We earn a commission if you purchase through our links, at no extra cost to you.

Privacy basics

Is Public Wi-Fi Safe? What Actually Happens on Hotel and Airport Networks

The honest version: the classic public Wi-Fi horror story is mostly out of date, and the risk that replaced it is quieter and harder to notice.

The short answer

Public Wi-Fi is safer than it was ten years ago and less private than most people assume. Those two things are both true, and confusing them is why the advice you see is so contradictory.

The old fear — someone at the next table reading your banking password out of the air — has largely been solved by the web itself. What has not been solved is that the network still gets a running list of every place you go, and that you have no way of knowing who runs the network in the first place.

What HTTPS already fixed

Nearly every site you use now loads over HTTPS — the padlock in the address bar. That encrypts the contents of the connection between your browser and the site. On an open hotel network, the person sitting three tables away cannot pull your password, your messages, or your card number out of the air, because none of that crosses the air in readable form.

This is a genuine, enormous improvement, and any article still telling you a stranger can casually "sniff" your bank login on café Wi-Fi is describing 2013. If you take one thing away: the contents of your traffic are already protected on any site with a padlock.

What is still exposed

HTTPS hides what you send. It does not hide where you sent it. The network you are connected to still sees:

None of that is your password. All of it is your behaviour. A hotel can tell that a room's guest spent the evening on a job site, a health forum and a dating app without ever decrypting a single byte.

The risk that actually matters now: you don't know whose network it is

Anyone can create a Wi-Fi network and name it anything. A hotspot called Airport_Free_WiFi or Marriott_Guest in an airport lounge takes about two minutes to set up, and your phone cannot tell it apart from the real one. It will happily hand out internet access — through a laptop in someone's bag.

Once your traffic is going through a network someone else controls, they get everything listed in the previous section by default, plus the ability to try things: redirecting you to look-alike login pages, tampering with anything not loaded over HTTPS, and quietly logging where you went.

This is the modern version of the public Wi-Fi problem. It is not dramatic and you will not notice it. It is also the part a VPN is genuinely built to solve.

What a VPN changes here

A VPN wraps everything leaving your device in a second layer of encryption and sends it to a server you chose, before it goes anywhere else. To the hotel network — or to whoever is pretending to be the hotel network — your laptop becomes an unreadable stream of data heading to a single address. The list of sites disappears. So does the ability to redirect you somewhere fake.

It does not make you anonymous, and it does not protect you from typing your password into a phishing site you found yourself. What it does is remove the network you are borrowing from the list of parties who get to watch. On a network you did not set up and cannot verify, that is the whole ballgame.

NordVPN — complete digital protection in one app

We earn a commission if you purchase through our links, at no extra cost to you.

Hotel networks, specifically

Hotel Wi-Fi has two quirks worth knowing. The first is the captive portal — the page that makes you enter a room number before it lets you online. That portal has to work before your VPN can connect, so the order matters: join the network, complete the portal, then turn on the VPN. If your VPN connects first, the portal usually never appears and the connection looks broken.

The second is that hotel networks are often flat, meaning every guest device can see every other guest device. Your laptop's file sharing, printer discovery and AirDrop-style features may be advertising themselves to the whole floor. Marking the network as "Public" in your operating system when you join turns most of that off — a free step people routinely skip.

Airport networks, specifically

Airports concentrate two things: a lot of travellers connecting to unfamiliar networks in a hurry, and a lot of look-alike network names. They also tend to have several legitimate networks — the airport's, the lounge's, individual restaurants' — which trains you to accept whatever appears. If you can, use your phone's own mobile hotspot instead; it is the one network in the terminal you know the provenance of. If you can't, a VPN puts the same wrapper around your traffic regardless of which of those networks you picked.

A short practical checklist

  1. Turn off "connect automatically" for public networks so your phone doesn't rejoin something it saw once in an airport.
  2. Mark the network as Public when your device asks.
  3. Finish the captive portal first, then connect the VPN.
  4. Prefer your own mobile hotspot for anything that involves money.
  5. Keep two-factor authentication on your important accounts — it is the thing that still protects you when everything else fails.
NordVPN

One tap covers every network you'll join this trip

NordVPN encrypts your connection before it reaches the hotel router, and one subscription covers 10 devices — the laptop, the phone, and whatever the rest of the family brought.

Get NordVPN →

30-day money-back guarantee · Read our full NordVPN review first.

So — is it safe?

Safe enough to check your email. Not private, at all, ever. And on a network you cannot verify, "safe enough" rests entirely on every site you touch being configured correctly, which is a bet you are making on your bank's behalf without being asked.

The reasonable position is somewhere between panic and indifference: assume the network operator sees your itinerary, assume the network might not be who it claims, and put a layer between you and both of those problems when the connection isn't yours.