Open beta: PryVPN and Plus are €0. Pro is out of stock.

HomeBlogTravel

Travel

Hotel Wi-Fi: what it logs, what it cannot see, and what to do first

The most hostile network you will join all year, explained honestly: captive portals, forged DNS, the 90-second window — and the check-in routine.

The short version. Hotel, airport and campus gateways see your DNS, your SNI hostnames and your metadata — and some monetize the login itself with ads and retargeting. Real 2026 campaigns hijacked hotel gateways to redirect even Microsoft logins. The defense is a routine, not an app: verify the network name, survive the captive portal with minimal exposure, connect the VPN immediately, and only then open anything sensitive.

What the gateway sees

A hotel gateway sits where your home router sits, except it is run by strangers with commercial incentives. Without a VPN it sees the full table from our companion post: DNS lookups in the clear, SNI hostnames of every TLS connection, metadata (addresses, sizes, timing), and anything still on plain HTTP. Some properties log per-room and per-device; all of them can, because the equipment ships with the feature.

The portal is a business, not just a login

That “enter your email for free Wi-Fi” page is programmatic advertising infrastructure: sponsored videos, email capture, post-stay retargeting. Your address joins a marketing database the moment you trade it for bandwidth. Worse, portals run over plain HTTP with DNS the gateway controls — which is why forged answers and redirect campaigns keep working there year after year, including credential harvesting aimed at cloud logins. The portal page deserves exactly as much trust as a billboard: read what it asks, give the minimum.

The 90-second window

No VPN can be up before you join the network, so the captive-portal dance — join, get redirected, log in, wait for clearance — happens in the clear by construction. Sixty to ninety seconds where DNS answers may be forged, redirects may point anywhere, and every lookup is visible. This window is where the real 2026 hotel-gateway attacks lived: not by breaking encryption, but by striking before any tunnel existed. Naming it is the defense: nothing sensitive happens inside those ninety seconds. No banking, no webmail, no cloud logins beyond the portal itself — and the portal credentials should be throwaway (room number plus a password you would print on a poster).

Chargers, USB ports and the business-center PC

Two travel myths to retire. First, public USB charging ports: modern phones negotiate power without exposing data by default — and have for years — so “juice jacking” through a lobby port is mostly a ghost story from 2019. A cheap data-blocking cable ends the debate either way. Second, the business-center PC: assume it is compromised (keyloggers, missing updates, previous guests' malware) and never log into anything personal there. A VPN cannot clean a dirty endpoint, and no checkout routine fixes typing your password into someone else's keylogger.

The check-in routine

  1. Confirm the exact network name at reception — rogue access points with plausible names are the oldest trick in the book.
  2. Join from your phone first if you can, keeping the laptop offline until the path is proven.
  3. Clear the portal with minimum data, watching certificates: a portal asking for a banking password is not a portal.
  4. Connect the VPN immediately — full tunnel, DNS inside it — and verify with a leak check before opening anything else.
  5. Keep the kill switch on for the whole stay: hotel networks drop constantly, and every reconnect without a tunnel repeats the exposure.
  6. Prefer mobile data for the two minutes of actual banking, even with everything above. Defense in depth is not paranoia on hostile networks; it is the baseline.

Questions we hear

Is hotel Wi-Fi safe with a VPN?
With the routine above, yes for practical purposes: DNS and SNI travel inside the tunnel, content stays end-to-end encrypted, and the kill switch covers the constant drops. The residual risks are the portal window itself and endpoint compromise — neither of which any VPN claims to fix.
Should I just use mobile data instead?
When you can, yes — your carrier sees metadata but the random hotel gateway sees nothing at all, and there is no portal window. Use hotel Wi-Fi plus VPN for bulk traffic (video, backups) and data for the sensitive two minutes.
Can the hotel block my VPN?
Some try: throttling UDP, blocking common VPN ports, forcing all DNS through their resolver. If the tunnel will not establish, fall back to mobile data rather than browsing bare — and treat a network that fights your VPN as confirmation you needed it.
What about the hotel business center PC?
Assume it is compromised: keyloggers, no updates, previous guests' malware. Never log into anything personal there. If you must print a boarding pass, use a one-time code, log out, and change nothing else. A VPN cannot clean a dirty endpoint.

Mara VidalNetwork Engineer

Mara runs the PryVPN exit network: WireGuard datapaths, node capacity, and the beacons that feed the live status page.

Reviewed by Jonas Keller · 13 October 2026

Take a lane.

PryVPN and Plus are €0 during the beta. A profile takes one click.