VPN for Public Wi-Fi: What Actually Puts You at Risk in Cafes and Airports
The old warnings about coffee-shop hackers are half outdated and half still true. Here's what's actually changed, and what a VPN for public Wi-Fi does and doesn't fix.
Quick answer
Public Wi-Fi is less dangerous than it was a decade ago because most web traffic is now encrypted by default with HTTPS, but real risks remain: unencrypted network traffic can still reveal which sites you visit and expose apps that skip HTTPS, rogue "evil twin" hotspots can impersonate a legitimate network entirely, and shared local networks make some older attacks easier to attempt. A VPN for public Wi-Fi closes the biggest gap by encrypting all your traffic between your device and the VPN server, so someone else on the same network can't read or tamper with it — but it doesn't stop you from being phished, doesn't verify the hotspot is genuine, and doesn't protect an account you're already logged into elsewhere. Use one as part of a small set of habits, not as a single fix for every risk.
What's actually different about public Wi-Fi versus your home network?
At home, you're (hopefully) the only person who knows your Wi-Fi password, and you control the router. On a public network — a cafe, an airport lounge, a hotel, a co-working space — the password is either shared with every other customer or there's no password at all. That single fact is the root of almost every public Wi-Fi risk you'll read about: you're sharing a local network segment with strangers whose devices and intentions you know nothing about, and in some cases you're connecting to a router that you also can't verify is what it claims to be.
This doesn't automatically mean you're being watched every time you order a latte and open your laptop. Most people connect to most public networks most of the time without incident. What it means is that the baseline level of trust you can reasonably place in the network itself is lower, and a few categories of attack that are impractical on a private home network become realistic on a shared one. Understanding which categories those are — and which ones aren't really about Wi-Fi at all — is what lets you make a sensible decision about when a VPN for public Wi-Fi actually matters and when it's a convenience add-on rather than a necessity.
Is public Wi-Fi actually dangerous, or is that outdated advice?
Some of it is genuinely outdated. A large share of the "hacker in the coffee shop" warnings that circulated widely in the early-to-mid 2010s were written when a much bigger share of everyday web traffic was unencrypted HTTP. Back then, someone else on the same network could run simple packet-capture software and directly read login pages, emails, and general browsing in plain text. That specific, easy version of the attack has become dramatically less viable because HTTPS — encryption between your browser and the website itself — is now the default for the overwhelming majority of sites, including virtually every major service you'd log into. Browsers actively warn you when a site doesn't use it, and that alone has closed off the crudest form of Wi-Fi snooping.
But "less viable" is not "eliminated," and treating public Wi-Fi as fully safe now goes too far in the other direction. HTTPS protects the content of a connection to a site that has it enabled, but it doesn't protect everything else happening on your device. Older apps, some smart-home companion apps, certain embedded devices, and misconfigured software can still make unencrypted connections without you noticing. DNS lookups — the step where your device asks "what server does this website name point to?" — have historically traveled unencrypted on most networks unless your device or apps specifically opt into encrypted DNS, which means someone watching network traffic can often still see a list of the domains you're visiting even when the content of those visits is encrypted. And HTTPS does nothing at all about the network-level attacks described below, because those happen before your traffic even gets to the point of being HTTPS-protected or not.
What can someone else on the same network actually see or do?
There are a few distinct categories worth separating, because they have different causes and different fixes.
Passive packet sniffing. On an open network with no password, or a network using an older, weaker Wi-Fi encryption standard, another device on the same network can potentially capture the raw wireless traffic passing through the air. If the traffic itself is HTTPS-encrypted, the attacker gets an encrypted blob they can't read. If it's plain HTTP, or if it's DNS traffic, they can potentially read it directly. This is the classic "coffee shop hacker" scenario, and it's real, just narrower in scope than it used to be because so much less traffic today is unencrypted at the application layer.
Rogue or "evil twin" access points. This is a more serious and more current risk. Rather than passively listening, an attacker sets up their own Wi-Fi access point with a name that mimics or duplicates the legitimate one — "Airport_WiFi_Free" instead of the real "Airport-Guest-WiFi," or an exact copy of a cafe's network name broadcast from a device sitting a few tables away. If you connect to the fake one instead of the real one, all your traffic passes through a device the attacker controls before it goes anywhere else. They can't break HTTPS encryption itself, but they can see which sites you're connecting to, they can serve you fake captive-portal login pages designed to harvest credentials, and they can attempt to downgrade or interfere with connections that aren't strictly enforcing HTTPS.
