Skip to content
AVO Security
Phones

Is It Safe to Use Free Wi-Fi at Coffee Shops, Airports and Hotels?

You’re at the gate with forty minutes to kill, or you’ve just ordered a flat white and opened your laptop, or you’ve checked into a hotel room and the first thing you do is hunt for the Wi-Fi password taped to the desk. In all three moments you’re about to do the same thing millions of people do every day without a second thought: join a network you don’t own, don’t control, and know almost nothing about.

The short answer: free Wi-Fi at coffee shops, airports and hotels is not inherently dangerous, but it is not safe by default either. The risk isn’t the coffee shop or the airline. It’s the fact that an open or shared network puts you on the same local segment as everyone else connected to it, some of whom may be running tools designed to watch what passes by. Whether that risk turns into an actual problem depends almost entirely on what protections are running on your device at the moment you connect, not on how trustworthy the venue “feels.”

This guide walks through what’s actually happening on a public network, how the risk differs between a cafe, an airport, and a hotel, and exactly what to do so that none of it matters, including how a tool like AVO Security automates most of this in the background so you’re not making these decisions manually every time you sit down with your laptop.

What Actually Happens When You Join a Public Network

To understand whether public Wi-Fi is safe, it helps to understand what a network actually does with your data, because “safe” isn’t one thing. It’s several separate questions bundled together.

When your phone or laptop connects to a Wi-Fi network, every piece of data it sends (a web request, an app syncing in the background, a login form being submitted) travels from your device, through the router, and out to the internet. On a private home network, you control that router and (mostly) trust everyone else using it. On a public network, you control neither.

Two things determine how exposed that data is in transit:

  • Whether the network itself is encrypted. Most modern public networks use WPA2 or WPA3 encryption between your device and the router, which stops someone from passively reading traffic out of the air with basic tools. Older or poorly configured networks, and a genuinely open network with no password at all, offer no such protection.
  • Whether the destination is encrypted. Almost every site you visit today uses HTTPS, which encrypts the connection from your device all the way to the website itself, independent of the Wi-Fi network. This is the single biggest reason public Wi-Fi is dramatically safer today than it was ten years ago: even on a hostile network, HTTPS means the specific words in your messages, the password you typed, and your card number are wrapped in a layer of encryption the network operator can’t see through.

So why does “public Wi-Fi security” still show up as a major concern? Because encryption at the network and website level solves the reading your data problem, but it doesn’t solve everything. A skilled attacker on the same network, or the person who set the network up, can still see that you connected, where you connected to (the domain, not the content), and can attempt several other tricks that don’t rely on breaking encryption at all. That’s the part worth understanding before you decide how much a coffee shop, an airport terminal, or a hotel room actually changes your risk.

The Real Risks of Public Wi-Fi Security

“Public Wi-Fi security risks” get talked about in vague, scary terms a lot, so it’s worth being specific about what can actually go wrong, because the fixes are different for each one.

1. Rogue and “evil twin” networks. This is the single most common real-world attack, and it doesn’t require breaking any encryption at all. An attacker sets up their own access point named something plausible (“Airport_Free_WiFi,” “Hotel_Guest,” “Starbucks_WiFi_2”) often with a stronger signal than the real network. Your phone or laptop, which just wants to connect to something with a familiar-sounding name, joins it automatically. From that point, every request you make passes through a device the attacker controls before it ever reaches the real internet.

2. Packet sniffing on unencrypted traffic. Any data that isn’t wrapped in HTTPS (an older app, a misconfigured site, background traffic from an out-of-date piece of software) can be read in plain text by anyone else on the same network with basic, freely available tools. This is a shrinking problem as HTTPS becomes closer to universal, but it hasn’t disappeared, especially with older apps and IoT devices that quietly phone home over unencrypted connections.

