Public Wi-Fi is safer than it used to be, and most of the warnings you've absorbed over the years no longer apply. Google found that its Chrome users spent over 95% of their browsing time on HTTPS-secured pages. So even if someone wants to use an unsecured page to crack someone's security, most web users probably won't end up on it. And nobody's likely plucking your bank password out of the air at the airport the way they might have a decade ago.
I want to be clear that this isn't a "relax, connect to anything" article. The risk didn't disappear. It evolved. The one attack that still works is the evil twin, a fake hotspot dressed up to look like the real network, and it's the threat your phone is least equipped to warn you about.
Get the full security checklist
This guide covers one of the five settings from our complete Android Privacy and Security Guide. The full checklist takes about an afternoon and handles the rest of your phone's weak spots, including: your Google account, app permissions, hidden apps, public Wi-Fi habits, and lost-phone protection. None of it requires downloading a thing, and most fixes take a minute or two each.
The Evil Twin is the attack that still works
An Evil Twin attack is when someone sets up a fake hotspot with a familiar-looking name, such as "Airport_Free_WiFi" or "Starbucks_Guest." You have to tap it to connect the first time, which is why a convincing name does so much of the work. But if it copies a network your phone has already saved, auto-join can reconnect you without a single tap.
The reason HTTPS doesn't save you here is sneaky. Those captive portal pages that public networks show you run over plain HTTP by design. An evil twin can present whatever portal it wants, including one that asks you to "sign in with Google" to get free Wi-Fi. That page is the trap, and it loads before encryption ever enters the picture.
Four habits that shut the attack down
Here's what I suggest you do when logging on to a public Wi-Fi network:
- Verify the network name. Ask the barista or the front desk for the exact Wi-Fi name. "CoffeeShop-Guest" and "CoffeeShop_Free_WiFi" are not the same, and one of them might be a trap.
- Turn off auto-join for public networks and forget them when you leave. On Android, tap the network, then forget it. That stops your phone from silently reconnecting to an evil twin next time you're nearby.
- Save the sensitive stuff for later. Use your cellular data or wait until you're home to access banking, shopping, and anything with a password worth stealing.
- Never click past a certificate warning. If your browser throws up a security or "not secure" alert, disconnect. That's your phone telling you something's wrong.
You don't need to be paranoid. You just need to stop letting your phone trust strangers on your behalf.
Do you still need a VPN?
You need one less than the scare stories suggest, and I say that as someone who's watched VPN marketing lean on outdated fears for years. HTTPS already encrypts the contents of what you send to almost every site that matters.
What a VPN still covers is the leftovers. It hides which sites you're visiting from the network operator, encrypts DNS lookups and app traffic that skip HTTPS, and wraps the roughly 1 in 20 connections that still aren't encrypted. It also lets you swap your apparent location, which is why plenty of people use one to reach content that's blocked where they are (guilty as charged). If you're on public Wi-Fi weekly, a reputable VPN is worth having (find our favorites in our VPN guide). If you connect twice a year at an airport, your cellular data is the better tool.
When to upgrade to a new phone
That's really the endgame here. The best defense against public Wi-Fi is not needing it. If you're forever hunting for free hotspots to save data, a plan with more of it often costs less than you'd expect, and it turns this entire article into someone else's problem.
Public Wi-Fi safety FAQs
Can hackers see my passwords on public Wi-Fi?
Hackers can't easily read your passwords on public Wi-Fi anymore, because more than 95% of web traffic is encrypted with HTTPS. The real danger is a fake network or login page that tricks you into entering credentials directly into an attacker's hands, which is why verifying the network name matters more than encryption concerns.
What is an evil twin Wi-Fi attack?
An evil twin attack is a fake hotspot named to look like a legitimate one, such as a coffee shop or airport network. Once you connect, the attacker can take control of your connection and display counterfeit login pages to capture your passwords or card details.
Do I still need a VPN on public Wi-Fi in 2026?
You need a VPN less than the scare stories suggest, but it still helps. HTTPS protects most traffic, while a VPN adds protection for your metadata, DNS queries, and the small slice of app traffic that remains unencrypted. It's worth it for frequent public Wi-Fi users and optional for everyone else.
Scott Houghton
Jr. Staff Writer