Using public Wi-Fi abroad without taking risks
Airport and cafe Wi-Fi is useful, provided you know what belongs on it and what does not.

Quick answer
- Use public Wi-Fi for reading and downloading, but do banking over your own mobile data instead.
- Turn off auto-join for remembered networks: a phone can rejoin a same-named network that is not the real one.
The main risk on public Wi-Fi is not that your phone gets hacked but that you do not know who runs the network. The safe frame is to treat it as a stranger's network and decide what a stranger may see.

Divide the work by network
| Task | Public Wi-Fi | Your own mobile data |
|---|---|---|
| Downloading maps, general browsing | Fine | Works but uses allowance |
| Banking and identity verification | Avoid | Preferred |
| First-time logins to important accounts | Avoid | Preferred |
| Streaming and large uploads | Fine | Expensive in data |
Settings worth changing before you go
- Turn off automatic joining so the phone does not silently attach to a familiar-looking name
- Delete saved networks you no longer use
- Enable two-step verification on important accounts in advance
- Update the operating system before departure, since mid-trip updates land on limited connections
Signs to back out
- A login page asking for far more than needed, such as card or email passwords
- Several similarly named networks in one place with nothing official confirming which is real
- A browser certificate warning, which should never be dismissed

What the owner of a network can and cannot see
Most public Wi-Fi advice describes risk in general terms and leaves the reader with nothing to do. A more useful frame is to ask what the person running this network could learn about you if they wanted to. Modern sites and apps encrypt their contents in transit, so what you type into an encrypted page is not simply floating there to be read. What remains visible is the trace of which destinations your device contacted and when, which says more than people assume. The bigger risk is therefore not somebody reading your messages: it is being steered to a page that is not the real one, or being invited to install something on your device while you believe it is a normal step in joining a network.
The join page is where most of the risk lives
When you join a public network the phone usually throws up a page asking you to accept terms or enter something before you can browse. That page is entirely under the network owner's control, and it is the easiest place to deceive you. A normal one asks you to tap accept, or asks for an email address or a room number to confirm you are a guest. An abnormal one asks for your email password, asks for card details, asks you to sign in with a social account for no apparent reason, or asks you to install a certificate or configuration profile before browsing will work. If you see the last kind, back out immediately rather than weighing it up: joining an ordinary venue's internet never requires any of that.
A network name is not evidence of who owns it
A network name is just a string, and nothing central certifies that a given name belongs to a given venue. A network named after the cafe you are sitting in could have been created by anybody else sitting in the same cafe. The check that actually works is not judging whether the name looks plausible; it is asking a member of staff which network and which password. Hotels usually print it on the welcome card or in the room, cafes usually post it at the counter. Be especially careful when several similar names appear in one place, differing by a single character or by the addition of the word free, because that pattern exists to be tapped by mistake.
| What you see | What it may mean | What to do |
|---|---|---|
| The name matches what staff told you and it has a password | Most likely the venue's own | Fine to use, while still keeping sensitive tasks off it |
| Several near-identical names | One of them may be an imitation | Ask staff before choosing |
| An open network with no password and no signage | Ownership unknown | Avoid if you have any alternative |
| It asks you to install a certificate or profile | It wants visibility it should not have | Leave the network at once |
| The browser warns about a site certificate | Something is interposed, or a configuration is wrong | Close the page and enter nothing |

