public Wi-Fi safe? What protects you and when a VPN helps

Public Wi-Fi in cafes and airports: what HTTPS protects today, the real risk of fake hotspots and login portals, when a VPN helps and why free VPNs can hurt.

Last updated: October 6, 2026

Is public Wi-Fi safe in 2026?

Public Wi-Fi is a wireless network shared by many strangers, often with no password or with one printed on the wall. Years ago, joining one meant the person next to you might sniff your passwords. That picture has changed.

In its phone security guide, CERT Polska states plainly that warnings about cafe eavesdropping describe how things were years ago. Most sites that require a login use HTTPS, an encrypted connection between your device and the server. It works the same on your home network, on mobile data and on a hotspot. Someone sniffing an open network sees only scrambled data.

The US Federal Trade Commission (FTC) takes a similar view: using public Wi-Fi is usually safe because encryption is now widespread. Older Polish government guidance (the gov.pl section on mobile devices) still advises against logging in to banking or email on public networks, or suggests mobile data or a VPN instead. That advice does no harm, but the newer guide from CERT Polska, the incident response team run by the research institute NASK, says that with HTTPS everywhere, password sniffing on public networks describes the situation of years ago and a VPN is not necessary for basic safety.

Why can public Wi-Fi be dangerous? The real risks

The risks did not disappear, they moved. Here is what can realistically happen:

1. A fake network. Someone sets up a hotspot with a convincing name, such as "Airport_Free". HTTPS still protects data sent to real sites, but the network can redirect you to a fake login page. That is ordinary phishing, covered in what phishing is and how to spot it.

2. A login portal. Many networks open a page with terms or a form when you connect. If it asks for your email password, card details, a bank login or an app install "to get online", walk away. Free Wi-Fi normally needs only acceptance of the terms, sometimes a phone number.

3. Unencrypted sites. Browsers clearly warn when a connection is not encrypted. On such a page, type nothing you would not say out loud in the cafe.

4. Visibility. The network owner cannot read encrypted pages but may see which services you connect to. Google's Chrome help notes that organisations managing your network may be able to observe your activity.

5. Device tracking. A phone is recognised on a network by its hardware (MAC) address. Apple uses private Wi-Fi addresses, a different one per network, so hotspot operators cannot link your visits. Since iOS 18 and macOS Sequoia (2024), the address on weakly secured or open networks rotates every 2 weeks by default.

How to use public Wi-Fi safely: a checklist

1. Before typing a password, look at the address bar. The domain matters, not the padlock. Scammers can have HTTPS too. We explain how to read an address in how to check if a website is safe.

2. Open your bank from its app or by typing the address yourself, never from a link shown after you join a network.

3. Do not install anything a hotspot page asks for.

4. Turn off auto-join for open networks and remove networks you no longer use.

5. Turn off file and printer sharing on your laptop on public networks (on Windows, choose the public network profile).

6. Turn on two-step verification for important accounts. Even if you type a password on a fake page, the password alone is not enough. See what two-step verification is.

7. Keep your system and browser updated. CERT Polska names updates as one of the simplest ways to protect a phone.

8. For something serious (a large transfer, logging in to company systems) on a network you are unsure about, switch to mobile data or your own phone's hotspot.

Not sure about a site the hotspot portal sends you to? You can check the domain for free: you will see its age, whether it is on the CERT Polska warning list and whether it resembles a known brand.

Does incognito mode hide anything on public Wi-Fi?

No. Incognito (private) mode stops the browser from saving history, cookies and form data on your device. Google's Chrome help says the sites you visit and organisations that manage your network, such as a school, employer or internet provider, may still see your activity. The same applies to a hotspot owner.

Incognito is useful on someone else's computer so you do not leave a session logged in. It does not protect you from the network.

Is a VPN worth it, and when does it make sense?

A VPN (virtual private network) is an encrypted tunnel between your device and the VPN provider's server. The hotspot owner then sees only that you connect to a VPN. Everything else is visible to the VPN provider. Trust does not disappear, it moves to another company.

CERT Polska's view is that with HTTPS everywhere, a VPN is not necessary for basic safety on public networks. The UK NCSC says something similar in its VPN guidance (reviewed May 2025): if none of the benefits of a VPN apply to you, there is no need to use one.

A VPN makes sense when:

1. Your employer requires it to reach company systems. Use the one the company provides.

2. You do not want the network owner to see which services you use.

3. You are on a network you genuinely distrust and have no mobile data.

A VPN does not protect you from phishing, malicious apps, weak passwords or a data breach at a service. It also does not make you anonymous to sites you log in to.

