The standard warning about café Wi-Fi — that someone can read your passwords out of the air — was largely true in 2012 and is largely false now. HTTPS is near-universal, and it encrypts content end to end regardless of the network. That does not make public Wi-Fi safe, but the risks have moved.

What HTTPS already protects

The contents of anything you send to an HTTPS site: passwords, messages, form data, page content. Someone on the same network capturing packets sees encrypted bytes. This is the risk most public Wi-Fi advice is still warning about, and it has been solved.

What is still exposed

  • Which sites you visit. DNS lookups and TLS handshakes reveal domain names even when content is encrypted.
  • Metadata: timing, volume and frequency of connections, which is more identifying than people assume.
  • Anything still travelling over plain HTTP, which is rare but not extinct.
  • Your device on the local network, if it has services exposed and the network permits client-to-client traffic.
A café interior with people using laptops
The realistic threat on public Wi-Fi is the network operator and the domains you reveal, not password sniffing.

The captive portal problem

Hotel and airport networks that make you accept terms on a login page can inspect and modify unencrypted traffic by design — that is how the portal works. Some inject tracking or advertising into pages. A VPN prevents this, but you must connect to the portal first, so there is a window where you are exposed.

What a VPN actually fixes

It hides which sites you visit from the network operator and anyone else on the network. It stops content injection by a captive portal. It prevents local network scanning from reaching your device meaningfully. That is a real improvement, and it is the clearest legitimate case for a VPN.

What it does not do: make you anonymous to the sites you log into, stop tracking cookies, or protect you from phishing. Those are different problems with different solutions.

The realistic public Wi-Fi threat in 2026 is the network operator profiling you, not a stranger reading your banking password.

Practical setup for travel

  • Turn on the kill switch before you connect, so nothing escapes if the tunnel drops.
  • Disable automatic connection to open networks on your phone.
  • Prefer your phone's hotspot over hotel Wi-Fi where data allowance permits.
  • Use a provider with obfuscation if the network blocks VPN traffic, which some hotel systems do.

Proton VPN is a good fit here — it has a Stealth protocol for networks that block VPN traffic, passed every leak and kill-switch test in our July cycle, and its free tier is enough to cover occasional travel if you do not need streaming.