Group your accounts by what happens if one is lost
Rather than memorising a list of dos and don'ts, group your accounts by the consequence of losing one. The heaviest group is your main email, because whoever reaches it can usually reset the passwords of everything else. Next come banking and anything tied to payments. Then accounts holding important documents, such as a copy of a passport. Last come ordinary accounts like a news reader or a music app. The first two groups should not be signed into for the first time on a network you do not know, and should not be transacting over it. The last group is fine. Grouping this way lets you decide quickly without reciting rules.
| Account group | What losing it costs you | Where to use it |
|---|---|---|
| Main email | It can reset the password of nearly everything else | Your own data, or your home network |
| Banking and payments | Direct financial loss that is hard to reverse | Your own data only |
| Storage holding important documents | Passport copies and personal papers exposed | Your own data |
| Travel and accommodation apps | An itinerary altered or cancelled | Sign in at home, then use it anywhere |
| Ordinary apps: news, music, maps | The damage stops at that account | Public Wi-Fi is fine |
Group them once before travelling and the on-the-spot decisions stop needing fresh thought.
Prepare the important accounts while you are still at home
Most travel security trouble does not begin with the network. It begins with having to sign into an important account somewhere you should not, because nothing was prepared. If you sign into everything you will need while still at home, and confirm that your verification method still works abroad, you will barely have to type an important password on somebody else's Wi-Fi for the whole trip. Of everything in this guide, that is the highest-value and lowest-effort measure.
- 1Sign into everything you will need, at homeRide apps, airline apps, accommodation apps and email. A first sign-in is when a service demands the most verification, so do it while you are on a network you trust and can still receive codes normally.
- 2Check your verification route still works abroadIf an account texts codes to a number, check with that operator whether it will still arrive abroad. If you use an authenticator app, check whether it works without a connection.
- 3Set up a recovery route in case the phone is lostKeep backup codes somewhere that is not the same device you sign in with, and make sure you can reach them without that device, because a recovery route stored on the lost phone helps nobody.
- 4Turn off auto-join and clear out old saved networksA phone that remembers old network names will try to rejoin anything with the same name, which may not be the same network. Where this menu lives differs by manufacturer and OS version; look under the Wi-Fi section of settings.
- 5Download what you will need before you goOffline maps, tickets, documents and translation packs. The less you must download on the move, the less you need anybody else's network at all.
- 6Update the system and apps before flyingMid-trip updates land on limited connections or on networks you did not choose. Finishing them at home is both easier and safer.
What a VPN does and does not do for you
A VPN gets talked about as though it were the whole answer, which does not match reality. What it does is reduce what the network owner can see, because your traffic is wrapped and sent out elsewhere. What it does not do is protect you from a fake page you typed a password into yourself, prevent a profile you agreed to install, or strengthen an account that has no second verification step. It also adds a little data overhead, can slow things down, and some services refuse connections coming from one. The remaining question is legal: some countries regulate VPN use, and that is something you have to check for your destination rather than something we can summarise for you.

