Public WiFi and Kids: The Coffee Shop Network Is Dangerous
Table of Contents

Public WiFi and Kids: The Coffee Shop Network Is Dangerous

Public WiFi is far more dangerous than most parents realize—especially for kids. Learn what the real risks are, which habits protect against them, and when a VPN actually helps.

Your teenager settles into a coffee shop booth with their laptop, connects to the café’s free WiFi, and logs into their school account, Gmail, and maybe their bank’s mobile site to check their balance. To the teenager, this is normal. To someone on the same network with freely available software, it’s a potential interception opportunity. The Federal Trade Commission’s guidance on public WiFi notes that “information sent through most WiFi hotspots is not encrypted and can be intercepted.” A 2023 survey by NordVPN found that 62% of Americans use public WiFi regularly, yet fewer than 25% use any protective measures while doing so. Children and teens are among the most frequent users of public networks—in libraries, coffee shops, schools, hotels, and airports—and among the least likely to know how to protect themselves.

Key Takeaways

  • Public WiFi is an open network where other users on the same network can potentially intercept unencrypted traffic
  • The most dangerous activities on public WiFi are logging into accounts, entering payment information, and accessing sensitive school or medical portals
  • HTTPS (look for the padlock icon) encrypts your connection to individual websites—but doesn’t protect all network traffic
  • A VPN encrypts all traffic from your device before it hits the network, providing comprehensive protection on any network
  • Habits matter more than tools: teaching children when NOT to do sensitive tasks is as important as configuring protection

How Public WiFi Actually Works

When you connect to a home WiFi router, you’re on a network that only your household controls. When you connect to a public WiFi hotspot—in a café, library, airport, or hotel—you’re sharing that network with every other person in the building. The network operator (the café, hotel, etc.) controls the router, but they don’t control what happens between devices on the same network.

The key vulnerability: On most public WiFi networks, data between devices and the internet travels as visible (or easily decryptable) packets that other devices on the network can potentially read. This is different from your home network, where other devices aren’t present.

The main attacks on public WiFi:

Packet sniffing: Tools that capture network traffic and analyze it for credentials, session cookies, and other data. On unencrypted connections, this can reveal sensitive information in plaintext.

Man-in-the-Middle (MitM) attacks: An attacker positions themselves between your device and the internet, intercepting and potentially modifying traffic. This can capture login credentials even on HTTPS connections through techniques like SSL stripping if the device doesn’t verify certificate validity properly.

Evil Twin attacks: An attacker sets up a fake WiFi hotspot with a name similar to the legitimate one (“Starbucks_Guest” vs. “Starbucks WiFi Free”). Devices connecting to the fake hotspot have all their traffic routed through the attacker.

Session hijacking: By capturing session cookies (the tokens that keep you logged in), an attacker can impersonate you on websites without needing your password.

What HTTPS Does and Doesn’t Protect

Many parents tell children to “look for the padlock” as a sign a website is safe. The padlock indicates HTTPS encryption, which means traffic between your device and that specific website is encrypted. This protects:

  • Login credentials sent to that website
  • Payment information entered on that page
  • Personal information in forms

HTTPS does NOT protect:

  • Which websites you’re visiting (domain names are still visible)
  • Non-HTTPS connections to other services
  • Apps that send data over unencrypted channels
  • The metadata of your internet session

For a teenager logging into a site with HTTPS on public WiFi, the credential is relatively safe. For an app that doesn’t use HTTPS (some older apps and games still don’t), credentials can be captured.

Risk Assessment by Activity

Activity on Public WiFiRisk LevelRecommended Action
Checking homework on Google DocsLowFine on HTTPS
Logging into school email (HTTPS)Low-MediumAcceptable with HTTPS verified
Logging into bank or financial accountHighWait for private network or use mobile data
Gaming on Roblox, FortniteMediumUse VPN or mobile hotspot
Streaming Netflix, YouTubeLowGenerally fine
Shopping and entering payment infoHighUse mobile data instead
Connecting to unfamiliar “free” networksVery HighAvoid; verify network name with staff
Logging into school portal (sensitive records)HighMobile data preferred

Practical Protective Habits for Families

Habit 1: Verify the Network Name

Before connecting to any public WiFi, verify the exact network name with a staff member. “Coffee Shop WiFi” and “CoffeeShopWiFi_FREE” may look identical on a device but one could be an attacker’s evil twin. This takes 30 seconds and eliminates the evil twin risk.

Habit 2: Never Enter Financial Information on Public WiFi

This is the most important rule: no purchases, no bank logins, no credit card numbers on public WiFi. Use mobile data (cellular) for any financial transaction when away from home. Cellular connections go through carrier encryption, not the public WiFi network.

Habit 3: Turn Off Auto-Connect

Most devices automatically connect to WiFi networks they’ve connected to before. In a location with an evil twin, this can mean connecting to an attacker’s network without realizing it.

iOS: Settings → WiFi → Tap the network name → Toggle “Auto-Join” off Android: Settings → Connections → WiFi → Saved Networks → Tap network → Forget (repeat for public networks) Windows: Settings → Network → WiFi → Manage Known Networks → Delete public networks

Habit 4: Check for HTTPS Before Logging In

Before entering any username or password on any website on public WiFi, verify the URL starts with “https://” and shows a padlock. If a site doesn’t have HTTPS, don’t log in on public WiFi.

