Everyone loves free WiFi, and that unfortunately includes hackers. They try to lure you in with fake networks and login pages, or use security exploits to cause damage. Knowing how to use public WiFi safely helps protect your logins and payment info while you’re out and about.

Stick to trusted networks, use HTTPS, 2FA, and a VPN, and avoid sensitive activities when you can. Disable auto-join for public networks, check your network sharing settings before going online, and update everything to get the latest security patches.

We’ll cover all of these tips in more detail below. Afterward, we’ll look at the threats you might encounter, including man-in-the-middle attacks, phishing, and security vulnerabilities that attackers can exploit.

How to use public WiFi safely

Public WiFi may be convenient, but it’s also a convenient way for hackers to target unsuspecting users. Fortunately, you can reduce the risks by taking a few simple precautions before, during, and after connecting.

1. Stay away from WiFi networks with no password

Anyone can connect to an unsecured WiFi network, including hackers looking for an easy target. Of course, a password alone doesn’t prove that a network is legit, as attackers can secure fake hotspots too. They rarely bother, since it adds another step to the scam, but it’s worth keeping in mind.

Either way, stick to password-protected networks when you can, and confirm the network name with the business running the hotspot.

2. Stick to HTTPS websites and double-check the URL

If your web browser warns you that a site is unsafe, don’t ignore it.

HTTPS encrypts the connection between your browser and the website, making it much harder for someone on the same WiFi network to read your traffic. Check for a padlock icon and make sure the address starts with https://.

Secure Site

A malicious wi-fi hotspot can redirect you to phishing and malware sites. Check the URL itself before entering passwords or other sensitive information. A fake site can use HTTPS too, so a padlock doesn’t mean you’re in the right place. Later, we’ll look at some of the tricks attackers use to send you to fake login pages, such as DNS spoofing and phishing scams.

3. Avoid sending sensitive information

Avoid sending sensitive information over public WiFi when you can, especially on networks you don’t trust. Switch over to mobile data if you need to handle banking, shopping, and other activities involving passwords or personal details.

4. Turn off auto-connect or forget public WiFi networks

Turn off automatic WiFi connections for public networks so your device doesn’t join them without asking. You can keep auto-join enabled for trusted networks, such as your home WiFi, while disabling it for networks you don’t use regularly.

Alternatively, you can forget public WiFi networks after using them. Both options are usually in the same spot, so use these steps to find them:

  • Windows 11: Right-click the WiFi icon on the bottom right of your screen and click Network and Internet settings. Go to Wi-Fi > Manage known networks, where you can Forget a network, or click the arrow on the right and disable the “Connect automatically when in range” option.
  • macOS: Click the Apple menu and go to System Settings > Wi-Fi > Advanced. Press the More options (…) button next to the connection, then uncheck Auto-Join or select Remove From List > Forget.
  • Android: Go to Settings > Connections > Wi-Fi, tap and hold the connection name, then tap Forget network. When connected, tap the gear icon next to the connection to toggle off Auto-reconnect.
  • iOS and iPadOS: Go to Settings > Wi-Fi > Edit, tap the info button (the circled “i”) next to the network, then tap Forget This Network or toggle off Auto-Join as needed.

The settings may be named differently depending on your device manufacturer and OS version.

5. Disable network sharing

Windows disables network discovery and file sharing by default on Public networks, so you usually don’t need to change anything. Make sure to use the Public network profile when connecting to an unfamiliar hotspot:

  1. Right-click the WiFi icon on the bottom right.
  2. Click Network and Internet settings > Wi-Fi.
  3. Select the network.
  4. Ensure the Public network option is selected.

On macOS, click the Apple menu, then go to System Settings > General > Sharing. Make sure you haven’t enabled services like File Sharing, Screen Sharing, or others you don’t need.

6. Use a VPN

Using a VPN on public WiFi encrypts your traffic between your device and the VPN server. This makes it much harder for someone else on the network to see what you’re doing or modify your data, including the network provider.

That said, a VPN doesn’t make every part of your online activity safe. You still need to watch for fake websites, phishing attempts, and other threats that happen outside the encrypted connection. Fortunately, some of the best no-logs VPNs include threat protection features that also block known phishing sites, malware downloads, and more.