3. Man-in-the-middle attacks and SSL stripping. Even where a site supports HTTPS, an attacker positioned between you and the router can attempt to downgrade the connection to plain HTTP before you notice, particularly on the first request to a site before a redirect kicks in. Modern browsers have gotten much better at blocking this, but it’s still part of why network-layer protection matters, not just “look for the padlock icon.”

4. DNS spoofing. Every time you type a web address, your device asks a DNS server to translate it into the correct destination. On a network an attacker controls, that DNS lookup can be quietly redirected, sending you to a convincing fake login page for your bank or email provider instead of the real one, without your browser’s address bar giving you any obvious sign something’s wrong.

5. Session hijacking. If a website doesn’t fully encrypt session cookies (rarer today, but not extinct), an attacker who can see your traffic can potentially capture the token that keeps you logged in and reuse it themselves, without ever needing your actual password.

6. Malware pushed through captive portals. Airport and hotel networks in particular often route you through a “captive portal”, the login page that asks you to accept terms or enter a room number before granting internet access. A fake version of this page is a common vehicle for pushing malicious downloads or credential-harvesting forms, because it’s the one moment you’re expected to interact with something unfamiliar.

None of this means every café, gate, or hotel room is crawling with attackers. It means the risk profile of public Wi-Fi is fundamentally different from your home network, and the appropriate response is to assume any given public network could be compromised and behave accordingly, not to try to judge, venue by venue, which ones are “probably fine.”

Common Myths About Public Wi-Fi Safety

A lot of the anxiety, and a lot of the false confidence, around public Wi-Fi comes from a handful of ideas that sound reasonable but don’t hold up.

Myth: “If a network has a password, it’s safe.” A password on a Wi-Fi network encrypts the traffic between your device and that specific router, which is genuinely useful, but it says nothing about who else has that password (in a hotel or café, potentially everyone who’s ever asked for it) or whether the network itself is the real one. An evil twin network can have its own password too, a fake one, set by whoever’s running it, that has nothing to do with security and everything to do with looking legitimate.

Myth: “HTTPS means I’m completely safe no matter what.” HTTPS is doing a lot of work. It’s the single biggest reason public Wi-Fi is safer today than a decade ago, but it protects the content of a specific connection, not the decision to connect to a fake network in the first place, not what a captive portal does before you reach HTTPS, and not whether a link you’re about to click leads somewhere malicious. It’s a necessary layer, not the only one.

Myth: “My antivirus already covers this.” Traditional antivirus is built to catch malicious files and known bad software on the device itself. It generally has nothing to say about whether the Wi-Fi network you just joined is a rogue access point, whether a QR code leads somewhere it shouldn’t, or whether your DNS requests are being quietly redirected, those are network-layer and link-layer problems, not file-scanning problems, which is why “public wifi security software” and antivirus aren’t quite the same category of tool.

Myth: “Big, well-known venues are inherently more secure.” A large airport or a major hotel chain often does have better-managed network infrastructure than a small independent business, but the size of the venue has no bearing on whether the network you personally connect to at that moment is the real one, or a convincing fake set up by someone sitting nearby. Evil twin attacks specifically target places with high trust and high traffic, which describes major chains just as well as small local spots.

Myth: “I’ll notice if something’s wrong.” This is the most dangerous myth, because the entire point of an evil twin network, a spoofed captive portal, or a quietly redirected DNS lookup is that nothing looks wrong. The browser still loads, the login page still looks right, the Wi-Fi icon still shows full bars. The absence of an obvious warning sign is not the same as confirmation that everything’s fine.

Is Coffee Shop Wi-Fi Safe?

Coffee shop Wi-Fi sits in the middle of the risk spectrum, and most of what makes it moderately risky comes down to two things: the network is genuinely open to the public (no barrier to entry beyond walking in), and it’s often shared across a chain, meaning the same password has been handed out to thousands of people at hundreds of locations.

That combination means a coffee shop network is an easy, low-effort target for an evil twin attack. There’s no verification step, no front desk checking your details, and customers are primed to just tap whatever network name looks closest to the shop’s branding. If you’ve ever seen two networks with almost identical names at the same café, that’s exactly the scenario to be cautious of.