Hotel Wi-Fi and cafe Wi-Fi are not quite the same thing
People assume a property's Wi-Fi is safer because it has a password, but a password handed to every guest does not separate you from the other guests on the same network. What genuinely differs is accountability: a property's network has an identifiable owner and usually a service contract behind it, while an open network in a public place may have nobody answerable for it at all. Worth knowing too: devices on the same network can sometimes see each other, depending on how the venue configured it, which is why file sharing and printer sharing are worth switching off on a laptop whenever you join a network that is not your own.
The laptop and the tablet are the devices people forget
Advice about public Wi-Fi tends to talk about phones, while the riskier device is often the laptop: file sharing was switched on at the office or at home, more software syncs in the background, and people do more consequential work on it. Before travelling, look over the laptop yourself. Turn off file sharing, make sure new networks are treated as public rather than trusted, and confirm the disk is encrypted. On a tablet a child uses, check that it is not set to join open networks automatically, because a child will not notice what it has attached to.
- Turn off file and printer sharing on the laptop before you travel
- Set new networks to be treated as public by default
- Disable automatic joining on every device you carry
- Delete saved networks left over from earlier trips
- Enable two-step verification on your main email and anything financial
- Confirm the laptop's disk is encrypted
- Keep backup codes off the device you normally sign in with
Sharing your own hotspot instead of hunting for somebody's network
If you already have a data plan, turning on your own hotspot for a laptop or a travelling companion is usually faster and more straightforward than hunting for a venue's network. Set a password that is not trivial, rename the hotspot so it does not announce whose device it is, and switch it off when you are done, because leaving it running all day drains the battery and invites attempts to connect. Note that some plans set conditions on hotspot use, decided by the seller and that specific plan, so check the details before making one phone the whole group's connection.
If you already did something on a network you now doubt
The useful response is not retrospective worry but closing the door quickly, in order of consequence. Start with the account that would hurt most, work downwards, and do all of it on a network you trust — your own data or your home network — rather than the one that worried you in the first place. If you did install a certificate or profile, remove it through the device's settings, where that menu lives differing by manufacturer and OS version.
- Change your main email password first, because it is the key to everything else
- Change anything financial next
- Sign out of all devices where the service offers that option
- Review the account's device list for anything that is not yours
- Remove any certificate or profile you installed
- Forget that network so the device cannot rejoin it automatically
- Check bank activity again the following day to be sure
Before you fly home, clear what the device remembered
When a trip ends, the device usually holds a list of every network it met along the way: airports, hotels, restaurants, trains. The list is not dangerous in itself, but it makes the phone try to rejoin anything with a matching name in future, which may not be the same network at all. Spending two minutes deleting the ones you will not use again is as good a habit as unpacking. And if you switched anything on for the trip — laptop file sharing, a hotspot — this is the moment to confirm it went back off.
If you are still unsure, ask us
Security has edges that cannot be reduced to fixed rules, because they depend on the device, the operating system and the country you are in. If you meet a screen you are unsure about, take a screenshot and send it to us on LINE at https://lin.ee/skDPoNx (@esimonline), by email at esimonline.asia@gmail.com, or by phone at 089-942-0818 / 088-521-6848, any time of day. A single screenshot usually says more than a long description and lets the first reply be a useful one. While you wait, the safe move is to type nothing into the page you doubt.
Časté dotazy
With an eSIM, do I still need public Wi-Fi?+
It still helps, especially for large downloads and photo backup, keeping your plan's allowance for time outside.
Should I use a VPN on public Wi-Fi?+
It reduces what the network owner can see but does not remove every risk, and some countries regulate VPN use, so check local rules first.
Is it risky to join airport Wi-Fi briefly just to check a flight?+
Reading public information such as a flight status is low-risk use. What deserves care is not the reading but the join page, which may ask for more than it needs, and the chance that you drift into something else — opening a banking app because a notification happened to arrive. Checking a flight is fine. If you already have your own data, using it settles the question faster.
With an eSIM, do I need to touch public Wi-Fi at all?+
It still helps in some cases, particularly large downloads, bulk photo uploads and heavy app updates. Putting those on Wi-Fi preserves your allowance for time spent outside, which is when you actually need it. A good division is volume on Wi-Fi and privacy on your own data.
Is a password-protected network safer than an open one?+
It is better in that it keeps passers-by out, but a password given to every guest does not separate you from the other guests, and it says nothing about who runs the network. The safer habit is to divide tasks by consequence regardless of whether there is a password, keeping anything that touches an important account on your own data.
Do I need to buy a VPN before travelling?+
Not for everybody. It reduces what a network owner can see, but it does not address the main risk, which is you entering details into a page that is not genuine. If you prepare accounts at home, turn on two-step verification and keep sensitive work on your own data, you already have most of the benefit. You also need to check the destination's own rules on VPN use, which differ from place to place.
What if I already accepted a network's request to install a profile?+
Remove it from the device's settings, where that menu lives differs by manufacturer and OS version, then forget the network. Change the passwords of your important accounts from a network you trust, such as your own data or your home connection. If you are not sure what was installed, screenshot it and ask us before deleting.
Is it all right for a child to use public Wi-Fi?+
Yes, provided that device carries no accounts touching money or the family's main email, and automatic joining is turned off. Better than forbidding it is arranging that the child does not need somebody else's network: download content in advance, or share a hotspot from a parent's phone when needed, because children rarely notice what a pop-up page is asking for.
Instagram and TikTok have no web share button, so we open your phone's share sheet or copy the link instead.