Hotel and airport Wi-Fi: is it safe?
FortiSafe team ·
Today, using public Wi-Fi is usually safe for most websites, because they already encrypt the connection (HTTPS). The risks that remain are different: a fake network with a similar name, a fake site that also shows the padlock, and apps that don't encrypt what they send. A VPN adds a layer: it hides where you're going from the network and protects the path to the server, but it doesn't spot fake sites or scams.
The risks that remain, and what fixes them
| Risk | What fixes it | What a VPN doesn't fix |
|---|---|---|
| A fake network named after the hotel or airport | Check the exact network name with the hotel. With a VPN, whoever runs the network only sees an encrypted connection to the server. | If you type a password into a fake site, a VPN won't stop it. |
| A fake site with a padlock | Check the address before typing a password or personal details. The padlock means the connection is encrypted, not that the site is honest. | A VPN doesn't spot fake sites. |
| The network sees the addresses you visit | With a VPN, the hotel network only sees the connection to the VPN server. | The VPN company sees them instead, which is why what it logs matters. |
| An app or site without HTTPS | With a VPN, the path between your device and the server stays encrypted. | From the server to the destination, anything without HTTPS is still unencrypted. |
What changed: most websites are already encrypted
The FTC, the US consumer protection agency, says that because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe. It also warns that scammers create encrypted fake sites too, so your data arrives protected, but in the scammer's hands.
From 30 August to 12 September 2026, about 84% of pages opened in desktop Firefox used HTTPS, worldwide and in Brazil alike, according to the telemetry data published by Let's Encrypt.
The hotel login page
Many hotel and airport networks open a login page before letting you online. The NCSC, the UK's cyber security centre, notes that a forced VPN can be incompatible with these pages.
So: join the network, sign in on the hotel's page and only then turn on the VPN.
What about FortiSafe?
FortiSafe uses WireGuard, with 82 servers in 45 countries.
Automatic connection on open Wi-Fi is in development, as is the kill switch, which blocks the internet if the VPN drops.
What we keep, for how long and what we don't log is on our What we log page.
Sales and apps coming soon.
At the hotel or airport
- Ask the hotel, or check the official notice, for the exact network name.
- Check the site's address before typing a password or card details.
- Update your system and apps before you travel.
- Turn off automatic joining of open networks you don't know.
- For anything that needs extra care, use your mobile data if you prefer.
Sources
Pages checked on 13 September 2026.
- FTC — Are public Wi-Fi networks safe? — Public Wi-Fi is usually safe because websites encrypt; scammers also encrypt fake sites.
- Let's Encrypt — statistics — Firefox telemetry on pages loaded over HTTPS; 14-day weighted average calculated by the FortiSafe team from the published data.
- NCSC (UK) — virtual private networks guidance — A forced VPN can be incompatible with public Wi-Fi login pages.