Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

What Are the Risks of Public Wi-Fi, and How Do You Actually Stay Safe?

Short answer: Now that HTTPS encrypts most web traffic, the old worry about strangers reading your passwords on public Wi-Fi is mostly outdated. The real remaining risk is a fake "evil twin" network with a phony login page, so confirm the exact network name with staff and use a VPN for anything sensitive.

The classic warning — "someone on the same coffee shop Wi-Fi can read your email and see your passwords" — was genuinely true fifteen years ago and is mostly outdated today. That doesn't mean public Wi-Fi is risk-free. It means the actual risk has moved, and it's worth understanding where it actually is now instead of repeating advice built for a web that doesn't exist anymore.

What's actually happening

Back in 2010, a browser extension called Firesheep made a real point loudly: most websites only encrypted the login page, not everything after it, so anyone else on the same open Wi-Fi network could grab an unencrypted session and effectively be logged in as you. That demonstration was a real part of why the entire web moved toward encrypting everything, not just logins. Today, HTTPS — the padlock in your browser's address bar — covers the overwhelming majority of web traffic, and it genuinely does encrypt what you send and receive on a properly secured site. The old "packet sniffing your password out of the air" scenario is much smaller than it used to be.

What HTTPS doesn't fully hide: the network operator (whoever actually controls the Wi-Fi router you're connected to) can generally still see which domains you're visiting, even if not what you're doing on them — a technical limitation in how secure connections are initially set up. And that points at the risk that hasn't gone away at all: it matters enormously who's actually running the network you just connected to.

The main real threat today is the "evil twin" — a rogue access point set up with a name that looks exactly like a legitimate network ("Airport_Free_WiFi," or the exact name of the café you're sitting in). Devices often remember and auto-connect to network names they've used before, which means a convincingly named fake network can pull a device onto it without anyone consciously choosing to connect. Once you're on an attacker's network instead of the real one, they control what you see — including the ability to show a fake "sign-in" page (a captive portal) asking for credentials before granting access, the same mechanism as phishing, just delivered through a Wi-Fi login screen instead of an email.

HTTPS protects what you send — it doesn't prove who's actually running the network

A local business scenario

(A composite, illustrative pattern — not one specific business's story.)

A business owner works from a café between meetings, connecting to a network name that matches the café's own Wi-Fi exactly — it's actually a rogue network set up by someone nearby, not the café's real one. Before granting internet access, a login page appears asking them to "sign in with Google to continue" — a normal-looking, if slightly unusual, extra step for public Wi-Fi. They enter their credentials to get online.

Every site they visit afterward, including their own business's login, shows the correct padlock and loads normally — HTTPS is doing its job protecting that traffic. But the damage already happened at the captive portal: the credentials typed into that fake sign-in page went straight to whoever set up the network, nothing to do with HTTPS at all.

Best practices

  1. Verify the exact network name and password with staff before connecting — asking out loud is the single most effective defense against an evil twin, and it takes ten seconds.
  2. Turn off Wi-Fi auto-connect for open/public networks specifically, so your device doesn't silently rejoin a remembered name without you choosing to that time.
  3. Treat any Wi-Fi login page asking for real account credentials — not just "accept terms and continue" — with the same suspicion as any other login page. A public network generally shouldn't need your Google or Facebook password to grant internet access.
  4. Use a VPN on public networks, especially for anything involving business or financial accounts — still the FTC's top recommendation, and it protects the parts HTTPS alone doesn't: traffic on a network you can't fully verify, and visibility into which sites you're visiting.
  5. Save sensitive actions for a network you trust when you can — not because HTTPS doesn't work, but because on public Wi-Fi you often can't fully verify which network you're actually talking to in the first place.

Helpful, free resources

A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.