Quick Answer
ChromeOS’s built-in sandboxing and automatic HTTPS use already cover most of the real risk on public Wi-Fi. The main things worth doing yourself are avoiding sensitive logins on unencrypted (no password/open) networks, keeping “Ask before connecting to networks” on, and using a VPN if you regularly handle sensitive work on public connections.

What’s Actually Risky on Public Wi-Fi
The realistic threat on open public Wi-Fi is a nearby attacker intercepting unencrypted traffic on the same network, not someone “hacking into” your Chromebook directly. Since most modern websites use HTTPS by default, the content of what you’re doing is already encrypted end to end even on an open network. What’s not protected is metadata like which sites you’re visiting, and any site that still loads over plain HTTP is genuinely readable by others on that network.
Fix Steps
Step 1: Prefer networks with a password over fully open ones
A password-protected network (even a shared cafe password posted on a chalkboard) uses encryption between your device and the router that an open network doesn’t. It’s not perfect security, but it’s meaningfully better than a fully open network with no password at all.
Step 2: Confirm you’re on the legitimate network
Fake lookalike hotspots (like “Airport_WiFi_Free” instead of the venue’s actual network name) are a known trick in busy public spaces. Confirm the exact network name with staff before connecting if multiple similar-looking options appear in the list.
Step 3: Check for the HTTPS padlock on sensitive sites
Before entering a password or payment info, confirm the address bar shows a secure connection. ChromeOS and Chrome actively warn you when a site isn’t using HTTPS, so pay attention to that warning rather than dismissing it out of habit.
Step 4: Turn on “Ask before connecting to networks”
Go to Settings > Network > Wi-Fi, and enable this option so your Chromebook doesn’t silently auto-join a previously used network name, which is another common spoofing trick where an attacker names their hotspot after a network you’ve connected to before.
Step 5: Use a VPN for sensitive work
If you regularly handle work accounts, banking, or other sensitive logins on public networks, a VPN encrypts all your traffic regardless of the network’s own security. See our guide on setting up a VPN on a Chromebook for the setup steps.
Step 6: Forget the network when you’re done
Once you leave, forget the network from Settings > Network rather than leaving it saved indefinitely, especially for one-time networks like a specific hotel’s Wi-Fi you won’t return to.
Common Public Wi-Fi Problems
If the login page for a hotel or airport network never appears, see our guide on a Wi-Fi login page that won’t show up. If you connect successfully but nothing loads afterward, see our guide on a Chromebook connected but with no internet.
FAQ
Is public Wi-Fi too risky to use at all?
No, modern HTTPS encryption means normal browsing, streaming, and most everyday use is reasonably safe. The extra precautions here matter most for sensitive logins and financial transactions, not general use.
Does ChromeOS have built-in protection against malicious networks?
Yes, ChromeOS’s sandboxed architecture (each site and tab runs in its own isolated process) and automatic security updates provide a meaningfully stronger baseline than many other operating systems, though no protection eliminates every risk on an untrusted network.
Should I avoid public Wi-Fi for online banking entirely?
Using a VPN or your phone’s cellular hotspot instead removes the remaining risk entirely, so it’s a reasonable extra precaution for banking specifically, even though HTTPS already encrypts the connection itself.
