Do You Need a VPN on Public Wi-Fi? An Honest Answer
By the VPNUncovered team · Checked 26 August 2026
Short answer. The classic warning — a hacker at the next table reading your bank password out of the air — is mostly out of date. The web is encrypted now. But two risks on public Wi-Fi are still real, and only one of them is a risk a VPN helps with. Here is the honest split.
We sell VPN subscriptions through affiliate links, so we have every commercial reason to tell you the scary version. We are going to tell you the accurate version instead, because you can check it in about ten seconds and we would rather you trusted us next time.
Why the old scare stopped being true
The coffee-shop story worked because, years ago, a lot of the web ran over plain HTTP. Anyone on the same network could read it. That is no longer how the web works.
Google published an update on 28 October 2025 setting out where HTTPS adoption stands. Encrypted browsing rose from roughly 30–45% in 2015 to the 95–99% range around 2020, and it has stayed there. Restricted to public sites, Google reports about 97% on Linux, 98% on Windows and over 99% on Android and Mac. The median user now sees fewer than one insecure-connection warning per week. Chrome is going further: "Always Use Secure Connections" turns on for Enhanced Safe Browsing users in Chrome 147 (April 2026) and for everyone in Chrome 154 (October 2026).
What that means in practice: when you load your bank, your email or a shop, the connection between your device and that site is already encrypted end to end. The café, the airport and everyone else on that network cannot read it. A VPN does not add encryption to traffic that is already encrypted.
So, is it safe to use public wifi for banking? On a device you keep updated, using your bank's own app or a URL you typed yourself, the encryption part is handled. The part that can still go wrong is the part below.
One caveat, in Google's own framing: a few percent of navigations is still a very large number of navigations. The risk is small and shrinking. It is not zero.
Real risk 1: the network itself is fake
This is the attack that actually happens, and it is not defeated by encryption.
On 28 June 2024 the Australian Federal Police announced charges against a man over "evil twin" free Wi-Fi networks. He allegedly ran fake networks at Perth, Melbourne and Adelaide airports and on domestic flights, using a portable wireless access device. People who connected were pushed to fraudulent login pages that harvested email and social-media credentials. The AFP said its analysis "allegedly identified dozens of personal credentials". Nine cybercrime charges were laid, including three counts of unauthorised impairment of electronic communication, each carrying a maximum of 10 years.
Look closely at the mechanism. Nobody cracked any encryption. The victims typed their passwords into a page that asked for them. That is a phishing attack wearing a Wi-Fi network as a costume.
A VPN would not have stopped it. If you connect to a hostile network and then hand over your password to a fake sign-in page, the VPN has no view into that. It carries whatever you send.
The AFP's own advice on free Wi-Fi is worth repeating: don't do anything sensitive, such as banking, while connected to a network you are not sure about, and once you are finished, set your device to forget the network.
Real risk 2: metadata
Here is where a VPN genuinely helps.
Even when the contents are encrypted, whoever runs the network can usually see which services you connect to, when, for how long, and how much data moved. Hotel networks, airport networks and shopping-centre networks log this. Some of them run it through analytics.
A VPN hides that from the local network. The network sees one encrypted connection to a VPN server and nothing else. That is a real, specific benefit, and it is the honest reason to run one on Wi-Fi you do not control.
The trade is that you have moved the trust, not removed it. Your VPN provider now sees what the café would have seen. Which is why who runs the app matters more than the marketing: see are free VPNs safe and who owns your VPN.
What a VPN does not protect you from
Say this part out loud before you buy one. A VPN encrypts the link between your device and the VPN server, and hides your IP address from the site at the other end. It does not:
- Stop you typing your password into a phishing page or a fake captive portal. That was the whole mechanism in the airport case above.
- Stop malware, a bad download, or a device that is already compromised.
- Hide you from services you log into. You are logged in. They know who you are.
- Stop browser fingerprinting, cookies or ad tracking.
- Make you anonymous. It shifts trust from your network and ISP to the VPN operator, whose logging you cannot audit.
- Protect data once it reaches the other end — breaches, data brokers and legal requests to that service are unaffected.
- Add anything to traffic that is already HTTPS. That was already encrypted.
And the protection claims themselves need checking. In December 2021, Consumer Reports' Digital Lab, working with Prof. Roya Ensafi's team at the University of Michigan, evaluated 16 VPNs in depth after screening 51 on Windows 10. 12 of the 16 either inaccurately represented their products and technology, or made exaggerated claims about the protection they provide. Only 6 of 16 had reproducible builds. Only one signed its Windows updates.
What actually helps on public Wi-Fi
- Never type credentials into a captive portal. A legitimate Wi-Fi splash page asks you to accept terms or enter a room number. It does not ask for your email password.
- Use the app, not a link. Open your bank's own app, or type the address yourself. Do not follow a link that appeared on the network.
- Turn on two-factor authentication on email and banking. It is the single biggest upgrade here, and it is free.
- Keep the device updated. Browser and OS updates are what deliver the HTTPS protections above.
- Forget the network when you leave, so your phone does not silently rejoin a name it recognises.
- Use your phone's hotspot for anything genuinely sensitive. Mobile data is a network you control.
- Then, if you want it, add a VPN as the metadata layer.
So, do you need one?
If you are on public Wi-Fi a few times a year and you keep your devices updated, a VPN is optional. If you work from cafés, hotels or airports every week, or you are travelling on networks you have no reason to trust, the metadata benefit is worth paying for — as one layer, alongside the checklist above.
If you decide you want one
Our travel and general-use pick is NordVPN. It covers 10 devices on one account and carries a 30-day money-back guarantee (checked 26 Aug 2026), which is long enough to actually test it on the networks you use rather than trusting a review. We do not print a price here, because we could not verify the US figures on the date we checked — read the current price on their page before you commit.
We earn a commission if you sign up through our links, at no extra cost to you. It never changes what we say about a product.
See NordVPN's current plans → Read our NordVPN review · NordVPN vs CyberGhost
How we get paid, in full: our affiliate disclosure.
Still not sure?
The quiz asks five questions about what you actually do online and gives you a pick, a runner-up and a budget option, each with the date we last checked the terms. No email required.
Sources
- Google Security Blog / The Keyword, HTTPS by default — https://blog.google/security/https-by-defau/ (originally https://security.googleblog.com/2025/10/https-by-default.html) — 28 October 2025.
- Australian Federal Police, Man charged over creation of 'evil twin' free WiFi networks to access personal data — https://www.afp.gov.au/news-centre/media-release/man-charged-over-creation-evil-twin-free-wifi-networks-access-personal — 28 June 2024.
- Consumer Reports Digital Lab with the University of Michigan (VPNalyzer), VPN testing: poor privacy and security, hyperbolic claims — https://www.consumerreports.org/vpn-services/vpn-testing-poor-privacy-security-hyperbolic-claims-a1103787639/ and https://digital-lab.consumerreports.org/2021/12/07/consumer-reports-digital-lab-evaluates-the-security-and-privacy-of-vpns-running-on-windows-10/ — December 2021.
- NordVPN device count and money-back window — read from NordVPN's own pages, checked 26 August 2026.