Start with what the network can actually do

A hotel network sits between your device and the internet. That means the operator can usually observe connection metadata, influence name resolution, and present captive-portal pages. It does not mean every encrypted session is immediately readable.

Modern HTTPS protects far more than the old public-Wi-Fi warnings imply. The useful question is not whether the network is “safe.” It is whether your device, browser and login habits still behave safely when the network is untrusted.

The practical controls

Keep the device and browser updated. Check that important sites use HTTPS. Use multi-factor authentication. Do not install unknown captive-portal software or profiles. Treat unexpected certificate warnings as a reason to stop, not click through.

A personal hotspot or trusted VPN is appropriate when the work, data or location justifies the extra control. It is a proportional decision, not a ritual.