
Airport Wi-Fi is the most-used untrusted network in most people’s lives, and the ninety minutes before a flight is when they use it least carefully. Together, those two facts are the risk.
Why the pre-flight window is the problem
In a departure hall you check in, move money or at least look at it, clear the work thing you promised to clear before eleven hours offline, and reply about the booking. That is a dense run of the accounts you would least like handled carelessly, done in a hurry, on a network shared with several thousand strangers.
The airport is not uniquely dangerous. The behaviour it produces is.
What a captive portal is
Any network that makes you agree to something before letting you through is inspecting your traffic to decide. Overwhelmingly that machinery is billing and terms-acceptance logic, and nothing sinister. It does show what you are on: infrastructure you do not control, run to a budget you did not set, patched on a schedule nobody told you. The portal also enforces any cap on how many of your devices may join. The airports and hotels in Asia that publish such a cap make a short list.
Lounge Wi-Fi is quieter and usually faster than terminal Wi-Fi, but you cannot verify that it is more trustworthy. That is the case for a tunnel that treats every unrecognised network identically, instead of one you switch on when a network looks dubious.
Three habits
Turn off automatic joining of open networks. This is the highest-value setting, and it is free. A phone set to join any open network will do so silently, including one named to look like the airport’s. You want joining to be a decision.
Keep a tunnel up by default. Ours is NordVPN, left on auto-connect for any network it does not recognise, so you decide once at home instead of every time. A VPN’s real contribution here is that it removes a judgement call when you are tired and rushing. A tool you must remember to switch on is one you will forget in the queue at immigration.
Use your own mobile data for anything involving money. Roaming or an eSIM is a private connection in a way a shared network is not, and the megabytes needed to check a balance cost almost nothing.
What this does not fix
- A VPN does not make a banking app secure. The app’s own encryption does that, and it was doing it before you connected.
- It does not stop you handing your password to a convincing fake login page, a far more common way to lose an account than anything at the network layer.
- It does not make a compromised device safe.
Some banks also treat an unfamiliar VPN endpoint as a suspicious signal in itself. If yours does, do banking on your own mobile data and leave the tunnel for everything else.
Our view, not an official rule
This is our own view, from working in a lot of departure halls, and you cannot look it up. No government page endorses a product here, and any article claiming official backing for one is telling you something untrue.
NordVPN is the one we travel on, and it does what this article describes Currently 75% off plus 3 months extra through this link. Our full write-up. (affiliate link)