7. Enable two-factor authentication (2FA)

Two-factor authentication adds another check when you log into an account, such as a code from an authenticator app. As a result, someone who gets your password will have a harder time accessing your account.

Use 2FA on important logins such as email, banking, and social media. An authenticator app or security key generally offers stronger protection than SMS, although SMS is still better than using a password alone.

8. Keep your OS, drivers, and apps updated

At home, you could probably get away with clicking that “Pause updates” button once—at least until you can confirm Microsoft’s vibe-coding isn’t breaking PCs again.

But public WiFi gives attackers more opportunities to probe devices on the same network. Meanwhile, AI tools are making it easier to find vulnerabilities and automate parts of the process.

If you regularly use public networks, then don’t gamble away your security with outdated software. Spend a few minutes updating your operating system, drivers, browser, and apps so you don’t spend hours on damage control afterward.

What are the risks of connecting to public WiFi?

Public WiFi can put your data at risk in several ways, whether attackers intercept your traffic, trick you into visiting fake sites, or exploit weaknesses in the network or your device.

1. Man-in-the-middle (MITM) attacks

A man-in-the-middle attack happens when someone gets between your device and the service you’re trying to reach. From there, they can intercept or tamper with traffic, although HTTPS and other forms of encryption can stop them from reading the data itself.

Two MITM attacks are worth watching out for on public WiFi in particular:

  • “Evil Twin” attacks: Hackers can set up fake WiFI networks that closely imitate the real thing. Once you connect, the attacker can potentially spy on your traffic or modify it in transit. use different DNS settings to send you to
  • DNS spoofing: By controlling the network’s DNS server or interfering with DNS requests, an attacker can send you to a fake website designed to steal your data or download malware. HTTPS can prevent this trick by warning you that the site’s certificate doesn’t match the domain.

2. Phishing scams

Public WiFi can also be used to push phishing pages that look like login screens, WiFi sign-in pages, or other familiar sites. If one asks for a password or payment details, check the web address carefully before entering anything.

Attackers can also tamper with captive portals on compromised networks, making a fake sign-in page look like part of the hotspot. A legitimate hotel or café should never need your email, password, or banking details just to get you online.

3. Security vulnerabilities

WiFi networks and connected devices can also have security flaws that attackers may exploit. For example, the SSID Confusion vulnerability can trick devices into connecting to an unintended network, including in some WPA3 configurations.

These problems can affect the WiFi equipment itself as well as your phone, tablet, or laptop. Keeping your operating system, browser, and other software up to date helps protect against known vulnerabilities.

4. Packet sniffing

Packet sniffing means capturing data as it travels across a WiFi network, using Wireshark or similar tools. For example, an attacker might capture an old-fashioned HTTP connection and see the data being sent between your device and the website.

HTTPS and VPN encryption have made this much less useful nowadays, but older or poorly secured services can still expose unencrypted traffic.

Using public WiFi safely FAQs

Is it safe to use public WiFi for banking?

We don't recommend using public WiFi for banking and other sensitive transactions. While banking apps and HTTPS-protected websites encrypt your data, attackers can still use fake WiFi networks or DNS spoofing to redirect you to malicious sites. Mobile data is a safer choice for sensitive transactions.

Is it safe to use public WiFi with a VPN?

Using public WiFi with a VPN is generally safe because the VPN encrypts your traffic before it leaves your device. This makes it harder for someone on the same network to snoop on your activity, although you should still avoid suspicious WiFi networks.

Can passwords be stolen on public WiFi?

Passwords can be stolen on public WiFi if someone sends them unencrypted, but almost all major websites now use HTTPS that secures your login info. 

A more likely scenario is that the fake WiFi hotspot will redirect you to a phishing site that tries to trick you into typing in a password. Phishing sites can use HTTPS, too, so your browser might not warn you. A VPN can add another layer of security to prevent these redirects.

Is it safe to use unsecured WiFi in hotels?

Using unsecured WiFi in hotels is risky because other people on the network may try to intercept or redirect your traffic. It's fine for everyday browsing, but use a VPN and HTTPS when logging into your accounts or sending anything sensitive.

What should you avoid when using public WiFi?

When using public WiFi, avoid logging into sensitive accounts on suspicious networks, downloading files from unfamiliar sites, or entering personal details on pages without HTTPS. It's also worth turning off automatic WiFi connections on your devices.