// NO KYC · NO LOGS · NO TRACKERS

8 COINS · PRICED IN USD

Public networks

Is public Wi-Fi safe?

Free Wi-Fi stopped being a password-stealing minefield years ago — HTTPS fixed that. What replaced it is quieter: a sign-in page that wants your surname, a network nobody can verify, and a hotel full of strangers on the same segment. Here is what is actually risky in 2026, and what it costs you.

9 min read Updated Aug 2026 No tracking · ever
01

The short answer

“Is public Wi-Fi safe?” is really two questions wearing one coat. Split them and the panic drops out, because the two halves have very different answers.

  • Your traffic: largely solved. Roughly 95% of web traffic is encrypted end to end. The café cannot read your inbox, your bank session or your messages.
  • App data: largely solved. Banking, messaging and mail apps pin or verify their connections. The 2012 demo of stealing logins over open Wi-Fi does not reproduce on a current phone.
  • Certificate warnings still work. A network that tries to sit in the middle of a modern HTTPS session produces an alarm rather than a silent success.
  • Your identity: worse than ever. You now have to sign in before you get online, and that page wants a surname, a room number, an email or a phone number.
  • Your local exposure: unchanged. You join a network you cannot verify, shared with everyone else in the building.
  • Your presence: logged. Connecting is a timestamped record that a specific device — and often a specific person — was in that building.

The modern risk of public Wi-Fi is not that someone reads your traffic. It is that connecting to it is an identity transaction, and nobody presents it as one. The same distinction runs through what an anonymous eSIM hides — and what it can’t.

If you only remember one thing: the danger moved from content to metadata. Encryption solved the first. Nothing about a free hotspot solves the second.

02

What HTTPS actually fixed

The public-Wi-Fi horror story everyone repeats comes from a specific era. Around 2010, most of the web was unencrypted, session cookies travelled in the clear, and a laptop in the same café could lift them out of the air with a browser extension. That era is over.

Three changes closed it, and they are all on by default:

  • Encryption everywhere. Browsers now treat plain HTTP as an exception to be warned about, not a normal way to load a page.
  • Strict transport rules. Major sites tell your browser, in advance, never to accept an unencrypted version of themselves — so the classic downgrade trick fails before it starts.
  • Encrypted name lookups. Modern browsers and phones increasingly resolve domain names inside an encrypted channel, which takes the venue’s router out of the loop.

This is why “never use public Wi-Fi for banking” has aged badly as advice. Your banking app is the best-defended thing on your phone. The soft targets are elsewhere.

03

What is still a real risk

Four things did not get fixed, because none of them are about encryption.

The lookalike network

Any device can broadcast a network called “Airport_Free_WiFi”. The name proves nothing about who is running it, and there is no way for you to check from the outside.

The sign-in page

A captive portal works by intercepting your first request — that is the mechanism, not a fault. Which means the one page you are guaranteed to type into is the one page you can least verify.

The room next door

On a network without client isolation, everything attached shares a segment: laptops with file sharing left on, printers, smart TVs, and whatever the other guests brought.

The silent re-join

Your phone remembers open networks and reconnects without asking. Months later, in another country, a network broadcasting that same familiar name gets you for free.

None of these are exotic. They are the ordinary consequences of joining an unauthenticated network run by someone you have never met — which is what “free Wi-Fi” means. What they mostly cost you is not money; it is the thing covered in the next section.

04

The cost nobody counts: the sign-in page

Free Wi-Fi is not free. The price is an identifier, collected at the door, and it is usually one you cannot rotate: your surname, your room, your real phone number.

Where you connectWhat the sign-in asks forWhat it ties the session to
HotelRoom number + surnameYour booking — which in most countries means the ID you showed at check-in
Airport terminal or loungeEmail address, or a social loginA durable marketing identity, reused on every visit
Café chainEmail or a loyalty accountYour purchase history across every branch of the chain
Conference or coworking spaceName and companyA named attendee list with arrival and departure times
Municipal or transport Wi-FiPhone number + SMS codeA number that is registered to a person by law in most countries

That last row is the one worth sitting with. In a country with mandatory SIM registration, “verify by SMS” is not a convenience step — it is an identity check running on top of an identity check. The SIM registration guide lists which countries those are, and what the scan of your passport actually gets attached to.

Hotel Wi-Fi is the sharpest example. Guest registration is a legal requirement across much of Europe, the Gulf and Asia — Spain tightened its reporting rules at the end of 2024 — so the booking behind that room number is already tied to a passport before you open the laptop.

