The short answer
Public Wi-Fi is safer than it was ten years ago and less private than most people assume. Those two things are both true, and confusing them is why the advice you see is so contradictory.
The old fear — someone at the next table reading your banking password out of the air — has largely been solved by the web itself. What has not been solved is that the network still gets a running list of every place you go, and that you have no way of knowing who runs the network in the first place.
What HTTPS already fixed
Nearly every site you use now loads over HTTPS — the padlock in the address bar. That encrypts the contents of the connection between your browser and the site. On an open hotel network, the person sitting three tables away cannot pull your password, your messages, or your card number out of the air, because none of that crosses the air in readable form.
This is a genuine, enormous improvement, and any article still telling you a stranger can casually "sniff" your bank login on café Wi-Fi is describing 2013. If you take one thing away: the contents of your traffic are already protected on any site with a padlock.
What is still exposed
HTTPS hides what you send. It does not hide where you sent it. The network you are connected to still sees:
- Every domain you visit. Your device has to ask "where is this site?" and then announce which site it wants — through DNS lookups and, on most connections, the server name in the opening handshake. Both are readable by the network.
- Timing and volume. When you connect, for how long, and how much data moves. That is enough to tell a video call from a download from an idle laptop.
- Every device you brought. Your phone, laptop and watch each announce themselves, and many broadcast the names of networks they have joined before.
None of that is your password. All of it is your behaviour. A hotel can tell that a room's guest spent the evening on a job site, a health forum and a dating app without ever decrypting a single byte.
The risk that actually matters now: you don't know whose network it is
Anyone can create a Wi-Fi network and name it anything. A hotspot called Airport_Free_WiFi or Marriott_Guest in an airport lounge takes about two minutes to set up, and your phone cannot tell it apart from the real one. It will happily hand out internet access — through a laptop in someone's bag.
Once your traffic is going through a network someone else controls, they get everything listed in the previous section by default, plus the ability to try things: redirecting you to look-alike login pages, tampering with anything not loaded over HTTPS, and quietly logging where you went.
This is the modern version of the public Wi-Fi problem. It is not dramatic and you will not notice it. It is also the part a VPN is genuinely built to solve.
What a VPN changes here
A VPN wraps everything leaving your device in a second layer of encryption and sends it to a server you chose, before it goes anywhere else. To the hotel network — or to whoever is pretending to be the hotel network — your laptop becomes an unreadable stream of data heading to a single address. The list of sites disappears. So does the ability to redirect you somewhere fake.
It does not make you anonymous, and it does not protect you from typing your password into a phishing site you found yourself. What it does is remove the network you are borrowing from the list of parties who get to watch. On a network you did not set up and cannot verify, that is the whole ballgame.
Hotel networks, specifically
Hotel Wi-Fi has two quirks worth knowing. The first is the captive portal — the page that makes you enter a room number before it lets you online. That portal has to work before your VPN can connect, so the order matters: join the network, complete the portal, then turn on the VPN. If your VPN connects first, the portal usually never appears and the connection looks broken.
The second is that hotel networks are often flat, meaning every guest device can see every other guest device. Your laptop's file sharing, printer discovery and AirDrop-style features may be advertising themselves to the whole floor. Marking the network as "Public" in your operating system when you join turns most of that off — a free step people routinely skip.
Airport networks, specifically
Airports concentrate two things: a lot of travellers connecting to unfamiliar networks in a hurry, and a lot of look-alike network names. They also tend to have several legitimate networks — the airport's, the lounge's, individual restaurants' — which trains you to accept whatever appears. If you can, use your phone's own mobile hotspot instead; it is the one network in the terminal you know the provenance of. If you can't, a VPN puts the same wrapper around your traffic regardless of which of those networks you picked.
A short practical checklist
- Turn off "connect automatically" for public networks so your phone doesn't rejoin something it saw once in an airport.
- Mark the network as Public when your device asks.
- Finish the captive portal first, then connect the VPN.
- Prefer your own mobile hotspot for anything that involves money.
- Keep two-factor authentication on your important accounts — it is the thing that still protects you when everything else fails.
One tap covers every network you'll join this trip
NordVPN encrypts your connection before it reaches the hotel router, and one subscription covers 10 devices — the laptop, the phone, and whatever the rest of the family brought.
Get NordVPN →30-day money-back guarantee · Read our full NordVPN review first.
So — is it safe?
Safe enough to check your email. Not private, at all, ever. And on a network you cannot verify, "safe enough" rests entirely on every site you touch being configured correctly, which is a bet you are making on your bank's behalf without being asked.
The reasonable position is somewhere between panic and indifference: assume the network operator sees your itinerary, assume the network might not be who it claims, and put a layer between you and both of those problems when the connection isn't yours.