Public WiFi in 2026 serves as the the WiFi the typical knowledge worker uses in the coffee shop, the airport, the hotel, the conference, the home of the friend. The privacy of the public WiFi in 2026 amounts to the privacy of a network the user does not control, the user does not trust, the user does not know. The 2026 honest guide covers what the public WiFi sees, what the public WiFi does not see, and what the user should actually do.
The 2024 CISA guidance, the 2025 NSA guidance, the 2026 FCC guidance all recommend the VPN on the public WiFi. The 2026 state of the public WiFi amounts to a state where the WiFi the typical user uses has the encryption (the WPA3), but the WiFi the typical user uses also has the operator (the coffee shop, the airport, the hotel) who can log the DNS, who can inject the ads, who can throttle the traffic, who can see the metadata. The encryption protects the content, the operator sees the destination. The user that does not use the VPN. the the user that has the destination exposed.
What the public WiFi sees
Three things, in roughly that order of how much they reveal. The first runs as the DNS queries category, where the public WiFi operator (or anyone on the same network with the packet capture) can see the DNS queries the device makes, the DNS queries reveal the domains the user visits, the domains reveal the services the user uses. The second runs as the IP address category, where the public WiFi operator can see the IP addresses the device connects to, the IP addresses reveal the services the user uses (even if the DNS is encrypted, the IP still leaks), the IP addresses allow the operator to correlate the activity. The third runs as the timing category, where the public WiFi operator can see the timing of the connections, the timing reveals the activity pattern, the timing allows the operator to correlate the user across the visits. The three things together allow the public WiFi operator to build the profile of the user that the encryption does not protect.
What the public WiFi does not see
Three things, in roughly that order of how much they matter. The first runs as the content category, where the WPA3 encryption (and the HTTPS, the TLS 1.3) does protect the content of the communication, the operator cannot read the email, the operator cannot read the chat, the operator cannot read the document the user downloads. The second runs as the password category, where the encryption does protect the password the user enters, the operator cannot capture the password through the network. The third runs as the form submission category, where the encryption does protect the form data the user submits, the operator cannot see what the user entered into the form. The three things together sit as the things the encryption does protect, the things the user can do safely on the public WiFi without the VPN. The three things together do not cover the metadata the operator does see.
What to actually do
Three moves if you are using the public WiFi in 2026. Use the VPN, because the VPN encrypts the DNS, the VPN hides the IP, the VPN obscures the timing, the VPN amounts to the protection the WPA3 does not provide. The user that uses the VPN on the public WiFi is what the user that has the destination hidden, the content protected, the activity uncorrelated. Use the HTTPS everywhere, because the HTTPS (and the HTTP Strict Transport Security) protects the content even on the untrusted network, the user that has the HTTPS enabled , the the user that has the content protected. Disable the auto connect, because the device that auto connects to the open WiFi is essentially the the device that has already connected before the user notices, the device has already exposed the metadata. The user that disables the auto connect is, in practice, the the user that controls the connection. The user that uses the VPN, uses the HTTPS, and disables the auto connect stands as the real the user that has the privacy on the public WiFi in 2026.

The bottom line
Public WiFi privacy in 2026 amounts to the privacy of a network the user does not control. The three things the network sees (DNS, IP, timing) reveal the activity even when the content sits protected. The three things the user should do (use the VPN, use the HTTPS, disable the auto connect) amount to the protection the user can apply. The user that does the three things counts as the first the user that has the privacy on the public WiFi.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



