Security checklist · 6 min

Safer public Wi‑Fi

Public networks are convenient, not automatically dangerous. A few habits reduce the most common risks without turning every coffee stop into an incident response.

Before you connect

  • Install operating-system, browser and security updates while you are on a trusted network.
  • Turn off automatic connection to open networks and disable file sharing or device discovery.
  • Ask staff for the exact network name. Attackers can create convincing lookalike hotspots.
  • Have mobile data or a trusted VPN available for tasks that need extra confidence.

While you are connected

Modern HTTPS encrypts the content exchanged with a website and is the most important baseline. Your browser should show no certificate warning. Leave any site that asks you to bypass a certificate error.

Avoid sensitive account changes or large financial transactions when you cannot verify the network. If you must sign in, use multifactor authentication—preferably an authenticator app or security key rather than SMS where available.

Captive portals

Hotels and airports often redirect you to a sign-in page. Confirm the venue and terms before providing personal data. A captive portal should not require software installation, browser extensions or your email password. Close the page if the request does not match the service being offered.

What other people can see

On a properly configured network, another guest should not be able to read HTTPS content. The network operator can still observe connection metadata such as when your device connected and which services it contacted. DNS may also be visible unless it is encrypted or routed through a VPN.

After you leave

  1. Disconnect and tell the device to forget the network.
  2. Turn sharing and discovery settings back to your preferred state.
  3. Check account notifications if you signed into an important service.
  4. Update any password only if you entered it on a suspicious page or saw a certificate warning; changing every password after normal HTTPS use is unnecessary.

A VPN is one layer

A trustworthy VPN can protect traffic between your device and its server, but it cannot prevent phishing, malicious downloads or account tracking after you sign in. Combine it with updates, HTTPS, multifactor authentication and attention to warnings.