Field Brief #006: Free WiFi Rules from CISA for Summer Travel

Airports, hotels, cafes, conferences - free WiFi is where attackers wait for you. The three-rule pre-flight card from CISA, plus the two-minute setup.

Field Brief #006: Free WiFi Rules from CISA for Summer Travel

Your action plan

RecognizeCheck advisory level, route, embassy alert, and date
ActOpen embassy app; save contact and offline route
VerifyConfirm STEP status and saved embassy contact record
In this guide
  1. Rule 1 - Assume the network is hostile {#rule-1}
  2. Rule 2 - Encrypt everything {#rule-2}
  3. Rule 3 - Do not authenticate anything sensitive {#rule-3}
  4. The two-minute pre-flight card {#pre-flight}
  5. What to remember
Sources and verification

Claims and links last reviewed July 22, 2026.

Field Brief #006 - The Free WiFi Trap: Three Rules from CISA for Summer Travel

Last reviewed: 2026-07-21 · Sources: 3.

Independent. This is the field-card version - not the deep guide.

Airports, hotels, cafes, conferences. Free WiFi is convenient. It is also where attackers wait for you.

You do not have to stop using public WiFi. You have to change how you use it. Three rules from CISA's public WiFi guidance cover it.

Quick Brief.

  • Assume the network is hostile. Every packet you send crosses hardware you do not control.
  • Encrypt everything. VPN + HTTPS-only in your browser + always-on device firewall.
  • Do not authenticate anything sensitive. Save the online banking, the tax filing, the health portal for a network you own.

Rule 1 - Assume the network is hostile {#rule-1}

CISA's guidance is blunt: any device that connects to a public network can be a target. The person next to you does not need to be a hacker. The router itself can be malicious, silently.

Two behaviors to change:

  • Forget the network after you leave. Your device will otherwise auto-reconnect on the next trip through the same airport.
  • Turn off file sharing and AirDrop-style discovery. If your laptop or phone advertises itself on the network, you are on the menu.

Rule 2 - Encrypt everything {#rule-2}

The single largest attack on public WiFi is not sophisticated. It is a rogue access point named "Airport-WiFi" that logs everything unencrypted flowing through it. HTTPS solves this for websites. A VPN solves it for everything else.

  • Browser: turn on HTTPS-Only mode. Chrome, Firefox, Safari, and Edge all have it. Every non-HTTPS site now warns you.
  • VPN: on for the whole session. Public WiFi is the one use case where a VPN is not paranoia - it is table stakes.
  • Firewall: on. Every laptop and phone ships with one. It stays on.

Rule 3 - Do not authenticate anything sensitive {#rule-3}

Even with a VPN, some transactions do not belong on shared infrastructure. If the credential is high-value and re-issue is painful, use cellular data instead.

  • Banking - cellular or wait.
  • Tax filing - same.
  • Health portals - same.
  • Corporate SSO into first-time systems - same.

Read-only email, browsing, streaming - fine on public WiFi with a VPN. Anything that changes the state of a sensitive account - do not.

The two-minute pre-flight card {#pre-flight}

Before you leave for the airport:

  1. VPN app installed and tested at home.
  2. HTTPS-Only mode enabled in your browser.
  3. File sharing / AirDrop disabled.
  4. Firewall on.
  5. Cellular hotspot ready as a fallback.

That is the entire setup. It does not take a security expert. It takes ten minutes once.

For the longer treatment - including the specific ways rogue access points harvest credentials, the difference between free-vs-paid airport WiFi, and how to recognize an evil-twin network before you connect - the full public WiFi safety guide walks through each with screenshots. The VPN buyer's guide covers which providers to trust for the encryption step, and the travel security guide covers the broader pre-trip setup, including passport photos, device-loss recovery, and the hotel-room security posture that pairs with these WiFi rules.

What to remember

Public WiFi is a tool with a known failure mode. The three rules - assume hostile, encrypt everything, do not authenticate sensitive - are the mitigations for that failure mode. They are not paranoia. They are the same posture every enterprise security team teaches.

If you are building a travel kit for the first time, the Silent Security kit builder walks you through the same decisions in a step-by-step form - VPN, backup power, spare charging cable, faraday sleeve. Get the setup right once and it lasts for years of travel.

Get the weekly Silent Security briefing - one threat, one fix, one product, every Tuesday. No spam, no sponsored content. Subscribe from the footer of any page.

Source notes

Every claim in this brief is grounded in one of two primary sources. The three-rule framing ("assume hostile / encrypt everything / do not authenticate sensitive") is a plain-language restatement of CISA's public guidance on wireless network security. The technical detail on why unencrypted traffic on shared infrastructure is trivially harvestable, and why VPN + HTTPS is the standard mitigation, is drawn from NIST SP 800-153. No vendor whitepapers, no marketing sources, no aggregators.

Sources


Silent Security Solutions. Independent. Disabled Veteran Owned.

Was this guide useful?

Report outdated information

Share this post

← All Posts Check Your Security Score →