For years, every security article repeated the same warning: never do banking on public Wi-Fi. That advice made sense in 2012, when most websites sent data unencrypted and anyone in the same cafe could read your traffic with free software. But the web has changed fundamentally since then, and the honest answer today is more nuanced: public Wi-Fi is much safer than its reputation, but not risk-free.
What changed: HTTPS everywhere
The overwhelming majority of websites now use HTTPS – the padlock in your address bar. HTTPS encrypts everything between your browser and the website: passwords, card numbers, messages, even which specific pages you visit on the site. Someone snooping on cafe Wi-Fi sees that you connected to your bank, but not your login, your balance or anything you did there. Banking apps on your phone add their own encryption on top.
This is why the classic “evil twin hotspot reads your passwords” scenario mostly stopped working. Even if you connect to a malicious access point, the attacker still cannot decrypt HTTPS traffic, and modern browsers loudly warn you when a connection is not secure.
What is still genuinely risky
Fake login portals
The realistic modern attack is not decrypting your traffic – it is presenting you with a fake page. A hotspot named “Airport_Free_WiFi” pops up a login page asking for your email password or card details “to access the network”. No legitimate network needs your email password. Captive portals asking for a room number or a ticket code are normal; ones asking for real credentials are harvesting them.
Old or misconfigured connections
Rare non-HTTPS sites, old email apps still fetching mail without encryption, and file sharing left switched on make you visible to neighbours on the network. Modern operating systems mark public networks as such and firewall them by default, but it is worth confirming your laptop treats new networks as “public”, not “home”.
Shoulder surfing
Decidedly low-tech, and still the most reliable attack in any cafe: someone watching you type a PIN or reading your screen. No software fixes this.
Do you need a VPN on public Wi-Fi?
A VPN encrypts all your traffic and hides which sites you visit from the network operator. That is a real privacy benefit, and on sketchy networks it adds a comfortable safety margin. But it is a privacy tool more than a necessity: with HTTPS, your passwords and card numbers are already encrypted without one. If you do use a VPN, choose carefully – a free VPN of unknown ownership can see far more of your traffic metadata than the cafe owner ever could, so you may be trading a small risk for a bigger one.
Three rules that actually matter in 2026
- Never enter real credentials into a network login portal. Wi-Fi access pages have no business asking for your email or bank password.
- Heed browser warnings. If your browser says a connection is not private while you are on public Wi-Fi, stop. That warning is the exact attack the old advice was about.
- Prefer your phone’s hotspot for the truly sensitive. Mobile data is not snoopable by the people around you. If something feels high-stakes – large transfers, work systems – tether for five minutes.
The bottom line
Checking your bank balance at the airport is fine. The web you use today was built to survive hostile networks. The dangers that remain are human ones: fake portals, ignored warnings and the person at the next table watching your fingers. Handle those three, and public Wi-Fi is just Wi-Fi.