Is the Café Wifi Safe, and Do I Need a VPN?

Is the Café Wifi Safe, and Do I Need a VPN?
Safer than it used to be, and still not somewhere to be careless. The specific danger most people were warned about has largely been designed out, while two others have quietly taken its place and get far less attention than they deserve.
For a work device the answer is more definite. The National Cyber Security Centre (NCSC) recommends that devices connecting over untrusted networks use a virtual private network, usually shortened to VPN, and that businesses force work traffic through it rather than leaving it to individual judgement.
What changed, and what did not
The old warning went like this: on shared wifi, anybody nearby can read what you type, so never do banking in a café.
That was a reasonable description of the internet around 2012, when a great deal of web traffic travelled unencrypted and could genuinely be read by anyone on the same network. It describes the internet of today rather badly. Almost every site of consequence now encrypts the connection between your device and its servers, so somebody watching the network sees that you connected to your bank, and not what you did there.
So that particular fear has largely faded away. What has not faded is the shared key problem, and it is worth being precise about what that means. A wifi password written on a blackboard is known to everybody in the room and to everybody who has been in the room this year. That does not hand them your banking session, but it does mean you are relying entirely on each individual website's encryption rather than on any privacy from the network itself.
Which is fine when every site does its job properly. Is that a safe assumption on a network you know nothing about? It becomes considerably less fine the moment something on that network is actively trying to interfere with you.
The two risks that actually matter now
The first is that the network might not be what its name says. Anybody can create a wifi network and name it whatever they like, including the exact name of the café you are sitting in. Your device sees a familiar name and connects. From that point every request passes through equipment somebody else controls, which lets them redirect you, present pages of their choosing, and generally decide what you see. This is usually called an evil twin, and there is nothing sophisticated about setting one up. (as outlined in the updated resilience guidance notes).
The second is subtler and gets almost no attention. Hotel and airport networks train you into a habit that is genuinely dangerous: connect, wait for a page to appear, enter details into it. Once you have accepted that pattern, a page asking for your room number, your email address, or a payment for premium access is entirely unremarkable. It is the one place people willingly type things into a page they did not navigate to.
Notice that neither of those is solved by encryption, and neither is solved by a VPN either. Both are about being pushed towards a page and then typing something into it.
What a VPN actually does
The marketing around VPNs is spectacularly overblown, which makes it worth being precise about what you are buying.
A VPN builds an encrypted tunnel from your device to a server elsewhere, and your traffic emerges there instead of on the local network. On an untrusted network that is genuinely useful. Whoever runs the wifi can no longer see which sites you visit, and cannot interfere with your traffic in transit, which removes most of the evil twin advantage.
What it does not do is protect you from yourself. A VPN carries your password to a fake login page with exactly the same care it would carry it to the real one. It is a private tunnel to a building, and it has no view on whether that building is the right one.
For businesses, the position is clear enough. Work devices leaving the office should use one, it should be forced rather than optional, and traffic should not be split so that some of it wanders off outside the tunnel. That is the NCSC's position and it is the right default for any company whose staff work from cafés, trains and client sites. Our guide on remote working controls covers how that fits into certification.
For personal use, a VPN is a reasonable precaution rather than an obligation. Be sceptical of free ones in particular, since running that infrastructure costs money, and if you are not paying then the traffic you are routing through somebody else's equipment is quite likely the product.
The habit that beats all of it
Look, most of this disappears without any software at all if you simply use your phone's own mobile data.
Tethering your laptop to your phone, or simply doing the task on the phone over its own connection, sidesteps the shared network entirely. There is no evil twin, no captive portal, and no shared key. For the ten minutes of genuinely sensitive work most people do while travelling, that is quicker than connecting to the café network anyway.
Beyond that, a few habits worth having:
Turn off automatic connection to open networks. Phones will otherwise reconnect to anything matching a name they have seen before, which is precisely the behaviour an evil twin relies on. It is worth going through the saved network list occasionally and deleting the ones you joined once, three years ago, in an airport you have no plans to revisit.
Never install anything a network asks you to install. A wifi network has no legitimate reason whatsoever to require software or a certificate on your device, and a prompt to do so is one of the few genuinely unambiguous warning signs in this whole subject.
Reach important sites from bookmarks or apps rather than links, which is the same discipline that defeats fake websites generally, and our guide on spotting a fake site covers how to read an address properly.
Turn on a second sign-in step for anything that matters, so a captured password is not enough by itself. That single control does more for you on a hostile network than any amount of care about which wifi you joined.
Does any of this change for a business?
Considerably, and mostly because of what is on the laptop rather than what is on the network.
A personal phone on café wifi risks one person's accounts. A work laptop on the same network carries client files, the accounting system, and a mailbox that resets every other password in the company. The consequences are simply on a different scale, which is why the guidance for organisations is firmer than the guidance for individuals.
There is also a practical failure worth naming, because it is extremely common. Staff are given a VPN, told to use it, and then it turns out to be slow or awkward on hotel networks, so they turn it off and get on with the job. Nobody ever mentions having done this to anyone. From the office it looks like the control is working, and in reality it has been quietly abandoned by the people it was issued to.
The fix is to make it automatic rather than to make it a rule, which is exactly why official guidance favours a forced VPN over a voluntary one. Any control that depends on a tired person choosing correctly at nine at night in a hotel room will eventually stop being a control at all.
Worth knowing about your own office
One small thing, since it comes up whenever this subject does. Your guest wifi should not be the same network your business runs on, and in a surprising number of small offices it is.
What about hotel wifi specifically?
It is the worst of the categories, and worth treating differently.
Hotel networks are shared with hundreds of strangers, frequently run on equipment that has not been updated in years, and they normalise the captive portal habit more thoroughly than anywhere else. They also tend to be used by people doing exactly the work worth intercepting, at the end of a long day, on a laptop full of client material.
If you are working from a hotel, use mobile data for anything that matters, or use the company VPN and check that it has actually connected before you start. Do not enter payment details into whatever page the network puts in front of you, and if the room wifi wants a card number for an upgrade, do that at reception instead.
Conference wifi deserves a similar mention, for a slightly different reason. Everybody present is in the same industry, the network name is published in the programme, and a room full of laptops belonging to people worth targeting is an unusually attractive place to run a fake access point. The name being printed in the agenda is precisely what makes it easy to imitate convincingly.
The honest summary
Safe enough for reading the news on your phone. Not the place to be casual with a work laptop full of client material.
The two risks worth caring about are that the network is not what it claims to be, and that you will be presented with a page asking you for something. A VPN deals with the first, which is why work devices should be using one automatically. Nothing deals with the second except the habit of refusing to type credentials into any page you did not deliberately navigate to yourself, and that habit is worth more than any product you could buy for the purpose.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.