"Public WiFi in Australia: a practical safety guide for travellers"
Public WiFi in Australia: a practical safety guide for travellers
Airports, hotels, cafes and conference centres all offer the same bargain: free connectivity in exchange for joining a network you control nothing about. For most of the last decade the received wisdom oscillated between "public WiFi is fine now, everything is HTTPS" and "never touch it". The truth sits in the middle, and it is navigable with a modest set of habits and about A$40 of hardware. This guide covers what actually threatens you on shared networks in Australia, what the national cyber security centre recommends, and the gear that closes the last gaps. This is practical security guidance, not legal advice, and it is written for lawful everyday use: protecting your own data, not testing other people's networks.
The ACSC baseline
Australia's Cyber Security Centre (ACSC, part of the Australian Signals Directorate) maintains public guidance on this exact scenario, and it is more measured than the alarmist version. The ACSC guidance on connecting to public WiFi and hotspots centres on checking that the webpages you visit are secure and what you expect, and is blunt about browser warnings: if your browser displays a warning message when you try to visit a website, do not continue — stop using the hotspot, disconnect, and forget the network on your device. Its broader device guidance applies anywhere: do not leave devices unlocked and unattended, secure accounts with multi-factor authentication and passphrases, keep backups, and run current device security software.
For travellers specifically, the ACSC security tips for travelling go a step further on shared networks: if you are working in public spaces such as an airport or cafe, avoid their WiFi or use a VPN. That single sentence is the spine of this article.
What the threats actually are
Evil twin access points. The highest-value attack on public WiFi is the fake hotspot: an attacker broadcasts a network with the same or near-identical name as the legitimate one — same SSID, often the same open-no-password setup — and lets your device auto-connect to whichever signal is stronger. From there the attacker relays your traffic and can see everything that is not encrypted, run fake captive portals to harvest credentials, or strip encryption in older scenarios. The mechanics and defences are well documented in security-industry guidance: Bitdefender's guide to fake Wi-Fi and evil twin hotspots notes that public networks often use no password or easily guessed ones, that an evil twin matching the real network down to the password arouses little suspicion, and that a trustworthy VPN switched on before connecting is the primary mitigation. Security researchers have even catalogued the detection problem formally — MITRE's detection strategy for evil twin access points describes the network-level signals (same SSID with unexpected BSSID, inconsistent encryption settings, captive portal redirections) that enterprise gear watches for, none of which a laptop user can see directly.
Fake captive portals. Hospitality networks authenticate users through a captive portal — the redirect page where you accept terms or enter a room number. Attackers replicate them, and a convincing fake is a credential-harvesting page. Hospitality-sector guidance makes the failure modes concrete: Purple's guide to hotel WiFi risks describes the rogue access point problem in hotel lobbies, confirms that hotel DNS resolvers and traffic logs can show which domains you visit, and answers the question travellers actually ask — is hotel WiFi safe for banking — with a direct no, not without a VPN.
Passive observation. Even with no attacker present, you are on shared infrastructure. HTTPS covers most content in transit now, which is why the "it's all fine" camp has a point — but metadata (who you connect to, when, how much) remains visible to the network operator, and the operator on a public network is whoever set up the hotspot.
The habit stack, in order of value
- Turn on the VPN before you connect, not after. The order matters: a VPN that starts after you have joined a hostile network has already exposed your initial traffic, app background connections and captive-portal exchange. This is the ACSC's advice in practice and the single highest-value habit. Our honest guide to VPNs in Australia covers choosing one you can trust, and the same reasoning extends to Tor for higher-stakes browsing — see our Tor in Australia guide.
- Verify the network name with staff. Ask which SSID is real. It takes thirty seconds and defeats most casual evil-twin setups, which rely on travellers connecting by plausible name.
- Trust browser warnings unconditionally. A certificate warning on public WiFi is not a nuisance to click through; it is either an attacker or a misconfigured network, and both mean the same action: disconnect, forget the network.
- Treat captive portals with suspicion. Type slowly, check the URL, and never enter credentials there that you would not hand a stranger. If a portal asks for an email password, it is a fake.
- Avoid banking on shared networks entirely. With a VPN the risk drops sharply, but the ACSC pattern still applies: MFA on everything so a stolen credential is not a stolen account.
- Disable auto-connect. Devices that automatically join known network names are the reason evil twins work. Setting your phone to ask before joining is free and permanent.
The hardware layer
Software closes most of the gap; two small products close the rest, and both travel in a laptop bag without weight penalty:
A travel router. Join the untrusted network once, with a VPN running on the router itself, and then connect your phone and laptop to your own private hotspot instead of to the venue's network. Every device behind it gets the encrypted tunnel without per-device configuration, and your devices stop broadcasting probes for network names you have used before — which is exactly the signal evil twins exploit. Our OpenWrt travel router at A$32.24 is configured for this pattern: untrusted uplink on the WAN side, your own WPA2/3 hotspot on the LAN side, VPN client on the router. It is the single most effective piece of travel-privacy hardware because it turns "many devices on a hostile network" into "one hardened device on a hostile network".
A USB data blocker. Charging from airport and cafe USB ports exposes a port that carries both power and data; a charge-only cable or data blocker passes power and physically severs the data lines. The ACSC-adjacent travel advice includes using a data blocker when charging in public, and our USB-C data blocker at A$9.80 is the cheapest line item in the kit. Pair it with the broader charging discipline: never log into sensitive accounts on devices that are not yours, and sign out fully when you do.
The combined kit — travel router plus data blocker — costs about A$42 and covers the two physical attack surfaces a laptop bag faces in transit: the hostile radio network and the untrusted charge port.
A note on what not to fear
Balance matters. Millions of Australians use public WiFi daily without incident, and HTTPS-by-default has genuinely raised the floor: an opportunistic snooper on a cafe network sees far less in 2026 than a decade ago. The residual risks concentrate in three behaviours: connecting without a VPN, clicking through certificate warnings, and entering credentials into portals you did not initiate. Eliminate those three and you have removed the scenarios where real harm happens, at a cost of one habit and one small gadget. Fear is not the strategy; configuration is.
The takeaway
The ACSC's two sentences — check that pages are what you expect, and prefer a VPN on public networks — plus unconditional respect for browser warnings, plus a travel router that puts the encryption under your control, cover essentially every realistic public WiFi threat in Australia. Add a data blocker for shared charging and MFA everywhere as the backstop, and public WiFi becomes what it should be: convenient infrastructure you have already de-fanged.