Phoenix in August pushes a lot of work indoors. The patio is out, the home office air conditioning bill is climbing, and the coffee shop down the street has cold brew and a free network. Add Sky Harbor layovers, hotel lobbies in Scottsdale during conference season, and the client site with a guest SSID taped to the reception desk, and most Arizona professionals connect to networks they do not control several times a week.
The advice about those networks has been repeated so often that it has stopped landing. It has also changed, and the update matters more than the warning.
The old warning, and what is actually different now
For years the standard guidance was blunt: assume anyone on the coffee shop network can read what you send. That was fair when much of the web still ran unencrypted.
Federal Trade Commission guidance now takes a more measured line. Because encryption is so widely deployed across the web, connecting through a public network is usually safe, and the practical check is to look for the lock symbol or the https prefix in the address bar. That applies on a phone browser as well as a laptop.
So the doomsday version of the warning is out of date. The nuance that replaced it is more useful, because it tells you exactly where the remaining gaps sit.
Four gaps that encryption on the website does not close
The network still sees where you go. Encryption protects the contents of your session with a site. It does not hide which sites you connected to. Whoever runs the network, and in some configurations other people on it, can build a reasonable picture of your browsing from that alone. If you are researching an acquisition target, a competitor, or a medical question, the destination list is itself sensitive.
Imposter hotspots. The Federal Communications Commission specifically warns about networks impersonating the venue you are sitting in, and advises checking with staff when more than one hotspot appears to belong to the same business. Standing up a plausible looking access point takes very little equipment.
Your devices join networks on their own. Phones and laptops reconnect automatically to anything matching a name they have seen before. A network called Guest or Airport Free WiFi is a name your device has almost certainly stored at some point.
Apps are harder to verify than browsers. With a website you can look at the address bar. With a mobile app there is no equivalent check, and while most do encrypt their traffic, you are taking that on trust.
Where a VPN fits, described plainly
A virtual private network builds an encrypted tunnel between your device and a server it operates. Everything leaving your device travels inside that tunnel, so the network you joined sees an unreadable stream rather than a list of destinations and sessions.
The FCC guidance says this directly: if you use public hotspots regularly, consider a VPN, since it encrypts all transmissions between your device and the internet. It also notes that individuals can subscribe on their own rather than waiting for an employer to provide one.
That last point is the one most people miss. If you are a sole practitioner, a consultant, an agent, or someone whose company laptop stayed at the office, nobody is provisioning this for you. A free VPN covers the realistic case of working outside the office a few times a week without a purchasing decision or an IT ticket.
Choosing one without making the problem worse
This is where the category earns its poor reputation, and the caution is warranted. A VPN provider sees the traffic the coffee shop no longer does. You are relocating trust, not eliminating it, so the provider matters more than the feature list.
The FTC published guidance on evaluating VPN apps that holds up well as a checklist: research the app before installing it, review what permissions it requests, confirm it actually encrypts your traffic, and check whether it shares information with third parties.
Two additions from practice. First, understand how the service is funded. Running server capacity costs money, and an app with no subscription, no parent company you can identify, and no explanation of its revenue is being paid somehow. Selling browsing data is the usual answer, which inverts the entire point. Second, look for an independent security audit with a published report, not a badge on a landing page.
INDUSTRY INSIGHTS: The 100 Best Doctors in Arizona for 2026
LOCAL NEWS: The 20 biggest employers in Arizona
A short checklist for the road
- Turn off automatic joining for networks you do not own. Reconnecting deliberately takes seconds.
- Confirm the network name with a member of staff rather than picking the strongest signal.
- Keep the operating system and browser current, since a good share of real world compromises exploit something already patched.
- Turn on two factor authentication everywhere it is offered. It limits the damage when a password does leak.
- For anything genuinely sensitive, such as payroll, banking, or signing documents, use your phone’s cellular hotspot instead.
The bottom line
Public Wi-Fi is no longer the open door it was a decade ago, and pretending otherwise makes the advice easy to dismiss. What remains is narrower and worth handling: your destinations are visible, imposter networks are cheap to run, and your devices will reconnect without asking.
Encrypting the connection closes those gaps in one step. For most people working outside the office occasionally, that is a few minutes of setup and no ongoing cost, which is a reasonable trade for not having to think about which network you are on.