Is public Wi-Fi safe without a VPN? Usually — with limits

Mostly, yes — for ordinary browsing. The FTC says public Wi-Fi is usually safe because most websites encrypt traffic with HTTPS. The network can still often see which sites you visit, and fake hotspots and phishing remain real risks. Use a VPN to hide your destinations, and use cellular data for banking and other sensitive logins.

Most advice on this question was written for an older web — one where pages traveled as plain text and anyone nearby could read them. That web is mostly gone. The FTC, which has nothing to sell you, says connecting through public Wi-Fi is “usually safe” because “most websites do use encryption.” The padlock in your browser means the content moving between you and a site is unreadable to the stranger two tables over.

“Usually safe” is not “safe for everything,” though. Washington State’s technology agency recommends a VPN on public Wi-Fi — and still advises against touching your bank account on an unsecured network even with one. So the useful question is not whether public Wi-Fi is safe. It is which tasks are fine, what the network still sees, and when a VPN changes the outcome.

What does HTTPS protect — and what leaks anyway?

HTTPS encrypts the content of your session: the pages you read, the passwords you type, the card number you enter at checkout. On an HTTPS site, nobody else on the café network can read any of that.

What HTTPS does not hide is where you go. In a standard setup your DNS lookups — the requests that turn a site name into a server address — are not encrypted, and the network operator can often see connection metadata: which domains you visited, and when. Proton VPN’s write-up on public Wi-Fi and HTTPS draws exactly this line: contents protected, destinations not.

A VPN moves the line. It wraps all your traffic, DNS included, in one encrypted tunnel, so the local network sees only a connection to a VPN server. The trade is real: your provider now sits where the café’s router used to, and can see your destinations instead. That is why provider trust — jurisdiction, audits, logging policy — leads our full VPN rankings. If tunnels and protocols are new territory, what a VPN is and how it works covers the mechanics.

What the Wi-Fi network can see, with and without a VPN (FTC and Proton VPN guidance, as of 23 Jul 2026)
Exposed to the local network?HTTPS onlyHTTPS + VPN
Page content, passwords, card numbersNo — encrypted on HTTPS sitesNo — encrypted
Which sites you visit (DNS, domains)Often yes, in a standard setupNo — the VPN provider sees them instead
Traffic on non-HTTPS sites and appsYes — readableNo — encrypted to the VPN server
That you are online, and data volumeYesYes — as one tunnel to a VPN server

What still goes wrong on an open network?

The attacks that survive HTTPS mostly involve tricking you rather than decrypting you. Kaspersky’s and Norton’s risk lists, and the state guidance behind them, converge on the same few:

  • Evil-twin hotspots. An attacker’s device broadcasting the same name as the venue’s network looks identical to the real thing. Join it, and every login page it serves can be fake.
  • Man-in-the-middle attempts. Sitting between you and the router works poorly against HTTPS — until a certificate warning appears and you click through it. That click is the whole attack.
  • Captive-portal phishing. A “sign in with your email for free Wi-Fi” page can be a harvesting form.
  • Interception, malware, and identity theft. Norton’s headline risks for public networks, aimed mostly at unencrypted traffic and unpatched devices.

None of the sources behind this article publish numbers on how often these attacks happen — no frequency data by venue or year appears in any of them. So the odds are unquantified, but the cost of one successful fake portal is high. Act on the cost, not the odds.

Which tasks are fine without a VPN?

Task-by-task calls from the FTC, Norton, Kaspersky, and Washington State guidance
TaskOn public Wi-Fi without a VPN
Reading, news, video, mapsFine over HTTPS — the FTC calls public Wi-Fi usually safe because most sites encrypt
Shopping and account loginsNorton advises against them on public networks; HTTPS plus multi-factor authentication is the floor if you must
Sensitive emailOn Norton's avoid list — an email account can reset every other password you own
Online bankingSkip it. Washington State advises against it even with a VPN on unsecured networks — use cellular data
Work systems and business resourcesKaspersky calls a VPN "a must" on an unsecured hotspot

The split is why one-line slogans fail. The same café network is fine for reading the news and wrong for checking your balance. Norton’s avoid list — banking, shopping, logging into accounts, sending sensitive email — is a list of tasks where a stolen session costs money or an identity, not a claim that HTTPS is broken.

What does a VPN actually fix?

Three specific things. It hides which sites you visit from the network operator. It encrypts traffic that HTTPS does not cover, including DNS in a standard setup. And it makes a hostile network mostly irrelevant, because an evil twin cannot read a tunnel it cannot open.

