← Field Guide

ABOUTVPNS / FIELD NOTE 02

Public Wi-Fi: Use Layers, Not Magic

A practical approach to hotel, airport and cafe networks without exaggerated VPN promises.

HTTPS already protects much of the web

Modern websites commonly use HTTPS. The FTC explains that widespread encryption has made public Wi-Fi safer than it once was. That does not mean every network or destination is trustworthy. A VPN can add a protected path to its endpoint, but it is one layer rather than a replacement for encrypted applications or careful account use.

Check the network before the tunnel

Confirm the network name with the venue rather than assuming the strongest signal is correct. Avoid auto-joining unfamiliar networks. A captive portal may need you to accept access conditions before a tunnel can connect. It should not require you to install an unknown root certificate, device-management profile or remote-control application. Stop and ask the venue or your IT team when the instructions look unusual.

Use a short travel checklist

Before travel, update the operating system and VPN client, test your sign-in, and make sure you can use your second factor. On a shared network, choose the device's public-network profile where available and avoid exposing file shares. For sensitive work, use your organization's approved connection method. A personal mobile hotspot can be an alternative, but it does not excuse ignoring application security.

Understand disconnects

Moving between Wi-Fi and cellular, sleep mode, and portal timeouts can interrupt a VPN. Check the client's documented reconnect and kill-switch behavior on your particular device. A kill switch is intended to restrict traffic when the tunnel is unavailable; implementations and exceptions differ. Test harmless browsing first rather than assuming every application is covered.

Keep the right perspective

An encrypted phishing website can still steal information you type into it. Use unique credentials or passkeys, enable two-factor authentication and verify unexpected requests. A personal VPN also does not give permission to bypass an employer's network rules. Ask for help with access rather than weakening certificates or endpoint protection to make a connection work.

Sources and Further Reading

Sources support the technical concepts. Examples and checklists are our educational synthesis, not a provider review or a substitute for current deployment guidance.

Next: Personal, Remote-Access and Site-to-Site VPNs

KEEP EXPLORING

Useful Internet Tools

A little curiosity goes a long way. Find your next useful tool or plain-English guide.

13 more places to explore

Part of our independent learning network Browse a topic. Learn something useful.