Guide
Public Wi-Fi checklist
Disclosure: Kit & Key is an independent privacy-stack site. Some links on this page are affiliate links. If you buy through them, we may earn a commission. That does not change the price you pay. It does change which paid tools we can recommend with a straight face. Mullvad and Bitwarden are unpaid controls. We do not earn anything when we point you there. How we choose tools.
Cafe and hotel Wi-Fi is a network you do not control. This is the pocket version of the Cafe Wi-Fi Privacy Kit. Print it. Do the home block once. Use the other two blocks every time you sit down.
The order does not change: password manager, antivirus, VPN. Why the manager comes first.
This page is meant to print. Use your browser’s print dialog.
Before you leave home
Do this on a network you already trust.
- Install a password manager. Cafe default is 1Password. Proton Pass if you already want Proton. Bitwarden is the unpaid control.
- Turn on the browser extension and Autofill. Save a unique password for email. Save a unique password for the VPN.
- Change the two or three reused logins you will actually open on cafe Wi-Fi.
- Install Malwarebytes. Real-time protection is Malwarebytes Premium Security (or the trial). Malwarebytes Free is scan-only. It is not always-on antivirus.
- On Mac, grant Full Disk Access first or the real-time layers stay inactive.
- Turn Real-Time Protection on after install if it is not already on.
- Run one full scan at home. Do not do that on cafe bandwidth.
- Install the VPN. Cafe default is Proton VPN. NordVPN is the other paid pick. Surfshark if one login has to cover a household (that is the family kit). Mullvad is the unpaid control.
- Kill switch: on. Proton calls it Kill switch. On Windows, Standard is the default mode. Advanced is not on Mac. NordVPN’s Windows name is Internet Kill Switch.
- Auto-connect: Proton Windows is Auto startup. Proton Mac is auto connect when the app starts. NordVPN is Auto-connect, set to On Wi-Fi networks (or On all networks). Proton has no consumer setting named untrusted networks.
- Protocol: leave the default (WireGuard / NordLynx).
- Connect once at home so you know the app works. Disconnect.
- Screen lock on. FileVault or BitLocker if it is not on already.
On the network
In this order.
- Join the Wi-Fi.
- Complete the captive portal (“Accept” / room number / email).
- Then connect the VPN.
- Then work.
- If Kill switch or Internet Kill Switch is already blocking all non-VPN traffic, the portal page may not load. That is expected. NordVPN’s own Kill Switch page says public Wi-Fi sign-ins may require turning it off briefly. Portal first. Tunnel second.
- Do not type passwords by hand. Let the manager fill them.
- Do not turn the VPN off to “make Slack faster.” If a site misbehaves, switch servers. If it still misbehaves, use your phone as a hotspot for that one task. Leaving the tunnel down on cafe Wi-Fi defeats the kit.
If something feels wrong
- Leave the tunnel up unless you must reach a captive portal. Then portal first, tunnel second.
- If the VPN will not connect, use your phone as a hotspot. Do not sit on raw cafe Wi-Fi to send one email.
- If Autofill refuses a page, that can be a fake domain. Do not paste the password by hand.
- If you downloaded a file you did not expect, do not open it on the cafe network. Scan it at home with Malwarebytes.
- If the laptop already looks compromised (new extensions, locked files, a login you did not type), stop. This checklist does not clean a machine that is already owned. Go home.
- Close the lid when you walk away. Screen lock is not optional.
Kits this belongs to
- Cafe Wi-Fi Privacy Kit is the full version of this page.
- Family Privacy Kit if the same login has to cover a household.
- Freelancer Privacy Stack if the rest of the week is invoices and client Wi-Fi.
- Password manager first if you have not installed the manager yet.