On the other hand, coffee shop Wi-Fi tends to be lower-value as a target compared to, say, a hotel network where guests are more likely to be doing sensitive work, banking, or business travel. Most cafés also aren’t running packet-inspection hardware or logging your traffic on purpose (the network operator itself is rarely the threat), the risk is almost entirely about who else happens to be sitting at the next table with a laptop and some free tools.

Practical takeaway: treat coffee shop Wi-Fi as public by default, verify the network name with staff before connecting rather than guessing, and don’t rely on “it’s a big brand, so it must be secure”, the brand name on the door has nothing to do with how the network itself is secured. A network security layer that checks a Wi-Fi network’s encryption and behavior before you join, which is exactly what AVO’s Wi-Fi Security feature does, removes the guesswork, flagging weak encryption or a router still on default settings the moment you connect, and can turn on the VPN automatically the instant it detects you’re on an unencrypted or open network.

Is Airport Wi-Fi Safe?

“Is airport wifi safe” is one of the most common versions of this question, and for good reason, airports combine several risk factors at once: extremely high foot traffic, travelers who are distracted and in a hurry, valuable targets (business travelers, people accessing banking or corporate email between flights), and Wi-Fi networks that are, by design, open to anyone who walks through security.

Airport Wi-Fi is also one of the most common environments for evil twin networks specifically, because airports typically have several legitimate Wi-Fi options at once (the official airport network, individual airline lounge networks, and sometimes retail or restaurant-specific hotspots) which makes it easy for a fake network to blend in among genuinely confusing, overlapping options. A network named “Free_Airport_Wifi” or matching the format of the real one (“[Airport]_Guest” when the real one is “[Airport]_Free”) is a classic setup.

There’s also a captive-portal specific risk at airports: the login screen you’re funneled through to accept terms of use is a well-known target for spoofing, sometimes appearing as a near-identical copy asking for an email address, frequent flyer number, or even payment details for a “premium” tier that doesn’t exist.

None of this means you should avoid airport Wi-Fi entirely, for most people, checking flight status, browsing, or reading email over HTTPS on an official airport network is low-risk. The exposure climbs sharply the moment you’re logging into a bank, entering payment details, or accessing work systems, which is exactly when the additional protection of a VPN matters most (more on that below).

A few airport-specific habits worth building:

  • Confirm the official network name at an information desk or on airport signage rather than picking whichever option has the strongest signal.
  • Be extra suspicious of any captive portal that asks for more than a name/email or a simple “accept terms” click, a real airport login page has no reason to ask for a password to an unrelated account or a card number.
  • If you’re doing anything sensitive between flights, that’s the moment to have a VPN active, not an optional extra.

AVO’s Wi-Fi Security feature checks the network’s encryption and router configuration the moment you join, which is particularly useful in an airport where you’re often choosing between several similarly-named options under time pressure and can’t manually vet each one.

Is Hotel Wi-Fi Safe?

“Is hotel wifi safe” and “is it safe to connect to hotel wifi” are both extremely common searches, and hotel networks deserve a closer look than either coffee shops or airports for one specific reason: hotel Wi-Fi is disproportionately targeted precisely because business travelers, people on vacation with banking apps open, and guests handling sensitive work email are a captive, predictable audience, often connected for multiple days in a row on the same network.

There are a few things that make hotel Wi-Fi its own category of risk:

Shared, long-lived passwords. Many hotels use a single Wi-Fi password for the entire property, printed on a card at check-in or on the back of the room key sleeve, unchanged for months at a time and known to every guest, past and present, who’s ever stayed there. That’s a much larger pool of people with legitimate access to the network than a home router ever has.

Weak router management. Hotel network infrastructure varies enormously by property, a large chain with a dedicated IT team is a different situation from a smaller independent hotel where the router hasn’t been reconfigured from its factory defaults in years. Outdated router firmware and default admin credentials are a known, documented weakness across the hospitality industry.