ARP spoofing and local network manipulation. On a shared local network, it's technically possible for another device to trick your device into routing its traffic through theirs, using a network-layer trick called ARP spoofing. This is a more technical attack that requires the attacker to already be on the same network and have some tooling in place, but it's squarely a "shared local network" problem — the kind of thing that essentially can't happen on your home network where you control every device connected to it.
DNS manipulation. A malicious or compromised access point can control what DNS server your device uses, which means it can potentially redirect a domain name to a different server than the real one — for example, sending you to a convincing fake login page for a banking site instead of the real one, even though you typed the correct address. This is one of the more dangerous public Wi-Fi risks precisely because it can happen without any visible sign that something's wrong.
Session hijacking on non-HTTPS or misconfigured sites. A small but nonzero number of sites and services still don't enforce HTTPS everywhere, or set session cookies in a way that can be intercepted on an unencrypted connection. If that happens on a shared network, an attacker who captures the right piece of data can potentially impersonate your logged-in session without ever seeing your password.
What is an "evil twin" network, and how would I even know?
An evil twin is simply a Wi-Fi access point set up specifically to impersonate a real one — same or similar network name, sometimes even the same password if the attacker knows it or leaves the network open. Your device generally can't tell the difference between a legitimate "Starbucks_WiFi" and a fake one broadcasting the identical name from a small device in someone's bag; Wi-Fi network names are not cryptographically verified the way, say, an HTTPS certificate is. Most phones and laptops will happily connect to whichever access point has the strongest signal among networks with a name they've seen before, which is exactly the vulnerability an evil twin exploits.
In practice, there's rarely an obvious visual sign you've connected to a fake network instead of the real one — that's the entire point of the attack. A few weak signals are worth noticing: an unusual number of networks with nearly identical names in the same location, a captive portal page that looks visually off or asks for unusual information (a full mailing address, a credit card "for verification," anything beyond a name and email or a simple click-through), or a network that appeared only after you sat down and wasn't there when you last visited the same location. None of these are reliable on their own. The more dependable defense isn't spotting the fake network — it's making sure that even if you do connect to one, the attacker gets nothing usable, which is exactly the problem a VPN for public Wi-Fi is designed to solve.
Does a VPN fix all of this, or just some of it?
A VPN encrypts the connection between your device and the VPN provider's server, and routes all your device's traffic through that encrypted tunnel before it goes out to the wider internet. Once that tunnel is established, whatever access point you're connected to — real or fake — sees only encrypted traffic going to a single VPN server address. It can't read the content of your traffic, and in most implementations it can't easily see which specific sites you're visiting either, because that lookup and connection now happens on the other side of the tunnel. That directly neutralizes passive packet sniffing, and it substantially reduces the value of connecting to an evil twin network, because even a fully attacker-controlled access point is left holding only encrypted traffic it can't decrypt or usefully manipulate.
It's worth being precise about what a VPN doesn't do, because overstating its protection is just as unhelpful as ignoring the risk entirely. A VPN doesn't verify that a Wi-Fi network is legitimate before you connect — you can still join an evil twin network in the first place; the VPN just limits what the attacker gets once you're on it. It doesn't protect you from phishing — if a fake captive portal or a fake login page tricks you into typing a password directly into it, a VPN running in the background doesn't stop that, because the compromise happens at the input stage, not the network stage. It doesn't protect an account that's already logged in on a device that gets physically accessed, and it doesn't substitute for basic account security like unique passwords and two-factor authentication. Think of a VPN on public Wi-Fi as removing the network itself as an attack surface, not as a general-purpose security product that covers every threat you might encounter while out with your laptop.
What does a VPN for public Wi-Fi actually need to do well?