Habit 5: Use Mobile Hotspot for Sensitive Tasks

When your child needs to do something sensitive away from home (college application, financial aid forms, medical portal), use their phone as a mobile hotspot rather than public WiFi. This routes through the cellular network, which doesn’t have the same interception risks.

When to Use a VPN

A VPN (Virtual Private Network) encrypts all traffic from your device and routes it through the VPN provider’s server before reaching the internet. Anyone on the local network sees only encrypted traffic—they can’t read content or capture credentials.

A VPN is strongly recommended when:

  • Your child regularly uses public WiFi for sensitive tasks
  • Your child travels frequently (airports and hotels are high-risk environments)
  • You want to protect all traffic, not just HTTPS-encrypted sites
  • Your family has a consistent need rather than occasional use

A VPN is less critical when:

  • Your child only uses public WiFi for low-risk activities (streaming, general browsing)
  • You’re diligent about using HTTPS and avoiding sensitive tasks on public networks
  • Mobile data is available as an alternative for sensitive tasks

Recommended family VPNs: Mullvad (no logging, anonymous), ExpressVPN (ease of use), or ProtonVPN (free tier available, Swiss privacy law).

The School Network Risk

Many parents focus on coffee shops and airports but overlook school networks. School WiFi is also a shared network—students and staff on the same network have the same technical access to each other’s traffic as strangers on a coffee shop network.

The risk on school networks is lower in practice (schools may use network segmentation), but it’s real. Sensitive logins (school accounts that access medical or psychological records, family financial information in portal forms) carry the same risk on school networks as on public WiFi. Teaching children to use their phone’s mobile data for especially sensitive transactions applies even at school.

What to Watch For Over 3 Months

  • Month 1: Check your family’s devices for auto-connect settings on public WiFi. Disable auto-join for any public network. Establish the household rule: no financial transactions on public WiFi.
  • Month 2: Evaluate whether a family VPN makes sense given your family’s pattern of public WiFi use. If your teenager uses coffee shop WiFi regularly for homework, a VPN is a worthwhile investment.
  • Month 3: Walk through the risk table with your teenager. Pick three of their typical activities and discuss whether each is appropriate for public WiFi. Making it concrete is more effective than rules.

Frequently Asked Questions

Is hotel WiFi safer than coffee shop WiFi?

Not meaningfully. Hotel WiFi is a public shared network with the same vulnerabilities as coffee shop WiFi. Additionally, hotels often have many more devices connected, providing more cover for a malicious actor. Business travelers are frequently targeted on hotel networks. Use the same precautions at hotels as anywhere else.

My child says HTTPS means a website is safe. Is that correct?

HTTPS means the connection between your device and that website is encrypted—not that the website itself is trustworthy. Phishing sites routinely use HTTPS. A criminal can have a malicious website with full SSL encryption. HTTPS addresses interception risk on the network; it doesn’t authenticate the site’s legitimacy. Both factors matter.

Can my child’s gaming accounts get hacked through public WiFi?

Yes, if the game uses an unencrypted connection (older games) or if the attacker captures session cookies and hijacks the session. Modern major platforms (Roblox, Epic, Steam) use HTTPS for their login processes, which mitigates credential interception. However, in-game traffic may be less protected. For gaming accounts with significant value, avoid public WiFi or use a VPN.

Does using a VPN slow down the internet significantly?

Most reputable VPNs add 10–30% latency overhead. For web browsing, email, and most gaming, this is imperceptible. For latency-sensitive gaming (competitive online games), the additional delay may be noticeable but usually doesn’t prevent play. VPN connection speed also depends heavily on which server you connect to—choose servers geographically close to you.


About the author

Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Federal Trade Commission. Public Wi-Fi Networks. consumer.ftc.gov. https://consumer.ftc.gov/articles/are-public-wi-fi-networks-safe-what-you-need-know
  2. Cybersecurity and Infrastructure Security Agency (CISA). Securing Wireless Networks. cisa.gov. https://www.cisa.gov/securing-network-infrastructure-devices
  3. National Institute of Standards and Technology (NIST). Guidelines for Securing Wireless Local Area Networks. NIST SP 800-153. csrc.nist.gov. https://csrc.nist.gov/publications/detail/sp/800-153/final
  4. NordVPN. Public WiFi Usage Survey 2023. nordvpn.com. https://nordvpn.com/research-lab/
  5. Electronic Frontier Foundation. HTTPS Everywhere and Padlocks. eff.org. https://www.eff.org/https-everywhere
  6. FBI. Cyber Safety. fbi.gov. https://www.fbi.gov/how-we-can-help-you/safety-resources/cyber-safety
  7. Internet Society. Wi-Fi Security: The Basics. internetsociety.org. https://www.internetsociety.org/resources/doc/2015/wifi-security-the-basics/
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.