Public WiFi is useful in airports, hotels, libraries, cafés, and shared offices, but the network name alone does not prove that a connection is safe. For routine browsing, the risk is often manageable when your device and websites use current encryption. The safer habit is to verify the hotspot, keep your device updated, and postpone sensitive work when you can.

Before you join a public WiFi network
Ask the staff for the exact network name and whether a sign-in page is required. A fake hotspot can copy a familiar name or add one extra word. If the network name appears twice, has a spelling mistake, or asks you to install an unfamiliar app or certificate, do not connect.
Turn off auto-join for open networks on your phone and laptop. Keep your operating system, browser, and security software updated before traveling. Updates close known problems that a public network can expose, and they do not replace the need for careful browsing.
Use the sign-in page without giving away too much
A legitimate captive portal may ask for a room number, email address, or a short access code. It should not ask for your banking password, email password, device passcode, or a full payment card number just to provide basic WiFi. If the page redirects repeatedly, shows a certificate warning, or asks you to download a profile, close it and ask the venue for help.
Check the address bar after the portal finishes. Look for HTTPS on the website you intend to use, not just on the portal. HTTPS protects the connection between your browser and that website, but it does not prove that the hotspot itself is genuine.
What is usually fine, and what should wait
| Task | Better choice |
|---|---|
| Reading news or checking directions | Usually fine after confirming the network name and using an updated device |
| Streaming or ordinary browsing | Use HTTPS sites and avoid downloading unknown files |
| Banking, tax, or medical accounts | Use cellular data or a trusted network when possible |
| Changing important passwords | Wait for a trusted connection, especially if the device is shared |
| Work files or customer data | Use your employer’s approved VPN and follow its policy |
Protect the device while you are connected
- Set the network type to Public on Windows so sharing is restricted.
- Turn off file sharing, printer sharing, and nearby device discovery unless you need them.
- Keep Bluetooth off when you are not using it, especially in a crowded place.
- Use a screen lock and do not leave a laptop unattended.
- Sign out of shared computers and remove the network from saved WiFi profiles when you leave.
A VPN can add protection on an untrusted network, but it is not a substitute for updates, strong passwords, or checking the hotspot name. Choose a VPN you trust because the VPN provider can see connection information. For short trips, cellular data may be the simplest option for sensitive tasks.
If the connection behaves strangely
Disconnect if a page opens unexpected login prompts, security warnings, or downloads. Forget the network, turn off auto-join, and report the hotspot to venue staff. If you entered a password on a suspicious page, change it from a trusted connection and enable multi-factor authentication. Watch the account for unfamiliar sign-ins.
For travel, a phone hotspot can be a useful fallback. Compare its data allowance and battery impact with your home plan in our mobile hotspot versus home internet guide. It is often easier to protect one phone connection than to troubleshoot an unknown hotspot.
Five-minute public WiFi checklist
- Confirm the exact network name with the venue.
- Decline unexpected certificates, apps, and downloads.
- Use Public network mode and disable sharing.
- Keep banking, password changes, and sensitive files on cellular data or a trusted VPN.
- Forget the network when you leave and change any password entered on a suspicious page.
Sources
For more detail, see the Federal Trade Commission guidance on public WiFi. It explains why encryption matters, how to keep devices updated, and why a public network should not be treated as automatically trusted.