Not every VPN feature matters equally for this specific use case. A few are genuinely important:
A kill switch
A kill switch blocks your device's internet access if the VPN connection drops unexpectedly, rather than silently falling back to your normal, unprotected connection. On a public network, where Wi-Fi drops and reconnects are more common than on a stable home router, this matters more than it does at home — without it, a brief VPN disconnect on an untrusted network could expose whatever traffic happens to be in flight at that moment without you noticing.
Reliable, fast reconnection
Public Wi-Fi tends to be flakier than home broadband — more people sharing bandwidth, weaker signal in some spots, and networks that occasionally bounce your device off entirely. A VPN that reconnects quickly and automatically after a drop is more useful in this environment than one that requires you to manually restart the connection every time the network hiccups.
DNS leak protection
This ensures that DNS lookups — the step that translates a site name into a server address — are routed through the encrypted tunnel too, rather than leaking out to the local network's own DNS server in plain text. Without it, a VPN can encrypt your browsing traffic while still leaking a readable list of every domain you visit to whoever is watching the local network, which defeats a meaningful part of the point on public Wi-Fi specifically.
An easy, low-friction connect step
A VPN you have to remember to turn on, and reliably forget to when you're rushing to catch a flight, protects you less in practice than a slightly less feature-rich one you actually use consistently. Some VPN apps offer a setting to auto-connect whenever the device joins a network that isn't on a trusted list; if you regularly work from cafes or travel, that kind of automatic behavior is worth more day to day than most of the feature checklist items that get more marketing attention.
Do I need a VPN if I'm just checking email or scrolling social media?
This depends more on what "just checking" actually involves than people usually assume. If you're only reading content on a well-known, HTTPS-enforcing app or site and not entering anything sensitive, the immediate risk from passive sniffing is low, because the connection to the app's own servers is already encrypted independently of Wi-Fi. But a few things quietly raise the stakes even for "light" browsing: DNS lookups for every site you visit can still be observable to the local network regardless of what you're doing on those sites, which reveals a behavioral trail even without exposing content. If you're on a network you didn't verify — and most people never do — you also can't be fully sure you're not on an evil twin, in which case even "just scrolling" traffic gets routed through a party you don't trust for the duration of the session, with the exposure only growing the longer you stay connected. And most sessions that start as "just checking email" don't stay that way — a quick check turns into logging into a work portal, a bank app, or making a purchase, at which point the stakes for that session are higher than they were a few minutes earlier. The practical answer for most people is that running a VPN by default on any network you don't personally control removes the need to constantly judge in the moment whether a given task is "sensitive enough" to warrant it.
Is airport or hotel Wi-Fi worse than a coffee shop's?
Not inherently, but a few features of travel-specific networks do shift the risk profile. Airports and hotels are higher-value targets simply because of the volume and predictability of travelers passing through — people who are tired, distracted, in a hurry, and more likely to click through a captive portal without scrutinizing it. Airport and hotel networks also often require going through a browser-based login or "click to accept terms" captive portal, and that portal page is itself a plausible target for spoofing, since travelers expect to see one and generally aren't surprised by unusual-looking login flows in an unfamiliar place. Large, multi-day hotel stays also mean a longer window of repeated connection to the same network, which gives any attacker already positioned on it more opportunities than a twenty-minute coffee-shop visit would.
Hotel and airport Wi-Fi also sometimes fails to isolate guest devices from one another, depending on how the local network is configured — some networks properly segment each device so guests can't see each other at all, while others are closer to an old-style shared network where devices are more exposed to one another. Because you generally have no way to know which setup a given hotel or airport is running, treating both categories the same way — connect, then immediately enable your VPN before doing anything else — is the simpler and more reliable habit than trying to judge each network's trustworthiness on the fly.
Will a VPN break the captive portal login page?
Usually not, if you sequence it correctly, but it's a common point of confusion. Captive portals — the "click to agree" or "enter your room number" pages that many public networks show before granting internet access — work by intercepting your very first web request after you join the network and redirecting it to their login page. If your VPN is already running and trying to route all traffic through an encrypted tunnel before you've completed that portal step, the portal sometimes can't intercept the request properly, and you may see a "no internet" error even though you're technically connected to the Wi-Fi.