Physical access to network hardware. Unlike a coffee shop where the router sits behind a counter, hotel network equipment is sometimes installed in semi-public areas (hallway closets, business centers) giving a motivated attacker more opportunity to physically interfere with a switch or access point than in most other public settings.

Extended dwell time. You’re typically on a hotel network for hours or days, not the twenty minutes you might spend at a café, which gives an attacker on the same network more time to observe patterns and attempt something targeted.

Is It Safe to Use Hotel Wi-Fi for Banking?

This is worth answering directly, because it’s one of the most-searched follow-up questions: doing your banking over hotel Wi-Fi is not automatically catastrophic, your bank’s site uses HTTPS regardless of the network, but it’s also the single situation where the extra layer of a VPN earns its keep the most. A hotel network is exactly the kind of shared, long-lived, variably-secured environment where an evil twin or DNS-spoofing attempt is more likely than on, say, your own home connection, and banking is exactly the kind of high-value target that makes such an attempt worth an attacker’s time. If you’re going to check a balance or move money while traveling, do it with a VPN active rather than on the hotel network directly, and avoid it entirely over an unsecured, password-free hotel lobby hotspot.

Practical hotel Wi-Fi habits:

  • Ask the front desk to confirm the exact network name rather than trusting whatever shows up in your device’s list, hotel evil twins frequently use names one character off from the real one.
  • Treat the hotel network as shared with every other guest currently staying there, because it is.
  • If you’re traveling with kids using hotel Wi-Fi on their own devices, it’s worth having per-device content controls in place regardless of network security, AVO’s Parental Controls apply the same safety profile across every device a child signs into, so a new hotel network doesn’t mean redoing that setup from scratch.
  • Keep a VPN running for the duration of your stay rather than turning it on only when something feels sensitive. You rarely know in advance which request on a hotel network is the one that matters.

Does a VPN Make Public Wi-Fi Safe?

“Is it safe to use public wifi with a VPN” comes up constantly, and the honest answer is: a VPN solves the specific problem it’s designed to solve, and it’s the single most effective thing you can add to your setup, but it’s not a magic word that makes every other risk disappear.

What a VPN actually does: it creates an encrypted tunnel between your device and the VPN provider’s server, so that anyone else on the local network, including someone running an evil twin access point, sees only that you’re connected to a VPN, and nothing about the sites you visit, the data you send, or the content of your traffic. This directly neutralizes packet sniffing, most man-in-the-middle attempts, and DNS spoofing at the local-network level, because your DNS requests are now going through the encrypted tunnel too, not the local (possibly compromised) network’s DNS server.

What a VPN doesn’t do: it doesn’t stop you from typing your password into a convincing fake login page if you’re tricked into visiting one. That’s a phishing problem, not a network problem, and needs a different layer of protection (see the next section). It also doesn’t do anything about malware you choose to download, or a device that’s already compromised before you connect.

This is why “is hotel wifi safe with a VPN” and “is public wifi safe with a VPN” both come back to roughly the same answer: dramatically safer for the specific class of attack a VPN addresses, materially unchanged for phishing, malicious downloads, and social engineering. The strongest setup pairs a VPN with the other layers covered in this guide, rather than treating it as a single fix.

One detail that matters in practice: a VPN only protects you if it’s actually turned on at the moment you connect, and most people forget to do that consistently, which is exactly the gap AVO’s VPN is built to close. Rather than being something you have to remember to toggle, it’s designed to start automatically the moment your device joins a network that isn’t encrypted, so the protection exists during the ten seconds after connecting when you’re most likely to forget, not just when you remember to think about it.

The QR Code Wi-Fi Trap (“Quishing”) at Hotels and Airports

A newer variation on the fake-network problem doesn’t involve Wi-Fi at all, at least not directly. Hotels, airport lounges, and cafés increasingly print a QR code instead of (or alongside) a written network name and password, scan it, and your device joins the network and opens a welcome page automatically.

