Public Wi-Fi: what the risk actually is now
Most sites are encrypted, so the old warnings are partly out of date. The real exposure on café and hotel networks is narrower, and a few habits cover nearly all of it.

The classic warning about café Wi-Fi was that anyone at the next table could read everything you did. For most browsing that's no longer true. Nearly every site and app now encrypts its traffic, so a stranger on the same network sees that you connected to a service, not what you typed into it.
That doesn't make public networks harmless. It means the risk has moved, and the useful precautions are different from the ones people still repeat.
What encryption now covers
When a site uses HTTPS — the padlock, or simply the absence of a "not secure" warning — the content of the page, your passwords, messages and card details are encrypted between your device and the site. Someone on the same network, or the person running it, can't read them. Most apps work the same way, even though they don't show a padlock.
What is still visible is metadata. The network operator can generally see which domains you connect to, when, and how much data moves. They can't see which article you read on a news site, but they can see that you visited it. For most people on a hotel network that's an acceptable level of exposure. If it isn't for you, that's a reasonable use for a VPN — what a VPN hides, and what it doesn't covers the trade-off honestly.
The risks that remain
Fake networks. Anyone can set up a hotspot called "Airport Free WiFi" or copy the name of the café's real one. Encryption still protects HTTPS traffic through a fake network, but the operator controls the sign-in page and can try to trick you into entering details there.
Sign-in pages that ask for too much. Legitimate captive portals ask you to accept terms, and sometimes for a room number or an email address. A portal that wants your email password, a social media login or card details for "free" Wi-Fi is a red flag.
Your own device being reachable. On a shared network, other devices can see yours. If file sharing, media sharing or remote access is switched on, you're offering those services to the whole room.
Ignored certificate warnings. If your browser shows a full-page warning that the connection isn't private, something is intercepting the connection. On public Wi-Fi, don't click through it.
Older or badly built apps. A small number of apps still send some data unencrypted. You can't easily check this yourself, which is one reason to keep apps updated and remove ones you no longer use.
Settings worth checking once
A few minutes on each device covers most of the exposure above.
- Windows: when you join a new network, choose Public rather than Private. You can check under Settings, Network & internet, then the network's properties. Public turns off discovery, so other devices can't browse yours.
- Mac: in System Settings, Network, turn the Firewall on. Under General, Sharing, switch off anything you don't actively use, such as file or screen sharing.
- Phones: turn off automatic joining for networks you only used once. On both iPhone and Android you can tap the network name and choose Forget, or disable auto-join.
- Browsers: most now have an HTTPS-only or "always use secure connections" setting. Turning it on means you'll get a warning before any page loads unencrypted.
Also keep your operating system and browser up to date. Several Wi-Fi-related weaknesses in recent years were fixed with ordinary updates rather than anything the user had to configure.
Habits that cover the rest
Confirm the network name. Ask staff or check the sign in the room. If there are two similar names, don't guess.
Treat the sign-in page as untrusted. Give it what it reasonably needs and nothing more. A throwaway or secondary email address is fine for Wi-Fi terms.
Use your phone's hotspot for anything sensitive. Mobile data is encrypted between your phone and the mast, and nobody else is on your hotspot unless you let them. For banking, tax returns or work systems, it's the simplest alternative.
Have two-factor authentication on important accounts. If a password is ever captured through a fake sign-in page, a second factor stops it being enough on its own. Which two-factor method to use matters here, because some are far harder to phish than others.
Log out on shared computers. Hotel business centre machines are a bigger risk than hotel Wi-Fi. If you must use one, use a private browsing window and sign out of everything before you leave.
Where a VPN fits
A VPN encrypts everything between your device and the VPN server, so the local network sees only that you're connected to a VPN. On public Wi-Fi that hides the domains you visit from the network operator and protects any app traffic that isn't properly encrypted.
It doesn't stop you entering a password into a fake sign-in page, it doesn't protect you from phishing, and it moves your trust from the café to whoever runs the VPN. It's a sensible layer if you work on the move a lot. It isn't a requirement for checking the news over a coffee.
A realistic summary
On a well-run public network with an up-to-date device, the practical risk is modest. Most of what's left comes down to three things: joining the right network, not handing extra details to a sign-in page, and not ignoring browser warnings. Set your device to treat new networks as public, forget networks you won't use again, and use your phone's hotspot when something really matters.