Public Wi-Fi is not automatically a data breach
Most modern websites and apps use encrypted HTTPS connections, which protects the content in transit between the device and the legitimate service. Shared networks still create risks involving fake hotspots, unencrypted services, device sharing and misleading login pages.
Confirm the network name
Attackers can create look-alike hotspot names. Ask the venue or check posted information rather than selecting the strongest signal with a familiar name.
Check the destination, not only the padlock
HTTPS protects a connection to the site you reached; it does not prove that the site itself is legitimate. A phishing page can also use HTTPS. Read the domain carefully before signing in.
Disable unnecessary sharing
Turn off file sharing, nearby sharing or network discovery when using an unfamiliar network. Keep the device firewall enabled.
Prefer your own connection for sensitive work
A cellular hotspot can reduce exposure to a malicious local network, though the account and destination still need protection. Avoid using shared public computers for primary email, financial accounts or password-manager access.
What a VPN changes
A VPN encrypts traffic between the device and the VPN provider, which can reduce visibility on the local network. It transfers trust to the VPN provider and does not make phishing, malware or unsafe accounts disappear.
Practical takeaway
Use legitimate HTTPS sites, verify the network and domain, disable sharing and avoid sensitive sign-ins on shared computers.
Captive portals and login pages
Hotels, cafés and airports often use a portal that appears before normal internet access. Confirm the venue’s process and avoid entering unrelated email or social-account credentials merely because the portal requests them. A legitimate network may ask for a room number, access code or acceptance of terms, but the request should fit the service.
After leaving the network
Choose “forget this network” when you do not want the device to reconnect automatically. Auto-join can connect later to a look-alike hotspot. Re-enable sharing only when back on a trusted network and review any browser warnings or account alerts that appeared during the session.
Shared networks at home and work
The same principles apply to guest networks, apartment Wi-Fi and shared workspaces. Change default router administration credentials, install firmware updates and separate untrusted smart devices or guests where the equipment supports it. Do not assume that every device on a familiar network is well maintained.
When sensitive work is unavoidable
Use the organization’s approved connection method, confirm the destination domain and avoid downloading confidential files to a borrowed device. Sign out fully, clear local copies where appropriate and verify that the browser did not save credentials. A private window reduces local history but does not make the computer trustworthy.