The fix is almost always sequencing: join the Wi-Fi network first, complete the captive portal's login or click-through screen with the VPN off or in its disconnected state, and only then turn the VPN on once you have general internet access. Most VPN apps handle this smoothly on their own or prompt you when a captive portal is detected; if yours doesn't, doing it manually in that order resolves the vast majority of "my VPN won't connect on this Wi-Fi" situations you'll run into at airports and hotels specifically.
Should I just use my phone's mobile data hotspot instead?
A cellular hotspot from your own phone plan is, from a network-trust standpoint, meaningfully different from a public Wi-Fi network — you're not sharing a local network segment with strangers, and the kind of local-network attacks described above (evil twins, ARP spoofing, a shared access point) don't apply in the same way, because there's no shared local network in the middle. That makes a personal hotspot a genuinely strong alternative to public Wi-Fi when the situation allows for it, and combining a VPN with a cellular connection is not redundant — the VPN and the cellular connection protect against different things, and running both together is a reasonable choice for particularly sensitive tasks.
The realistic limits are practical, not security-related: hotspot data usage counts against your mobile plan's allowance and can get expensive or hit data caps quickly, especially for anything involving video calls, large downloads, or extended work sessions. Cellular signal can also be weak or congested in exactly the places public Wi-Fi tends to be offered as an alternative — packed airport terminals, conference venues, basement-level cafes. For a quick, sensitive task like checking a bank balance or logging into a work account, a personal hotspot is a solid option when signal and data allowance permit it. For longer sessions of general browsing or work, a VPN over the venue's public Wi-Fi is usually the more practical default, and the two approaches aren't mutually exclusive — some people default to Wi-Fi-plus-VPN for everyday use and switch to a hotspot specifically for the handful of tasks each day that feel highest-stakes.
Are free VPN apps safe to use on public Wi-Fi?
This is worth thinking through carefully rather than assuming "any VPN is better than none," because the economics of a free VPN app matter. Running VPN server infrastructure costs money, and a provider offering the service for free has to fund that somehow — through advertising inside the app, through a paid tier the free version funnels you toward, or in less transparent cases, through collecting and using data about your traffic and browsing in ways a paid, policy-driven provider has a direct financial incentive not to. That last possibility is particularly relevant to the public Wi-Fi use case specifically, because the entire point of using a VPN there is to stop a third party from seeing your traffic — if the VPN provider itself is that third party, you haven't actually solved the problem, you've just moved who's watching.
This isn't a blanket claim that every free VPN is harvesting data, and we're not going to assert that as fact about any specific app without evidence. It's a structural point: a free product needs a revenue model, and it's worth understanding what that model is before trusting it with all your traffic on a network you already don't fully trust. A few practical checks help here regardless of which provider you're evaluating — does the app have a clear, specific privacy policy rather than vague marketing language, is the company identifiable and reachable, and does it explain what data it does and doesn't collect in concrete terms rather than only using the phrase "we respect your privacy" without specifics. Some app-store VPN apps, particularly ones that appear and disappear quickly or have no identifiable company behind them, are worth treating with more skepticism than a small monthly subscription fee from an established, named provider. If budget is a genuine constraint, a lower-cost paid option is generally a more defensible choice for this specific use case than an unfamiliar free one, precisely because the incentive structure is more aligned with what you're actually trying to get out of it.
Does my company's VPN already protect me on public Wi-Fi when I'm working remotely?
Sometimes, but not always in the way people assume, and it's worth understanding the difference before relying on it. A corporate VPN is typically designed to give you secure access to internal company systems — file servers, internal tools, resources that shouldn't be exposed to the open internet — by creating an encrypted tunnel from your device into the company's network. In many configurations, that also happens to route all of your general internet traffic through the encrypted tunnel too, in which case it does provide the same network-level protection against public Wi-Fi risks that a personal VPN would, for as long as it's connected.
But not every corporate VPN setup works that way. Some are configured as "split tunnel," where only traffic destined for internal company resources goes through the encrypted connection, and everything else — general browsing, personal accounts, anything not related to work systems — goes out over the regular, unencrypted local network connection exactly as it would with no VPN at all. In a split-tunnel setup, being connected to your work VPN gives you no public Wi-Fi protection whatsoever for anything outside the company's own systems, which is a common source of false confidence. If you're not sure which setup your employer uses, it's a reasonable question to ask your IT department directly, since the answer changes whether you need a separate personal VPN for your own browsing and accounts while working from a cafe or airport. It's also worth checking whether your employer's policy allows a personal VPN to run alongside a company one in the first place — some corporate security policies restrict this, so this is a case where the practical answer depends on rules specific to your workplace, not a general rule about VPNs.
