Practical guide · verified against the real thing
Public Wi-Fi: the honest risks (they are not the ones you were told)
In one line: Modern encryption fixed most of the coffee-shop threat. What actually remains: fake hotspots, captive portals and your own habits.
Old security advice treats every airport network as a sniper's nest where anyone reads your traffic. That advice is a decade out of date, and knowing why makes you both calmer and correctly paranoid about the threats that remain.
What changed
Most of the web now encrypts the connection itself — the padlock in the address bar means the coffee shop, the network and anyone on it see that you talked to your bank, not what was said. HTTPS arrived near-universally, so the classic "sniffing passwords from the air" attack mostly died with it. If a site would accept a password over plain unencrypted HTTP today, the site is the emergency, not the Wi-Fi.
The three real risks
The evil twin: a hotspot named "Airport_Free_WiFi" that is actually someone's laptop collecting whatever you send before encryption, or simply positioned to phish a login portal. The fake captive portal: the "sign in to continue" page that asks for an email and password — real portals almost never need a password, only an email or room number. You: shoulder-surfing in a crowded terminal, and the habit of doing banking where a camera over your shoulder works harder than any hacker.
What actually helps
Prefer a phone's personal hotspot when you have one — you control that network. Verify the exact network name with staff, not with the strongest signal. If a portal demands a password a real portal would not want, walk away. Keep the device updated; browser and OS updates patch the genuine drive-by flaws. A VPN adds a tunnel for unencrypted traffic and hides your activity from the network — honest but narrow: it protects you from the café, not from the VPN company, and it does not make a fake login page real.
The one-line version
Encryption made public Wi-Fi mostly fine; humans remain the exploit. The same judgement applies to messages — see how to read a link before tapping it, and for messaging privacy specifically, our Signal and WhatsApp comparison covers what each app encrypts and what metadata stays.
Next