The problem is that a QR code is a link you can’t read before you follow it. A sticker placed over a legitimate one, or a fake table-tent printed to look identical to the venue’s real signage, can point your device to an attacker-controlled network or a credential-harvesting page instead of the real Wi-Fi login, and unlike a suspicious-looking URL, there’s no text to glance at and question before you scan.

This kind of attack, sometimes called “quishing” (QR phishing), has shown up at hotels, parking meters, and restaurant tables, and public Wi-Fi onboarding is a natural target because scanning a code to get online is now such a normal, low-suspicion action. A QR scanner that decodes the destination and checks it the same way it would check a typed link, which is what AVO’s QR Scanner does, closes this gap by showing you exactly where a code leads, and flagging it if the destination is already known for phishing, before anything opens on your device.

How to Spot a Fake or “Evil Twin” Wi-Fi Network

Since the evil twin is the most common real-world attack across coffee shops, airports, and hotels alike, it’s worth having a specific checklist for it rather than a vague sense of caution.

  • Multiple networks with near-identical names. “Hotel_Guest” and “Hotel_Guest_5G” might both be legitimate (a real dual-band setup), but “Hotel_Guest” and “Hotel_Free_Guest” appearing at the same time is worth a second look.
  • A network with no password where you’d expect one. If a hotel or venue told you there’s a password and you see an open, password-free option with a similar name, that’s a red flag, not a convenience.
  • Unusually strong signal from an unexpected source. Evil twins are sometimes run from a device sitting close to victims (a laptop in a backpack, a small Wi-Fi Pineapple-style device) which can produce a stronger signal than the venue’s actual, properly-placed access point.
  • A captive portal asking for more than it should. A login page that wants a full name and room number is normal for a hotel; one that wants your email password, a card number for a “free upgrade,” or unrelated account credentials is not.
  • Your device reconnecting to something you didn’t expect. Phones and laptops automatically rejoin previously-used network names, which is exactly what makes a spoofed “Starbucks WiFi” or “Airport Free Wifi” so effective. It doesn’t even need you to actively choose it.

Manually checking all of this every time you sit down at a café or check into a hotel isn’t realistic, which is the specific gap AVO’s Wi-Fi Security feature is built to close. It evaluates a network’s encryption, checks for signs of interception, and flags a router still running on default settings automatically, rather than asking you to make that judgment call yourself in the ten seconds after your device shows you a list of network names.

How to Safely Use Public Wi-Fi: A Practical Checklist

Here’s the condensed version, the specific, repeatable habits that address every risk covered above, whether you’re at a café, a gate, or a hotel desk.

  1. Confirm the network name with staff rather than picking from your device’s list based on which one looks right. This alone defeats most evil twin attempts.
  2. Turn on a VPN before you do anything else, not after you notice something sensitive is coming up. If your VPN doesn’t start automatically on unsecured networks, get in the habit of doing it manually the moment you connect, or use one that does it for you.
  3. Avoid entering passwords or payment details on any page reached through a captive portal beyond what’s clearly the venue’s own login flow. If a Wi-Fi login page asks for anything beyond your name, email, or a simple terms acceptance, stop.
  4. Keep software and your operating system up to date. Many public Wi-Fi exploits rely on known vulnerabilities in outdated software, patched systems close off a large share of the available attack surface before you even connect.
  5. Turn off auto-connect for open networks. Most phones and laptops will happily rejoin any network name they’ve seen before, or auto-join anything open. Disabling this removes the single easiest way an evil twin catches people.
  6. Use HTTPS-only browsing where possible. Modern browsers largely enforce this automatically, but it’s worth checking that “always use secure connections” is switched on in your browser’s settings.
  7. Avoid installing anything from a public network’s login page. A legitimate hotel or airport Wi-Fi portal has no reason to ask you to install an app or a certificate to get online.
  8. Run a quick device check after extended use of an unfamiliar network, particularly after a multi-day hotel stay. AVO’s Smart Scan looks at what’s changed on a device (new software, altered settings, unusual downloads) and puts anything worth addressing at the top, which is a fast way to confirm nothing slipped through during a trip.
  9. Check any link before you click it, especially one that arrives unexpectedly while you’re traveling, a “your flight has changed” text or a hotel loyalty email is a classic vehicle for phishing precisely because it’s plausible in the moment. AVO’s Link Checker follows the full redirect chain and tells you the real destination, who owns it, and how old the domain is before you open anything.
  10. Enable network-level filtering that blocks malicious sites automatically, so a mistake in the moment, a tired tap on the wrong link at 11pm after a long flight, doesn’t automatically become a problem. This is what AVO’s Web Shield does at the DNS layer, covering every app on the device rather than just one browser.

