Smarter sites, safer businesses — no strings attached.
Short answer: Now that HTTPS encrypts most web traffic, the old worry about strangers reading your passwords on public Wi-Fi is mostly outdated. The real remaining risk is a fake "evil twin" network with a phony login page, so confirm the exact network name with staff and use a VPN for anything sensitive.
The classic warning — "someone on the same coffee shop Wi-Fi can read your email and see your passwords" — was genuinely true fifteen years ago and is mostly outdated today. That doesn't mean public Wi-Fi is risk-free. It means the actual risk has moved, and it's worth understanding where it actually is now instead of repeating advice built for a web that doesn't exist anymore.
Back in 2010, a browser extension called Firesheep made a real point loudly: most websites only encrypted the login page, not everything after it, so anyone else on the same open Wi-Fi network could grab an unencrypted session and effectively be logged in as you. That demonstration was a real part of why the entire web moved toward encrypting everything, not just logins. Today, HTTPS — the padlock in your browser's address bar — covers the overwhelming majority of web traffic, and it genuinely does encrypt what you send and receive on a properly secured site. The old "packet sniffing your password out of the air" scenario is much smaller than it used to be.
What HTTPS doesn't fully hide: the network operator (whoever actually controls the Wi-Fi router you're connected to) can generally still see which domains you're visiting, even if not what you're doing on them — a technical limitation in how secure connections are initially set up. And that points at the risk that hasn't gone away at all: it matters enormously who's actually running the network you just connected to.
The main real threat today is the "evil twin" — a rogue access point set up with a name that looks exactly like a legitimate network ("Airport_Free_WiFi," or the exact name of the café you're sitting in). Devices often remember and auto-connect to network names they've used before, which means a convincingly named fake network can pull a device onto it without anyone consciously choosing to connect. Once you're on an attacker's network instead of the real one, they control what you see — including the ability to show a fake "sign-in" page (a captive portal) asking for credentials before granting access, the same mechanism as phishing, just delivered through a Wi-Fi login screen instead of an email.
(A composite, illustrative pattern — not one specific business's story.)
A business owner works from a café between meetings, connecting to a network name that matches the café's own Wi-Fi exactly — it's actually a rogue network set up by someone nearby, not the café's real one. Before granting internet access, a login page appears asking them to "sign in with Google to continue" — a normal-looking, if slightly unusual, extra step for public Wi-Fi. They enter their credentials to get online.
Every site they visit afterward, including their own business's login, shows the correct padlock and loads normally — HTTPS is doing its job protecting that traffic. But the damage already happened at the captive portal: the credentials typed into that fake sign-in page went straight to whoever set up the network, nothing to do with HTTPS at all.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
The fake email that looks just real enough to trust. How phishing actually works, and the one habit that catches almost all of it.
Security awarenessAll sectorsNot a dramatic hack-movie moment — a normal Tuesday until every file on the network is locked. How ransomware actually gets in, and the one habit that makes it survivable.
Security awarenessAll sectorsA password is one point of failure. Why MFA is the single highest-leverage security habit a small business can turn on — and what it actually does when a password gets stolen.
Security awareness