Many people think a VPN is only needed where something is blocked — in Russia, China, Iran. That's a common misconception. Protection is also needed in countries with a completely free internet — when connecting to public Wi-Fi networks. The coffee machine in a café, a terminal in an airport, a free hotspot in a hotel, a network in a shopping mall — in each of these places your data can be intercepted with no censorship at all.
In this article we'll break down how the risks of public networks work, what scenarios attackers use and why a VPN solves the problem regardless of the country you're in.
Why public Wi-Fi is dangerous by nature
A public access point is an open network that anyone can connect to: other visitors, the venue owner and an attacker nearby alike. A Wi-Fi radio signal isn't confined to the café walls — it's picked up on the street, on the floor above, in a parked car across the road.
The main problem is that you don't control the network. You don't know who administers it, whether someone keeps a connection log, or whether your ISP is swapping out the network. On your home network you can set up encryption and be sure that only you and your household are connected to it. In a café — you can't. Traffic goes through a router that belongs to someone else, and that "someone" is physically able to read it.
Censorship blocks access to resources — that's unpleasant but predictable. Public Wi-Fi can steal your data — passwords, correspondence, banking details. The first is a restriction, the second is a direct threat to your money and privacy.
What data can be intercepted
If you've connected to a foreign network without protection, everything that goes over the internet is at risk:
- Passwords to email, social networks, messengers — if the website or app doesn't use encryption.
- Banking data — card numbers, online banking logins and passwords when entering through an unencrypted channel.
- Personal correspondence and photos — everything you send through apps without encryption.
- Browsing history — DNS requests show which websites you open, even if the sites themselves use HTTPS.
- Files and documents — if you download or upload something over open protocols.
Attack scenarios: how it happens in practice
An attacker doesn't need sophisticated tools. Most attacks on public networks are carried out with programs available to anyone in a couple of minutes. Here are the main scenarios.
1. Traffic interception (sniffing)
The simplest and most common scenario. The attacker connects to the same open network as you and runs a sniffer — a program that "listens" to all traffic in range. On an unencrypted network they see your requests almost as clearly as if you were working at their computer.
In the past, literally everything was intercepted this way: passwords, logins, page contents. Now that most websites have moved to HTTPS, "bare" interception works less often, but it's still dangerous — especially for old websites, apps and devices that don't use encryption.
2. Fake access point (evil twin)
The attacker creates their own network with the same name as the legitimate one — for example, "Cafe_Free_WiFi". Devices often connect automatically to the access point with the stronger signal, and you won't even notice you're working through the attacker's router. All information — passwords, correspondence, files — goes through their equipment in plain text.
This scenario is especially dangerous in airports, hotels and train stations, where people are in a hurry and connect to the first network with a fitting name.
3. Fake bait page (captive portal)
When connecting to public Wi-Fi, an authorization page often appears: "Enter your phone number for access" or "Enter your email". The attacker can replace this page with their own version — with a field for entering your card number, "paying" for an hour of internet or logging into your email. You enter the data, the network "doesn't work", and your details are already in the attacker's hands.
4. Session hijacking
Even if you logged into a website over a secure connection, after login the server issues you a session token — a "pass" that confirms you're authorized. On a public network this token can be intercepted. With it, the attacker enters your account without a password — and you only find out when you notice something odd.
5. Interception via certificate substitution (Man-in-the-Middle)
In an active "man-in-the-middle" attack, the attacker positions themselves between you and the website. They substitute certificates, redirect requests to fake versions of pages and collect everything you enter. The user thinks they're working with the real bank website, when in fact they're on a copy created by the attacker.
HTTPS encrypts traffic between your browser and the website, but it's not that simple. DNS requests often remain visible, TLS can be "downgraded" to an old version, and some traffic goes without encryption entirely. More reliable than relying on HTTPS on each individual website is to encrypt the whole channel at once. That's exactly what a VPN does.
Real negative scenarios
Attacks on public networks aren't theory from textbooks. Here are typical stories that happen all the time.
Scenario A: a café in a business district. A freelancer works in a coffee shop, connects to a free network and checks email. The email password goes out in plain text (an old mail client without TLS). Within an hour, spam is being sent from their account and emails are being read. Access can be restored, but the correspondence is already compromised.
Scenario B: an airport. A traveler connects to the network "Airport_Free_WiFi_5G" — a fake copy of the real one. On the authorization page they're asked to "confirm their email". The email login and password go to the attacker. A week later they discover that the email password is the same as for other services, and all of them have been hacked.
Scenario C: a hotel. A guest goes online through the hotel network and pays for something with a card, not noticing that the payment page has no HTTPS. The card data is intercepted. A few days later — charges the bank reports by notification.
In all three cases, no country blocked access to resources. The problem was only that the connection went through an unsecured public network.
How a VPN solves the problem
A VPN creates an encrypted tunnel between your device and the VPN server. All your traffic — HTTP and HTTPS, DNS requests, and app traffic alike — is packed into a single encrypted stream and transmitted inside it.
What this gives you in practice in a café or airport:
- No one sees the content. Even if an attacker is listening to the network, they only see an encrypted stream. It's impossible to decipher.
- DNS is hidden. Requests for which websites you open go inside the tunnel — the network owner and the attacker can't see them.
- Evil twin is useless. Even if you end up on a fake access point, the attacker will only get encrypted noise, not your data.
- Session hijacking is impossible. The authorization token is transmitted inside the encrypted channel and is invisible from outside.
- Unencrypted websites are protected. A VPN also encrypts traffic that would otherwise go in plain text.
An open network without a VPN is like a conversation on speakerphone in a crowded hall. With a VPN you talk into an encrypted handset that no one can hear. The difference between these two situations — is the difference between risk and protection.
What else to remember about public networks
A VPN solves the main task — encrypting the channel — but doesn't cancel common sense. A few additional rules:
- Check the website address. Even with a VPN, make sure HTTPS is in the address bar and the domain is spelled without errors (not "go0gle.com" instead of "google.com").
- Don't enter banking details on networks you don't trust. Plan financial operations at home or over mobile internet.
- Turn off auto-connect to Wi-Fi. In your phone's settings, disable automatic connection to open networks — this reduces the risk of landing in an evil twin.
- Turn on VPN automatically. In the AmneziaWG app you can set up auto-connect when entering networks. Then protection works even if you forgot to turn it on manually.
- Use two-factor authentication. Even if a password is stolen, the second factor will stop the attacker.
- Prefer mobile internet for important things. A cellular network with encryption (4G/5G) is often safer than open Wi-Fi, especially for banking.
Summary
You need a VPN not only where there's censorship. Public Wi-Fi — in a café, airport, hotel, transport — is a high-risk zone in any country in the world. Password interception, fake access points, session hijacking, fake authorization pages — all of this works regardless of the state and its policies.
Plan B is suitable for this task too: the AmneziaWG protocol encrypts all traffic up to the server, and plans start from 49 rubles per month. One subscription works on all your devices — turn on the VPN whenever you connect to any unfamiliar network, and public Wi-Fi will stop being a threat.
Related articles: "Why free VPNs are dangerous", "Online security: 7 habits" and "How to choose a VPN in 2026".