Fundamentals
Public Wi-Fi in 2026: what changed and what did not
Almost all traffic is encrypted now, which retires some old advice. A few risks remain, and they are not the ones people worry about.
For years the standard warning was that anyone on a café network could read your traffic. With HTTPS now effectively universal, that specific risk has mostly disappeared. The content of your browsing is encrypted between your device and the site.
What remains true
- The network operator can see which domains you connect to, even when the content is encrypted.
- Captive portals sometimes ask for more information than they need, and that data is genuinely handed over.
- A hostile network can attempt downgrade tricks or serve a convincing sign-in page. Certificate warnings on public Wi-Fi should never be dismissed.
- Devices set to auto-join open networks with familiar names can be tricked into joining an impostor.
Practical settings that help
Turn off automatic joining of open networks, and remove saved public networks you no longer use. Keep the operating system firewall on and file sharing off. If you need to hide destination domains from the network operator, a reputable VPN or encrypted DNS achieves that — but understand that it moves the trust to the VPN provider rather than removing it.
Mobile tethering remains the simplest option when you are doing something genuinely sensitive.
Keep reading
Fundamentals
Password reuse is the breach that keeps happening to you
Most account takeovers do not start with a clever attack on your account. They start with a leaked password from somewhere else entirely.
Scams
How to read a phishing message before it reads you
Phishing works on timing and emotion far more than on typos. Here is a practical way to check a message in under thirty seconds.
Architecture
What end-to-end encryption does not protect
Encryption is not a single property that a product either has or does not have. Knowing where it stops is what makes it useful.