Free Wi-Fi has become standard in Indonesian cafes, airports, hotels, hospitals, and shopping centres. For many people it is a lifeline when data runs low or the mobile signal weakens indoors. Unfortunately, that convenience often arrives with a mistaken assumption: that as long as the network is provided by an official venue, everything is automatically safe.
Reality is more nuanced. Public Wi-Fi is not automatically dangerous, but it does move part of the security control into someone else's hands. What follows explains the risks that matter in 2026, then gives 12 concrete steps you can apply before, during, and after connecting.
The real risks behind open Wi-Fi
Ten years ago, the main threat on public Wi-Fi was passive eavesdropping: anyone on the same network could read your traffic because most sites still used HTTP. That has changed considerably. More than 95 per cent of pages loaded in a modern browser now use HTTPS, which means the content is encrypted between your device and the destination server.
The focus of the threat has therefore shifted to four things.
1. Evil twin networks
An attacker sets up an access point with a name similar or identical to the official network,
Airport-Free-WiFi alongside Airport_Free_WiFi, say. Your device cannot
tell them apart. Once connected, all your traffic passes through the attacker's equipment, which
can then steer you to a fake login page.
2. Imitation captive portals
The login page that appears automatically when you connect is an easy target. A fake portal can ask for your email password, card number, or push you to install a "security certificate" that actually opens the way to interception. A legitimate portal never asks for the password to another of your accounts.
3. Data collection by the network operator
This risk is lawful but rarely appreciated. A Wi-Fi operator can see the addresses of the sites you visit (though not their contents), your device's MAC address, how long you were connected, and whatever you entered on the registration form. Some use it for visitor analytics and ad targeting.
4. Devices left open on the local network
If file sharing, AirDrop, or printer sharing is active, other devices on the same network can see your computer. On a home network that is convenient; in a cafe it is an attack surface.
Worth remembering: the greatest risk almost always comes from misconfiguration and social engineering, not from sophisticated hacking. That is good news, because it means most of it is preventable with simple habits.
Before connecting: 4 steps
Step 1, Confirm the network name with an official source
Ask the barista, the receptionist, or read the information board. The correct network name is usually printed, not guessed. If there are two networks with nearly identical names, that alone is warning enough to cancel.
Step 2, Turn off automatic connection
A phone holding hundreds of saved networks will connect on its own to a matching SSID anywhere. On Android: Settings › Network & internet › Internet › the gear icon, then disable "Connect to open networks". On iOS: Settings › Wi-Fi › "Ask to Join Networks" set to "Ask".
Step 3, Update the operating system and browser
Most holes exploited on public networks were patched months earlier. A device two or three versions behind is far more vulnerable than a current one, whatever network it uses.
Step 4, Mark the network as "public"
Windows asks for a network profile on first connection; choose "Public", not "Private". That automatically disables network discovery and file sharing. On macOS, disable File Sharing in System Settings › General › Sharing.
While connected: 5 steps
Step 5, Check for the HTTPS padlock, but do not stop there
The padlock means the connection is encrypted, not that the site is trustworthy. Fraudsters use
HTTPS too. What matters more is reading the domain name in full, from right to left.
your-bank.co.id.login-verify.xyz does not belong to your bank.
Step 6, Do not install any certificate or app
No legitimate Wi-Fi network requires you to install a configuration profile or a root certificate merely to browse. A request like that is reason enough to disconnect.
Step 7, Fill in the captive portal only as far as needed
A reasonable portal asks for a name, email, or phone number, and shows a link to a privacy policy. A portal asking for a national ID number, card details, or another account's password is not reasonable. You are entitled to refuse and use mobile data.
Step 8, Turn on a VPN for sensitive activity
A VPN wraps all traffic in an encrypted tunnel as far as the provider's server. The effect: the Wi-Fi operator no longer sees which sites you open. Choose a paid provider with an independently audited no-log policy; free VPNs frequently fund themselves by selling their users' data.
Step 9, Use two-factor authentication
If your password leaks, the second factor holds an attacker at the gate. Prefer an authenticator app or a physical security key over SMS, which is vulnerable to number takeover.
