Warnings about coffee shop networks date from a period when most traffic was unencrypted. Nearly all of it is encrypted now, which changes what a hostile network can and cannot do. What the real remaining risks are, and which of the familiar precautions still earn their place.
Where the advice came from
It was correct, and urgently so. When most web traffic travelled in plaintext, anybody on the same network could read it: passwords as typed, email bodies, everything. The network was genuinely the adversary, and the warning matched the threat exactly.
It has outlived the conditions that produced it, which is what happens to good advice when nobody revisits it. The instruction survived; the reason for it quietly did not.
What changed
Transport encryption became close to universal.
The practical consequence is precise. An observer on the network now learns which services you reach and when. They do not learn what you did there. The contents that used to be the whole prize are no longer available to them at all.
That is a large reduction in exposure, and it is why most of the familiar warnings now point at something that has already been handled.
What a hostile network can still do
Observe destinations and timing. Which services, how often, at what hours. A profile rather than a transcript, and a useful one.
Observe volume. Large transfers, streaming, backup activity — the shape of what you are doing, without the content.
Interfere with name resolution. Sending you to a server of their choosing, which matters only if you then ignore what your browser tells you about it.
Present a captive portal. A page you must pass through, which is an unusually good position from which to imitate a login screen.
The two things that actually get people
Clicking through a certificate warning. This is the one moment the modern arrangement hands the decision back to you, and the entire model depends on you declining. A warning at that point is not a technicality. It is the system telling you the connection is not what it claims to be, and proceeding is the only way an attacker gets in.
Entering credentials into a captive portal. Portals train people to type things into unfamiliar pages in order to get online. A portal asking for a service account password is phishing with the network's assistance, and it works because the situation legitimately requires you to fill in a form.
Which precautions still earn their place
Keep software current. What remains is attacks on implementations rather than on protocols, and that is what updates address.
Never dismiss a certificate warning. Single highest-value habit on this list.
Treat captive portals as untrusted. Give them a network password if one is needed. Never an account password, for anything.
A VPN, honestly framed. It genuinely helps here, because it moves the observer off the local network. It does not remove the observer — it appoints a different one, who now sees more than the café ever did.
What is now mostly theatre
Avoiding banking on public networks. No less safe than banking on any network you do not personally control, which includes most of them. The protection is in the application, and it travels with you.
Elaborate rituals about file sharing. Defaults tightened years ago, and the threat this addressed is largely superseded. It persists because it is easy to say and feels diligent.
The underlying shift
Protection moved from the network layer into the application layer. That single change is why network-level advice aged badly — it was written when the network was the boundary of trust, and the boundary has moved.
Worth applying to other advice you currently follow: what was the threat when this was written, and is it still the threat?
Close
The coffee shop network is not your problem. The warning you click past to get to the coffee shop network is.
