Skip to content
SYNTHESISCYBER

Fundamentals

Public Wi-Fi in 2026: what changed and what did not

Almost all traffic is encrypted now, which retires some old advice. A few risks remain, and they are not the ones people worry about.

Fundamentals
Synthesis Security Team5 min read

For years the standard warning was that anyone on a café network could read your traffic. With HTTPS now effectively universal, that specific risk has mostly disappeared. The content of your browsing is encrypted between your device and the site.

What remains true

  • The network operator can see which domains you connect to, even when the content is encrypted.
  • Captive portals sometimes ask for more information than they need, and that data is genuinely handed over.
  • A hostile network can attempt downgrade tricks or serve a convincing sign-in page. Certificate warnings on public Wi-Fi should never be dismissed.
  • Devices set to auto-join open networks with familiar names can be tricked into joining an impostor.

Practical settings that help

Turn off automatic joining of open networks, and remove saved public networks you no longer use. Keep the operating system firewall on and file sharing off. If you need to hide destination domains from the network operator, a reputable VPN or encrypted DNS achieves that — but understand that it moves the trust to the VPN provider rather than removing it.

Mobile tethering remains the simplest option when you are doing something genuinely sensitive.