Public Wi-Fi

Public Wi-Fi safety, explained by what actually goes wrong

Public Wi-Fi is not one risk. It is four or five different ones collapsed into a single scary phrase, and most of them have specific, fairly boring mechanics. Once the mechanics are clear it becomes obvious which problems a VPN removes and which ones it leaves exactly where they were.

This is the long version: what a captive portal is doing to your traffic, what HTTPS already protects and what it still reveals, how a hotspot with a real-looking name works, and why a password that everyone in the building knows is not a secret. Then, honestly, where a tunnel helps and where it cannot.

Networks you will meet
Cafés · Hotels · Airports · Trains · Co-working spaces

The captive portal has to happen before the tunnel

A captive portal is the sign-in page a cafe, hotel or train pushes at you before it lets any traffic out. Technically it is a gateway that answers every name lookup with its own address and redirects unencrypted web requests to its terms page. Until you accept, the only thing on the network you can reach is the portal itself.

This is why a VPN looks broken on a network you have just joined. A WireGuard tunnel comes up by exchanging a handshake with the server it is configured for, and the gateway drops that handshake along with everything else. Nothing is wrong with the app; there is simply no path to the internet yet for it to use.

So the order matters. Join the network, let the portal open, give it whatever the venue legitimately needs, confirm you have a working connection, then bring the tunnel up. The seconds between joining and connecting are the one window where your ordinary traffic sits on the raw network, which is a good reason to keep that window short and not open your mail while you wait.

  • Your phone notices a portal by requesting a known address and seeing that the answer was replaced. That is what makes the page appear on its own.
  • Portal pages are plain HTTP more often than you would expect, because a gateway cannot cleanly intercept a hostname whose certificate it does not hold.
  • Treat the portal form as untrusted input, not as a login. A room number and a surname are normal. A password you use anywhere else is not.

HTTPS hides the page, not the fact that you asked for it

Nearly everything is HTTPS now, and that genuinely is most of the problem solved. Someone listening to the air between your laptop and the access point cannot read the body of a page, a message you sent or a form you submitted. That part is finished, and it is not where the remaining exposure lives.

What still travels in the open is addressing. Your device looks up a hostname before it connects, and unless both your device and the network happen to be using encrypted DNS, that lookup is a readable question. The TLS handshake then names the site again in its Server Name Indication field, which stays unencrypted even in TLS 1.3 unless Encrypted Client Hello is supported at both ends. Add destination addresses, which are unavoidable, plus packet sizes and timing, and an observer has a timestamped list of the services you used without decrypting a single byte.

  • Visible on a shared network: the hostnames you look up, the server name inside each TLS handshake, destination addresses, how much you transferred and when.
  • Not visible: page contents, credentials submitted over HTTPS, message bodies, anything inside the encrypted session.
  • A tunnel moves that whole list inside one encrypted connection, so the local network sees traffic to a single address and learns nothing about what is in it.

An evil twin is just a name, and names are free

A network name is a string broadcast by a radio. Nothing registers it, nothing verifies it, and nothing prevents a second device in the same room from broadcasting the same one. That is an evil twin: an access point advertising a familiar name so nearby devices treat it as somewhere they have already agreed to trust.

What makes it work is a convenience you asked for. Phones and laptops remember networks by name, rejoin them without asking, and prefer whichever signal is strongest. A radio sitting two metres from your table is stronger than the router behind the counter, so the decision is usually made before you look at the screen. Everything after that is ordinary operation: whoever runs the access point runs the DHCP server, chooses your resolver, and sees every address you try to reach.

This is the one threat here that a tunnel handles cleanly, because a WireGuard peer is authenticated by its key, not by the name of the network the packets crossed. If the handshake completes, the far end is the server you configured. A hostile access point in the middle can refuse to carry the connection, but it cannot be the other end of it.

