The short answer: the real risk on public Wi-Fi abroad is not the interception people warn about. It is fake access points, the sign-in page that opens when you connect, and your phone reconnecting on its own. Because HTTPS now protects the contents of almost every connection, the centre of gravity has moved. Change three settings before you fly and most of what remains disappears.

How much of "public Wi-Fi gets your password stolen" is still true

There was a time when anyone on the same network could capture traffic and read usernames and passwords. Today the major sites and apps encrypt their traffic with HTTPS (TLS), and encrypted traffic cannot be read by someone sitting on the same network.

So the claim that your data is taken the moment you join a public network no longer matches reality. What someone on the network can still see is which servers you connected to, not what you typed into them. That is a privacy concern rather than a credential-theft one.

Public Wi-Fi still deserves care, because encryption does not address every kind of attack.

The risks that actually remain on public Wi-Fi

Fake access points (evil twin)

An attacker broadcasts a network with the same name as the airport or cafe network, or one close enough to be mistaken for it. If you join it, your traffic passes through their equipment. HTTPS still hides the contents, but it gives them a foothold to redirect you to a look-alike site. Abroad this is harder to spot, because you do not know what the legitimate network is called.

The sign-in page that opens on connection

Many public networks open a login or terms-of-service page as soon as you connect. By design this page can be served without encryption, so anything you type into it may not be protected. Portals that ask you to sign in with a social account are worse, because the permissions you grant are usually broader than the network needs.

Automatic reconnection

Your phone remembers network names and rejoins them silently whenever it sees a matching signal. If an attacker broadcasts that same name, you connect without touching your phone. This is what makes evil twin attacks work in practice.

Your device being visible on the network

If file sharing or printer sharing is still enabled, other devices on the same network can see yours. This mainly affects laptops taken abroad without any change to their settings.

The Wi-Fi checklist to complete before you fly

Judging any of this at an airport gate is difficult, so finish it at home.

  1. Turn off automatic reconnection. On iPhone, open each saved network in Wi-Fi settings and disable Auto-Join. On Android, forget the saved networks. This is the single most effective step against fake access points.
  2. Force HTTPS in your browser. Chrome has a setting that always prefers secure connections, and Safari upgrades where it can. If a certificate warning appears, close the page instead of continuing.
  3. Disable file sharing, AirDrop and network discovery. On Windows, set the network type to Public.
  4. Update your OS and browser. Do not take an out-of-date device onto an unknown network.
  5. Activate your eSIM before departure. If you arrive already connected, you never have to hunt for a network and make these judgement calls under pressure.

How to judge a network once you are there

  • Ask staff for the exact network name, especially when several similar names appear in the list.
  • If the portal asks for your full name, date of birth, passport number or a social login, stop and use something else.
  • Do not do online banking, government paperwork or password changes on public Wi-Fi.
  • Forget the network when you are finished so your phone will not rejoin it later.

A VPN is a legitimate tool for hiding your traffic path, but it is not a cure. Your traffic then runs through the VPN provider, so you are moving your trust rather than removing the need for it. Free VPNs deserve particular scrutiny. A VPN also cannot help if you typed your details into a fake portal yourself.

Choosing between public Wi-Fi and an eSIM

Using both, deliberately, works better than picking one.

When public Wi-Fi is the better choice

  • In your hotel room, for app updates or downloading video, where the volume is large
  • When you want to preserve your data allowance

When to use your own connection

  • Maps and transit directions while you are moving. There is no Wi-Fi outdoors.
  • Ride-hailing and restaurant bookings, where location and payment are involved
  • Sign-ins and verification codes, where an interruption is a real problem
  • The moment you land, before you have found anything to connect to

An eSIM uses a mobile operator's network directly, so it does not carry the "who is running this network" uncertainty that public Wi-Fi does. Having a connection you chose is itself a security measure. Country coverage and the available day and data combinations are listed on the Coral eSIM plans page.

A simple rule works well: your own connection outdoors and on the move, Wi-Fi only indoors for large downloads. Removing the need to search for a network removes the decision entirely. For the comparison with rental hotspots, see eSIM vs pocket WiFi.

Public Wi-Fi conditions differ by country

Coverage is uneven, so your assumptions should change with your destination.

  • South Korea and Taiwan: public Wi-Fi is widespread, including on transit and in cafes. The flip side is a crowded list where similar names sit next to each other.
  • Europe: cafes and hotels mainly, with very little outdoors or in transit. On an itinerary with a lot of intercity travel, Wi-Fi alone leaves long gaps without maps.
  • Mainland China: network restrictions mean some services will not open even once you are connected. Being online and being able to use what you need are two different things there.
  • Southeast Asia and the Middle East: some portals require SMS verification to a local number, which a visitor cannot complete.

Because "connected but unusable" is a real state, plans built on Wi-Fi alone tend to break. For the wider set of options including carrier roaming, see international roaming vs eSIM.

Airport and rail operators often publish their official network names on their own websites. Checking once before you travel gives you something to compare against on arrival.

FAQ

Does a VPN make public Wi-Fi safe?

It hides your traffic path, but it does not make the network safe. Your traffic runs through the VPN provider instead, so the question becomes whether you trust them. If you enter details into a fake portal yourself, a VPN does not help.

Is it safe to use a credit card on public Wi-Fi?

If the payment page is HTTPS, the connection itself is protected. That protection does not apply if you have been redirected to a fake site. For larger payments, switch to a connection you control first.

Is hotel Wi-Fi safer than cafe Wi-Fi?

Knowing who operates it helps, but you are still sharing the network with other guests, so file sharing should be off. In lobbies where several similar names appear, confirm the correct one at the front desk.

If I have an eSIM, should I avoid public Wi-Fi entirely?

No. Wi-Fi is the better option for large downloads in your room. Use your own connection outdoors and for anything involving sign-in or verification.

Can I activate an eSIM on airport Wi-Fi?

You can, but it is not advisable. Activation needs a stable connection, and busy airport Wi-Fi drops. An interrupted activation sometimes requires the profile to be reissued, so complete it on your home connection before you leave. The steps are in how to set up an eSIM for travel.

Deciding when to use public Wi-Fi beats trying to avoid it

Public Wi-Fi abroad is not something to avoid outright. It is something to use in specific situations. The risk sits in fake access points, captive portal pages and automatic reconnection, not in the interception people usually describe. Turn off Auto-Join, force HTTPS and disable sharing, and most of the exposure is gone. Move everything that happens outdoors or involves verification onto a connection you chose, and the moment where you stare at an unfamiliar network name never arrives.

Related articles