Back to all articles

Public Wi-Fi: When It's Fine and When It's Not

The old blanket advice — never use public Wi-Fi — doesn't match how most people actually live. The more useful question is what you're doing on it, not whether you're on it at all.

The old blanket advice — never use public Wi-Fi — doesn't really match how most people live, especially with mobile data costs being what they are in South Africa. Free Wi-Fi at a mall, a coffee shop, or an airport is a genuine part of how people get online, and telling someone to simply never use it isn't realistic advice. The more useful question isn't whether you're on public Wi-Fi, but what you're doing while you're on it.

What the actual risk is

On an open or shared network, someone else on that same network — technically capable and specifically motivated — could potentially intercept unencrypted traffic passing between your device and the router. In practice, the risk is lower than it once was, because most websites and apps now use HTTPS encryption by default, which protects the content of what you're sending even over an insecure network. The remaining risk concentrates in a few specific situations rather than being evenly spread across everything you might do.

Low-risk activities

Browsing news sites, checking social media, watching videos, and general browsing on HTTPS sites (look for the padlock icon, though it's the default now for the vast majority of sites) carry limited additional risk on public Wi-Fi specifically. This covers most of what people actually use public Wi-Fi for.

Activities worth avoiding, or protecting

Online banking and anything financial. Even with HTTPS in place, this is worth minimising on public networks where possible — use your mobile data instead if you need to check a balance or make a payment while out.

Logging into work systems without your company's VPN active, if they provide one — company data deserves the extra layer.

Any site that doesn't show HTTPS (no padlock, or a browser warning) — on public Wi-Fi specifically, treat this as a hard no rather than a minor inconvenience.

The setup that removes most of the risk

If you find yourself needing to do something more sensitive while out and about, a VPN (covered in more detail elsewhere on this site) closes the gap entirely by encrypting all your traffic regardless of what the underlying network is doing. For most people, though, simply reserving banking and sensitive logins for mobile data or home Wi-Fi is a perfectly adequate and much simpler habit.

A few smaller habits worth having

  • Turn off automatic Wi-Fi connection to open networks — this stops your device from silently joining networks you never actively chose.
  • Confirm the network name with staff before connecting — a network called "Free_Mall_WiFi" is trivial for anyone to set up nearby as a lookalike, designed to capture traffic from people who connect without checking.
  • Forget public networks after you're done with them, rather than leaving your device set to auto-rejoin every time you're back in range.

The short version

Public Wi-Fi for everyday browsing is fine. Reserve banking, work logins, and anything you'd genuinely mind someone seeing for your mobile data, your home network, or a VPN. That one distinction covers almost all of the practical risk without requiring you to avoid public Wi-Fi altogether.