Earlier quoted context omitted.
> No, you have to trust the one company, as well as everyone you were trusting before. You are still using the router, and now you are also trusting the VPN provider, as well as the nodes in between the VPN provider and your original destination. As long as the VPN is up, the worst the wifi can do is cut you off. It can't alter your connections. It's far fewer trust points. > Also, you are just switching up the "unpr…
>For most wifi networks, there is no encryption between users. And it's quite likely that the neglected router got hacked over the internet and is part of a botnet. WPA2? Sure it can be broken, but you still would have to break HTTPS on top of that. I don't deny that a third layer adds security in that scenario, as 3 layers is more than 2 layers. But you necessarily weaken some other stretch in a zero-sum fashion, as…
If you're on a WPA2 network you just have to observe a device connecting and you can crack their session key. It's very easy. Not that you need to do that, you could ARP spoof. Or the router could be hacked.
And you don't have to break HTTPS to have a good chance of attacking someone. There's enough HTTP around.
So it's easy to fall through both of those layers.