Travel
Hotel Wi-Fi: what it logs, what it cannot see, and what to do first
The most hostile network you will join all year, explained honestly: captive portals, forged DNS, the 90-second window — and the check-in routine.
The short version. Hotel, airport and campus gateways see your DNS, your SNI hostnames and your metadata — and some monetize the login itself with ads and retargeting. Real 2026 campaigns hijacked hotel gateways to redirect even Microsoft logins. The defense is a routine, not an app: verify the network name, survive the captive portal with minimal exposure, connect the VPN immediately, and only then open anything sensitive.
What the gateway sees
A hotel gateway sits where your home router sits, except it is run by strangers with commercial incentives. Without a VPN it sees the full table from our companion post: DNS lookups in the clear, SNI hostnames of every TLS connection, metadata (addresses, sizes, timing), and anything still on plain HTTP. Some properties log per-room and per-device; all of them can, because the equipment ships with the feature.
The portal is a business, not just a login
That “enter your email for free Wi-Fi” page is programmatic advertising infrastructure: sponsored videos, email capture, post-stay retargeting. Your address joins a marketing database the moment you trade it for bandwidth. Worse, portals run over plain HTTP with DNS the gateway controls — which is why forged answers and redirect campaigns keep working there year after year, including credential harvesting aimed at cloud logins. The portal page deserves exactly as much trust as a billboard: read what it asks, give the minimum.
The 90-second window
No VPN can be up before you join the network, so the captive-portal dance — join, get redirected, log in, wait for clearance — happens in the clear by construction. Sixty to ninety seconds where DNS answers may be forged, redirects may point anywhere, and every lookup is visible. This window is where the real 2026 hotel-gateway attacks lived: not by breaking encryption, but by striking before any tunnel existed. Naming it is the defense: nothing sensitive happens inside those ninety seconds. No banking, no webmail, no cloud logins beyond the portal itself — and the portal credentials should be throwaway (room number plus a password you would print on a poster).
Chargers, USB ports and the business-center PC
Two travel myths to retire. First, public USB charging ports: modern phones negotiate power without exposing data by default — and have for years — so “juice jacking” through a lobby port is mostly a ghost story from 2019. A cheap data-blocking cable ends the debate either way. Second, the business-center PC: assume it is compromised (keyloggers, missing updates, previous guests' malware) and never log into anything personal there. A VPN cannot clean a dirty endpoint, and no checkout routine fixes typing your password into someone else's keylogger.
The check-in routine
- Confirm the exact network name at reception — rogue access points with plausible names are the oldest trick in the book.
- Join from your phone first if you can, keeping the laptop offline until the path is proven.
- Clear the portal with minimum data, watching certificates: a portal asking for a banking password is not a portal.
- Connect the VPN immediately — full tunnel, DNS inside it — and verify with a leak check before opening anything else.
- Keep the kill switch on for the whole stay: hotel networks drop constantly, and every reconnect without a tunnel repeats the exposure.
- Prefer mobile data for the two minutes of actual banking, even with everything above. Defense in depth is not paranoia on hostile networks; it is the baseline.
Questions we hear
Is hotel Wi-Fi safe with a VPN?
Should I just use mobile data instead?
Can the hotel block my VPN?
What about the hotel business center PC?
Reviewed by Jonas Keller · 13 October 2026