The Public Wi-Fi Habit I Finally Broke
The Public Wi-Fi Habit I Finally Broke
For years my first move at a coffee shop, airport or hotel was the same. Order first, then find the Wi-Fi password, then get on with whatever I needed to do, usually without a second thought about which network I was actually joining. Free Wi-Fi felt like a small convenience everyone was entitled to, the digital equivalent of asking for tap water. It never occurred to me that the network itself might be the problem rather than whatever I did once connected to it.
What changed my thinking wasn't a single dramatic incident. It was a slow accumulation of small things I read and heard about how easy public networks are to abuse, until the convenience stopped feeling worth the risk I'd been ignoring.
What's Actually Happening When You Join a Public Network
The basic issue with most public Wi-Fi is that you have no way of verifying who actually controls it. A network called "Cafe Wi-Fi" could be the genuine router behind the counter, or it could be a laptop sitting in someone's bag two tables away, broadcasting a nearly identical name and waiting for people to connect. This is often called an evil twin, and it works precisely because nobody stops to check. You see a familiar-sounding name, you join, and from that point on your traffic can pass through a device controlled by someone with no good reason to be watching it.
Even on a genuine, honestly-run network, the risk doesn't disappear entirely. Many public hotspots still use weak or no encryption between your device and the router, which means anyone else on the same network with the right tools can potentially see unencrypted traffic passing by. Most websites now use HTTPS, which protects the contents of what you're sending, but it doesn't hide which sites you're visiting or protect you from a network that's been set up specifically to intercept traffic before it gets that far.
The Moment I Actually Got Nervous About It
The thing that actually pushed me to change my habits was working out how little effort an evil twin hotspot takes to set up. It's not a specialist attack requiring rare skill or expensive equipment. The tools are freely available, and a rogue hotspot can be running within minutes on a device no bigger than a phone, sitting quietly in someone's pocket in a busy departure lounge. Once I understood how low the bar actually was, the odds stopped feeling abstract. It wasn't about whether someone would bother targeting me specifically. It was about how easy it had become for anyone to cast a wide net and see what wandered in.
I also thought back to how casually I'd used public Wi-Fi for things that actually mattered, checking my bank balance while waiting for a flight, logging into work email from a hotel lobby, entering my card details on impulse to finish an order before boarding. None of that felt risky at the time because none of it felt different from doing the same things at home. That was exactly the assumption I needed to unlearn.

What I Actually Do Differently Now
The single biggest change is that I don't do anything sensitive over public Wi-Fi without a VPN running first. I've written before about why I run a VPN on every device I own, and public networks are the clearest example of why that matters. A VPN encrypts my connection before it ever reaches the local network, so even if I've genuinely joined a rogue hotspot, whoever's running it sees encrypted traffic they can't do anything useful with.
I also stopped letting my devices auto-connect to open networks. That setting exists for convenience, but it means your phone can join a network you never actively chose, sometimes without you noticing at all. Turning it off adds a few seconds of friction when I actually want to connect somewhere, which is a small price for not being quietly joined to networks I haven't looked at.
Where possible I check with staff which network is genuinely theirs rather than trusting whichever name looks most plausible. It takes ten seconds and it's caught a mismatched network name more than once. And for anything involving money or login details specifically, I've got into the habit of just using my phone's mobile data instead of hunting for Wi-Fi at all, especially somewhere like an airport where the incentive for a rogue hotspot is highest.
The One Change That Made the Rest Unnecessary
If I'm honest, the VPN habit is the one that's done the most heavy lifting, because it means I don't have to correctly judge every network I encounter in order to stay protected. I'm not always going to spot an evil twin, and I'm not always going to remember to ask staff which name is real, especially when I'm tired or rushing for a gate. Having encryption running by default means those lapses matter less, because the thing that actually protects sensitive data isn't my vigilance in the moment, it's a habit that's already switched on before I've even opened the network list.
None of this means I've stopped using public Wi-Fi altogether. It's genuinely useful, and refusing to touch it entirely isn't realistic for most people, myself included. What changed is that I stopped treating it as equivalent to my home network, and started treating it as a space I pass through carefully rather than one I settle into without thinking. That one shift in attitude, more than any single tool, is what actually closed the gap I'd been ignoring for years.
If you want a fuller rundown of the other basics I'd put in place alongside this, I've pulled them together in a free Safety Toolkit. For wider guidance on staying safe on public networks from the UK's national authority on the subject, the NCSC has clear advice worth reading too.