What non-VPN habits matter just as much on public Wi-Fi?
A VPN addresses the network layer, but several other habits close gaps a VPN doesn't touch at all, and skipping them while relying entirely on a VPN leaves real exposure:
Keep your operating system and apps updated
Security patches routinely close vulnerabilities that could otherwise be exploited by another device on the same local network — a class of risk that's specific to shared networks and that a VPN doesn't address, since it concerns your device's own software rather than the traffic passing through it.
Turn off automatic Wi-Fi connection to open networks
Most phones and laptops have a setting that automatically joins previously-used or open networks without asking. This is convenient but also exactly the setting that makes it easiest to end up on an evil twin network without ever consciously choosing to connect to it. Requiring a manual tap or click to join any new network gives you a moment to actually notice what you're connecting to.
Use two-factor authentication on important accounts
If a password does get compromised through a phishing page or a captive-portal spoof, two- factor authentication is what stops that compromise from turning into full account access. This protects you regardless of what network you're on, which makes it one of the highest-value habits generally, not just a public Wi-Fi consideration.
Watch for HTTPS on anything that asks for a password or payment details
Browsers flag connections that aren't using HTTPS, typically with a warning or a "not secure" label in the address bar. Getting in the habit of glancing at that indicator before entering credentials or payment information — VPN or no VPN — closes gaps that exist independently of which network you're on.
Be skeptical of captive portals that ask for more than a click-through
A legitimate hotel or cafe captive portal typically asks for, at most, a room number, a name and email, or a simple agreement to terms. One that asks for a full payment card number, a government ID, or other unusual personal details for "free Wi-Fi access" is a stronger signal of a spoofed portal than almost anything else on this list, and is worth declining regardless of how plausible the surrounding network name looks.
Log out of sensitive sessions when you're done, on shared devices especially
This one isn't specific to public Wi-Fi at all, but it matters more in public settings where you're more likely to be using a shared computer — a hotel business center, a library — or stepping away from your own device briefly in a way you wouldn't at home.
How should I actually choose a VPN for this use case?
For public Wi-Fi specifically, prioritize the operational basics covered above — a kill switch, DNS leak protection, and reliable reconnection — over more marketing-driven feature lists, since those are the features that determine whether the protection actually holds up when a cafe's Wi-Fi drops mid-session or you jump between airport gate networks. Beyond that, ease of use matters more here than in most VPN use cases, precisely because the situations where public Wi-Fi protection matters most — rushing through security, working from an unfamiliar cafe, on a laptop balanced on your knees in an airport gate — are exactly the situations where a clunky app is most likely to get skipped.
Among the providers we cover on this site, the general positioning differs enough to be worth knowing before you dig into full reviews. NordVPN is a large, long-established provider known for a broad server network and apps across a wide range of platforms, which is useful if you regularly switch between a laptop, phone, and tablet on different networks. Proton VPN is built by the team behind Proton Mail and leans into privacy-first engineering and a Swiss legal jurisdiction, which may matter to you if jurisdiction and policy transparency weigh heavily in your decision alongside the public Wi-Fi use case specifically. PureVPN is a veteran provider with a large server footprint and additional security add-ons bundled alongside the core VPN app. FastestVPN is positioned toward users who want core VPN functionality — encryption, a kill switch, server switching — at a lower price point, which is a reasonable trade-off if your main use case really is limited to occasional cafe and airport sessions rather than an always-on daily habit. We don't publish scores, star ratings, or pricing claims for any of these providers until we can verify them directly, so read the individual reviews for the fuller, evolving picture rather than treating any summary — ours included — as the final word.
Does any of this change when I'm traveling internationally?
