"public Wi-Fi means instant hacking"
loresecurityprivacy
A decade-old truth gone stale: with HTTPS now near-universal, the café network sees hostnames, not contents. The realistic risks shrank to fake portals, rogue twins, and the rare unencrypted service.
The EFF - once the loudest public-Wi-Fi warner - published 'Why Public Wi-Fi Is a Lot Safer Than You Think' (2020) after HTTPS adoption changed the math. Caution, yes; panic, no.
The warning that public Wi-Fi is dangerous dates from an era when most web traffic was unencrypted, and in that era it was entirely correct: anyone on the same network could read sessions and steal cookies with trivial tooling. The advice was proportionate to the threat.
Then the web encrypted. With HTTPS effectively universal and strict transport security widely deployed, a network operator sees which sites you contact and not what you do there, which is a genuine privacy exposure and a much smaller one than the original warning implied. The threat did not disappear; it shrank to something specific.
What remains worth caring about is narrower and worth stating precisely: the names you resolve and the hosts you connect to are visible, captive portals can and do interfere with connections, a malicious network can attempt downgrade attacks against anything not enforcing encryption, and older devices with unpatched network stacks are exposed to the local segment. Encrypted DNS addresses part of it and a VPN addresses more, which is a real use case for one. Panic is not warranted; awareness of what is actually visible is.
Disputed / commonly mistold A popular version of this story is inaccurate - see the note above.
Sources
- EFF - Why Public Wi-Fi Is a Lot Safer Than You Think (2020)
- Google Transparency Report - HTTPS usage across the web