
For years, every article about public Wi-Fi opened the same way: a hacker at the next table could see your passwords, read your email, and empty your bank account. That was overstated then and is mostly out of date now — the web changed underneath the advice. The real risks of free Wi-Fi in 2026 are different, narrower, and worth understanding clearly so you spend your caution on the right things.
What changed since the old warnings
Almost every site you care about now uses HTTPS by default. That padlock means traffic between your device and the server is encrypted end to end. Even on a hostile network, someone nearby cannot read your traffic — not your passwords as you type them, not your email, not your bank balance. This one change knocked down the most dramatic part of the old story. The classic “Wi-Fi sniffing” attack against an HTTPS site simply does not work anymore.
What is still risky
That does not make free Wi-Fi harmless. The risks just moved into a smaller set of categories worth taking seriously.
Fake networks
The most common modern attack is not eavesdropping, it is impersonation. An attacker stands up a network called “Airport_Free_WiFi” or “Starbucks Guest” and waits. Once you connect, they control the route to the internet — a classic evil twin. They cannot break HTTPS, but they can serve fake login pages, redirect downloads, or push “install this app” prompts. The defense is simple: mind the network name. If unsure which is real, ask staff. “Airport Wi-Fi” and “Airport-WiFi” are not the same thing.
Captive portals
The login page that pops up on a café network is a captive portal, and it often wants an email before letting you online. That address feeds the venue’s marketing system, sometimes resold to partners. This is a privacy and spam problem, not a hacking one — and it is the case I built LettMail for. Hand the portal a temporary email, click the confirmation link, get online, and let the address expire while your real inbox stays clean. (More everyday cases like this.)
Non-HTTPS connections
The few services still on plain HTTP — some legacy email setups, old hardware admin pages — do expose data on hostile networks. The category has shrunk hugely but not vanished. If your work still has an HTTP-only internal portal, do not use it over public Wi-Fi.
Outdated devices
An old laptop or phone missing years of security updates is more exposed on any network. Attackers on the same Wi-Fi can probe known holes in old systems. Keep devices patched; if one cannot get current updates, keep it off public networks for anything sensitive.
Shoulder surfing
Unglamorous and effective: the person two seats over can read your screen. A privacy filter costs less than a meal and removes most of it.
The VPN question
Should you use a VPN on free Wi-Fi? Probably, but for clearer reasons than the ads suggest. A VPN tunnels your traffic through an encrypted link to a server you choose, so a local attacker sees only encrypted traffic to your provider — useful against the impersonation and DNS games fake networks play. What it does not do is make you anonymous: the VPN provider sees what the local network would have. Pick one with a transparent no-logs policy and a real audit, not the loudest sponsor of the week.
A practical free Wi-Fi routine
- Verify the network name with staff. Use only the posted one.
- Use a temporary email for captive portals. Keep your real address off the venue’s marketing platform.
- Turn off auto-join for open networks, so your phone will not silently connect to a lookalike elsewhere.
- Use HTTPS-only mode in your browser.
- Run a VPN for general traffic, especially if you travel or work from cafés often.
- Disable file sharing and AirDrop in public.
- Save sensitive logins for trusted networks — and if a login ever feels phished, check how to spot it.
The hotel and Airbnb variant
Hotel networks are much like café networks, but they often expose cheap routers and smart-TV admin pages on the same subnet as your laptop. Same advice, plus one addition: do not assume the room’s smart TV is friendly. Avoid signing into personal streaming accounts on hotel TVs unless there is a clear sign-out for the TV itself. The previous guest who logged in and forgot is a story you do not want to repeat.
What you do not need to worry about
For balance, what is no longer a meaningful risk on free Wi-Fi:
- Someone reading your password as you log into a normal modern site
- Someone reading your webmail through any current provider’s interface
- Someone seeing your bank dashboard
All protected by HTTPS, which the attacker cannot break (the underlying trick is a man-in-the-middle attack, and modern encryption defeats it). The story moved on; use that to focus on what is still real.
The quiet default
Free Wi-Fi is part of normal life — you will use it dozens of times this year. The right mindset is not fear but a quiet routine: confirm the network, use a temporary email for the portal, keep devices updated, run a VPN, and let HTTPS do the heavy lifting. Then stop thinking about the network and get back to the coffee.