Public Wi-Fi Safety for Travelers: The Real Risks and Simple Fixes
Airport and café Wi-Fi is convenient and genuinely risky. Here is what can actually go wrong, what is overblown, and why your own eSIM data is the simplest fix.
Public Wi-Fi advice online swings between "you will be hacked instantly" and "it is fine now". The truth sits in between, and the practical fix is easy.
Short answer: modern HTTPS protects most of your traffic, so the realistic risks are fake hotspots, captive-portal phishing and outdated devices — not someone reading your bank password out of the air. The simplest mitigation is to use your own mobile data for anything sensitive.
What is actually risky
1. Evil-twin hotspots. Anyone can name a hotspot "Airport_Free_WiFi". Connect to it and all your traffic passes through a stranger's device. This is the real, common threat.
2. Captive-portal phishing. That "sign in with your email/card" page may not belong to the venue. Never enter payment details on a Wi-Fi login page.
3. Unpatched devices. Old, unupdated phones and laptops on a shared network are far more exposed than current ones.
4. Shoulder surfing. Unglamorous, but a genuinely common way people lose credentials in airports and cafés.
What is largely overblown
- "They can read your passwords." Nearly all sites use HTTPS, which encrypts content in transit even on a hostile network.
- "You need a VPN or you are doomed." A VPN helps, particularly against evil twins, but it is not the only answer — and a shady free VPN is worse than no VPN.
The simple fixes, in order of value
- Use your own eSIM data for anything sensitive. Banking, bookings, work email. Mobile data is a private link to the carrier — no shared network, no evil twin. This is the single highest-value change.
- Turn off auto-join for open networks so your phone does not silently reconnect to a spoofed hotspot later.
- Keep your devices updated before you travel.
- Use a reputable VPN if you must use public Wi-Fi for sensitive work.
- Never enter card details on a Wi-Fi portal.
- Forget the network when you leave.
Where public Wi-Fi is still fine
Streaming, browsing, downloading maps, big photo backups — anything where you would not mind a stranger seeing the traffic. Use hotel Wi-Fi for the heavy lifting and your eSIM for the private stuff. That split also saves your data.
The airport Wi-Fi code trap
Many airports gate their free Wi-Fi behind an SMS code sent to a local number you do not have. Travelers with their own data walk straight past this. It is a small thing that causes disproportionate frustration — see eSIM for layovers.
The bottom line
Public Wi-Fi is fine for casual use and a poor choice for banking. Carry your own data and the question mostly disappears. Browse plans for 190+ destinations.
One habit: sensitive things on your eSIM, heavy things on hotel Wi-Fi. That covers both security and your data allowance.