Skip to main content

Technical Breakdown: The Hidden Risks of Using Public Wi-Fi

Public Wi-Fi is convenient, but fake hotspots, insecure websites and technical security risks can still put your data at risk. Here’s what you need to know before connecting.

By Mittapalli Sriram
Published: Oct 06, 2026
4 mins read
👁️ 11 Unique Views
Technical Breakdown: The Hidden Risks of Using Public Wi-Fi
The scale of inference: Optimized for multimodal workloads.
Premium Insight

Why It Matters

Public Wi-Fi is common in Indian railway stations, airports, cafés and other public places, so knowing how to spot fake hotspots and when to use mobile data can help people protect their UPI, banking and personal information.

You’re at a railway station with 12 per cent battery and a nearly spent data pack. Your phone lists three networks with almost the same name. You tap the one that looks right, and it connects without asking anything. Whether that was a smart move depends on a few things you can’t see.

What Can Actually Go Wrong on a Hotspot

Public Wi-Fi is an untrusted network. Anyone can set one up, and the name on your screen proves nothing. The classic trick is the “evil twin”: an attacker creates a hotspot whose name is nearly identical to the real one, such as “StarbucksWiFi” instead of “Starbucks-WiFi”. Some attackers even knock the genuine network offline for a moment with a deauthentication attack, which nudges devices to join the fake one.

Once you’re on it, the operator can sit between you and the internet. They can see which sites your phone contacts, send you to a fake login page that asks for your email password or phone number, or look for weaknesses in other devices on the same network. A password printed on a café menu doesn’t fix this, because everyone in the café, attacker included, has the same password.

What HTTPS Protects, and What It Doesn’t

HTTPS is the padlock version of a web address. It scrambles the data travelling between your browser and a website, so the hotspot owner sees gibberish instead of your password or card details. Google’s HTTPS transparency report shows that HTTPS is now used for the vast majority of Chrome navigations. That is why the US Federal Trade Commission now says connecting to public Wi-Fi is usually safe, a big change from the older “never touch it” advice.

The Recent Change: Chrome Gets Stricter About Insecure Sites

Google has announced a change to Chrome that matters on public networks. With Chrome 154, Google plans to enable the ‘Always Use Secure Connections’ setting by default for public sites. Chrome will ask for your permission before the first access to a public site that does not support HTTPS.

Google’s enterprise notes say this feature rolls out gradually, so don’t assume it is already active in your browser; you can check Chrome’s security settings. On a hotspot, treat that warning seriously. Plain HTTP pages are exactly the ones an attacker on the same network can read or tamper with. Don’t click through.

When Mobile Data Is the Safer Choice

Use your phone’s own 4G or 5G connection for anything involving money or identity: UPI payments, net banking, logging into email or work accounts, and anything you’d regret sharing. Mobile data uses security protections between your phone and the carrier’s network, and a nearby stranger cannot simply create a lookalike mobile network in the same way they can create a fake Wi-Fi hotspot. However, cellular networks are not immune to attacks, so mobile data should not be treated as completely risk-free. Attacks on mobile networks exist, but they are harder to pull off than a fake hotspot, which needs little more than a cheap gadget and a convincing name.

Also switch to mobile data when a network asks for more than it should, like your phone number plus an OTP, or when the name doesn’t match what staff tell you. Free Wi-Fi is perfectly fine for reading news, checking maps or streaming a video.

A few free habits help. Turn off auto-join for public networks, delete hotspots you no longer use, and keep your phone updated. If your laptop needs internet, use your phone’s hotspot instead.

So can you trust public Wi-Fi? Not the network, but you don’t have to. Treat it as a shared corridor: fine for casual browsing, the wrong place for your bank.

Found this analysis insightful?

Share with colleagues, engineers, and your network.

Tags & Topics

Discussion

Leave a Comment

No comments yet. Be the first to start the conversation!

Link copied to clipboard!