🌙 LATE NIGHT MODE ACTIVATED — THE CLOWN IS WATCHING 🌙

Public WiFi.
Encrypted.

Cafes, airports, hotels, conferences, libraries. Untrusted networks you connect to anyway because it's free. Here's what can go wrong and how a VPN solves most of it.

🤖 Get The Free App
☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED • ☕ CAFE WIFI • ✈️ AIRPORT WIFI • 🏨 HOTEL WIFI • 📚 LIBRARY WIFI • 🤡 ALL ENCRYPTED •

🎪 The Public WiFi Threat Model

Concrete threats on an untrusted network, in rough order of how likely you are to encounter each:

👁️ Passive packet sniffing

Anyone on the same network with basic tools (Wireshark) can capture all unencrypted traffic in the air. They don't have to attack you — they just watch.

Difficulty: trivial. Detectability: none.

🎭 Evil twin access point

An attacker sets up a WiFi network with the same name as the legitimate one ("Starbucks_Free" or similar). Your phone connects automatically. They see all your traffic.

Difficulty: easy. Detectability: hard.

🚪 Captive portal MITM

Some "free WiFi" captive portals inject ads, replace cookies, or perform tracking via JavaScript injection. The portal is literally a man-in-the-middle by design.

Difficulty: done by the venue itself. Detectability: medium.

🌐 DNS spoofing

The network operator (or someone who's compromised it) can return false DNS results — sending you to a fake login page, or a fake bank, or worse.

Difficulty: medium. Detectability: medium.

🎪 How A VPN Neutralizes Each

Threat With ClownVPN Why
Passive packet sniffingMitigatedAll traffic is AES-256-GCM ciphertext. They see noise.
Evil twin APMitigatedEven if the attacker is the AP, your traffic is encrypted end-to-end to a ClownVPN server they don't control.
Captive portal MITMMitigated (post-login)After portal login, the tunnel kicks in and the venue can't inject anything.
DNS spoofingMitigatedDNS queries go through the tunnel to Cloudflare 1.1.1.1, never the local network's DNS server.
ARP poisoningMitigatedEven if traffic is redirected, the contents are encrypted.
Direct attack on your deviceNot mitigatedThat's a host-OS problem. Keep your phone patched.

🎪 How To Actually Do This Right

1
Enable Always-On VPN on Android

Settings → Network & internet → VPN → ClownVPN ⚙️ → toggle Always-on VPN + Block connections without VPN. Now even before you open any app, the tunnel is up.

2
Disable "Connect to open networks automatically"

Settings → Network & internet → Internet → ⚙️ → toggle off auto-connect. This stops your phone from joining evil twins of networks you've previously trusted.

3
Handle captive portals deliberately

When you hit a "click to log in" page, briefly disconnect ClownVPN, accept the terms, then reconnect. Or use split tunneling to exclude the browser temporarily.

4
Verify the tunnel

Once a quarter or after Android updates, run the leak verification guide to confirm everything is routing through the VPN as expected.

🎪 Venues Where This Matters Most

✈️ Airports + Lounges

High traffic, lots of evil-twin attempts during peak hours. Also commonly logged by venue infrastructure.

🏨 Hotels

Notoriously sketchy infrastructure. Captive portals routinely inject ads or track users.

☕ Cafes & Restaurants

Open networks with weak management. Easy to set up an evil twin in the next booth.

🎤 Conferences

The classic VPN demo venue. Lots of curious people on the network, plus deliberate research traffic.

🏫 Schools / Universities

Often heavily logged "for security". Many also block specific categories of legitimate traffic.

🚂 Trains, Buses, Planes

Shared satellite or cellular uplinks with poor performance and unknown logging policies.

🎪 FAQ

Isn't HTTPS already enough on public WiFi?
HTTPS encrypts the contents of a connection but the destination (the SNI hostname, the IP) is still visible to the network. A VPN encrypts the entire path including those metadata bits.
Are public WiFi attacks actually common?
Passive packet sniffing is trivial and silent (you'd never know). Active attacks (evil twin AP, captive portal MITM, ARP poisoning) require some effort but happen in conference venues and travel hubs. The threat is small but real, and a VPN nullifies the entire class.
Should I leave the VPN on permanently?
Yes, especially with the Always-on VPN setting we recommend. Battery cost is minimal and you never have to remember to flip it on for a "real" public network.
What about captive portals that block VPN?
Some hotel WiFi captive portals break with a VPN active. Workaround: disconnect ClownVPN briefly, log into the portal, reconnect VPN. Or use split tunneling and exclude the browser temporarily.
Does mobile data (5G) need a VPN too?
Less than public WiFi (your cellular carrier is at least a known entity with a contract), but still useful — your carrier sees every domain you connect to without a VPN. With one, they don't.

🎪 Related

🕵️ General Privacy →

The broader privacy use case.

🪓 Kill Switch →

The feature that backs up your public WiFi use.

🔍 Verify The Tunnel →

Confirm no leaks before you trust the network.