  • Forget networks you will not use again, particularly the generic names that hotel and transport chains reuse in every location.
  • A portal that asks for something it should already have, or asks again on a network you finished joining a minute ago, is worth a second look.

Everyone in the building has the password

Venue Wi-Fi is usually WPA2 with one pre-shared key printed on a receipt or a chalkboard. The encryption is real, and it is better than an open network, but the key is shared, and a secret a hundred guests know is a secret in name only. Someone who has that password and is capturing the air at the moment your device joins can derive the keys for your session, because they come from the handshake plus the key they already hold.

There is a second, quieter consequence of joining. You are now on a local segment with strangers, and anything your device offers its neighbours it is offering to them: file shares, screen sharing, a discoverable printer, a media server, a development server left running on a laptop port. At home that behaviour is a feature, which is exactly why it is easy to forget that it travels with you.

  • Newer equipment is better here. WPA3 gives each device its own session keys, and Enhanced Open does the same on networks with no password at all. You do not get to choose which one the venue bought.
  • Switch off file and printer sharing before you travel rather than after you arrive, and let the operating system treat these networks as public rather than trusted.
  • A tunnel protects traffic leaving your device. It does nothing about a service your device is advertising to the room.

What a tunnel actually changes

With WrapVPN connected, your device builds one encrypted connection to a server you pick and sends everything through it. The access point, and anyone listening to it, sees a single stream to a single address. The name lookups and TLS handshakes that were readable a moment ago now happen at the far end instead.

Two details matter on poor Wi-Fi specifically. WireGuard completes its handshake in a single round trip, so the reconnect after a train enters a cutting, or after a hotel hands your laptop to a different access point, is quick rather than a visible stall. And because ad and tracker filtering happens at the DNS layer, those domains are refused before your device contacts the host at all, which on a congested shared link removes requests you were never going to look at.

A reconnect is also the moment a tunnel could leak, and a shared network gives you a great many of them. That window is what the kill switch covers: when the tunnel drops, traffic stops at your device instead of falling back to the open network, and DNS and IPv6 stay pinned inside the tunnel until it is back. It is enforced at the system level rather than by the app, so it holds whether or not a WrapVPN window is open. On a network that drops every few minutes, the difference is whether each drop costs you a pause or spills a few requests onto the access point in the clear.

One account covers iPhone, iPad, Mac and Android, with a Windows build in review, which is relevant here because the laptop is usually the device with sharing enabled and the phone is the one that rejoins networks by itself. The pricing fits the shape of the problem too: $1.99 per week or $3.99 per month, with no annual subscription, so a week of hotel and cafe networks does not need a year-long commitment.

  • Choose the exit from the region list, which shows live latency, so a slow local connection is not made slower by a needlessly distant server.
  • Connect after the portal and then leave it connected. The exposure is the unprotected gap, not the tunnel.

What it does not fix

A tunnel is transport security. It makes the network you are standing on irrelevant to your traffic, and that is the whole claim. Threats that do not care which network you are on are untouched by it.

A phishing page reached through a tunnel is still a phishing page, and the encryption works perfectly while you type your password into it. A file you choose to download and run arrives just as faithfully. If the device is already compromised, whatever is on it saw what it wanted before the tunnel existed. And a reused password that leaked somewhere else is equally a problem on hotel Wi-Fi, at home, and on a cellular connection.

  • Not solved by any VPN: phishing, a malicious download, a device that is already compromised, a weak or reused password, or someone reading your screen from the next table.
  • Worth doing instead: a password manager, two-factor authentication on anything that matters, automatic updates, and a screen you do not point at the room.
  • Also not a network problem: staying signed in on a shared or borrowed computer. Nothing in a tunnel can sign you out of it.

What people use it for

Cafés

Two hours on one shared key with a dozen strangers, a signal weak enough that your phone keeps hunting for something stronger, and a laptop on the table that is probably the device with sharing switched on. Join, clear the portal, connect, and let it stay connected until you pack up.

