Borrowed Laptops and Hotel Business Centres: What a VPN Cannot Fix
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
There is a specific situation where the usual advice quietly stops applying: when the computer itself belongs to somebody else. A hotel business centre, a library terminal, a print shop, a conference machine, a friend's laptop, a shared family desktop. People reach for a VPN here out of habit, and it is close to useless, for a reason worth understanding — a VPN protects data in transit, and on an untrusted machine the exposure happens before anything is in transit at all.
Where the Exposure Actually Sits
A VPN encrypts the journey between your device and a server. That is the right defence when the network is the suspect part, which is the case in a café or an airport and is why the advice is so widely repeated. On a machine you do not control, the suspect part is the machine. Anything capable of recording what you type does so at the keyboard, before encryption exists; anything capable of reading the screen reads the decrypted page, after encryption has already done its job. Software that logs keystrokes, a browser extension that reads page content, a saved-password store that keeps what you enter, screen-capture software, or simply a browser profile that stays signed in after you leave — none of these care in the slightest that the connection was encrypted. Running a VPN on a borrowed computer moves the encryption endpoint and leaves both ends of the actual problem untouched. It is not harmful; it is answering a question nobody asked.
Private Browsing Is Not a Defence Either
The other reflex is a private or incognito window, and it is worth being precise about what that does. It stops the browser writing history, cookies and form data to that profile when the window closes, which is genuinely useful against the next person who sits down and clicks around. It does nothing about software running on the machine, because that software sees the same keystrokes and the same pixels either way. Treat private mode as tidying up after yourself rather than as protection from the environment — good practice, and not the thing standing between you and a compromised terminal. The same applies to clearing the browser afterwards: worth doing, aimed at the casual observer, and irrelevant to anything with actual access to the system.
What to Do Instead
The most reliable move is to not use the machine for anything that matters. Read the news, print a boarding pass, look up an address — fine. Bank, email, work systems and anything holding a payment method: use your own phone instead, on mobile data if the network is questionable. That sounds like an evasion of the question, but it is the honest answer, because there is no configuration that makes an untrusted computer trustworthy. Where you genuinely have no alternative, reduce what a compromise can reach rather than trying to prevent it: sign in with a second factor so that a captured password is not sufficient on its own, prefer an app-based code or a security key over SMS, and sign out explicitly rather than closing the window. That last one is not fussiness: closing a browser window frequently leaves the session cookie intact, and a live session cookie is as good as the password to whoever sits down next — signing out is what tells the service to invalidate it. And treat anything you type there as potentially recorded, which means changing that password afterwards from a device you do trust — the point of the second factor is to buy you the time to do exactly that.
Do Not Sign In to Your Password Manager on It
This one deserves its own warning, because the instinct is entirely understandable and the consequence is the worst on the list. Unlocking your password manager on an untrusted machine exposes not one credential but every credential you own, and it hands over the master password that protects them. If you need one password on a shared computer, retrieve it on your phone and type it in manually, or use the manager's own one-time sharing feature if it has one. The same applies to signing into a browser profile that syncs your saved passwords — that pulls the whole vault onto a machine you are about to walk away from. A password manager makes uniqueness practical, which is exactly why it is the account that must never touch a computer you do not control. Our comparison of password managers covers how the major ones handle sharing a single credential without unlocking the vault.
Work Laptops Are a Different Case
A machine issued by your employer is not untrusted in the same sense, but it is not private either, and conflating the two causes real problems. Managed devices commonly carry monitoring and management software as a matter of policy, and depending on the configuration, traffic may be inspected at the corporate boundary even when it is encrypted, because the organisation controls the certificate store on its own hardware. That is generally lawful and disclosed in an acceptable-use policy, and it means a personal VPN on a work laptop is at best ineffective and at worst a policy breach that is trivially visible to whoever administers the fleet. The practical rule is simple: do personal things on personal devices. If you need privacy from your employer, the answer is a device your employer does not own, not a clever configuration on one they do.
So When Is the VPN the Right Tool?
When the network is the untrusted part and the device is yours. That is the café, the hotel Wi-Fi, the airport, the conference network, the apartment you are renting for a week — every situation where you control the endpoint but not the path between it and the internet. In those cases a VPN is not a nice-to-have, it is precisely the correct tool, and it is why we recommend one for travel and for anyone regularly on networks they do not own. What it cannot do is extend that protection to a computer that was compromised before you sat down at it. Knowing which of the two situations you are in is most of the skill. The VPN privacy guide sets out the protection model in full, do you really need a VPN is the honest buying question, and if you travel a lot the VPN and eSIM combination covers keeping your own connection rather than depending on anyone else's.
Frequently Asked Questions
Does a VPN protect me on a public or borrowed computer?
Barely. A VPN encrypts data in transit, and on a machine you do not control the exposure is at the keyboard and the screen — before encryption and after decryption. The right tool for an untrusted device is a different device.
Is incognito mode enough on a shared computer?
No. Private browsing stops the browser saving history, cookies and form data, which protects you from the next person to use it. It does nothing about software already running on the machine, which sees the same keystrokes either way.
Can I log into my password manager on a hotel computer?
Do not. Unlocking the vault there exposes every credential you own plus the master password. Look the one password up on your phone and type it manually, or use the manager's one-time sharing feature.
Should I use a personal VPN on my work laptop?
Generally no. Managed devices carry monitoring software and the organisation controls the certificate store, so it is often ineffective and may breach the acceptable-use policy. Do personal things on a personal device.
What should I do after using a shared computer for something important?
Sign out explicitly rather than closing the window, then change that password from a device you trust. Having a second factor on the account is what buys you the time to do that before a captured password can be used.
Also worth comparing
Other providers we recommend for this topic. Sponsored links — we may earn a commission at no extra cost to you.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy