top of page
  • Facebook
  • Linkedin

Public Wi-Fi Is Safer Than It Used to Be, but Not Risk-Free

Writer: Steven Burstyn
Steven Burstyn
Aug 30
4 min read
Man in a cozy cafe types on a laptop beside coffee, notebook, and phone, with blurred patrons in the background.

An employee opens a laptop at a coffee shop, connects to the free Wi-Fi, and finishes an invoice before a client meeting. The connection is fast, the invoice uploads, and nothing on the screen suggests a problem.


Connecting at a coffee shop rarely feels like a security decision. It feels like getting an invoice finished before the next meeting.


Fifteen years ago, much more web traffic traveled without HTTPS. On an open or poorly configured network, someone with the right tools could sometimes read that unencrypted traffic. That is a different problem than an unencrypted Wi-Fi signal, and it is largely the problem that has changed.


What Changed

Most websites now encrypt traffic by default, and many modern business applications do the same. The lock icon and HTTPS at the start of a web address mean the connection between the browser and that specific website is encrypted, regardless of what network carries it. They do not prove that the website itself is legitimate, which matters for reasons covered below. The FTC now says connecting through public Wi-Fi is usually safe because encryption has become so widespread, a notable shift from older guidance that treated any public network as inherently dangerous.


That does not mean public Wi-Fi security is a solved problem for a small business. When employees use updated devices and properly encrypted services, the open network itself is usually not the greatest risk. Device settings, outdated software, and misleading login pages deserve more attention, and each of those is still something a business can get wrong.


What Can Still Go Wrong

Fake or spoofed hotspots. An attacker can set up a network with a name nearly identical to the real one. Connecting to it does not defeat the encryption on a legitimate website, but it can put an employee in front of a fake login page, or expose anything sent through a connection that never reaches an encrypted site to begin with. CISA recommends confirming the hotspot's exact name and login procedure with staff before connecting, every time, not just when something already looks off.


Devices that are not configured for a public network. Windows sets a newly connected network to public by default, and that profile makes the device undiscoverable to others on the same connection, with the firewall blocking unsolicited inbound traffic unless a rule permits it. Marking an unfamiliar network private instead can make the device discoverable and allow sharing rules that would normally stay restricted. Whether another device on that hotspot can actually reach it also depends on the firewall, the sharing settings, and whether the hotspot isolates connected devices from each other.


Older tools that were never updated to require encryption. Not every piece of software a business relies on defaults to a secure connection the way modern browsers do. An older internal tool, a legacy login page, or a system that has not been updated in years may transmit information without adequate encryption, creating a real opportunity for interception on a network the business does not control.


A device or account that is already compromised. Encryption protects data in transit. It does not protect a laptop that already has malware on it, or an account where the login itself was captured through a phishing email or a fake sign-in page. Public Wi-Fi does not cause this kind of compromise, but it does not fix it either.


A VPN Protects the Connection, Not Everything Else

A virtual private network creates an encrypted tunnel between a device and a VPN server or company gateway. Traffic routed through that tunnel is protected from local network observers, which is genuinely useful on an unfamiliar connection.


A VPN protects one part of the connection. Device security, authentication, and network verification still matter alongside it. Traffic sent before the VPN connects does not travel through its tunnel, though properly configured HTTPS services still provide their own encryption in the meantime, and some public networks require a captive portal to load before a VPN connection can even be established. A compromised device stays compromised regardless of the VPN, and a fraudulent hotspot's fake login page is still fake whether or not the VPN is running. An automatically initiated, company-managed VPN reduces the need for employees to remember when to turn it on, which is real value even though it does not close every gap on its own.


Set Up the Device Before the Employee Leaves the Office

Much of the protection that matters is configured before the employee leaves the office.

  • Keep the operating system, browser, and security software up to date

  • Leave the device's firewall turned on, and confirm unfamiliar networks are marked public, not private

  • Turn off automatic connection to open Wi-Fi networks

  • Use multi-factor authentication on email, cloud storage, and any account that supports it

  • Confirm the hotspot's exact name and login procedure with staff before connecting, every time, not just when something looks off

  • Never enter a reusable business password, payment information, or other sensitive credentials into an unexpected captive portal, and do not ignore browser certificate warnings

  • Use a company-managed mobile hotspot for sensitive work when one is available and practical

  • Lock the screen whenever the device is left unattended, even for a minute


These are the controls that hold up regardless of which coffee shop, airport, or client office an employee happens to be working from that day.


Give Employees a Rule They Can Follow

A business may choose a stricter rule than the technology itself requires, and many reasonably do. A simple rule, such as not accessing financial systems on any network the business does not control, is easier for employees to follow consistently than a set of conditions about which specific protections happen to be active at the time.


What matters is knowing the difference between a technical requirement and a business decision. A properly configured, company-managed VPN can support secure access to sensitive systems from a public network. Choosing not to allow that anyway is a legitimate call for a business to make. It is worth being clear internally about which kind of rule it is.


Review What Your Team Is Working With

Unfrustrating Computers helps Long Island small businesses review the devices, networking, and remote-access setup their employees rely on outside the office. That includes confirming that laptops are configured correctly and creating an infrastructure plan for how remote work should be handled.


Call 516-679-5540 or email info@unfrustratingcomputers.com to review the devices and remote-access setup your team already relies on.

 
 
 

Comments


Contact Us

Thanks for submitting!

 Address. 6 Zinnia Ct., Commack, New York, 11725

Tel. 516-679-5540

Website Created and Maintained by Boxer Media Services Corp.

Copyright © 2026 Unfrustrating Computers.  All Rights Reserved

bottom of page