After you finish: 3 steps
Step 10, Forget the network
Once you leave the venue, remove the network from the saved list. This stops your device connecting automatically to a matching SSID somewhere else.
Step 11, Switch Wi-Fi off while moving
A phone continuously scanning broadcasts a list of the SSIDs it has used. That data can be used to track your movements between locations.
Step 12, Review account activity periodically
Most large services provide an "active devices" or "security activity" page. Checking it once a month helps you catch an unfamiliar session early.
Four real scenarios and how to handle them
Scenario A, An airport with dozens of similarly named networks
Airport lounges are where evil twin networks turn up most, because many strangers gather briefly and nobody knows anyone. Get into the habit of reading the airline information board or asking at the desk, rather than picking whichever network has the strongest signal. A portal asking for flight number and name is reasonable; one asking for passport or card details is not.
Scenario B, A hotel giving the password on the room card
Hotel networks usually do not isolate guests from one another. That means your device can be seen by other guests on the same floor. Before connecting, make sure file sharing is off and the network profile is set to public. If you are carrying a work laptop, turn on the company VPN before opening anything.
Scenario C, A cafe displaying the password on a chalkboard
A shared password that is never changed gives a false sense of security. WPA2 encryption with a password everyone in the room knows only protects against people outside the room. Treat a network like this as equivalent to an open one.
Scenario D, Wi-Fi on public transport
Trains and intercity buses increasingly offer Wi-Fi. Because the connection is usually backhauled over a mobile network, capacity is small and shared among many passengers. Beyond applying the same security steps, lower your speed expectations and avoid downloading large files that disadvantage other passengers.
Specific settings per operating system
| Device | Settings to check |
|---|---|
| Android | Private Wi-Fi address on, "Connect to open networks" off, Nearby Share set to contacts only |
| iOS / iPadOS | Private Wi-Fi Address on, AirDrop set to "Contacts Only", "Ask to Join Networks" set to Ask |
| Windows | Network profile "Public", network discovery off, File and Printer Sharing off |
| macOS | File Sharing off, Firewall on, "Remember networks this computer has joined" reviewed periodically |
Taking the time once to go through the list above is far more effective than relying on vigilance every time you connect. Most gaps open precisely when someone is in a hurry.
Three myths worth correcting
Myth 1: "A password-protected network is automatically safe." The password only limits who can get in. Once inside, everyone is in the same position.
Myth 2: "Incognito mode protects me on public Wi-Fi." That mode only prevents history being saved on your own device. The network operator sees exactly the same traffic.
Myth 3: "I have nothing worth stealing." Your email account is the key to recovering almost every other account you hold. Its value goes far beyond the contents of the inbox itself.
A quick summary
| Situation | Risk level | Suggested action |
|---|---|---|
| Reading news, watching video | Low | Just make sure HTTPS is active |
| Signing into social media | Medium | Turn on 2FA, avoid suspicious portals |
| Work email, internal documents | Medium–high | Use the company VPN |
| Banking transactions | High | Prefer the official app or mobile data |
| A portal asking for a certificate or another password | Critical | Disconnect immediately |
In short: public Wi-Fi is worth using as long as you treat it as a network you do not fully trust. The twelve steps above take under five minutes to set up once, then run on their own afterwards.
Want to understand the mechanism behind that login page appearing automatically? Read the full explanation of captive portals. If you are considering a VPN, we discuss when the tool is genuinely useful and when it is not in the guide to VPNs for public Wi-Fi.
Frequently asked questions
Is public Wi-Fi always dangerous?
Not always. Most modern web traffic is already encrypted over HTTPS, so the content of your communications is hard for anyone else to read. The greatest risk comes from fake networks, imitation login pages, and unpatched devices, not from public Wi-Fi itself.
Do I need a VPN every time I use public Wi-Fi?
Not necessarily, but it helps considerably if you often use unfamiliar networks or work with sensitive data. A VPN hides where your connection is going from the network operator and protects traffic that is not already encrypted.
How do you recognise a fake Wi-Fi network?
Watch for duplicate or near-identical network names, open networks asking for excessive data, and login pages asking for your email password or card details. Always confirm the official network name with staff at the venue.