Hotels

Hotel networks are the ones most likely to identify you by room number and to reuse one name across every property, which is convenient and also the easiest name in the world to impersonate. Expect a portal, expect to be handed between access points on the walk to your room, and expect a television that wants to pair with your phone.

Trains and coaches

A moving network drops constantly, which punishes slow reconnection harder than anything else on this list. A handshake that finishes in one round trip is the difference between a pause and an outage, and the portal usually wants clearing again at the start of each journey.

Co-working spaces

These feel like an office and are not one: a shared key, strangers on the same segment, and a printer that anyone present can discover. The habits that protect a laptop in a cafe are the habits to keep here, including leaving file sharing off even though the room looks private.

How to set it up

  1. 1

    Join the network first

    Connect to the Wi-Fi and wait a moment for the captive portal to appear. If nothing appears, open any plain http address in a browser and the gateway will redirect you to its page.

  2. 2

    Clear the portal carefully

    Accept the terms, or give the venue what it legitimately needs, which is usually a room number and surname or an email address. Do not reuse an important password on a portal form, and close the tab once it lets you through.

  3. 3

    Bring up the tunnel

    Open WrapVPN and connect. Pick a region near where you are from the list, which shows live latency, unless you have a reason to be somewhere else. The handshake needs one round trip, so it should take about a second.

  4. 4

    Check it before you need it

    Confirm the app shows a live connection and load one page. If a handshake will not complete on an unusually restrictive network, try a different region before concluding the Wi-Fi is unusable.

What it costs

Short plans, priced so a week costs what a week is worth. Cancel by not renewing.

$1.99per week

$3.99per month

No annual subscription. No long-term commitment.

7-day free trial

See all plans

Common questions

Do I still need a VPN if every site I use is HTTPS?

HTTPS protects what you send and receive, so on the modern web the contents are already covered. What it does not hide is which hosts you contact: DNS lookups and the server name in each TLS handshake are normally readable on the local network. A tunnel is what puts that addressing out of the access point's reach.

Why does my VPN fail to connect on hotel or cafe Wi-Fi?

Almost always because the captive portal has not been completed. Until you accept its terms the gateway blocks everything except its own page, including the handshake the tunnel needs. Join the network, finish the portal in a browser, then connect. If it still fails somewhere that otherwise works, try another region.

Is a password-protected network safe?

It is safer than an open one, but the password is printed on a receipt and shared with everyone in the building, so it is not a secret between you and the router. Under WPA2 a shared key means anyone holding it who captures your device joining can derive that session's keys, and you are also sharing a local segment with strangers.

How can I tell a fake hotspot from the real one?

Reliably you cannot, which is rather the point. A network name is a string any radio can broadcast, and your device quietly prefers the strongest signal with a remembered name. Instead of trying to identify the genuine one, assume you may be on the wrong one and make that irrelevant: a WireGuard peer is verified by key, not by network name.

Does a VPN protect me from everything on public Wi-Fi?

No. It secures the path between your device and the server, which is exactly the part a shared network puts at risk. It does not stop phishing, a file you download and run, a device that is already compromised, or a password that leaked elsewhere. Those need a password manager, two-factor authentication and updates.

Should I leave it on all the time or only for sensitive things?

Leave it on. The risk on a shared network is the time your traffic spends outside the tunnel, and switching it on only before something sensitive means everything else travelled in the open, including the background syncing your device does without being asked. There is no advantage to the gap.

What happens if the tunnel drops on a flaky train or hotel network?

The kill switch holds traffic at your device rather than letting it fall back to the open network, and DNS and IPv6 requests stay pinned inside the tunnel while it re-establishes. It is enforced at the system level, not by the app window, so an unstable network costs you a pause rather than a stretch of unprotected traffic you were never told about.

Get WrapVPN

One account covers your phone, tablet and computer. Connect in a tap, from any of our regions.