What Actually Happens on a Public Network

When you connect to a public Wi-Fi network, your device joins a shared channel that other people in the same location are also using. In the early days of the internet, this was genuinely alarming—data sent over those networks could be read by anyone with the right software. That picture has changed substantially.

The vast majority of websites now use HTTPS (look for the padlock icon in your browser's address bar), which encrypts the data traveling between your device and the website's server. Even if someone on the same network captured your traffic, they'd see scrambled data rather than readable information. The shift to HTTPS has made casual public Wi-Fi use much safer than it once was.

That said, not every app, service, or older website uses proper encryption. And the network itself still presents some risks worth understanding before you connect.

HTTP vs. HTTPS: A Quick Distinction

HTTP (without the 'S') is the older, unencrypted version of web communication. HTTPS uses TLS encryption to protect data in transit between your browser and the server. Most major websites have switched to HTTPS, but some smaller or older sites haven't. The padlock icon in your browser's address bar is the quickest way to check which one you're using.

The Genuine Threats You Should Know

Two scenarios represent the most realistic risks on public Wi-Fi today:

Rogue Hotspots

A rogue hotspot is a fake network designed to look like a legitimate one. Someone with a laptop and basic software can broadcast a network named 'CoffeeShop_Guest' or 'AirportWifi_Free' in a crowded location. When you connect, all your traffic flows through their device first. This is sometimes called an evil twin attack. Because these networks often still provide working internet, you may not notice anything is wrong.

Unencrypted App Traffic

Not every app on your phone or computer sends data over HTTPS. Some apps—particularly older ones or those with less rigorous development—transmit information in plain text. On a public network, this data could be captured. This is harder to spot than a rogue hotspot because there's no visible warning in the app itself.

~85%

of web traffic now uses HTTPS encryption

According to Google's Transparency Report, the vast majority of pages loaded in Chrome use HTTPS, reflecting a broad industry shift toward encrypted web traffic.

1 in 4

public hotspots worldwide offer no encryption

A global Wi-Fi security report by Kaspersky found approximately 25% of public hotspots operate without any encryption, leaving unencrypted app traffic exposed.

For a broader look at the habits that reduce your overall digital exposure, see our guide to habits that keep accounts safe online.

What's Lower Risk Than You Might Think

Security headlines about public Wi-Fi often overstate the danger. Passively reading a news site, streaming a video, or searching on a well-known search engine over HTTPS involves very little risk—even on an open network. The encryption protects the content of your session.

Logging into your bank, accessing work systems with sensitive data, or submitting forms with personal details is a different matter. Those activities are where caution is warranted. The risk isn't that the network itself is malicious—it's that if something does go wrong, the consequences are greater.

Use Mobile Data for Sensitive Tasks

Your phone's cellular data connection (4G or 5G) is a private, encrypted channel—unlike a shared Wi-Fi network. If you need to log into your bank account or submit sensitive information while out, switching off Wi-Fi and using mobile data is a straightforward precaution that doesn't require any additional tools or setup.

It's also worth separating Wi-Fi reliability from Wi-Fi security. If you're experiencing dropped connections on public networks, that's a different issue entirely—our guide on dropped Wi-Fi connections covers that in detail.

Practical Steps That Actually Help

You don't need technical expertise to reduce your exposure on public Wi-Fi. A few consistent habits do most of the work:

  • Check for HTTPS. Before entering any login or personal information, confirm the site address starts with https:// and shows a padlock icon. If it doesn't, hold off.
  • Verify the network name. Ask a staff member for the exact Wi-Fi name before connecting. Rogue hotspots often use plausible but slightly different names.
  • Avoid sensitive logins. Save banking, tax, or work system access for your home network or mobile data when possible.
  • Use a VPN. A VPN encrypts all traffic from your device, which is one of the most effective defenses on any shared network. Our comparison of VPNs and incognito mode explains exactly what a VPN does and doesn't protect.
  • Keep your software updated. Updates frequently patch security vulnerabilities that could be exploited on shared networks.

For a comprehensive look at keeping your devices secure day-to-day, see everyday device security habits. And if you want a full grounding in digital privacy from scratch, our digital privacy walkthrough for non-technical users covers the full picture.

“The padlock icon in your browser doesn't mean the whole internet is safe—it means your connection to that specific site is encrypted. Understanding what encryption does and doesn't cover is the first step to making smarter decisions online.”

— Bruce Schneier, Security technologist and author of multiple books on cybersecurity and privacy