Is it safe to use public Wi-Fi on an Android phone?
Updated
Mostly, yes. HTTPS already encrypts what you type on most sites, so nobody on the café Wi-Fi can read your passwords or messages. The network can still see which sites and apps you use, and fake hotspots can trick you with lookalike login pages. A VPN hides your traffic from the network; a few Android settings close the rest.
"Never use public Wi-Fi" was good advice in 2012, when most websites sent everything in plain text. It isn't anymore. Today almost every app and website encrypts its traffic, and Android has quietly added protections of its own. But "safe" isn't the same as "private", and a few real risks remain. This guide separates the two, so you know what to actually do on café, hotel, airport and train Wi-Fi.
What public Wi-Fi can and can't see
Assume the person running the network, or anyone who set up a hotspot nearby, can watch everything that passes through it. Here is what that gets them:
| Without a VPN | With a VPN | |
|---|---|---|
| Passwords, messages, card numbers on HTTPS sites and apps | Encrypted, not readable | Encrypted, not readable |
| Which websites and services you connect to (domain names) | Visible | Hidden |
| Which apps on your phone are online, and when | Visible | Hidden |
| Pages that still use plain HTTP | Readable and changeable | Encrypted to the VPN server |
| Your real IP address, as seen by websites | The hotspot's address | The VPN server's address |
So the main thing public Wi-Fi exposes today is metadata: a list of where you go and when. That's enough to build a profile of you, and some hotspots do exactly that to sell ads.
The risks that are still real
Fake hotspots ("evil twins")
Anyone can create a network called Airport_Free_WiFi or copy the name of the café you're sitting in. Your phone may even join it automatically if you've used a network with that name before. Once you're on it, the attacker controls your DNS and can show you a convincing login page.
Login pages that ask for too much
Real Wi-Fi login pages ask you to accept terms, maybe enter a room number or an email. Be suspicious of any Wi-Fi page that asks for your Google or Apple password, or card details. HTTPS can't help if you type them into the attacker's page yourself.
Old or careless apps
Android blocks unencrypted traffic by default for apps built in the last several years, but older apps and some smart-home or media apps still send data in the clear. On an open network, that data is readable.
Other devices on the same network
On a shared network, other people's devices can see yours and try to connect to it. Modern Android exposes very little, but it's one more reason not to treat public Wi-Fi like home.
A 2-minute checklist for Android
- Check the network name with staff or on a sign before joining. If two networks have nearly the same name, ask which one is real.
- Don't type account passwords or card details into a Wi-Fi login page. Close it and use mobile data if it insists.
- Turn off auto-connect for public networks: Settings → Network & internet → Internet → tap the network → turn off Auto-connect. Or Forget the network when you leave.
- Keep MAC randomisation on. Android 10 and later use a random hardware address per network by default (network details → Privacy → Use randomized MAC), so hotspots can't track your phone from place to place.
- Set Private DNS to a provider (Settings → Network & internet → Private DNS → Private DNS provider hostname, for example
dns.google). Your DNS lookups are then always encrypted, which hides some of the domain names from the network. Automatic encrypts only when the network's own DNS supports it. - Notice open networks. A network without a lock icon in the Wi-Fi list has no encryption at all. Networks with a password (WPA2, WPA3) or "Enhanced Open" encrypt the radio link, which helps against people sitting nearby, but not against the network owner.
- Use a VPN on networks you don't control. It hides all of the metadata in the table above and protects the leftover plain-text traffic.
What a VPN does and doesn't do on public Wi-Fi
A VPN encrypts everything between your phone and the VPN server, including DNS lookups and the names of the sites you visit. The hotspot only sees encrypted traffic to one server. That covers the metadata problem, old apps, and DNS tricks on fake hotspots.
It doesn't stop you from typing a password into a phishing page, it doesn't remove malware, and it moves trust from the hotspot to the VPN provider. Pick one with a clear no-logs policy and a business model you understand. Our free vs paid VPN guide explains what to look for.
Two practical notes:
- Sign in to the Wi-Fi first, then connect the VPN. The login page has to load outside the VPN. If you use Android's kill switch, see Always-on VPN on Android for how to handle login pages.
- Some hotel and office networks block VPNs. If yours won't connect, this guide explains why and which protocol still works.
How SimpleV fits
SimpleV VPN for Android is built for exactly this: tap once on unfamiliar Wi-Fi and you're covered.
- Free: 500 MB every day with no account. That's plenty for messaging, maps, email and browsing on a café or airport network. See how much data a VPN uses.
- No traffic logs. We don't record the sites you visit or the content of your traffic.
- Auto mode uses WireGuard, and switches to VLESS with Reality on port 443 when a hotel or office network blocks VPNs.
- Always-on support, so the VPN reconnects by itself when you join a new network.
- Premium removes the daily limit and opens 33 locations in 20 countries.
FAQ
Can someone on the same Wi-Fi see my passwords?
Not on HTTPS websites and modern apps, which covers almost everything you use. They can see which sites and apps you connect to, unless you use a VPN. The real danger is typing a password into a fake page yourself.
Is hotel Wi-Fi safer than café Wi-Fi?
Not really. A password on the network encrypts the radio link, but everyone who has the password, and the hotel itself, is still on the same network. Treat both as public.
Do I need a VPN if a site uses HTTPS?
HTTPS protects what you send to that site. A VPN additionally hides which sites you visit, protects apps that don't use HTTPS, and keeps your real IP address from websites. On public Wi-Fi, it's worth having.
Is mobile data safer than public Wi-Fi?
Generally yes. Mobile networks encrypt the connection between your phone and the tower, and nobody at the next table can set up a fake one easily. Your carrier can still see which sites you visit.
Should I turn off Wi-Fi when I'm out?
You don't have to, but turning off auto-connect for public networks stops your phone from joining fake hotspots that copy the names of networks you used before.