About this tool
Score your cafe, airport or hotel Wi-Fi habits against the controls that still matter, and get the gaps ranked by impact.
The Public Wi-Fi Safety Checklist scores eleven controls that still change the outcome on a network you do not own, weights them by real impact, and scales the total by where you are and what you plan to do. It is built on how browsing works now: HTTPS already encrypts the content of nearly everything, so the meaningful risks are the ones that need your cooperation — clicking through a certificate warning, typing a Google or work password into a captive portal, installing something a portal demands, or joining a lookalike network. The output ranks your gaps by weight so you fix the two that matter instead of all eleven.
Open Public Wi-Fi Safety Checklist on AltFTool — it loads instantly in your browser.
Set Where are you connecting? — cafe, airport, hotel, conference, transport or an open network with no obvious owner — and What will you do on it?, from casual browsing up to admin access to systems or customer data.
Tick the habits you already keep across the Non-negotiable, High impact and Useful groups, from never clicking through a certificate warning to forgetting the network when you leave; Tick everything and Clear all set them in one go.
The Residual risk index out of 100 arrives with its band, Controls in place, Coverage by weight, the Setting multiplier and Non-negotiable gaps, and Fix these first orders your missing controls by weight — Copy result saves the lot.
Certificate warnings and portal credentials outrank forgetting the network, and the score says so.
The same habits score differently for casual browsing in a cafe and admin access on an unnamed open network.
It does not repeat pre-HTTPS advice about strangers reading your passwords off the air.
Far less than the old advice suggests, because almost all traffic is HTTPS and browsers now block or flag plain HTTP. The remaining risks need you to act: accepting a certificate warning, entering real credentials into a fake portal, installing a profile or app the portal asks for, or joining an evil-twin network with a copied name.
A VPN is useful but not the main control. It hides which sites you contact from the network operator and covers any stray unencrypted traffic, yet it does nothing against a phishing page, a malicious download, or credentials you type in yourself — and a free VPN app simply moves your trust to its operator.
Confirm the exact network name with staff, since an evil twin works by copying the venue's name with a small change such as an extra underscore. Be suspicious of any portal that asks for a Google, Apple or work password, or that requires you to install a certificate or app — genuine networks ask at most for a room number, ticket number or OTP.
Banking apps pin their own certificates and refuse to run over an intercepted connection, so the app itself is well protected. Even so, switching to mobile data for the transaction removes the shared network from the picture entirely, which is the simplest control available and the highest weighted item on this checklist.