Skip to content
Public Wi-FiPublished ·

What a public Wi-Fi network can actually see about your traffic

HTTPS encrypts a site's content, but not everything. Here's what a network can still see without a VPN — and what an encrypted tunnel changes.

"I've got HTTPS, the padlock's green, what else is there" is a common assumption. HTTPS covers a lot — just not everything a network you're connected to can see.

The DNS request: the first step that's often unprotected

Before opening a site, a device asks a DNS server which IP address matches that domain name. If that request goes out unencrypted — which, by default, it often does — the network sees the domain name before the HTTPS connection itself even begins.

This happens for every single site you open in a session — DNS requests build a fairly precise picture of what you're using, even when each individual page's content is fully encrypted.

SNI: a hostname sent in the clear, even over HTTPS

At the start of an HTTPS connection, the browser sends the server a field called SNI (Server Name Indication) — the hostname it's connecting to. This lets the server know which certificate to present when multiple sites share one IP address.

For historical reasons, SNI is sent unencrypted in a classic TLS handshake. So the network sees the hostname, even though the page's content is fully encrypted from that point on.

Metadata: volume and timing

Even without reading content, a network sees how much data moved, how long a connection stayed open, and how often. That's often enough to distinguish, say, a video call from a text conversation — from the traffic pattern alone, not the content.

What's unprotected if a site skips HTTPS entirely

A minority of sites still serve some content over plain HTTP. In that case, the network — and anyone technically positioned to listen in on it — sees the page's content outright: text, images, form data, unless it's protected some other way.

What changes with a VPN

An encrypted tunnel pushes this whole set of problems up one level: DNS requests and SNI still exist, but they travel inside the tunnel, to the VPN node — the hotel's or café's local network sees only an encrypted stream to one address, not domain names or per-site traffic volume.

Related questions

So does regular HTTPS protect nothing at all?

It protects plenty — the content of a specific page: text, images, form data on submission. It doesn't protect the metadata around the connection: the DNS request, SNI, traffic volume and timing.

Can a network fake a DNS response?

Technically, yes, if DNS requests go out unencrypted and the network is set up to intercept and replace them — that's its own attack category, DNS spoofing. A VPN that routes DNS requests inside the tunnel removes that option from the local network.

Does a VPN hide absolutely everything?

No — the network you're connected to still sees that you're connected to a VPN node. What the node itself sees on its way out to the internet depends on its logging policy, not the encryption protocol.