Quiet Wire

Notes on VPN security, privacy law and the difference between a marketing claim and a verifiable one.

Public Wi-Fi Security: What Hackers See in 2026

October 6, 2026 · Quiet Wire

Using free Wi-Fi in places like airports or coffee shops offers convenience but also exposes your online activity. While modern browsers and banks use HTTPS to encrypt traffic, other information—like DNS lookups, server name indication, and timing data—can still reveal patterns to an observer. A VPN can secure these gaps, provided it meets specific technical and legal standards.

The HTTPS Shield: What’s Now Private

HTTPS (TLS-encrypted HTTP) encrypts the content of web requests. This means a passive observer on the local network cannot read page content, form fields, or cookies. By the end of 2025, over 95% of sites within the Alexa top 1 million are expected to use TLS 1.2 or higher with strong cipher suites. This is a significant increase from roughly 78% in 2020, with adoption growing by about 4-5 percentage points annually.

This encryption hides login credentials for services like email, social media, and banking from local network attackers. A typical HTTPS handshake creates a session key known only to the client and server, rendering captured packets unintelligible as random data to a Wi-Fi sniffer.

However, HTTPS doesn’t protect everything. A small percentage of legacy sites still use plain HTTP. A scan of the top 10,000 sites shows about 2% still serve unencrypted pages. These sites expose form fields, search terms, and cookies not marked as secure. Visiting such a page on public Wi-Fi can leak data that HTTPS otherwise protects.

Still Exposed: DNS, SNI, and Metadata

DNS queries

Before establishing a TLS connection, a browser must resolve a domain name to an IP address. Most operating systems send these DNS lookups unencrypted to the configured resolver, often the ISP’s server. On a public hotspot, an eavesdropper can capture a query for bankexample.com and identify the intended destination, even if the subsequent HTTPS traffic is encrypted.

To mitigate this, enable DNS over HTTPS (DoH) or DNS over TLS (DoT) in your device settings, or use a VPN that routes all DNS traffic through its encrypted tunnel.

Server Name Indication (SNI)

During the TLS handshake, the client sends the hostname it wishes to connect to in a clear-text extension called SNI. This allows a single server to manage multiple websites with different certificates. Until TLS 1.3’s optional encrypted SNI, most browsers sent this information in plaintext. An observer can thus link encrypted traffic to a specific domain.

To mitigate this, use a VPN that terminates TLS after the VPN tunnel, or use browsers that support Encrypted Client Hello (ECH), which encrypts the SNI field.

Unencrypted traffic and IoT

Not all applications use HTTPS. Older firmware on smart devices like plugs, printers, or point-of-sale terminals often communicates over raw TCP or UDP, or even plain HTTP. A simple packet capture can reveal passwords, telemetry, or command-and-control data.

Connection metadata

Even with encrypted payloads, packet size, timing, and direction are observable. Machine learning models can analyze these patterns to infer user activity, such as streaming video, sending email, or conducting financial transactions. For instance, a burst of approximately 150 KB packets at regular intervals might indicate a video stream, while a short, two-packet exchange of about 1 KB each is typical for a login POST request.

A VPN can obscure original packet sizes and timing by encapsulating traffic within another encrypted layer, especially when using padding or obfuscation techniques.

The Threat of Evil Twin Hotspots

An “evil twin” is a fraudulent Wi-Fi access point disguised as a legitimate public hotspot. Attackers use a stronger signal or strategic placement to trick devices into connecting. Once connected, all your traffic passes through the attacker’s hardware before reaching the internet.

Interception scenarios

  1. Passive capture – The attacker records all packets, extracting DNS queries, SNI, and any unencrypted payloads.
  2. Active man-in-the-middle (MITM) – The attacker intercepts your TLS connection and presents a fake certificate. Modern browsers flag certificate mismatches, but users may bypass these warnings, especially on smaller screens.
  3. Credential harvesting – For services not enforcing certificate pinning, like some older email clients, the attacker can relay traffic while capturing usernames and passwords.

Users may ignore certificate warnings because they are unfamiliar or because the network is “free,” making evil twins a viable vector for data theft, even on sites that enforce HTTPS.

When a VPN Becomes Essential

A Virtual Private Network (VPN) creates an encrypted tunnel between your device and a remote server, adding a layer of confidentiality on public Wi-Fi that bypasses local network vulnerabilities.

Core protections

  1. Full-traffic encryption – The VPN client encrypts all IP packets using strong symmetric ciphers (e.g., AES-256-GCM). Captured Wi-Fi frames appear as ciphertext, indecipherable without the session key.
  2. IP address masking – Your public IP address is replaced by that of the VPN exit node, preventing location-based profiling and certain geo-targeting attacks.
  3. DNS leak prevention – Reputable VPN apps route DNS requests through the encrypted tunnel to the provider’s resolvers, preventing local observers from seeing domain names.
  4. SNI concealment – As the VPN terminates TLS on its server, the original SNI is hidden from the local network. Only the VPN server’s IP address and port are visible.

