How these networks differ from home
- Many unknown devices share the segment. You cannot tell who else is connected or what their devices are doing.
- The name is not proof of the network. Anyone can broadcast "Hotel_Guest_WiFi" from a device in the lobby.
- Captive portals intercept traffic by design. That is normal, but it also normalises the certificate warnings you should not ignore.
- Maintenance varies widely. Equipment may be years old and managed by a third party.
Before you leave home
- Update the operating system, browser and apps while on a trusted connection.
- Turn on full-disk encryption and a short auto-lock timeout.
- Install and test an encrypted-connection tool on every device, with the kill switch enabled.
- Enable two-factor authentication on email, banking and cloud storage; prefer an authenticator app or hardware key over SMS while roaming.
- Disable automatic joining of open networks, and turn off unused sharing.
At the airport
- Confirm the official network name on airport signage, not from the list alone.
- Prefer your own mobile hotspot for short, sensitive tasks — it is often the simplest answer.
- Complete the portal sign-in, then connect the VPN before opening work tools.
- Use a privacy screen; lounges and gates are dense with cameras and shoulders.
- Avoid unknown public USB ports for charging — carry your own plug or a power-only cable.
At the hotel
- Ask reception for the exact network name and, where offered, request the per-room or per-guest password rather than an open network.
- Mark the network as public so file and printer sharing stay off.
- Keep the VPN always on for the stay; hotel signal drops are common and a kill switch keeps traffic from slipping out.
- Do not sign in to personal accounts on the business-centre computer or the room's smart TV.
- Treat unexpected "update required" or certificate prompts as a reason to stop, not a box to click.
A five-minute routine on arrival
- Join the venue network and finish the portal sign-in.
- Connect the VPN and confirm it reports an active tunnel.
- Check that sharing, AirDrop-style features and Bluetooth are off if unused.
- Open only the tools you need; leave high-value actions for later if they can wait.
- When you leave, forget the network so devices do not rejoin a look-alike later.
What this routine does not solve
Encrypting the connection does nothing about phishing emails, malware you install, a laptop left in a taxi, or a password reused across services. The network layer is one part; account hygiene and device settings carry the rest. Our public Wi-Fi guide covers account habits in more depth, and the VPN guide sets out the boundaries of what a tunnel can do.
FAQ
Is hotel Wi-Fi safe for online banking?
It can be acceptable with an encrypted connection and two-factor authentication in place, but if a transfer or password change can wait until you are on a connection you trust, wait.
Why does my VPN block the hotel login page?
Captive portals must load before the tunnel is established. Connect to the network, complete the portal sign-in, then enable the VPN before doing anything sensitive.
Should I use the hotel business-centre computer?
Avoid signing in to personal accounts on shared computers. If you must, use a private window, never save credentials, sign out fully, and change that password afterwards.
Encrypt the connection first
See the privacy solution we selected for hotel and airport networks.