Do You Need a VPN on Public Wi-Fi?
A calibrated take on public Wi-Fi safety: why HTTPS defused the classic risks, which threats genuinely remain, and where a VPN still adds real protection.
The classic warning is mostly outdated
For years the advice was blunt: never do anything sensitive on public Wi-Fi because hackers can steal everything. That warning made sense in an era when most websites sent data in plain text. Today it is largely out of date. The Electronic Frontier Foundation has argued that public Wi-Fi is a lot safer than most people think, precisely because the web itself became encrypted.
This does not mean coffee-shop Wi-Fi is risk-free, but the specific fear, someone at the next table silently harvesting your passwords and bank details, is far less realistic than it used to be. Understanding why helps you focus on the risks that actually remain instead of the ones that no longer apply.
Why HTTPS changed the math
The single biggest change is HTTPS. When you see the padlock, your connection to that site is encrypted end to end, so anyone sharing the network sees only that you contacted the domain, not your credentials, messages, or the pages you load. According to Google's Transparency Report, the large majority of web traffic is now encrypted this way, and browsers actively warn you before loading insecure pages.
That encryption travels with you regardless of the network. A login over HTTPS is protected the same way on airport Wi-Fi as it is at home. This is why the old 'sniffing' attacks, which relied on unencrypted traffic, no longer work against most everyday browsing, email, shopping, and banking.
The real risks that remain
Encryption is not total, and some genuine gaps persist. Your DNS lookups and the TLS SNI field often still reveal which sites you visit, even if not what you do there. Any site that is not on HTTPS, or an app that validates certificates poorly, can still expose data. These leaks are about metadata and edge cases, not the wholesale theft the old warnings implied.
The more serious threat is an actively malicious network. An attacker can run a rogue hotspot with a convincing name, then control your DNS, serve fake login pages, or abuse the 'captive portal' sign-in screen to push malware or phishing. Here the danger is not passive eavesdropping but a network you have been tricked into trusting.
Where a VPN genuinely helps
A VPN is most valuable against exactly these residual risks. By tunneling all of your traffic, including DNS, to a trusted server, it hides the domains you visit from others on the network and protects the small share of traffic that is not already encrypted. On a hostile or rogue network, that consistent encryption is a meaningful safety margin, and it also prevents the network operator itself from logging your browsing.
What a VPN does not do is make a fake login page real or stop you from typing your password into a phishing site. It protects the transport, not your judgment. Treat it as one useful layer alongside keeping software updated, heeding certificate warnings, and using two-factor authentication.
So, do you need one?
For routine browsing on public Wi-Fi, a VPN is a reasonable precaution rather than a strict necessity, because HTTPS already carries most of the load. If you frequently work on untrusted networks, want to hide which sites you visit from the network operator, or simply prefer a consistent layer of encryption, a reputable VPN is worth having.
Choose a trustworthy provider, since your traffic now flows through it instead of the cafe's router, and keep the basics in place. The goal is calibrated caution: public Wi-Fi is not the minefield it was once described as, but a VPN still closes real, if narrower, gaps.
References & Further Reading
- 1.EFF: Why Public Wi-Fi is a Lot Safer Than You Think
- 2.Google Transparency Report: HTTPS encryption on the web
- 3.Let's Encrypt: Encryption statistics
External links are provided for research reference only and do not constitute an endorsement or medical advice.
Alex Carter
Lead VPN Analyst & Editor
Alex leads VPN testing and editorial at Top5 VPN. He and the team benchmark every provider on the same criteria — real-world speed, audited privacy, streaming, and value — so the rankings stay consistent and independent.