Last year I sat in a gate at Heathrow with my laptop open, deliberately connected to the airport's public Wi-Fi, running Wireshark to sniff my own traffic. Just to see what I could see. The answer was... kind of boring? Most of what I captured was encrypted garbage — TLS handshakes, HTTPS headers, nothing readable. But there was enough interesting stuff in the corners to make me want to dig deeper.
So I spent the next few months doing informal tests across café networks in three countries, two major airports, and a hotel chain I won't name (yet). Here's what I actually found — and honestly, the truth is more nuanced than either "public Wi-Fi is totally fine" or "never connect or you'll be immediately robbed."
The Threats That Are Actually Real
Evil Twin Networks
This one's legitimate and I've seen it in the wild. An evil twin attack is where someone sets up a rogue Wi-Fi access point with a name that looks like the real network. You're at a Starbucks, you see "Starbucks_WiFi" and "StarbucksWiFi" — one of those might be someone with a $40 Wi-Fi Pineapple from Hak5 sitting three tables over.
Your device connects, and now all your unencrypted traffic routes through their machine. They can see exactly what you're doing if the destination isn't using HTTPS. The Hak5 Wi-Fi Pineapple Mark VII retails for around $99 and it's genuinely plug-and-play for this kind of thing. I bought one to test with. Setup took maybe 20 minutes.
The good news: if you're visiting sites over HTTPS (and in 2026, the vast majority of the web is), the evil twin operator sees encrypted traffic even if they're the middleman. They'd need to pull off an SSL stripping attack to actually read it — and modern browsers make that much harder than it used to be.
SSL Stripping — Still Possible, Less Common
SSL stripping downgrades your HTTPS connection to HTTP so traffic is readable. Tools like Bettercap can do this on a local network. I ran Bettercap in a controlled lab environment against one of my own devices and it still works — against older apps and sites that don't enforce HSTS (HTTP Strict Transport Security).
Here's the thing though: major sites like Google, Gmail, your bank, and most apps have had HSTS preloaded in browsers for years. Chrome, Firefox, and Safari maintain a hardcoded list of domains that must always use HTTPS. Your bank's login page isn't getting stripped. A random local restaurant's website from 2014 that doesn't have SSL? Different story, but you're probably not logging into anything sensitive there anyway.
DNS Spoofing on Captive Portal Networks
This one I think is underrated. When you connect to a hotel or café network with a captive portal — that annoying login page — the network operator has full control over DNS responses. They can technically redirect you to a fake version of a site before you even realize it.
I tested this on a hotel network in Portugal (purely my own traffic, my own devices). The network was routing DNS through a third-party provider I didn't recognize, and DNS responses were not encrypted. Someone controlling that infrastructure could serve spoofed responses without me knowing — unless I was using encrypted DNS.
"DNS is the phone book of the internet. If someone controls your phone book, they can send you anywhere they want — including a fake destination that looks exactly like the real one." — this is how I explain it to my non-tech friends and it tends to land.
The fix is dead simple: use 1.1.1.1 with WARP (Cloudflare's free app), or Quad9, or any resolver that supports DNS-over-HTTPS or DNS-over-TLS. Takes two minutes to set up on your phone or laptop and it's free.
The Stuff People Panic About That's Mostly Fine
"Someone Will Steal My Passwords"
I hear this constantly. The fear is that someone's passively scooping up credentials as you type them. Honestly? In 2026, this is really hard to pull off against normal browsing behavior on sites that properly implement HTTPS with HSTS.
I used Wireshark on a shared test network and tried to capture login credentials being submitted to Gmail, a major bank's site, and a popular e-commerce platform. Got nothing usable. The TLS encryption did exactly what it's supposed to do. The only scenario where this becomes a real risk is if you're logging into something over plain HTTP — and those sites are becoming genuinely rare.
That said: weak spots still exist in native apps that talk to poorly configured servers. This is where things get grayer. Not every mobile app implements certificate pinning properly. According to research published by the Georgia Tech Information Security Center, a non-trivial percentage of Android apps still had TLS implementation flaws as recently as 2022. So your main browser? Probably fine. That random loyalty app for a local coffee chain? Less sure.
Packet Sniffing From Other Users
The classic fear: someone on the same café Wi-Fi is watching all your traffic. This was a legitimate problem in the WEP days. Modern WPA2 and WPA3 networks assign each client its own encryption key, so even though you're on the same network as 20 other people, you can't just sniff their traffic with Wireshark anymore.
WPA3 specifically (which is now required for Wi-Fi 6 certification) makes this even harder with Simultaneous Authentication of Equals (SAE). If the café network is running WPA3 — and more are, slowly — passive sniffing is basically a dead end for attackers.
