How it works
Public Wi-Fi risk concerns the trust and configuration of a network shared with unfamiliar users. Modern encrypted services protect much ordinary traffic even on a public network. The useful question is which parts are protected and what the user is being asked to trust, rather than assuming every hotspot can read every password.
A practical example
A café network can provide access to the genuine HTTPS site while its sign-in portal requests acceptance of network terms. A separate lookalike network might display a deceptive page asking for unrelated account details. The network name alone does not identify its operator or authenticate a website.
What to check
Confirm the intended network with the venue and use genuine apps or independently known HTTPS addresses. Do not ignore certificate warnings or install a certificate from an unexpected portal. Use the public-network profile where applicable and review unnecessary device sharing. A managed work device should follow its organization’s connection policy.
Limits and safe use
HTTPS does not make a fraudulent destination honest, and a VPN does not protect against giving information voluntarily to a scam page. Connecting alone does not prove compromise. If the portal asks for unrelated sensitive data or the identity cannot be confirmed, stop and choose a trusted alternative connection. Keep software updated and disable unnecessary automatic reconnection.