Andrew Mercer
on this page

A practical checklist for using coffee shop, airport, and hotel Wi-Fi without exposing your traffic or your laptop.

1. Understanding the Risks

Public Wi-Fi (coffee shops, airports, hotels, conferences) is risky mainly because you share a broadcast-ish medium and often a single access point with strangers, and you have no idea how that network is configured or who else is on it.

Concrete threats:

  • Rogue/evil-twin access points — an attacker sets up a Wi-Fi network with the same name as the legitimate one ("Airport_WiFi") and waits for devices to auto-connect, putting all your traffic through their machine.
  • Man-in-the-middle (MITM) attacks — on a shared network, an attacker can position themselves between you and the router (ARP spoofing on older networks, or simply controlling the access point itself) and intercept or modify unencrypted traffic.
  • Packet sniffing — on networks with weak or no encryption, traffic can be captured and read by anyone else on the same network with basic tools.
  • Malicious captive portals — the "click to agree" login page some hotspots show can be spoofed to harvest credentials or push malware.
  • Session hijacking — if a site's session cookie is sent over plain HTTP, it can be captured and reused to impersonate you on that site.
  • Local network exposure — file sharing, AirDrop, or network discovery features can expose your laptop to other devices on the same subnet.

The practical upshot: assume every public network is hostile by default and unencrypted traffic on it is potentially visible to someone else in the room.

2. Before You Connect

  • Verify the network name with staff. Evil-twin networks often use a near-identical name (Starbucks-Guest vs Starbucks_Guest). Ask an employee for the exact SSID rather than picking the most obvious one from the list.
  • Turn off Wi-Fi auto-connect for open/unsecured networks in your OS settings, so your laptop doesn't silently join a network you've connected to before (or one spoofing that name) without you noticing.
  • Forget old public networks periodically. Saved networks named things like "Airport Wi-Fi" will auto-join anywhere with that same broadcast name.
  • Turn off file sharing, AirDrop, and network discovery before connecting — Windows: set the network profile to Public; macOS: System Settings → General → Sharing, disable everything; Linux: check your firewall (see Section 5).
  • Update your OS and browser beforehand if possible — you don't want to be pulling security patches over the same untrusted network you're trying to protect yourself from.
  • Have your VPN client ready to auto-connect (Section 3) so there's minimal window between joining the Wi-Fi and having your traffic protected.

3. Use a VPN

A VPN is the single biggest thing you can do here: it encrypts everything leaving your laptop before it ever touches the local Wi-Fi, so a rogue access point or a nosy fellow patron sees only opaque encrypted traffic.

Using your own WireGuard tunnel: since you already run WireGuard back to your OPNsense home lab (see the companion setup guide), you have a ready-made private VPN. On public Wi-Fi, switch that client config to a full tunnel rather than the split tunnel used for lab access:

[Peer]
...
AllowedIPs = 0.0.0.0/0, ::/0

This routes all traffic — not just home-lab-bound traffic — through the encrypted tunnel to OPNsense, which then forwards it out your home internet connection. To anyone on the coffee shop network, your traffic is indistinguishable encrypted noise.

Trade-offs of self-hosting the VPN endpoint:

  • ✅ You control the endpoint completely — no third-party VPN provider logging your traffic.
  • ✅ Uses your home IP as the exit point, useful for accessing geo-restricted home services or appearing to browse from home.
  • ⚠️ Your home upload bandwidth becomes the bottleneck for all your browsing while connected — fine for browsing/email, may be noticeably slower for heavy downloads or video calls.
  • ⚠️ If your home internet or OPNsense box goes down, the tunnel goes down too (some people keep a commercial VPN as a fallback).

If you don't have your VPN handy: a reputable commercial VPN provider (audited no-logs policy) is far better than nothing, but understand you're shifting trust from the coffee shop to that provider.

Never rely on the network's own "VPN" or "secure" branding — some hotel/airport networks advertise built-in protections that offer little real security.

4. Browser & DNS Hygiene

Even with a VPN, layer these — VPNs can misbehave (leaks, drops) and defense in depth costs little:

  • Confirm HTTPS everywhere. Modern browsers flag plain-HTTP sites; pay attention to those warnings on public networks specifically. Consider an extension like HTTPS-only mode (built into Firefox and Chrome now under browser settings — no third-party extension needed).
  • Use encrypted DNS. Plain DNS queries are readable by anyone on the network and reveal every site you visit even if the page itself is HTTPS. Enable DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) in your OS or browser settings, or point DNS at a provider like Cloudflare (1.1.1.1) or Quad9 (9.9.9.9) with encryption enabled. If you're on your WireGuard tunnel, your DNS queries already ride encrypted inside it.
  • Avoid entering credentials on unfamiliar captive portals. Legitimate hotel/airport portals rarely need more than a room number or email — anything asking for a password you use elsewhere is a red flag.
  • Log out of sensitive sessions you don't need active (banking, work systems) before connecting to a public network, especially if not using a VPN.
  • Be skeptical of unexpected browser or software update prompts while on public Wi-Fi — a MITM position can be used to serve fake update dialogs that install malware. Update through the OS's own trusted update mechanism, not a pop-up.
  • Use a password manager rather than typing passwords manually — it also helps avoid phishing pages that mimic real sites, since it won't autofill on a lookalike domain.

5. Device & Network Hardening

  • Enable your OS firewall and set it to block incoming connections by default:
  • macOS: System Settings → Network → Firewall
  • Windows: set the network profile to Public (this automatically tightens Windows Defender Firewall rules)
  • Linux: sudo ufw enable with a default-deny incoming policy (sudo ufw default deny incoming)
  • Disable Bluetooth discoverability when not actively pairing something — it's a smaller but real attack surface in crowded public spaces.
  • Full-disk encryption (FileVault, BitLocker, LUKS) protects your data if the laptop itself is lost or stolen while traveling — separate risk from network snooping, but travel is when both risks spike together.
  • Keep a screen lock with a short timeout and require a password/biometric to wake — shoulder-surfing and momentary unattended laptops are a real risk in public spaces.
  • Consider a hardware privacy screen for airports/trains where people sit close enough to read your screen.
  • Prefer your phone's mobile hotspot over unknown public Wi-Fi when the option exists and signal is good — you trust your carrier's network far more than an arbitrary café's router, and it sidesteps most of the risks above entirely.

6. Quick Checklist & What to Avoid

Before/while connecting:

  • [ ] Confirm the exact SSID with staff
  • [ ] Auto-connect to open networks disabled
  • [ ] File sharing / AirDrop / network discovery off, network profile set to Public
  • [ ] VPN connected (full tunnel) before browsing anything sensitive
  • [ ] OS firewall enabled, default-deny incoming
  • [ ] Screen lock with short timeout active

Avoid entirely on untrusted public Wi-Fi, even with a VPN as backup:

  • Online banking or moving money, if it can wait until you're on trusted network
  • Entering a password you don't already protect with 2FA
  • Accepting unexpected "update" or "certificate" prompts from the browser
  • Leaving Bluetooth/AirDrop discoverable
  • Using the same password across sites (a password manager fixes this everywhere, not just on public Wi-Fi)
  • Trusting a network's own "secure connection" or "VPN included" marketing at face value

When in doubt, the mobile hotspot from your own phone plan is almost always the safer default over an unfamiliar public access point.