Choosing a VPN that truly protects

When selecting a VPN for public Wi-Fi, look beyond marketing claims and verify these criteria:

Criterion What to verify Reason
Jurisdiction Provider’s corporate registration and server locations. Prefer countries with strong privacy laws and no mandatory data retention. Minimizes legal risks of compelled data handover.
No-logs policy Independent audit reports confirming no retention of connection timestamps, IP addresses, or traffic metadata. Ensures there are no logs to hand over, even if compelled.
Protocol support Modern protocols (WireGuard, OpenVPN 2.5+, IKEv2) with forward secrecy (ECDHE). Avoid older protocols like PPTP or L2TP/IPsec without strong authentication. Weak protocols are vulnerable to breakage or downgrade attacks.
Kill switch Test that all network traffic is terminated if the VPN tunnel drops. Prevents accidental data exposure during brief disconnections.
DNS handling Verify VPN forces DNS over TLS/HTTPS to its own resolvers and blocks system DNS fallback. Use sniffing tools to confirm no DNS leaks. Prevents domain discovery via DNS queries.
Ownership transparency Check corporate filings or reputable news for ultimate owners. Avoid providers with opaque ownership. Reduces risk of undisclosed government affiliations.
Audit frequency Look for regular (annual, biennial) third-party security and privacy audits covering code, infrastructure, and logging. Ongoing verification demonstrates a commitment to security.

These steps significantly enhance security on public Wi-Fi, making a targeted attack less likely to succeed against the average user.

Example of a practical check

  1. Install the VPN client on a laptop.
  2. Connect to an unsecured public Wi-Fi hotspot.
  3. Before activating the VPN, use a packet capture tool (e.g., Wireshark) on the Wi-Fi interface. You will see unencrypted DNS queries for example.com and SNI, along with raw IP headers.
  4. Activate the VPN and repeat the capture. The only visible packets should be to the VPN server’s IP, marked as encrypted (typically UDP 4500 for WireGuard or TCP 443 for OpenVPN). No DNS queries or target site IPs should be visible.
  5. Disconnect the VPN abruptly and test the kill switch by attempting to ping an external host. Traffic should be blocked.

If these steps confirm the described behavior, the VPN effectively addresses the primary threats on public Wi-Fi.

Simple Habits for Better Security

  1. Always enable a reputable VPN before joining any open Wi-Fi. Turn it on first, then connect to the hotspot. This ensures even the DHCP request is encrypted (most VPNs default to full-tunnel mode for public Wi-Fi).
  2. Keep operating systems, browsers, and applications updated. Security patches often fix TLS vulnerabilities and improve certificate validation.
  3. Visually confirm network names. Check airport signage, café receipts, or staff to distinguish legitimate SSIDs from fake ones.
  4. Disable “auto-join” or “auto-connect” for Wi-Fi on all devices. This prevents them from silently connecting to an evil twin when it appears.
  5. Use a password manager that flags HTTP sites and refuses to auto-fill credentials on non-HTTPS pages. This helps prevent sending passwords in cleartext.

Implementing these habits significantly reduces your attack surface, making it difficult for even well-resourced adversaries to steal meaningful data.

Key Takeaways

  • HTTPS encrypts web page content, but DNS lookups, SNI fields, and connection metadata remain visible on public Wi-Fi.
  • Evil-twin hotspots can trick devices into connecting to attacker-controlled networks, enabling passive sniffing and active man-in-the-middle attacks.
  • A properly vetted VPN encrypts all traffic, hides DNS and SNI from the local network, and masks your IP address, offering practical protection on open Wi-Fi.
  • Always verify network names, keep software updated, and use a reliable VPN before connecting to public hotspots.

Frequently Asked Questions

Can a VPN see my browsing activity on public Wi-Fi?

A trustworthy VPN encrypts the tunnel to its server, shielding your payload from local network observers. However, the VPN provider itself could technically see the traffic passing through its servers. Opting for a VPN with an independently audited, strict no-logs policy minimizes this risk.

Is my online banking safe on public Wi-Fi without a VPN?

If the banking website uses HTTPS (as all regulated banks do), your login credentials and transaction data are encrypted end-to-end. However, the DNS request to resolve the bank’s domain and the SNI field during the TLS handshake are still visible to local eavesdroppers. A VPN eliminates this residual visibility.

What’s the difference between Wi-Fi encryption (WPA2/3) and a VPN?

Wi-Fi encryption secures the radio link between your device and the access point, preventing outsiders from capturing raw data over the air. This protection ends once traffic leaves the access point. A VPN adds a second encryption layer that secures traffic from your device all the way to the VPN server, shielding it from anyone controlling the local network, including the hotspot operator.


This article is for general information only. It does not constitute legal or security advice; laws and provider policies change, so verify current terms before relying on any service.