Skip to content
Get guide

Do You Need a VPN for Travel?

Back to all articles

Malta Priority Pass Lounge View of Computers

Yes, but not for the reason you’ve been given.

For about twenty years the advice was that public wifi would get your bank password stolen in a coffee shop, and that a VPN was what stopped it. That threat was real once. It mostly isn’t anymore, and the Federal Trade Commission says so on its own consumer advice page:

Connecting through a public Wi-Fi network is usually safe.” Past tense on the danger, too: “In the past, if you used a public Wi-Fi network to get online, your information was at risk.”

So if the coffee shop hacker is why you were going to buy one, you can put that down. Checking your email on airport wifi is not the reckless act you were told it was. What’s left is smaller and more specific, and nobody has updated the advice to mention it.

What actually changed

Encryption won.

The old danger was simple. You typed a password into a website, it crossed the café’s network as readable text, and anybody sitting on that network with the right software could read it. Every “don’t use public wifi” article was written about that.

Then websites almost universally switched to encrypted connections, the ones with the padlock and the “https” in the address bar. The FTC’s explanation is one sentence: “most websites do use encryption to protect your information.” The conversation between your phone and your bank is scrambled before it reaches the network, so it matters much less who else is on it.

That’s the good news and it’s most of the news.

What didn’t change

Encryption protects the conversation. It doesn’t tell you who you’re talking to, and it doesn’t tell you whose network you joined.

The FBI is blunt about this in an advisory written specifically about hotels. Criminals, they say, “create their own malicious network with a similar name to the hotel’s network. Guests may then mistakenly connect to the criminal’s network instead of the hotel’s.”

Picture how that looks. You’re in the lobby at the end of a travel day and your phone shows you a list. Hotel_Guest. Hotel-Guest. Hotel Free WiFi. Hotel_Guest_WiFi. One of them is the hotel’s and there is nothing on the screen to tell you which. You pick one, it works, you’re online, and nothing about it feels wrong.

Once you’re on a network somebody else runs, here’s what the FBI says they can do with it: “monitor a victim’s internet browsing or redirect victims to false login pages.”

That second one is the part encryption doesn’t help with. The FTC’s own warning: “They also create fake websites and encrypt them to make you think they’re safe when they’re not.” The padlock means the connection is private. It has never meant the website is honest.

The fix for all of this is free and takes ten seconds: ask at the desk what the network is actually called. The whole attack depends on you guessing, so stop guessing. And while you’re there, one more thing from that FBI advisory, which is that “smaller hotels will often post placards at the service desk stating the password for Wi-Fi access, and change this password very infrequently.” A network having a password is not evidence it’s the right network. That card by the kettle has been handed to every guest for years, so treat the password as a formality rather than as proof of anything.

So do you need one? Here’s the order I’d do it in

Two of these three are the FBI’s own recommendations, in their order.

Use your own data instead of joining at all. This is their first suggestion, in their words: “If available, use your phone’s wireless hotspot instead of hotel Wi-Fi.” It’s what we do most of the time now, because a travel eSIM made it cheap enough to stop being a decision. Airalo for an ordinary trip, Pangea if you’re gone a month at a time or you’re going to use a lot of data. There’s more on how eSIMs work here if you’ve never used one. A network you didn’t join can’t do anything to you.

If you are using the wifi, put a VPN on it. That’s the FBI’s second recommendation, and their reasoning is that it encrypts your traffic so nobody on that network can eavesdrop. It also means the network can’t watch which sites you visit, which is the part that matters to me. We use NordVPN, and I turn it on every time I do anything to do with work on a hotel network.

Set it up at home, before you go, while you have decent wifi and a normal amount of patience. Everything about travel preparation that goes badly goes badly because somebody tried to do it in an airport.

Bare public wifi, for things that don’t matter. Reading the news, looking up a restaurant, maps. This is the category the FTC means when it says usually safe, and it genuinely is.

What a VPN won’t do

Now let me tell you what a VPN won’t do, because that’s just as important.

It won’t make a fake website real. If you’ve been sent to a convincing copy of your bank, a VPN will encrypt your connection to the fake bank beautifully, but it won’t stop you going to a fake website in the first place. Always open your bank’s own app, or type the address yourself, rather than following a link.

And it won’t stop you joining the wrong network. That’s a ten-second habit, not a piece of software, and it’s the one above.

And it isn’t antivirus. It does nothing for a phone or laptop that’s already infected.

And it can be a nuisance. Some hotel and airport networks won’t let you finish their sign-in page with a VPN already running, so you have to connect first, get through the sign-in, then switch it on. Some apps and websites object to a connection that’s running through a VPN or won’t allow a connection at all. Neither is a reason to skip it, just things to be aware of.

Two more habits, and then you can stop thinking about this

Turn off automatic WiFi joining. Your phone will otherwise reconnect to anything sharing a name with a network you’ve used before, which is a gift to somebody who names theirs the same. Tell it to forget the network on your way out.

And treat the sign-in page as a stranger. It can reasonably ask for a room number or an email address. It has no business asking for a password, a card number or your date of birth, and if it does, close it.

The other half of why we have one

Everything above is my reason. Matt’s is completely different and it’s probably the one that gets more use in our house.