None of these steps is complicated on its own. The reason people skip them isn’t that the habits are hard. It’s that remembering to do all ten, every single time, across every device in a family, isn’t realistic without something doing it automatically in the background.

Public Wi-Fi Security Best Practices for Remote Workers and Business Travelers

The stakes are higher for anyone connecting to public Wi-Fi to do actual work (client files, company email, a video call with a screen share) rather than casual browsing, and the best practices shift slightly as a result.

Separate personal and work traffic where you can. If your employer provides a company VPN for accessing internal systems, that’s a different tool solving a different problem than a personal VPN for general Wi-Fi safety, the two aren’t mutually exclusive, and using both isn’t redundant. A company VPN typically only routes traffic to internal company resources; it doesn’t necessarily protect your general browsing, email, or personal accounts on the same device.

Assume any hotel or conference-venue network could be more actively targeted, not less. A hotel hosting a conference full of executives, or a co-working space with a rotating cast of strangers, is a more attractive target than an average residential café, precisely because the concentration of valuable accounts and sensitive documents is higher. Business travel is one of the few contexts where “is it safe to use public wifi with a vpn” isn’t really a question. It’s closer to a minimum requirement.

Lock your screen every time you step away, even for a minute, even in a hotel business center or an airport lounge that feels safe. Physical access to an unlocked device sitting on a public Wi-Fi network combines two risks that are each individually manageable and, together, considerably worse.

Avoid public, shared computers entirely for anything involving your accounts. A hotel business center or airport kiosk computer isn’t a “your device on a risky network” problem. It’s a fully unknown device that may already have keylogging software installed, which no amount of good Wi-Fi hygiene protects against.

Standardize the same protections across every device your team travels with, rather than leaving it to individual judgment. A single unprotected laptop on a hotel network during a work trip is often the actual point of entry in reported incidents, not a dramatic, sophisticated attack, which is why consistent, automatic protection across every device (rather than a policy people are expected to remember and follow manually) tends to hold up better in practice. This is the same principle behind AVO covering an entire household’s phones, tablets, and computers under one subscription rather than securing devices one at a time as an afterthought.

What to Do If You Think Your Data Was Exposed on Public Wi-Fi

If you’ve connected to a network you’re now unsure about (maybe you noticed a duplicate network name after the fact, or a captive portal asked for something it shouldn’t have) a few steps matter more than panicking:

  • Change passwords for any account you accessed on that network, starting with email (since it’s usually the recovery path for everything else) and financial accounts.
  • Check whether your email address has appeared in a known data breach. This isn’t always caused by the Wi-Fi incident itself, but it’s a fast way to see whether credentials tied to that email are already circulating, AVO’s Email Breach Scan checks an address against known breaches and names the specific site, year, and exactly which fields were exposed, ranking passwords and payment details first since those are the ones worth acting on immediately.
  • Look for unfamiliar logins or sessions in your email, banking, and social accounts, most major services show a list of recent sign-ins and let you remotely log out anything you don’t recognize.
  • Run a device scan rather than assuming everything’s fine because nothing looks obviously wrong, a lot of the more serious outcomes of a compromised network session aren’t visible without actually checking.

