Monday's study showed you can't count on a router maker to tell you what it collects. So set the router up to give away as little as possible. Open your router's settings (usually 192.168.1.1 or the vendor's app) and work down this list. Most are one toggle, and you only do them once.
1. Change the admin password
This is the login for the router's settings, not your Wi-Fi password. If it's still the default printed on the box, anyone who can reach the router can change everything. Set a long, unique one.
2. Update the firmware, then turn on auto-updates
Old firmware is how the camera and router flaws we cover get exploited. Update now, and set it to update itself.
3. Use WPA3 and a long Wi-Fi password
Pick WPA3 if your router offers it, WPA2 if not. Make the Wi-Fi password long. Length beats complexity.
4. Set an encrypted DNS resolver
Point the router at a resolver you trust, like Quad9 (9.9.9.9, Wednesday's resource), and turn on encrypted DNS if the router supports it. Now every device is covered.
5. Put smart-home gadgets on a guest network
Create a separate guest network and connect your TV, speakers, and other IoT devices to it. If one gets hacked, it can't reach your phone or laptop.
6. Turn off remote management, UPnP, and WPS
These let devices (or people) outside your control open the network up. If you don't use them, switch them off.
7. Add "_nomap" to your Wi-Fi name
Rename your network to end in nomap (MyWiFi becomes MyWiFinomap) to opt out of Google's and Apple's Wi-Fi location databases.
8. Prefer local management
Where you can, run the router without a required vendor cloud account. That's the account that collects your name, email, and address.
Quick tip
The single highest-impact step for most homes is the guest network. Move every smart gadget onto it this weekend, so a cheap hacked device can't see the computer with your tax returns on it.
Up next · Monday
The week's most important privacy story, in plain English: what happened, why it matters, and what to do about it.