Streaming services license their content country by country, so the shows you pay for at home often aren’t there when you land. A VPN puts them back, because it makes the connection look like it’s coming from the US. Same subscription, entirely different problem, and it’s the reason he set ours up in the first place.

I’ve written that half up separately, including which services still work, how to get it onto an actual television rather than a laptop, and what to take on the plane: how to watch American TV while traveling.


The network is the easy half

All of this is about the connection. The harder problem is the device.

A friend of mine had her phone taken out of her hand by a man on a motorbike in Lima, in the middle of the day, on a busy street. It was unlocked. No VPN in the world would have touched that.

The Smart Woman’s Guide to Safer Travel has a full chapter on the phone rather than the network. Where it lives so it doesn’t get taken, and the café-table trick that gets them taken. The one setting that decides whether a stolen phone is an annoyance or a financial emergency. Why the two-factor codes your bank texts you are the weak point, and what to use instead. What to set up at home so a phone that’s gone can be locked from a borrowed laptop in a minute. And the order to do things in afterward, which is most of the value.

Eight grab-and-go checklists and a fill-in emergency contact card. It’s $19.99.

Get the guide – $19.99


The bottom line

The scary version of this is out of date and you can stop carrying it around. Public wifi is usually fine, and the FTC will tell you so itself.

What’s left is that you can’t tell which network is the hotel’s, and somebody who runs the one you picked can watch where you go or send you somewhere that looks like your bank.

So ask at the desk what the network is called. Use your own data when you can. Put a VPN on the wifi when you can’t. That’s ten seconds, one subscription and a habit, and then you can use the wifi like a normal person again.

Frequently asked questions

Is a VPN worth it if I only travel once or twice a year? Take a monthly plan rather than an annual one and turn it on for the trip. The thing I’d actually spend the money on first is enough travel eSIM data of your own, because not joining the network beats securing it.

Is it safe to check my bank on hotel wifi? Usually, because your bank’s connection is encrypted. The risk isn’t somebody reading it, it’s you being sent somewhere that looks like your bank. Open the bank’s own app instead of following a link, and if you didn’t verify the network, it can wait.

What’s an evil twin? A wifi network somebody sets up with a name close enough to the real one that you pick it by mistake. The FBI’s advisory describes exactly this in hotels. Asking at the desk what the network is called is the whole defense.

Is my phone’s hotspot really safer than hotel wifi? Yes, and it’s the FBI’s first recommendation. It’s your connection rather than a stranger’s.

Someone told me the padlock means a site is safe. It means the connection is private, not that the site is honest. The FTC is direct about it: criminals “create fake websites and encrypt them to make you think they’re safe when they’re not.”

Should I use a free VPN? A VPN sees all your traffic by design, so the question is who you’re handing that to and how they make their money instead. Worth an answer before you install one.

Will it slow things down? A little, because your traffic takes a longer route. You won’t notice it for most things. On bad apartment wifi you might, and the fix is usually a nearer server rather than switching it off.

Do I need it on the laptop or just the phone? Both, and it’s the laptop that people forget. That’s where most of us do the things we’d least like to have watched.


Subscribe to my newsletter!

I send one email a week to 21,000 subscribers. Real stories, what worked, what didn’t, and the practical things I only figure out by doing them. Plus my free packing guide and international travel checklist when you sign up.

Sign up here

Leave a comment

Your email address will not be published.

The only audience we own

One useful travel email a week

Smarter, safer, cheaper travel - the best of what I learn, straight to your inbox. Free, and easy to unsubscribe.

Subscribe free

No spam, ever. One email a week - unsubscribe in one click.

General Privacy Policy
Logo

This website uses cookies to ensure the correct functioning of its pages and, with the user’s consent, to analyze traffic and measure the performance of advertising campaigns.

Through services such as Google Analytics, Google Tag Manager, Google Ads, and Meta Pixel, technical data may be collected, including visited pages, session duration, device type, approximate location, and traffic source.

This information is used exclusively for website performance analysis, audience measurement, and optimization of advertising and marketing activities.

For complete details regarding the processing of personal data, please consult the Privacy Policy.

Strictly Necessary Cookies

These cookies are essential for the proper functioning of the website and cannot be disabled.

They enable basic features such as page navigation, saving cookie consent preferences, security mechanisms, and protection of forms.

These cookies are not used for analytics, advertising, or marketing purposes.

Statistics / Analytics

These cookies allow the collection of statistical information regarding website usage, such as visited pages, session duration, device type, browser type, and traffic source.

Data is collected through Google Analytics, via Google Tag Manager, and is used exclusively to analyze and improve the performance of the website.

The information may be processed by Google in accordance with its own privacy policy.

Marketing / Advertising

These cookies are used to measure the effectiveness of advertising campaigns and to deliver relevant advertisements.

They allow understanding how users interact with the website after viewing or clicking on advertisements served through Google Ads or Meta platforms, and support conversion tracking, remarketing, and audience analysis.

Some pages of this website may load advertising containers or scripts provided by Google, which are activated only based on the user’s consent.

Data may be processed by Google and Meta in accordance with their respective privacy policies and may be transferred outside the European Union, based on applicable legal safeguards such as standard contractual clauses.