Just as important is what it does not touch. A VPN cannot stop you from typing your password into a convincing fake page, and phishing links, malicious downloads, and an already-compromised device ride inside the tunnel like any other traffic. Washington State’s guidance is the sharpest version of this: even with a VPN, it advises against personal banking on unsecured public networks.

If you do use one, CNET’s feature shortlist for public Wi-Fi is short: a kill switch, so a dropped tunnel never silently exposes your traffic, and DNS leak protection. What a VPN kill switch does covers the first in detail. And because a VPN relocates trust rather than removing it, the provider’s audit record is the first thing to check — no-log VPN audits explained shows what those reports prove and what they skip.

For occasional use — an airport layover, a hotel week — you do not need to pay. Proton VPN’s free tier covers one device with no data cap, and Proton publishes its no-logs audit reports in full (Securitum, five consecutive years through 2026). Windscribe gives 10 GB a month free with a confirmed email address; its most recent independent audit is a June 2024 Packetlabs test of its server stack, not a formal no-logs attestation. Both are covered in our best free VPN picks.

How do you stay safe, with or without a VPN?

Three rules cover the decision:

  • HTTPS alone is enough for reading, watching, and browsing on an updated device — as long as you treat any certificate warning as a stop sign, not a pop-up.
  • Add a VPN when you do not want the operator seeing your destinations, when the network is one you have no reason to trust, or when you are reaching work systems — Kaspersky’s line, not ours.
  • Use cellular data for banking and anything else you would hate to explain to a fraud department. Washington State draws that line even for VPN users, and your phone’s connection is not shared with strangers.

Whatever you choose, the basics in the state and FTC-aligned guidance do more than any single tool: keep your OS and browser updated, use strong passwords with multi-factor authentication, keep the firewall on, confirm the exact network name with the venue before joining, and turn on your browser’s always-use-HTTPS setting — advice Kaspersky makes explicitly.

Frequently asked questions

Frequently asked questions

Can hackers steal your passwords on public Wi-Fi without a VPN?

On an HTTPS site with an up-to-date browser, intercepting a password in transit is no longer the practical attack — the connection is encrypted. The realistic route is a fake hotspot or phishing page that gets you to type the password in yourself, and a VPN cannot prevent that either.

Can the Wi-Fi network see which websites you visit?

Often, yes. HTTPS hides page content but, in a standard setup, not your DNS lookups or connection metadata, so the operator can see the domains you visit. A VPN hides those destinations from the local network — the VPN provider can see them instead.

Is it safe to use banking apps on public Wi-Fi without a VPN?

Guidance splits on this. Some current sources treat an official banking app on a patched phone as generally safe because the connection is encrypted. Washington State's technology agency is stricter: it advises against accessing bank accounts on unsecured public networks even with a VPN. Cellular data ends the debate.

Is HTTPS enough on public Wi-Fi?

For ordinary browsing on an updated device, current guidance mostly says yes — the FTC calls public Wi-Fi usually safe because most websites encrypt. HTTPS does not hide which sites you visit, does not cover non-HTTPS traffic, and cannot help if you click through a certificate warning. Those gaps are what a VPN and basic caution cover.

Should you use public Wi-Fi for email without a VPN?

Reading email over HTTPS is generally treated as lower risk. The caveat is stakes, not encryption: an email account can reset every other password you own, which is why Norton counsels against sensitive email on public networks and why multi-factor authentication on the account matters more than the network.

What should you do if you have to use public Wi-Fi without a VPN?

Stick to HTTPS sites and official apps, confirm the exact network name before joining, keep your OS and browser updated, turn on multi-factor authentication, and never click through a certificate warning. For banking or anything similarly sensitive, switch to cellular data instead.

Sources

  1. FTC — Are public Wi-Fi networks safe? What you need to know — accessed
  2. Washington State WaTech — Tips for safely using public Wi-Fi — accessed
  3. Norton — Public Wi-Fi risks — accessed
  4. Kaspersky — Public Wi-Fi risks — accessed
  5. CNET — Do you really need a VPN for public Wi-Fi? — accessed
  6. Proton VPN blog — Public Wi-Fi and HTTPS — accessed
  7. Proton VPN — Free plan — accessed
  8. Proton VPN blog — No-logs audit — accessed
  9. Windscribe — Use for free — accessed
  10. Windscribe — Has Windscribe been audited? — accessed