Annonces
Public WiFi is safer in 2026 than it was ten years ago, mostly because almost every website and app now encrypts its traffic. That doesn’t make every cafe network harmless. The risks just moved: fake hotspots with a convincing name, sign-in pages that ask for more than they should, and phones that join any network they’ve ever seen without asking.
This guide is for anyone who uses airport, hotel, cafe or library WiFi and wants a short set of habits and a few apps that cover the real risks without making the internet a chore. You’ll get the phone settings to change once (with the actual menu paths on iPhone and Android), the apps I keep for public networks, and a clear list of things I don’t do on shared WiFi.
I’m not going to tell you never to use public WiFi. That advice is useless, and it pushes people into burning their data plan. The goal is to use it with your eyes open.
What can actually go wrong on public WiFi
It helps to know what you’re defending against, so you don’t waste effort on the wrong thing.
Fake hotspots
Someone sets up a network called “Airport Free WiFi” or copies the name of the cafe’s real network. Your phone sees a familiar name and may join it on its own. Once you’re on their network, they can show you fake sign-in pages and see which sites you visit, even if they can’t read the encrypted content.
Sign-in pages that ask for too much
Many legitimate networks show a “captive portal”, the page where you accept terms. A malicious one asks you to “log in with Google” on a page that isn’t Google, or asks for a card number “to verify”. Real public networks almost never need anything beyond an email address, a room number, or a click on Accept.
Your phone being visible to strangers
On a shared network, other devices can sometimes see yours. File-sharing features like AirDrop or Quick Share, set to accept from everyone, invite unwanted files and messages.
Apps and sites that don’t encrypt
Most do, but older apps, some smart-home dashboards, and a few small websites still send data in the clear. On a hostile network, that data is readable.
What you’re mostly not up against is someone reading your bank session over HTTPS from the next table. That’s why the habits below focus on which network you join and what you type into sign-in pages.
Change these phone settings once
These take ten minutes and protect you every time after.
Turn off auto-join for public networks
On iPhone, go to Settings > Wi-Fi, tap the info button next to a public network you’ve used, and turn off Auto-Join. Also check Settings > Wi-Fi > Ask to Join Networks and set it to Notify or Ask, so your phone tells you about networks instead of joining quietly.
On Android, go to Settings > Network & internet > Internet, tap the gear next to a saved network, and turn off Auto-connect. On Samsung, it’s Settings > Connections > Wi-Fi, tap the gear next to the network, and turn off Auto reconnect. Menu names change a bit between brands, but the switch exists on every recent Android phone.
Better still, forget public networks after you leave. On iPhone, the info button has Forget This Network; on Android, the same screen has Forget.
Use a private, rotating WiFi address
Phones can use a different hardware address (MAC address) for each network, so networks can’t track you from place to place. On iPhone with iOS 18 or later, go to Settings > Wi-Fi, tap the info button next to the network, then Private Wi-Fi Address, and choose Rotating for public networks. Apple’s own guide to private Wi-Fi addresses explains the Off, Fixed and Rotating options. On Android, the same screen for each network has Privacy > Use randomized MAC, which is on by default.
Lock down file sharing
On iPhone, set AirDrop to Contacts Only or Receiving Off in Settings > General > AirDrop. On Android, open Quick Share from the quick settings panel and set it to Your contacts. Do this once and forget about it.
Keep the system up to date
Most serious WiFi attacks rely on old bugs. Turn on automatic system updates: on iPhone, open Settings > General, tap the update entry, and turn on Automatic Updates; on Android, look in Settings > System > System update on most phones.
The apps I keep for public WiFi
Proton VPN
A VPN encrypts everything between your phone and the VPN server, so the network you’re on sees only that you’re connected to a VPN. That handles the fake hotspot and unencrypted-app problems in one step. Proton VPN, from the Swiss company behind Proton Mail, has a free plan with no data limit and no ads, for one device. Proton VPN Plus costs $11.99 a month on the App Store, less on a yearly plan, and adds server choice and more devices.
The free plan can be slower at busy hours, and you don’t choose the server country. For public WiFi, neither matters much. My tip: turn on the “always-on” or “connect on launch” option, so the VPN reconnects when you join a new network instead of relying on you to remember.
Cloudflare 1.1.1.1 + WARP
If you want something even simpler, Cloudflare’s 1.1.1.1 app with WARP encrypts the traffic from your phone through Cloudflare’s network. It’s free, with optional paid upgrades. It isn’t designed to hide your location or change your country the way a traditional VPN does; it’s designed to keep the local network out of your traffic, which is exactly the public WiFi problem.
