Monday's study showed you can't count on a router maker to tell you what it collects. So set the router up to give away as little as possible. Open your router's settings (usually 192.168.1.1 or the vendor's app) and work down this list. Most are one toggle, and you only do them once.

1. Change the admin password

This is the login for the router's settings, not your Wi-Fi password. If it's still the default printed on the box, anyone who can reach the router can change everything. Set a long, unique one.

2. Update the firmware, then turn on auto-updates

Old firmware is how the camera and router flaws we cover get exploited. Update now, and set it to update itself.

3. Use WPA3 and a long Wi-Fi password

Pick WPA3 if your router offers it, WPA2 if not. Make the Wi-Fi password long. Length beats complexity.

4. Set an encrypted DNS resolver

Point the router at a resolver you trust, like Quad9 (9.9.9.9, Wednesday's resource), and turn on encrypted DNS if the router supports it. Now every device is covered.

5. Put smart-home gadgets on a guest network

Create a separate guest network and connect your TV, speakers, and other IoT devices to it. If one gets hacked, it can't reach your phone or laptop.

6. Turn off remote management, UPnP, and WPS

These let devices (or people) outside your control open the network up. If you don't use them, switch them off.

7. Add "_nomap" to your Wi-Fi name

Rename your network to end in nomap (MyWiFi becomes MyWiFinomap) to opt out of Google's and Apple's Wi-Fi location databases.

8. Prefer local management

Where you can, run the router without a required vendor cloud account. That's the account that collects your name, email, and address.

Quick tip

The single highest-impact step for most homes is the guest network. Move every smart gadget onto it this weekend, so a cheap hacked device can't see the computer with your tax returns on it.

Up next · Monday

The week's most important privacy story, in plain English: what happened, why it matters, and what to do about it.