The problem: plenty of networks still run WPA2, and some still run no encryption at all. I found two completely open (no password) networks in a single afternoon of walking around a city center in Southeast Asia. On those? Old-school sniffing works, at least for unencrypted traffic.
Your Streaming or Gaming Getting Hijacked
Not really a thing. I see this in comments all the time. Someone's Netflix session isn't getting taken over via public Wi-Fi in any practical sense. Session cookies are tied to device fingerprinting and geographic checks in most major platforms now. People confuse this with credential theft, which is a different attack vector entirely.
Who's Actually At Risk
Here's where I want to be real with you. The average person checking Instagram and reading news articles on airport Wi-Fi? The risk is pretty low if their devices are updated and they're not ignoring browser security warnings.
But that's not everyone.
Journalists, Activists, and People in Sensitive Jobs
If you're a journalist covering sensitive topics, a political dissident, or someone working in finance or government — the calculus is completely different. Groups like APT28 (Russian GRU-linked) and Lazarus Group (North Korea) specifically run operations targeting high-value individuals in transit. Hotels and airports are known hunting grounds because targets are away from their secure office environments.
The FBI and CISA put out a joint advisory in 2023 about state-sponsored actors targeting travelers specifically at international airports. These aren't theoretical attacks — they're documented operations with named victims in intelligence community reporting.
People on Older, Unpatched Devices
If you're running Windows 10 without updates (Microsoft officially ended support in October 2025), or an Android phone that hasn't gotten a security patch in two years, public Wi-Fi is a genuinely higher risk environment for you. Not because of packet sniffing — but because local network attacks can sometimes probe for vulnerabilities in network-facing services. Old SMB implementations, outdated Bluetooth stacks, things like that.
I know a lot of people in developing countries are running older devices because that's what's affordable. I'm not going to pretend the advice "just get a newer phone" is helpful. In that case: keep your browser updated even if the OS is old (Chrome and Firefox update independently), use HTTPS-everywhere browser extensions, and be extra cautious about which networks you connect to.
What Actually Works (And What's Overkill)
A VPN — Yes, But Pick Carefully
A VPN encrypts your traffic before it leaves your device and routes it through the VPN provider's server. On a hostile network, this is genuinely useful — an evil twin operator sees encrypted tunnel traffic, not your actual requests.
But I want to be clear: a VPN moves the trust from the café network to the VPN provider. If your VPN provider is logging and selling your data — or gets subpoenaed — that's a different problem. I've been using Mullvad ($5/month, accepts cash and crypto, audited no-logs policy) for a while and I trust it more than most. ProtonVPN is solid too and has a free tier that's actually usable.
I spent way too long going through VPN marketing claims before settling on these two. Most of the "no-logs" VPNs you see advertised on YouTube have never had an independent audit. That should tell you something.
Things You Should Actually Do
- Turn off auto-connect for Wi-Fi networks on your phone. iOS and Android 12+ both let you manage this — do it.
- Use a browser that enforces HTTPS — Chrome, Firefox, and Safari all do this by default now, but check that HTTPS-Only mode is enabled in Firefox settings.
- Set up encrypted DNS. Cloudflare's 1.1.1.1 app is free, takes two minutes, works on iOS and Android.
- If you're doing anything sensitive — logging into work systems, accessing financial accounts — either use your mobile data or make sure your VPN is running first.
- Forget the network when you leave. Don't let your device auto-reconnect to "Starbucks" wherever you go in the world — that's how evil twin attacks get you without you even realizing it.
Things That Are Probably Overkill for Most People
- Buying a travel router and building your own hotspot at every hotel (unless you're a road warrior with specific threat concerns)
- Completely avoiding public Wi-Fi and using only mobile data — expensive, impractical in areas with weak mobile coverage, and the actual risk reduction for average users is minimal
- Running your own VPN server at home — adds complexity and your home IP becomes a tracking vector
The Honest Bottom Line
Public Wi-Fi in 2026 is meaningfully safer than it was in 2012. HTTPS is nearly universal, WPA3 is spreading, and browsers actively fight SSL stripping attacks. The horror stories you read online are often based on decade-old threat models that don't fully apply to modern devices and modern web infrastructure.
That doesn't mean the risk is zero. Evil twin networks are real and cheap to deploy. DNS manipulation on captive portals is underappreciated. And if you're a high-value target — journalist, executive, activist — the risk profile is genuinely different and you should be using a VPN, full stop.
For most people though: keep your software updated, use HTTPS-only mode in your browser, set up encrypted DNS, be skeptical of captive portal login pages that ask for more than they should, and maybe get a VPN if you travel a lot. That's it. You don't need to treat every café network like it's a DEFCON hacking competition floor.
Honestly, the biggest security risk most people face isn't the coffee shop Wi-Fi. It's reusing passwords, skipping two-factor authentication, and clicking phishing links in email. Fix those first and public Wi-Fi moves way down the priority list.