Is a VPN safe? What to check before you choose one

VPN safety depends on the provider, not on the technology. A study of 283 Android VPN apps (CSIRO Data61 and ICSI, IMC 2016 conference) showed that marketing promises are not enough: 18% tunnelled traffic without encryption, about 84% did not route IPv6 traffic through the tunnel and about 66% leaked DNS traffic. Four apps intercepted encrypted (TLS) connections and two injected advertising code into pages. The data is old, but it shows what to ask.

Before choosing a VPN, check:

1. The business model. What you pay for, and if nothing, who pays the provider and for what.

2. The privacy policy: what connection data is logged, for how long and who it is shared with.

3. An independent security or no-logs audit, with a date and the auditor's name. A claim on a website is not an audit.

4. The protocol. Look for open, well-known protocols (such as IPsec, WireGuard or OpenVPN), not undocumented "proprietary technology".

5. Protection against DNS and IPv6 leaks, plus a kill switch that cuts the connection if the tunnel drops.

6. App permissions. A VPN does not need your contacts or text messages. In the same study, 82% of apps requested access to sensitive data such as user accounts or text messages.

7. Who is behind the app: full company name, country and contact details. See how to check if an app is safe.

Free VPNs: are they worth it and are they safe?

A free VPN has to make money somehow, usually through ads, tracking or selling traffic data. In the study above, 75% of the free VPN apps that promised privacy protection contained at least one third-party tracking library, and over 38% of all apps studied had at least one malware detection on VirusTotal. According to the authors, about 16% of the apps may have routed traffic through other users' devices, in which case strangers' traffic can pass through your connection.

The practical takeaway: if you do not need a VPN, do not install a free one "just in case". You would give an unknown company a view of all the traffic that, without a VPN, only the cafe network owner could partly see. If you do need one, choose it using the checklist above, and judge VPNs built into browsers or antivirus products by the same criteria.

In short

  • Public Wi-Fi is usually safe for HTTPS sites. According to CERT Polska, encryption protects your data regardless of the network.
  • The biggest real risk is a fake network or login portal that leads to a copycat page. Always read the domain in the address bar.
  • Incognito mode hides nothing from the network owner.
  • A VPN is not required for basic safety. It moves trust from the network owner to the VPN provider, so choose one by business model, audit and permissions.
  • Free VPNs often make money from your data. Without a specific need, it is better not to install one.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is public Wi-Fi safe for online banking?

Banking apps and sites use encryption which, according to CERT Polska, protects data on public networks too. Still, open your bank from its app or a typed address, never from a link shown by a hotspot page, and for large transfers you can switch to mobile data.

Can someone on public Wi-Fi see what I do in incognito mode?

Partly, yes. Incognito does not save history on your device, but the network owner may see which services you connect to. They cannot read the content of HTTPS pages.

Is a VPN worth having every day?

For most people it is not necessary, because sites and apps encrypt their connections. It is worth it when your employer requires one, when you do not want the network owner to see which services you use, or on a network you do not trust.

Is a VPN safe?

It depends on the provider. A VPN sees all your traffic, so check its business model, logging policy, independent audit, protocol and app permissions. Research on VPN apps found cases of missing encryption and ad injection.

Are free VPNs safe?

Often nobody knows. Free services usually earn money from ads and user data, and in a 2016 study of 283 VPN apps, 75% of the free apps promising privacy contained tracking libraries. If you do not need a VPN, not installing one is the safer choice.

Why is public Wi-Fi considered dangerous?

Because years ago most sites did not encrypt connections and passwords could be sniffed. Today the main risk is fake networks and login portals that lead to copycat pages, in other words phishing.

How can I spot a fake Wi-Fi network?

Often you cannot from the outside, because anyone can choose a network name. Ask staff for the exact name, give the hotspot page nothing beyond accepting the terms and do not install anything it asks for.

Sources

  1. CERT Polska: Phone security guide (wiedza.cert.pl, Public Wi-Fi chapter)
  2. Polish government portal gov.pl, knowledge base: Using mobile devices
  3. Federal Trade Commission: Are Public Wi-Fi Networks Safe? What You Need To Know
  4. Google Chrome Help: Browse in Incognito mode
  5. Apple: Use private Wi-Fi addresses on Apple devices
  6. NCSC (UK): Virtual Private Networks guidance (reviewed 13 May 2025)
  7. Ikram et al.: An Analysis of the Privacy and Security Risks of Android VPN Permission-enabled Apps (IMC 2016)

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also