The underlying network risks — evil twins, unencrypted DNS, shared local networks — are the same wherever you are; public Wi-Fi in an airport abroad isn't inherently more or less risky at the technical level than one at home. A few practical factors do shift, though. Roaming cellular data is often more expensive or simply unavailable on your home carrier's plan while traveling, which pushes more people toward relying on hotel and airport Wi-Fi for longer stretches than they would at home, increasing the amount of time spent on networks you don't control. Unfamiliar surroundings also make it harder to judge whether a network name or a captive portal looks legitimate, since you don't have the same baseline familiarity with what "normal" looks like at a venue you've never been to before.
A separate and genuinely different consideration when traveling is that a small number of countries restrict or regulate VPN use, sometimes significantly. This has nothing to do with public Wi-Fi risk specifically, but it's relevant if your travel plans include a country with such restrictions — it's worth checking the current legal situation for your specific destination before you travel, rather than assuming VPN use is treated the same everywhere. For a fuller look at planning VPN use around travel generally, including this jurisdiction question, see our guide to VPNs for international travel.
A practical checklist for cafes, airports, and hotels
Pulling the above into something usable in the moment:
- Confirm the exact network name with staff if there's any ambiguity, rather than picking the first similarly-named option from the list.
- Join the network, complete any captive portal login with the VPN off, then turn the VPN on before doing anything else.
- Make sure your VPN's kill switch is enabled so a dropped connection doesn't silently fall back to the open network.
- Avoid entering payment details or sensitive credentials into any captive portal page that asks for more than a name, email, or simple agreement.
- For a handful of especially sensitive tasks — banking, work systems with confidential data — consider a personal cellular hotspot instead of, or alongside, the venue's Wi-Fi if your data plan allows it.
- Keep automatic connection to open or previously-used networks turned off, so you have to consciously choose each network rather than joining one automatically.
- Turn on two-factor authentication for your important accounts as a backstop that doesn't depend on the network being safe in the first place.
None of these steps require deep technical knowledge, and none of them alone is a complete solution. Together — a VPN doing the job it's actually good at, plus a small set of habits that cover what it isn't designed to touch — they cover the realistic range of things that can go wrong on public Wi-Fi without requiring you to treat every cafe visit as a security emergency.
Frequently asked questions
Is public Wi-Fi still dangerous now that most websites use HTTPS?
Less dangerous than a decade ago, but not risk-free. HTTPS protects the content of your connection to sites that enforce it, which closes off the crudest form of Wi-Fi snooping. It doesn't protect DNS lookups on most networks, doesn't stop rogue "evil twin" access points from impersonating a legitimate network, and doesn't cover apps or older sites that skip HTTPS entirely.
Does a VPN completely protect me on public Wi-Fi?
It protects the parts of the risk that come from the network itself — it encrypts your traffic so someone else on the same Wi-Fi can't read or tamper with it, even on a fake or compromised access point. It does not protect you from phishing pages, from typing a password into a fake captive portal, or from an account that's already logged in on your device.
Why won't my VPN connect at the airport or hotel Wi-Fi login page?
This is almost always a captive portal sequencing issue. Join the Wi-Fi network, complete the venue's login or click-through page with the VPN off, and only then turn the VPN on. Trying to route traffic through an encrypted tunnel before completing the portal step often blocks the portal from loading at all.
Is a mobile hotspot safer than public Wi-Fi with a VPN?
A personal cellular hotspot avoids the shared-local-network risks that public Wi-Fi carries, such as evil twin networks and other devices on the same network, because there's no shared network segment involved. It's a strong option for a handful of sensitive tasks, though data caps and weak cellular signal in crowded venues limit it as a full-time replacement for Wi-Fi plus a VPN.
What is an "evil twin" Wi-Fi network?
It's a fake access point set up to mimic a legitimate network's name, so devices connect to it instead of the real one. Once connected, the attacker controlling it can see which sites you visit and may attempt to serve fake login pages, though a VPN running on the connection prevents them from reading or altering your actual traffic.
Do I need a VPN for quick tasks like checking email on public Wi-Fi?
Even brief, low-stakes browsing exposes a readable trail of which domains you're visiting to the local network in most setups, and short sessions have a habit of turning into logging into something more sensitive. Running a VPN by default on any network you don't personally control removes the need to judge each task individually.