For years, the standard warning went: never do banking on coffee-shop Wi-Fi, because a hacker at the next table can read everything. Security advice has a habit of outliving the world that made it true, and this is the clearest example. We publish this correction because a site that only ever says "be more afraid" is not doing its job.

What changed

The 2012-era danger was real: most websites sent traffic unencrypted, so anyone on the same network could capture logins and messages out of the air. What killed it was the quiet, near-total migration of the web to HTTPS. The padlock in your address bar means the connection between your browser and the site is encrypted before it leaves your device. Someone capturing café traffic today mostly collects gibberish and the names of the sites you visited, not the contents. Modern browsers also warn loudly before you submit a password over an unencrypted page, which is why you almost never see one anymore.

What is still true

Three real residues remain. First, fake hotspots: anyone can name a network "Airport_Free_WiFi" and put a fake login portal in front of it. The network cannot read your encrypted traffic, but the portal can phish whatever you type into it, so never enter account credentials into a Wi-Fi landing page that asks for more than a room number or email. Second, auto-join: your phone happily reconnects to any network whose name it remembers, so turn off auto-join for public networks. Third, the site names: an observer can still see which domains you visit, which is a privacy leak, if rarely a security one.

The rules that still apply
  • Look for the padlock; heed browser warnings about insecure pages, which are now rare and always serious.
  • Treat Wi-Fi login portals as untrusted: never enter account passwords into one.
  • Turn off auto-join for public networks.
  • A VPN encrypts the hop your network can see. Useful for privacy on hostile networks; irrelevant to breaches, phishing, and reused passwords.

Where the risk actually moved

Here is the useful reframe: the coffee shop was never the prize, your accounts were. Attackers stopped sniffing café air because credential stuffing breached passwords at scale for less effort, and phishing works identically on any network. A VPN subscription defends against almost none of what actually threatens most people, which is why our guides spend their energy on passwords, two-factor authentication, and freezes instead. Spend your caution where the attacks went, not where they were fifteen years ago.

Keep reading

Misplaced fear wastes energy. Here is where the fear is entirely justified, and exactly what to do about it:

What Someone Can Actually Do With Your Social Security Number

The SSN was never designed to be a secret, and you cannot change it. The four locks that make a stolen one nearly useless.

← Back to all guides