Field Brief #006 - The Free WiFi Trap: Three Rules from CISA for Summer Travel
Last reviewed: 2026-07-21 · Sources: 3.
Independent. This is the field-card version - not the deep guide.
Airports, hotels, cafes, conferences. Free WiFi is convenient. It is also where attackers wait for you.
You do not have to stop using public WiFi. You have to change how you use it. Three rules from CISA's public WiFi guidance cover it.
Quick Brief.
- Assume the network is hostile. Every packet you send crosses hardware you do not control.
- Encrypt everything. VPN + HTTPS-only in your browser + always-on device firewall.
- Do not authenticate anything sensitive. Save the online banking, the tax filing, the health portal for a network you own.
Rule 1 - Assume the network is hostile {#rule-1}
CISA's guidance is blunt: any device that connects to a public network can be a target. The person next to you does not need to be a hacker. The router itself can be malicious, silently.
Two behaviors to change:
- Forget the network after you leave. Your device will otherwise auto-reconnect on the next trip through the same airport.
- Turn off file sharing and AirDrop-style discovery. If your laptop or phone advertises itself on the network, you are on the menu.
Rule 2 - Encrypt everything {#rule-2}
The single largest attack on public WiFi is not sophisticated. It is a rogue access point named "Airport-WiFi" that logs everything unencrypted flowing through it. HTTPS solves this for websites. A VPN solves it for everything else.
- Browser: turn on HTTPS-Only mode. Chrome, Firefox, Safari, and Edge all have it. Every non-HTTPS site now warns you.
- VPN: on for the whole session. Public WiFi is the one use case where a VPN is not paranoia - it is table stakes.
- Firewall: on. Every laptop and phone ships with one. It stays on.
Rule 3 - Do not authenticate anything sensitive {#rule-3}
Even with a VPN, some transactions do not belong on shared infrastructure. If the credential is high-value and re-issue is painful, use cellular data instead.
- Banking - cellular or wait.
- Tax filing - same.
- Health portals - same.
- Corporate SSO into first-time systems - same.
Read-only email, browsing, streaming - fine on public WiFi with a VPN. Anything that changes the state of a sensitive account - do not.
The two-minute pre-flight card {#pre-flight}
Before you leave for the airport:
- VPN app installed and tested at home.
- HTTPS-Only mode enabled in your browser.
- File sharing / AirDrop disabled.
- Firewall on.
- Cellular hotspot ready as a fallback.
That is the entire setup. It does not take a security expert. It takes ten minutes once.
For the longer treatment - including the specific ways rogue access points harvest credentials, the difference between free-vs-paid airport WiFi, and how to recognize an evil-twin network before you connect - the full public WiFi safety guide walks through each with screenshots. The VPN buyer's guide covers which providers to trust for the encryption step, and the travel security guide covers the broader pre-trip setup, including passport photos, device-loss recovery, and the hotel-room security posture that pairs with these WiFi rules.
What to remember
Public WiFi is a tool with a known failure mode. The three rules - assume hostile, encrypt everything, do not authenticate sensitive - are the mitigations for that failure mode. They are not paranoia. They are the same posture every enterprise security team teaches.
If you are building a travel kit for the first time, the Silent Security kit builder walks you through the same decisions in a step-by-step form - VPN, backup power, spare charging cable, faraday sleeve. Get the setup right once and it lasts for years of travel.
Get the weekly Silent Security briefing - one threat, one fix, one product, every Tuesday. No spam, no sponsored content. Subscribe from the footer of any page.
Source notes
Every claim in this brief is grounded in one of two primary sources. The three-rule framing ("assume hostile / encrypt everything / do not authenticate sensitive") is a plain-language restatement of CISA's public guidance on wireless network security. The technical detail on why unencrypted traffic on shared infrastructure is trivially harvestable, and why VPN + HTTPS is the standard mitigation, is drawn from NIST SP 800-153. No vendor whitepapers, no marketing sources, no aggregators.
Sources
- CISA. Securing Wireless Networks (Cybersecurity & Infrastructure Security Agency). cisa.gov/news-events/news/securing-wireless-networks
- NIST SP 800-153. Guidelines for Securing Wireless Local Area Networks (WLANs). csrc.nist.gov/pubs/sp/800/153/final
Silent Security Solutions. Independent. Disabled Veteran Owned.