The standard warning about café Wi-Fi — that someone can read your passwords out of the air — was largely true in 2012 and is largely false now. HTTPS is near-universal, and it encrypts content end to end regardless of the network. That does not make public Wi-Fi safe, but the risks have moved.
What HTTPS already protects
The contents of anything you send to an HTTPS site: passwords, messages, form data, page content. Someone on the same network capturing packets sees encrypted bytes. This is the risk most public Wi-Fi advice is still warning about, and it has been solved.
What is still exposed
- Which sites you visit. DNS lookups and TLS handshakes reveal domain names even when content is encrypted.
- Metadata: timing, volume and frequency of connections, which is more identifying than people assume.
- Anything still travelling over plain HTTP, which is rare but not extinct.
- Your device on the local network, if it has services exposed and the network permits client-to-client traffic.

The captive portal problem
Hotel and airport networks that make you accept terms on a login page can inspect and modify unencrypted traffic by design — that is how the portal works. Some inject tracking or advertising into pages. A VPN prevents this, but you must connect to the portal first, so there is a window where you are exposed.
What a VPN actually fixes
It hides which sites you visit from the network operator and anyone else on the network. It stops content injection by a captive portal. It prevents local network scanning from reaching your device meaningfully. That is a real improvement, and it is the clearest legitimate case for a VPN.
What it does not do: make you anonymous to the sites you log into, stop tracking cookies, or protect you from phishing. Those are different problems with different solutions.
The realistic public Wi-Fi threat in 2026 is the network operator profiling you, not a stranger reading your banking password.
Practical setup for travel
- Turn on the kill switch before you connect, so nothing escapes if the tunnel drops.
- Disable automatic connection to open networks on your phone.
- Prefer your phone's hotspot over hotel Wi-Fi where data allowance permits.
- Use a provider with obfuscation if the network blocks VPN traffic, which some hotel systems do.
Proton VPN is a good fit here — it has a Stealth protocol for networks that block VPN traffic, passed every leak and kill-switch test in our July cycle, and its free tier is enough to cover occasional travel if you do not need streaming.



