← All articles
Security

VPN on public Wi-Fi: what it protects you from, and what it does not

The real risks of open networks in cafés, hotels and airports — fake hotspots, DNS hijacking, captive portals — and an honest look at what a VPN covers.

October 1, 2026 · 2 min read

Today almost every site uses HTTPS, so the classic "hacker in the café reads your passwords" scenario is rarer. But open Wi-Fi still gives the network owner and your neighbours far more opportunities than your home network does.

Risks that remain with HTTPS

  • Fake hotspots (evil twin). An attacker creates a network with the same name as the café's. A phone that "remembers" the network joins it by itself.
  • Metadata. HTTPS encrypts content, but DNS queries (often unencrypted) and site names in the TLS handshake are visible to the network owner: they know which sites you visit and when.
  • DNS spoofing. The network can answer DNS queries with false addresses and lead you to a phishing copy of a site. HTTPS usually catches this, but not every app checks certificates strictly.
  • Unencrypted apps. Old apps and devices still send data over HTTP.
  • Attacks on devices in the same network. On an open network your laptop is visible to others; vulnerable services can become targets.

What a VPN does

A VPN builds an encrypted tunnel from your device to the VPN server. To the café's network, all your traffic — DNS included — looks like one encrypted connection. The network owner cannot see which sites you open and cannot tamper with the answers.

In Colitu the tunnel is protected by TLS 1.3 (Hysteria2, VLESS Reality, Trojan) or by Shadowsocks 2022's AEAD encryption. Details on the security page.

What a VPN does not do

  • It does not protect you from phishing if you type your password into a fake site yourself.
  • It does not remove malware or protect a device that is already compromised.
  • It does not make you anonymous to sites where you are signed in.

The right order of steps

  1. Join the Wi-Fi and complete the network's sign-in page (captive portal) if there is one. The VPN cannot connect before that.
  2. Turn on the VPN straight away, and only then open your mail and messengers.
  3. On Android, turn on Always-on VPN and Block connections without VPN; on Windows, the kill switch.
  4. Turn off auto-join for open networks and forget saved networks you no longer use.
  5. Turn off file and printer sharing on public networks (Windows offers the "Public network" profile for this).

Check it

Open What is my IP: with the VPN on, the page shows a Colitu server's address instead of the café's.