Wi-Fi security · Plain-English answer
Treat it as untrusted. Hotel networks are shared with every guest, often run on ageing equipment, and frequently skip client isolation, so other devices can see yours. The password on the key card controls entry, not security. HTTPS protects most browsing, and a VPN covers everything else your device sends.
A hotel network is a small ISP run as an afterthought. Hundreds of strangers share it, the hardware may not have seen a firmware update in years, and configuration quality varies enormously between properties. Client isolation, the setting that stops guests' devices talking to each other, is often missing, which leaves your laptop visible to every other room.
The password on your key card only gates access to the network. It says nothing about who else is on it or how well it is run, and hotel networks have historically been targeted precisely because travellers do valuable things on them.
HTTPS covers the contents of most browsing, so the practical additions are a VPN for everything else and a little portal caution. Connect the VPN as soon as you are through the hotel's login page, and it hides your browsing from the network and shields you from other guests. Keep any Allow LAN setting off, and mark the network as public so your device stops advertising file shares.
Give the captive portal the minimum it demands, since room number and surname forms are collection points, not security features.
ROOT VPN is free to start with unlimited data, no card needed, and no activity logs.
Get ROOT VPN, free