Acting within the first day or two closes most of the window an attacker would otherwise have, which is the main reason this is worth doing immediately rather than only if you notice something wrong weeks later.

Public Wi-Fi Safety by Device: Phones vs. Laptops

It’s worth noting that “how safe” a device is on public Wi-Fi isn’t identical across phones, tablets, and laptops, mostly because of what each operating system allows a security app to actually do.

On iPhone and iPad, Apple restricts how deeply any third-party app, security software included, can inspect what other apps are doing, so protections like network scanning are limited to what’s visible at the settings and network level, while parental controls are similarly limited to what iOS exposes. On Android, Mac, and Windows, a security suite can operate much more fully across the device. This is a genuine platform limitation rather than a gap in any particular product, and it’s worth knowing rather than assuming every device gets identical protection from the same app, a security suite that’s transparent about where a feature runs at full strength versus a reduced, platform-limited mode (rather than implying blanket coverage everywhere) is worth trusting more, not less, for saying so plainly.

Public Wi-Fi vs. Mobile Data: Which Should You Use for Sensitive Tasks?

When a task feels sensitive enough to give you pause (logging into a bank, sending a work document, entering a card number) it’s worth knowing how public Wi-Fi actually compares to your phone’s cellular data, since the two have genuinely different risk profiles rather than one simply being “the safe option.”

Cellular data has a real structural advantage: your phone has a dedicated, encrypted connection to your carrier’s network rather than sharing an access point with every other stranger in the building. There’s no equivalent of an “evil twin cell tower” that a random person nearby can casually set up the way they can spin up a fake Wi-Fi hotspot with cheap, easily available hardware. That’s why, when the stakes are genuinely high and you have signal, switching to mobile data for the specific sensitive action, then switching back afterward, is a reasonable, simple precaution.

That said, cellular data isn’t a perfect substitute for good habits, for a few reasons. It’s slower and often more expensive, which makes it impractical as a full-time replacement for Wi-Fi, especially internationally, where roaming charges can be steep or data simply isn’t available. It also doesn’t protect against phishing links, malicious QR codes, or a compromised device, those risks travel with you regardless of which network you’re on. And a growing number of people don’t have the luxury of choosing: airports and hotels overseas frequently have poor or no cellular coverage indoors, making Wi-Fi the only realistic option regardless of preference.

The more durable answer isn’t “always use mobile data instead of Wi-Fi”. It’s building the habits in this guide (VPN, network verification, link and QR checking) so that public Wi-Fi itself becomes close to as safe as cellular data, rather than something to route around whenever possible. For the rare moment cellular data isn’t available and a task genuinely can’t wait, that’s exactly when having a VPN active on the public network matters most.

Frequently Asked Questions

Is public Wi-Fi safe in general? It’s safer than it used to be, mostly because HTTPS now encrypts the large majority of web traffic regardless of the network, but it’s not risk-free. The main dangers (evil twin networks, DNS spoofing, and compromised captive portals) don’t depend on breaking that encryption, which is why a VPN and network-level checks still matter even on networks that “look” secure.

Is it safe to use public Wi-Fi for banking? It’s not automatically unsafe, since your bank’s site is encrypted independent of the network, but it’s the highest-value target for anyone monitoring a public network, so it’s the situation where a VPN is most worth having active rather than optional.

Is it safe to use public Wi-Fi with a VPN? Yes, substantially safer, a VPN encrypts your traffic end-to-end from the network’s perspective, which neutralizes packet sniffing, most man-in-the-middle attempts, and local DNS spoofing. It doesn’t protect you from phishing pages you’re tricked into visiting on purpose, which is why it works best paired with link and QR checking rather than used alone.

