How to Secure Devices and Accounts on Public Wi-Fi
Treat café networks as hostile: VPN on, HTTPS everywhere, disk encrypted before you sit down.
[ journal ]
Café Wi-Fi is a shared hallway with no lock. I assume someone else on the network is curious, incompetent, or both. That is not paranoia as a personality. That is the threat model for a laptop that holds mail, tokens, and the work I am supposed to ship from Tāmaki Makaurau as easily as from New Orleans.
VPN on before I do anything I would mind leaking. The VPN is not magic, and a bad VPN is just another company in the path. I still want encryption to a network I chose, not to whoever named the SSID “Airport_Free.” If the VPN will not connect, I tether. I do not “just send this one email” on the raw public AP.
HTTPS is the floor, not a nice-to-have. I notice when a site fails to lock. I do not log into banking, payroll, or admin consoles on a network I do not trust, even with the VPN, if I have a cellular option. Airport lounges feel professional. They are still public.
Disk encryption is decided at home, not at the café. Full-disk on, strong passphrase, auto-lock short enough that a bathroom trip does not leave a session open. If the bag walks, I want a brick, not a filing cabinet. This is separate from the physical kit: cable locks, bag placement, the theater of watching a room. Those are another note. This one is the radio.
I keep software updates current enough that I am not the oldest browser on the network. I do not use the café’s “log in with Facebook” captive portal on a browser profile that holds work sessions. A throwaway profile or the phone’s hotspot is cheaper than a stolen cookie.
Account hygiene (password manager, hardware keys, not recycling logins) still matters, and it is not the same job as network hygiene. On public Wi-Fi the job is: assume the path is hostile, encrypt what you can, and keep the valuable logins off the worst paths. Then finish the work and leave. The flat white does not require you to live on that SSID all afternoon.
— JV · Dark Heart Labs.