How to use hotel public Wi-Fi more safely
Verify the network, protect your accounts and understand a VPN's role without expecting complete protection.

Three networks appear on your phone in a hotel lobby. One uses the hotel's name, another adds “Guest,” and a third promises a fast connection. A password printed at the desk may seem to settle which one is genuine. It does not: a network name can be copied. Before opening work email or banking, ask staff for the exact network name and how sign-in works.
That does not make every public Wi-Fi network a trap. The US Federal Trade Commission says widespread web encryption has made public Wi-Fi safer. HTTPS encrypts the connection to a site. Yet the padlock does not prove the site is genuine; a fraudulent page can use HTTPS too. For a traveler, the problem is not always someone “reading” all their traffic. It may be joining an imitation network, following a phishing link or handing over a login code.
The first defense comes before you connect
Confirm the network with reception through a channel you control. If the hotel uses a welcome page, enter only the information staff say is needed for that step. A page demanding that you install software, give your email password or pay for the room again calls for a pause. Ask before proceeding. A captive portal is a gate to the network, not a reason to disclose unrelated credentials.
If you have the option, use mobile data for a particularly sensitive task when the hotel's connection is unreliable or its portal seems suspect. That is a practical alternative, not a rule against reading the news over Wi-Fi. On any connection, type the bank or service's address yourself instead of following an unexpected link. HTTPS protects communication with the site you reached; it does not correct a mistaken identity.
Accounts matter more than one app
An outdated phone and a reused password can compromise an account even on a genuine network. Update the device before leaving and enable extra verification for email and other important services. CISA recommends multifactor authentication because it adds a barrier when a password is stolen. Use distinct passwords; a manager can help you keep them without repetition.
Do not give a login code to a call or page you did not expect. If an email says you must urgently sign in, open the app or website independently. A password manager can help by matching a password to the right address, but it is no substitute for judgment or multifactor authentication.
A VPN protects one link, not every risk
A VPN encrypts the connection between your device and the VPN server, making that leg harder for someone on the hotel network to inspect. It also moves some trust to the VPN provider. The FTC cautions VPN shoppers that some apps request excessive permissions, may share data and do not make users anonymous. A destination site can still see information you provide, and a phishing link remains a phishing link.
If you already use a VPN you trust, check that it actually shows a connection before a sensitive task. Some products offer a “kill switch” to cut traffic if the tunnel drops. NordVPN describes its implementation, whose behavior depends on the operating system. That is a manufacturer description, not an independent test proving that every leak is impossible.
Hotels create a particular snag: the captive portal may prevent a VPN from completing its connection. If that happens, verify the network, complete only the hotel's official sign-in, then check the VPN again. NordVPN provides instructions for this situation. If the portal asks for unrelated information, stop and ask reception rather than changing settings blindly.
When you leave, sign out of shared devices and stop your device automatically rejoining a network you no longer need. Most phones let you forget that network or turn off automatic joining. This reduces the chance of the device looking for a network with the same name later.
This publication carries commercial links to NordPass, a password manager, and NordVPN. We may receive a commission on purchases made through them. The advice to identify the network, protect your accounts and recognize fake sites works without buying either product. Check current prices, device support, privacy policy and terms before deciding.
There is no magic security switch. Safety is a sequence: join the right network, reach the right site, protect the account and understand which part of the connection each tool covers.



