Public Wi-Fi Security

Public Wi-Fi isn't safe.
Here's what actually happens.

Most public Wi-Fi is completely unencrypted. Your passwords, banking sessions and emails are readable to anyone on the same network. A VPN encrypts everything before it leaves your device.

What “unencrypted Wi-Fi” actually means

When you connect to most public Wi-Fi networks, your data travels through the air as readable text. There is no encryption between your device and the router. Anyone on the same network with free, readily available software can capture every packet you send.

This includes the coffee shop you're sitting in, the hotel you're staying at, and the airport lounge you're waiting in. The WPA2 password on a public network protects access — it doesn't protect traffic between users on the same network.

Real attacks that happen on public Wi-Fi

Man-in-the-middle attacks

An attacker positions themselves between you and the network, intercepting all traffic. Free tools make this trivially easy on unencrypted networks. Banking sessions, emails, passwords — all visible.

Evil twin hotspots

"Free Airport WiFi" vs "Free_Airport_WiFi." Attackers create a fake network with a near-identical name. You connect, they see everything. You often can't tell which is real.

Packet sniffing

Software like Wireshark captures all data passing over a network. On unencrypted Wi-Fi, form submissions, cookies and HTTP pages travel as plain text — readable to anyone with the right software.

Session hijacking

Your browser session cookie is stolen. The attacker uses it to access your logged-in account — no password needed. Works on any service that isn't using full HTTPS.

Highest-risk networks

Airport Wi-Fi
Highest
Prime target, hundreds of users, frequent travellers with banking apps
Hotel networks
Very high
Shared with hundreds of guests, often poorly secured
Coffee shops
High
Open networks, no authentication, steady traffic
Hospital / waiting rooms
High
Open networks, users often distracted
Shopping centres
Medium
Open but lower-value targets than airports
Train stations
Medium
High footfall, opportunistic attacks

“But websites use HTTPS — doesn't that protect me?”

HTTPS encrypts the content of individual website connections. But it doesn't protect your DNS queries (the list of every site you visit), your connection metadata, or any traffic that isn't HTTPS.

An attacker on the same network can still see every domain you visit, even with HTTPS. They can also intercept any non-HTTPS traffic — which includes more than you might think.

What a VPN does on public Wi-Fi

A VPN encrypts all your traffic before it leaves your device. The network — and anyone on it — only sees encrypted gibberish. Even if intercepted, it's completely unreadable.

  • AES-256 encryption wraps every packet before it hits the network
  • DNS queries are encrypted — nobody can see which sites you visit
  • Kill switch disconnects your internet if the VPN drops — no accidental exposure
  • DNS leak protection prevents your ISP from seeing your browsing

AES-256 encryption on every network

Coffee shops, hotels, airports — encrypted automatically. From £0.11/day.

Get Protected Now