Free Wi-Fi has become standard in Indonesian cafes, airports, hotels, hospitals, and shopping centres. For many people it is a lifeline when data runs low or the mobile signal weakens indoors. Unfortunately, that convenience often arrives with a mistaken assumption: that as long as the network is provided by an official venue, everything is automatically safe.

Reality is more nuanced. Public Wi-Fi is not automatically dangerous, but it does move part of the security control into someone else's hands. What follows explains the risks that matter in 2026, then gives 12 concrete steps you can apply before, during, and after connecting.

The real risks behind open Wi-Fi

Ten years ago, the main threat on public Wi-Fi was passive eavesdropping: anyone on the same network could read your traffic because most sites still used HTTP. That has changed considerably. More than 95 per cent of pages loaded in a modern browser now use HTTPS, which means the content is encrypted between your device and the destination server.

The focus of the threat has therefore shifted to four things.

1. Evil twin networks

An attacker sets up an access point with a name similar or identical to the official network, Airport-Free-WiFi alongside Airport_Free_WiFi, say. Your device cannot tell them apart. Once connected, all your traffic passes through the attacker's equipment, which can then steer you to a fake login page.

2. Imitation captive portals

The login page that appears automatically when you connect is an easy target. A fake portal can ask for your email password, card number, or push you to install a "security certificate" that actually opens the way to interception. A legitimate portal never asks for the password to another of your accounts.

3. Data collection by the network operator

This risk is lawful but rarely appreciated. A Wi-Fi operator can see the addresses of the sites you visit (though not their contents), your device's MAC address, how long you were connected, and whatever you entered on the registration form. Some use it for visitor analytics and ad targeting.

4. Devices left open on the local network

If file sharing, AirDrop, or printer sharing is active, other devices on the same network can see your computer. On a home network that is convenient; in a cafe it is an attack surface.

Worth remembering: the greatest risk almost always comes from misconfiguration and social engineering, not from sophisticated hacking. That is good news, because it means most of it is preventable with simple habits.

Before connecting: 4 steps

Step 1, Confirm the network name with an official source

Ask the barista, the receptionist, or read the information board. The correct network name is usually printed, not guessed. If there are two networks with nearly identical names, that alone is warning enough to cancel.

Step 2, Turn off automatic connection

A phone holding hundreds of saved networks will connect on its own to a matching SSID anywhere. On Android: Settings › Network & internet › Internet › the gear icon, then disable "Connect to open networks". On iOS: Settings › Wi-Fi › "Ask to Join Networks" set to "Ask".

Step 3, Update the operating system and browser

Most holes exploited on public networks were patched months earlier. A device two or three versions behind is far more vulnerable than a current one, whatever network it uses.

Step 4, Mark the network as "public"

Windows asks for a network profile on first connection; choose "Public", not "Private". That automatically disables network discovery and file sharing. On macOS, disable File Sharing in System Settings › General › Sharing.

While connected: 5 steps

Step 5, Check for the HTTPS padlock, but do not stop there

The padlock means the connection is encrypted, not that the site is trustworthy. Fraudsters use HTTPS too. What matters more is reading the domain name in full, from right to left. your-bank.co.id.login-verify.xyz does not belong to your bank.

Step 6, Do not install any certificate or app

No legitimate Wi-Fi network requires you to install a configuration profile or a root certificate merely to browse. A request like that is reason enough to disconnect.

Step 7, Fill in the captive portal only as far as needed

A reasonable portal asks for a name, email, or phone number, and shows a link to a privacy policy. A portal asking for a national ID number, card details, or another account's password is not reasonable. You are entitled to refuse and use mobile data.

Step 8, Turn on a VPN for sensitive activity

A VPN wraps all traffic in an encrypted tunnel as far as the provider's server. The effect: the Wi-Fi operator no longer sees which sites you open. Choose a paid provider with an independently audited no-log policy; free VPNs frequently fund themselves by selling their users' data.

Step 9, Use two-factor authentication

If your password leaks, the second factor holds an attacker at the gate. Prefer an authenticator app or a physical security key over SMS, which is vulnerable to number takeover.

