Is public Wi-Fi safe? What a VPN adds, what it does not

The advice changed over the last few years. Here is the current picture, without the scare stories.

Safer than the old warnings, with three gaps left

Usually, yes. The FTC's consumer guidance now says connecting through public Wi-Fi is usually safe, because almost every site and app encrypts its traffic. The risks that remain are narrower than the old warnings suggest: the network owner sees which services you use, fake hotspots exist, and no network setting protects you from a phishing page.

Why the advice changed

Ten years ago a lot of the web still ran on plain HTTP, so anyone on the same café network could read pages and sometimes grab login cookies. Browsers and sites have since moved to HTTPS almost everywhere, and modern apps encrypt by default. The danger moved from "someone reads your traffic" to "someone tricks you into handing over a password", which is a different problem with a different fix.

Browsers also learned to refuse insecure versions of sites they have seen before, and sign-in cookies are now usually marked so they only travel over encrypted connections. Old tricks such as reading a neighbor's session from the café network mostly stopped working because of changes like these, not because cafés got better at security.

What an open network still exposes

  • The names of the services your devices contact, visible in DNS lookups and connection details.
  • Your device name and hardware address, often collected by the login page.
  • Traffic from older apps or smart gadgets that still skip encryption.
  • You, to a look-alike network if your phone joins it automatically.

Do VPNs protect you on public Wi-Fi?

For the first, third and fourth points, yes. With a VPN key on, the café or library sees one encrypted connection to our server. DNS lookups travel inside it, unencrypted app traffic gets wrapped, and a fake hotspot gains nothing readable.

It does nothing about phishing. If you type your password into a fake bank page, the password goes to the scammer through a perfectly encrypted tunnel. Two-factor sign-in and checking the address bar handle that part.

ViewPoint VPN drafted this page with AI assistance, using the service's own setup and the FTC guidance cited below. We sell VPN keys, so read the verdict with that in mind.

Habits that matter more than the network

  • Turn off automatic joining of open networks.
  • Keep two-factor sign-in on for email, banking and cloud storage.
  • Update your phone and laptop; old software is the bigger hole.
  • Read the address bar before typing a password.
  • Prefer your phone's hotspot for anything sensitive if your plan allows it.

Libraries, coffee shops and campuses

Library and coffee shop networks are usually open with a simple login page, so the habits above apply as written. Campus networks often require a university account and may filter some sites; a key can carry your traffic through the filter on an ordinary connection, but check your school's acceptable use rules before you rely on it.

Questions

Is it safe to use public Wi-Fi for online banking?

Through the bank's app or its HTTPS site, generally yes. Avoid typing passwords on a page you reached from a link in a message.

Can someone on the same Wi-Fi see my screen or files?

Not your screen. Shared folders could be visible if file sharing is on, so turn it off on public networks.

Is a VPN enough on its own?

No. It protects the connection, not your accounts. Pair it with two-factor sign-in and updates.

Is Starbucks Wi-Fi safe?

It works like any open network: fine for HTTPS, with the usual care about fake networks and automatic joining.

Do I need a VPN on my phone's hotspot?

Not for the Wi-Fi part, since only your devices are on it. Your mobile carrier still sees which services you use.

What is the one setting to change today?

Turn off automatic joining of open networks on every device.

Back to Wi-Fi

Your key is at the desk

Five free days, five devices, no card. Pick it up in Telegram.

Get 5 days freeOpens Telegram