Airport and hotel wifi networks get used for banking logins, boarding pass downloads, and hotel bookings constantly, and most travelers give almost no thought to what that network actually is or who else is on it.
What the actual risk looks like
Open wifi networks, ones with no password or a password posted at the front desk for everyone, don’t encrypt traffic between a device and the router the way a home network with WPA2 or WPA3 security does. On a shared open network, another device on the same network can, with the right tools, potentially intercept unencrypted traffic. Most modern websites use HTTPS encryption that protects the content of what’s being sent even on an open network, which reduces the real risk considerably compared to a decade ago, but it isn’t a complete shield.
Where the real exposure is
The bigger practical risk on public wifi isn’t dramatic packet-sniffing; it’s fake networks with names like “Airport_Free_WiFi” set up specifically to capture whoever connects, or legitimate-looking login pages asking for an email and password that get harvested. Checking the actual network name with airport or hotel staff before connecting, rather than picking whichever open network shows up first, closes most of this gap.
VPNs: useful, not magic
A VPN encrypts traffic between a device and the VPN provider’s server, which is genuinely useful on an untrusted network and worth using for anything sensitive, banking, work email, logins. It doesn’t make a device invisible or immune to malware, and a free VPN with no clear business model is its own kind of risk, since the provider itself can see and potentially log unencrypted traffic. A reputable paid VPN is a reasonable $3-$10 a month expense for anyone who travels enough to justify it.
The simple habits that matter most
Turning off auto-connect to open wifi networks on a phone’s settings prevents a device from silently joining a network with the same name as one it’s connected to before, a technique sometimes used to lure devices onto spoofed networks. Enabling two-factor authentication on email and banking accounts means a stolen password alone isn’t enough to get in, which matters more for actual security than almost anything else on this list. Using a phone’s own cellular hotspot instead of public wifi for anything sensitive, even briefly, sidesteps the entire problem when it’s available.
Public computers and charging stations
Hotel business center computers and airport kiosks should never be used to log into anything sensitive; there’s no way to know what’s installed or logging keystrokes on a shared machine. Public USB charging ports carry a smaller but real risk of data access through the cable itself, sometimes called juice jacking, which a USB-C or Lightning cable that only carries power, sold specifically for this purpose, avoids entirely. This is a natural companion habit to choosing between eSIM, local SIM, and roaming, since a personal data connection sidesteps public wifi risk altogether for anyone who values convenience over the small extra cost.
Guidance worth checking
For anyone spending extended time working remotely abroad, official guidance from agencies like the Cybersecurity and Infrastructure Security Agency covers public wifi risk in more depth than most travel blogs do, and it’s a useful once-a-year refresher even for people who already know the basics, particularly relevant for anyone researching how digital nomad visas actually work and planning to work from cafes and coworking spaces regularly.
A realistic checklist
- Confirm the actual network name with staff before connecting
- Turn off auto-connect to open networks
- Use a VPN or a personal hotspot for anything involving logins or payment
- Enable two-factor authentication on important accounts before the trip, not during it
- Avoid logging into anything sensitive on shared hotel or airport computers
Software updates before departure
A surprising number of security problems on the road trace back to a phone or laptop that hadn’t been updated in months before the trip started, running with known vulnerabilities that a routine software update would have patched. Doing a full update of the phone’s operating system, browser, and any banking or email apps a few days before leaving, rather than in an airport lounge on spotty wifi, closes gaps that matter far more on an unfamiliar network than they do at home.
Bluetooth and file sharing settings
Features like Bluetooth visibility and file-sharing services such as AirDrop set to accept from everyone are a minor but real exposure in crowded public spaces, airports and train stations especially, where a device broadcasts itself to anyone nearby. Setting file sharing to contacts-only and turning off Bluetooth visibility when not actively pairing a device closes an avenue that has nothing to do with wifi at all but gets lumped into the same general travel security habit.