The limitation is that some banking and streaming apps occasionally act up with WARP on; turn it off for that app and back on after. Choose either Proton VPN or WARP, not both at once.
WiFi Map
WiFi Map is a crowdsourced map of hotspots, and here I use it for a safety reason: the comments and photos tell you what the legitimate network name is at a given cafe or airport. If WiFi Map users say the network is “Cafe_Guest” and you see both “Cafe_Guest” and “Cafe Guest Free”, the second one deserves suspicion.
It’s free with ads; WiFi Map Premium costs about $34.99 a year on the App Store. One honest caveat: the passwords on WiFi Map are shared by users, so only use networks that the business actually offers to customers.
Instabridge
Instabridge is the other large hotspot community, with over 100 million downloads on Google Play. It serves the same purpose for safety: it shows which networks nearby have a known password and how other users rate them. Free with ads and in-app purchases. I use it as a second source when WiFi Map has no entry for a place. If you’d like a full comparison of finder apps, my free WiFi apps roundup covers them in detail.
Fing
Fing is a network scanner. On a hotel or cafe network, it shows how many devices are connected, and it can tell you whether the network looks like a normal router setup. If a “free WiFi” network has only two devices on it (you and something unnamed), in a busy airport, that’s odd. Fing is free with a paid Premium tier for home network monitoring, which you don’t need for this.
Use it to look, not to poke at other people’s devices; scanning ports on a network you don’t own may break the network’s terms.
A password manager
A password manager protects you from the most common public WiFi trap, the fake sign-in page. It only fills your password on the real website address, so if a portal pretending to be Google asks for your password and the manager offers nothing, that’s your warning. I compared the options in my guide to the best password manager apps.
What I don’t do on public WiFi
Even with a VPN, I keep a short list of things for cellular or home WiFi only:
- Typing a password into a captive portal or a “log in to continue” page that appears right after joining.
- Entering card details on any page the network itself shows me.
- Accepting a prompt to add a “profile” or “certificate” to the phone to “get online”. No legitimate cafe needs that.
- Using an old app that I’m not sure encrypts its connection, like an old smart camera or a router admin page.
- Leaving the network saved after a trip, especially in airports.
For banking, I switch to cellular for the minute it takes. It costs a few MB and removes the question entirely.
When your own hotspot is the better choice
If you need to work on a tablet or laptop in a place with dodgy WiFi, your phone’s personal hotspot is often safer than the venue’s network, and with a reasonable data plan it’s affordable for an hour or two. On iPhone it’s Settings > Personal Hotspot; on Android, Settings > Network & internet > Hotspot & tethering (Samsung: Settings > Connections > Mobile Hotspot and Tethering). Set a strong password on it.
If you’re traveling and paying for data, a travel eSIM makes this even more practical; I explain how in my guide to staying online abroad without roaming charges.
Common questions
Is it safe to use public WiFi without a VPN?
For browsing sites that use HTTPS (the padlock), the content of what you do is encrypted. The remaining risks are fake hotspots and sign-in pages, which a VPN plus the habits above reduce a lot. I’d still use a VPN for anything personal.
How do I spot a fake WiFi network?
Ask staff for the exact network name, look for near-duplicates with extra words or different spacing, and be suspicious of open networks in places that normally use a password. A sign-in page that asks for an email password or a card is a red flag.
Does the iPhone “Weak Security” warning matter?
Yes. It appears under networks that use no password or old encryption. It doesn’t mean the network is malicious, but anyone nearby can see unencrypted traffic, so turn the VPN on.
Is incognito mode enough on public WiFi?
No. Incognito only stops your browser from saving history on the phone. It doesn’t hide anything from the network.
My five-minute setup before the next coffee shop
Do this once: turn off Auto-Join for every public network already saved on your phone, set Ask to Join Networks to Notify (iPhone) or switch off Auto-connect for open networks (Android), set AirDrop or Quick Share to contacts only, and choose Proton VPN or Cloudflare WARP with the auto-connect option on.
Then, each time you’re out: ask staff for the network name, check it against WiFi Map if something looks off, join, accept only a terms page, and let the VPN connect before you open anything personal. When you leave, forget the network. It’s a few taps, and it covers nearly every way public WiFi actually goes wrong.