05

Countries where the Wi-Fi itself wants ID

In several countries the identity check is not a marketing choice by the venue — it is written into the rules for offering public internet access at all. As a visitor you meet it in the same way every time: the portal wants a local mobile number, and you do not have one.

  • China — public hotspots typically verify with an SMS code to a Chinese number, which most visitors cannot receive.
  • Russia — public Wi-Fi has required user identification since 2014, normally by phone number.
  • India — airport and café portals routinely send a one-time code to an Indian number.
  • United Arab Emirates — hotel access is tied to the room and the guest record; some public networks want a local number.
  • Turkey, Indonesia and much of the Gulf — SMS verification is the default pattern for open networks.

The practical result is a catch-22: you need internet to arrange a local number, and you need a local number to get internet. A travel profile you installed before departure sidesteps it, which is the same mechanism explored in the censorship and blocked apps guide. Country pages for China, India and the United Arab Emirates have the specifics.

A myth worth retiring: Italy has not required ID for public Wi-Fi since the Pisanu-era rules were dropped in the early 2010s. Guides still repeat it a decade later. The hotel will still know who you are, but that is the booking, not the Wi-Fi law.

06

What a VPN fixes — and what it doesn’t

A VPN is the standard advice, and it is good advice as far as it goes. It is worth being precise about how far that is.

  • It hides your traffic from the venue. The network sees an encrypted tunnel to a single address instead of a list of destinations.
  • It takes the venue’s router out of your name lookups. That closes the redirection tricks a hostile portal would otherwise have available.
  • It defuses the lookalike network. If the tunnel comes up, it matters much less who is operating the access point.
  • It does not un-tell them who you are. The portal came first. The surname, the room number, the phone number — all of that was handed over before the tunnel existed.
  • It does not take your device off the local network. You are still attached, still discoverable, still sharing whatever your laptop is configured to share.
  • It does not help while it is off. Captive portals frequently refuse to load with a VPN running, so the routine becomes: disconnect, sign in, forget to reconnect.
  • It does not stop presence logging. The network still records that a device joined, when, and for how long.

A VPN and a private connection are not competing answers — they solve different halves. The VPN protects what your traffic contains. Where it exits, and who the connection is registered to, is a separate question entirely.

07

The simpler fix: bring your own connection

Every problem above starts at the same place: joining somebody else’s network on their terms. Mobile data removes the step. There is no portal to sign into, no shared segment, no name to give — you are simply on the internet the moment you land.

  1. 01
    Buy before you fly

    Pick your destination, pay a crypto invoice, and a QR code comes back in about two minutes. No account, no email, no ID.

  2. 02
    Install at home on Wi-Fi

    Scan the QR while you are still on a network you trust. Validity starts at first connection abroad, not at install.

  3. 03
    Land and switch it on

    Turn the travel line on for data and leave your home SIM in place for calls and texts. The airport Wi-Fi becomes something you can walk past.

The full walkthrough is in how to buy an eSIM with crypto and install & activate your eSIM. Your own number stays exactly where it is — WhatsApp, iMessage and bank codes keep working off the home SIM.

08

Public Wi-Fi vs Wi-Fi with a VPN vs your own data

Public Wi-FiWi-Fi + VPNTravel eSIM data
Who carries your trafficThe venue and its providerThe VPN, over the venue’s linkA mobile operator
Identity handed over to connectName, room, email or phone numberThe same — the portal comes firstNone, when the profile was bought without KYC
Exposed to others on the networkYes, unless the venue isolates clientsTraffic is encrypted; the device is still on the segmentNo — nobody else is on your link
Can you verify who runs itNoNo, but it matters much lessYes — the profile is yours
Works in the taxi and on the streetNoNoYes
Typical costFree, or $8–25 a day on planes and in hotelsFree Wi-Fi plus a subscriptionFrom $0.40/GB, paid once
Setup before you travelNoneInstall and test the appInstall the QR at home, about two minutes

The honest reading of that table: a VPN over hotel Wi-Fi fixes the traffic column and leaves the identity column untouched. Your own data connection fixes the identity column — provided the connection itself was never tied to you, which is the entire point of a no-KYC eSIM. Prices per country are on the destinations page.

