Coffee shop wifi, airport lounges, and hotel networks are where most remote work actually happens between destinations, and they’re also where most of the damage gets done. This guide covers the specific settings, tools, and habits that keep your accounts and client data safe when you’re logged into a network you don’t control, and what to reach for instead of public wifi when the work can’t wait.
Before you connect, question the network itself
The biggest risk on public wifi isn’t the legitimate network, it’s the fake one sitting next to it. An “evil twin” attack is when someone sets up a hotspot with the exact same name as the real one, often broadcasting at a stronger signal so your device prefers it automatically. Once you’re on it, every unencrypted request you make can be read, and in more advanced setups, HTTPS itself gets stripped so what should be a secure connection isn’t. Setting up an evil twin takes nothing more than consumer hardware and free software, which is exactly why it’s so common in airports and hotel lobbies.
- Ask staff for the exact network name before connecting, don’t just tap the strongest signal or the most obvious name.
- Turn off auto-join for wifi networks. Both iPhone and Android let known or open networks reconnect automatically in the background, which is how you end up on a spoofed network without noticing.
- Turn off Bluetooth and AirDrop or Nearby Share when you’re not actively using them. Bluetooth-based attacks can take control of a device with no interaction from the user at all.
Skipping this step is how a 25-minute layover turns into a compromised laptop before you’ve even opened your email.

Put a VPN between you and the network
A VPN encrypts your traffic before it leaves your device, so even if someone is sitting on the same network capturing packets, what they get is unreadable. This is the single highest-impact habit on this list, and it costs less than a coffee a month if you buy an annual plan instead of paying month to month.
- NordVPN: around $3.49/month on a 2-year plan, 9,000+ servers across 167 countries, independently audited no-logs policy (fifth audit completed in late 2024).
- ExpressVPN: around $3.49/month on a 24-month plan, 3,000+ servers in 113 countries, the most heavily audited of the major providers at 23 audits to date.
- Surfshark: around $2.49/month on a 2-year plan, unlimited connected devices on one account, which matters if you’re traveling with a phone, laptop, and tablet.
Pick one with a kill switch, a setting that cuts your internet entirely if the VPN connection drops, so you never fall back to an unprotected connection mid-session without realizing it. Turn it on in settings, it isn’t always the default.

Lock accounts down with something better than SMS
A VPN protects the connection. It doesn’t help if someone gets into your accounts a different way, and the weak point for most people is still the login itself. If you’re on any two-factor authentication that texts you a code, that’s worth fixing before your next trip.
- Switch from SMS to an authenticator app. SMS codes travel over SS7, a signaling protocol from the 1970s with no built-in encryption, and are vulnerable to SIM-swap fraud, where someone convinces your carrier to move your number to their SIM. The FBI logged over 2,000 SIM-swap complaints in 2023 alone, with losses exceeding $72 million.
- Use Aegis, 2FAS, or Authy for authenticator codes. Aegis and 2FAS are open-source with local encrypted backups, Authy syncs across devices if you want a cloud backup option.
- Run a password manager. Bitwarden’s free tier covers unlimited passwords across unlimited devices, and Premium is $1.65/month if you want the built-in authenticator and encrypted file storage bundled in.
- Save backup codes offline for every account you enable 2FA on, so a lost or stolen phone abroad doesn’t lock you out of your own accounts.
None of this stops an evil twin from existing, but it means that even a captured password isn’t enough to get someone into your accounts.
Skip public wifi entirely when the work matters
For anything sensitive, the safest move is not connecting to public wifi at all. This is more realistic while traveling than it used to be.
- A local eSIM installs in minutes and gives you your own encrypted mobile data connection instead of a shared network. Airalo plans start around £3.50 (roughly $4.50) for a week of data in many regions, cheaper than most portable wifi rentals.
- Use your phone’s hotspot for your laptop when you need real work done, rather than the hotel or cafe network, especially for anything involving banking, client invoicing, or company logins.
- Save public wifi for low-stakes browsing, maps, reading, anything that doesn’t touch a password or payment method.
The instinct to save mobile data by hopping on every free network you see is understandable, but a week of eSIM data usually costs less than a single client email getting intercepted.

The mistake almost everyone makes: trusting the padlock icon
Seeing “https://” and a padlock in the address bar feels like a green light, and most people treat it as one. It confirms the connection between your browser and that specific site is encrypted, it says nothing about the network you’re on. On a compromised hotspot, an attacker can still redirect you to a fake login page that also shows a padlock, because the fake page has its own valid certificate too. The padlock protects the pipe, not the destination. Combine it with the habits above rather than treating it as proof a network or page is safe.
Working from public wifi is unavoidable some of the time, that’s part of the job. Between a VPN running in the background, an authenticator app instead of SMS, and an eSIM in your back pocket for anything that actually matters, none of it needs to slow you down or cost more than a few dollars a month. Wherever your next stretch of work takes you, search flights on FlyBibe and get moving with your setup already locked down.