After you finish: 3 steps

Step 10, Forget the network

Once you leave the venue, remove the network from the saved list. This stops your device connecting automatically to a matching SSID somewhere else.

Step 11, Switch Wi-Fi off while moving

A phone continuously scanning broadcasts a list of the SSIDs it has used. That data can be used to track your movements between locations.

Step 12, Review account activity periodically

Most large services provide an "active devices" or "security activity" page. Checking it once a month helps you catch an unfamiliar session early.

Four real scenarios and how to handle them

Scenario A, An airport with dozens of similarly named networks

Airport lounges are where evil twin networks turn up most, because many strangers gather briefly and nobody knows anyone. Get into the habit of reading the airline information board or asking at the desk, rather than picking whichever network has the strongest signal. A portal asking for flight number and name is reasonable; one asking for passport or card details is not.

Scenario B, A hotel giving the password on the room card

Hotel networks usually do not isolate guests from one another. That means your device can be seen by other guests on the same floor. Before connecting, make sure file sharing is off and the network profile is set to public. If you are carrying a work laptop, turn on the company VPN before opening anything.

Scenario C, A cafe displaying the password on a chalkboard

A shared password that is never changed gives a false sense of security. WPA2 encryption with a password everyone in the room knows only protects against people outside the room. Treat a network like this as equivalent to an open one.

Scenario D, Wi-Fi on public transport

Trains and intercity buses increasingly offer Wi-Fi. Because the connection is usually backhauled over a mobile network, capacity is small and shared among many passengers. Beyond applying the same security steps, lower your speed expectations and avoid downloading large files that disadvantage other passengers.

Specific settings per operating system

DeviceSettings to check
AndroidPrivate Wi-Fi address on, "Connect to open networks" off, Nearby Share set to contacts only
iOS / iPadOSPrivate Wi-Fi Address on, AirDrop set to "Contacts Only", "Ask to Join Networks" set to Ask
WindowsNetwork profile "Public", network discovery off, File and Printer Sharing off
macOSFile Sharing off, Firewall on, "Remember networks this computer has joined" reviewed periodically

Taking the time once to go through the list above is far more effective than relying on vigilance every time you connect. Most gaps open precisely when someone is in a hurry.

Three myths worth correcting

Myth 1: "A password-protected network is automatically safe." The password only limits who can get in. Once inside, everyone is in the same position.

Myth 2: "Incognito mode protects me on public Wi-Fi." That mode only prevents history being saved on your own device. The network operator sees exactly the same traffic.

Myth 3: "I have nothing worth stealing." Your email account is the key to recovering almost every other account you hold. Its value goes far beyond the contents of the inbox itself.

A quick summary

SituationRisk levelSuggested action
Reading news, watching videoLowJust make sure HTTPS is active
Signing into social mediaMediumTurn on 2FA, avoid suspicious portals
Work email, internal documentsMedium–highUse the company VPN
Banking transactionsHighPrefer the official app or mobile data
A portal asking for a certificate or another passwordCriticalDisconnect immediately

In short: public Wi-Fi is worth using as long as you treat it as a network you do not fully trust. The twelve steps above take under five minutes to set up once, then run on their own afterwards.

Want to understand the mechanism behind that login page appearing automatically? Read the full explanation of captive portals. If you are considering a VPN, we discuss when the tool is genuinely useful and when it is not in the guide to VPNs for public Wi-Fi.

Frequently asked questions

Is public Wi-Fi always dangerous?

Not always. Most modern web traffic is already encrypted over HTTPS, so the content of your communications is hard for anyone else to read. The greatest risk comes from fake networks, imitation login pages, and unpatched devices, not from public Wi-Fi itself.

Do I need a VPN every time I use public Wi-Fi?

Not necessarily, but it helps considerably if you often use unfamiliar networks or work with sensitive data. A VPN hides where your connection is going from the network operator and protects traffic that is not already encrypted.

How do you recognise a fake Wi-Fi network?

Watch for duplicate or near-identical network names, open networks asking for excessive data, and login pages asking for your email password or card details. Always confirm the official network name with staff at the venue.