Public Wi-Fi Risks in 2026: What Actually Matters
The classic public Wi-Fi threats have changed. Here's what's actually risky on hotel and coffee shop networks today — and what a VPN does and doesn't fix.
By VeilTun Team
The threat model has changed
Ten years ago, the canonical public Wi-Fi warning was "someone on the same network can read your traffic." That threat is mostly gone in 2026. Almost every website you actually care about — banking, email, social media, shopping — uses HTTPS by default. Modern browsers refuse to load passwords or payment forms over plaintext HTTP. The classic "guy with Wireshark at the coffee shop" attack against your Gmail session simply doesn't work anymore.
So why does public Wi-Fi still matter? Because the threats moved.
What's actually risky on public Wi-Fi
1. DNS hijacking
DNS — the system that translates bank.com into an IP address — is still routinely unencrypted on most networks. The Wi-Fi router controls which DNS server your device uses. A malicious or compromised router can return wrong answers: route paypal.com to a phishing page, or apple.com to a fake "your account was locked" prompt.
HTTPS protects you after you reach a server, but it doesn't protect the lookup that tells you which server to reach. If your DNS resolver is hostile, you can land on an attacker-controlled site that still shows a green padlock for their domain.
2. Captive portal manipulation
The hotel/airport "Wi-Fi login" page is itself an attack surface. It can:
- Inject scripts that scan your local network for vulnerable devices.
- Drop tracking cookies for ad networks.
- Run JavaScript that fingerprints your browser and OS for later targeting.
You're forced to interact with the captive portal before getting internet access. Most users do this without thinking.
3. Metadata leakage
Even when traffic is encrypted, the fact that you connected to specific servers is visible to the network operator. Connecting to:
tinder.comat 11pmwebmd.com/std-symptomsfrom a conference Wi-Filinkedin.com/jobs/[competitor company]from your current employer's guest network
…all of these are visible to whoever runs the access point, even with HTTPS. The destination IP and SNI hostname are not encrypted.
4. Captive portal certificate warnings
Some networks deliberately trigger TLS warnings and ask users to "install our certificate" to access the internet. Users who comply have effectively given the network operator the ability to intercept all of their HTTPS traffic going forward — until they remove the certificate.
If you've ever clicked through to install a certificate to get hotel Wi-Fi working, you should remove it from your iPhone now: Settings → General → VPN & Device Management.
5. Evil twins
A malicious actor sets up an access point named Starbucks Wi-Fi near a Starbucks. Your phone, which remembers connecting to Starbucks Wi-Fi before, joins automatically. Now an attacker controls the entire network path.
iOS has gotten better at warning about this since iOS 14 (the "Private Wi-Fi Address" feature reduces tracking), but it doesn't prevent the connection itself.
Why a VPN actually helps
A VPN tunnel addresses the threats above by changing where the network boundary lives:
| Threat | Without VPN | With VPN |
|---|---|---|
| DNS hijacking | Hostile router resolves your queries | DNS goes through the VPN to a trusted resolver |
| Metadata leakage to AP | AP sees every destination IP/SNI | AP sees only one IP: the VPN server |
| Captive portal scripts | Run in your browser context | Still run, but only see VPN-side traffic afterward |
| Evil twin | Full traffic interception | Encrypted tunnel; attacker sees only encrypted blobs |
| Malicious TLS certificate | Possible HTTPS interception | VPN's own TLS validation is separate |
The VPN doesn't fix every problem (you still need to dismiss the captive portal carefully, and not install certificates), but it collapses several attack surfaces into one: now the only network operator that sees your traffic is the VPN provider.
This is why the question "do I trust the VPN provider" matters more than "is the coffee shop secure." You're moving trust, not eliminating it.
The iPhone-specific gotchas
iOS makes VPN usage slightly more complicated than on a laptop:
1. Captive portals require the VPN to be off. Hotel and airport networks won't let traffic flow until you log in to their portal. iOS detects this and shows the portal in a Safari-like window — but only if your VPN is disconnected. Practical flow: connect to Wi-Fi → log in to portal → enable VPN → continue.
2. iCloud Private Relay is not a VPN. It only proxies Safari and unencrypted HTTP from other apps. It doesn't protect anything your apps do over their own HTTPS connections. If you rely on Private Relay for coffee shop protection, you're getting partial coverage.
3. Always-on / on-demand rules. A good iPhone VPN supports on-demand rules: automatically connect whenever I join a Wi-Fi network that isn't my home network. This is configurable in iOS Settings under VPN profiles, and VeilTun ships sensible defaults for it.
4. The kill switch matters more on cellular handoff. When you walk out of Wi-Fi range and your iPhone falls back to LTE mid-connection, there's a brief window where traffic could leak before the VPN reconnects. A proper kill switch blocks all non-VPN traffic during this window. (Apple's built-in "Connect On Demand" handles most of this, but only if configured.)
When you don't need a VPN
Honest answer: not every situation does.
- Home Wi-Fi. Your ISP can see metadata, but the local network is yours.
- Cellular. Modern LTE/5G encrypts the radio link. The carrier can still see metadata, but local interception isn't realistic.
- HTTPS-only sites. If everything you do is on well-known HTTPS sites and you trust your DNS resolver (1.1.1.1, 9.9.9.9), the marginal benefit is mostly metadata privacy from your ISP.
The strong case for an always-on VPN on iPhone is when you regularly use untrusted Wi-Fi — travel, hotels, cafes, conferences — or when you specifically care about hiding browsing metadata from your ISP. For someone who only uses home and cellular, a VPN is more about category-level privacy than acute security.
The bottom line
Public Wi-Fi is less dangerous than the 2015-era warnings suggested, but the threats that remain are subtler and harder to detect: DNS manipulation, metadata leakage, captive portal abuse, and evil twins. A VPN doesn't eliminate these threats — it concentrates them with one provider you (hopefully) chose carefully.
Pick a VPN that runs WireGuard, uses on-demand connection rules on iOS, doesn't keep logs, and has a clear no-logs policy. Then leave it on when you're away from home. That covers most of what matters.