Is hotel Wi-Fi safer than airport Wi-Fi? Neither is uniformly safer. They carry different risk profiles. Hotel Wi-Fi involves longer dwell time and shared, long-lived passwords known to far more people than a single flight’s worth of travelers; airport Wi-Fi involves more overlapping, similarly-named networks and higher foot traffic in a short window. Both benefit from the same core habits: confirm the network name, keep a VPN active, and be cautious with anything a captive portal asks for.

Do I need a VPN if I only browse, and don’t log into anything sensitive? Even casual browsing benefits from a VPN because it hides which sites you’re visiting from anyone else on the network and closes off DNS-spoofing attempts, but the highest-value case is still banking, work email, and anything requiring a login. That’s where the consequences of a successful attack are worst.

Is it safe to connect to hotel Wi-Fi on the first night, before I’ve confirmed anything with staff? It’s fine for casual use (checking flight status, browsing) but worth confirming the exact network name at check-in before treating it as trusted for anything sensitive, and keeping a VPN running regardless.

What security risk does a public Wi-Fi connection actually pose, in one sentence? The core risk is that anyone else on the same network, or anyone who set up a fake version of it, may be positioned to see, intercept, or redirect your traffic before it reaches its real destination, in ways that don’t require breaking into your device at all.

Is public Wi-Fi safe to use on an iPhone specifically? iOS’s app restrictions mean a security app can check the network’s settings and general safety but can’t inspect what other individual apps are doing the way it can on Android, Mac, or Windows. Practically, this means the fundamentals (confirming the network name, using a VPN, checking links before opening them) matter just as much on iPhone, since some of the deeper device-level checks available on other platforms simply aren’t possible under Apple’s restrictions.

Is it safe to use public Wi-Fi for checking email? Reading email over HTTPS on public Wi-Fi is low-risk on its own, but email is also the account most other services use for password resets, which makes it a higher-value target than it might feel like in the moment, worth the same VPN habit as banking, especially on a hotel network you’ll be reusing for several days.

Do free VPN apps offer the same protection as a full security suite’s built-in VPN? A free, standalone VPN can encrypt your traffic the same way any VPN does, but it typically doesn’t know anything about the network’s encryption status, doesn’t check links or QR codes, and won’t turn itself on automatically when you join an unsecured network. You have to remember to open the app and connect every time, which is the habit most people eventually drop.

The Bottom Line

Free Wi-Fi at coffee shops, airports, and hotels isn’t something to avoid. It’s something to use with the right habits and the right protection running quietly in the background, because the actual risks (evil twin networks, DNS spoofing, fake captive portals, and the odd unencrypted app still leaking data) are well understood and, individually, not hard to defend against. The hard part is doing all of it, every time, across every device in a household, without it becoming a chore you eventually stop bothering with.

That’s the specific problem AVO Security is built around: one subscription that puts Wi-Fi Security, a VPN that starts itself on unsecured networks, Web Shield filtering at the DNS level, a Link Checker and QR Scanner for anything you’re about to open, an Email Breach Scan for after the fact, Smart Scan for device health, and Parental Controls for the rest of the family, on every phone, tablet, and computer in the house, so the next time you sit down at a café, walk up to a gate, or check into a hotel room, none of the decisions in this guide need to be made manually.

None of these are separate apps you have to remember to open one at a time, and none of them require you to correctly judge, in the moment, whether a given café’s network or a hotel’s login page looks trustworthy enough. That judgment call is exactly what evil twin networks, spoofed captive portals, and quishing QR codes are designed to survive. They’re built to look fine to a reasonably careful person who’s tired, in a hurry, or just wants to get online. The eight features covered in this guide exist because that specific moment (the ten seconds after your device shows a list of network names, or after a QR code opens something) is the one place good habits alone tend to break down, and it’s the one place worth having something running automatically instead.

If you travel often, work remotely from cafés, or simply want your family’s devices protected the same way no matter which airport, hotel, or coffee shop they happen to be connected to next, that’s what AVO Security is for, see the full list of features or check what’s included on every plan before your next trip.

Last updated September 25, 2026.

Scan every device in the house for free