09

When you have to use the Wi-Fi anyway

Sometimes there is no choice: the conference streams over its own network, the data pack ran dry, the hotel is a concrete box with no signal. A short list that genuinely helps:

  • Give the portal the least you can. If it wants an email, give it one that exists only for portals. Room number and surname you cannot avoid — most of the rest is optional in practice.
  • Forget the network on your way out. That single step kills the silent re-join months later in another country.
  • Turn sharing off before you connect. AirDrop to contacts only, file and printer sharing off, and mark the network “Public” on Windows.
  • Never click through a certificate warning. On a modern site it is not a glitch to work around; it is the one alarm that still means something.
  • Keep the VPN on after the portal loads. The gap between signing in and reconnecting is where the whole session leaks.
  • Do anything sensitive on mobile data. Banking, document uploads, work logins — flip to your own connection for two minutes and flip back.

The cheapest habit of all: install the travel profile at home, before departure. Arriving with data already working is what removes the pressure to take whatever network the terminal is offering.

10

Isn’t mobile data the expensive option?

It used to be, and that assumption is why people queue for airport Wi-Fi in the first place. It is no longer true. Roaming from a home contract still costs $5–15 a day in many places, but a prepaid travel profile is a few dollars for the whole trip — and the “free” Wi-Fi you were comparing it against is often $8–25 a day the moment you are on a plane or in a business hotel.

  • A week of maps, messaging and email fits comfortably in 1 GB.
  • Video calls and streaming are what actually move the number, not browsing.
  • Hotel Wi-Fi still does the heavy lifting for backups and downloads — the point is not to stop using it, it is to stop depending on it.

The arithmetic is laid out in eSIM vs roaming, and the sizing question in how much data do you need abroad.

11

What your own connection does not fix

This guide would be dishonest if it stopped at the sales pitch. Swapping the café’s network for your own moves one specific problem and leaves others exactly where they were.

  • The mobile network still sees a device on a tower. Coarse location comes with cellular service; there is no version of mobile data without it.
  • Your accounts still identify you. Signing into your usual email from a fresh connection identifies you to that provider just as thoroughly.
  • Apps still report home. Nothing about the connection changes what the software on your phone chooses to send.
  • It is not encryption. A private link is not a substitute for TLS or a VPN — it is the layer underneath them.

The full threat model, including what a network operator can and cannot infer, is set out in the privacy limits guide and is an eSIM trackable?.

12

Questions, answered

Is public Wi-Fi safe in 2026?

For your traffic, mostly yes. Around 95% of web traffic is encrypted end to end, and banking and messaging apps verify their connections, so the classic scenario of a stranger reading your passwords out of the air does not work on a current phone. What is not safe is the identity side: you generally cannot get online without handing over a surname, a room number, an email or a phone number, and that connection is logged against the device that made it.

Can someone steal my passwords on hotel Wi-Fi?

It is very unlikely through the network itself. Logins travel inside encrypted connections, and an attempt to sit in the middle of one produces a certificate warning rather than a silent capture. The realistic risks are different: clicking through that warning, a device on the same segment with file sharing left switched on, or a lookalike network with a familiar name that your phone joins on its own.

Does a VPN make public Wi-Fi safe?

It makes the traffic private, which is worth doing. It does not undo the sign-in page, because the surname, room number or phone number was handed over before the tunnel existed. It also does not take your device off the local network, and it does nothing while it is disconnected — which happens routinely, because captive portals often refuse to load with a VPN running. Treat it as one layer, not the whole answer.

Why does hotel Wi-Fi ask for my room number and last name?

Officially to check that you are a guest and to bill or limit the session. Practically, it links every request from your devices to your booking, and in most countries the booking is already tied to the identity document you presented at check-in. It is the most personal Wi-Fi login you will do all trip, and it is the one nobody thinks twice about.

Is mobile data safer than public Wi-Fi?

For most travel situations, yes. There is no portal asking who you are, no shared local segment with other guests, and no network of unknown ownership to join. The link between your phone and the tower is encrypted by the mobile standard itself. It is not anonymity — the operator still sees a device attached to a cell — but it removes the identity handover and the local exposure in one step.

Can free Wi-Fi track my location?

Yes, at the venue level and often across venues. Connecting records that a device was in that building at that time. Phones randomise their hardware address per network by default now, which breaks the simplest form of cross-venue tracking, but signing in with the same email, loyalty account or phone number re-links the visits regardless of what the hardware address says.

Is airport Wi-Fi safe for online banking?

The banking app itself is fine — it is among the best-protected things on your phone. The weaker parts of the session are around it: a portal you cannot verify, a network name anyone can copy, and the fact that logging in ties your visit to an email or social account. If you have your own data connection, use it for that five minutes; it costs a few cents and removes the question.