Wi-Fi security basics: passwords, guest networks, and safer settings
Your router is the front door of your digital home — every device you own walks through it. Yet most people never change a single default setting. The good news: you don't need to become a security expert. A few settings, changed once, close the easy doors and stop the opportunistic problems. Here's what actually matters, in order.
1. Change the router's admin password
Your router has two passwords, and people mix them up. The Wi-Fi password is
what devices use to join the network. The admin password is what you use to log
into the router's settings page — and it ships from the factory as something guessable
like admin/admin. Anyone on your network (or who guesses their
way onto it) can log in with the default and change your settings. Open the router's
admin page (the address is usually printed on the router's label) and set a unique admin
password first. This is the single most-skipped step in home network security.
2. Use a strong Wi-Fi password with modern encryption
In the router's wireless settings, check the security type. It should say WPA2 or WPA3 (or "WPA2/WPA3"). If it says WEP — an ancient, thoroughly broken standard — change it immediately; some very old routers still default to it. Then set a Wi-Fi password that's long and unique to the router: a passphrase of four or five random words is both strong and easy to type when guests visit. Don't reuse your email password, and don't keep the password printed on the router's label forever — that's fine as a starting point, but it's better to change it to something only your household knows.
3. Set up a guest network
Nearly every modern router can broadcast a second network just for guests and smart devices, isolated from your main network. Turn it on and use it for:
- Visitors — they get internet without getting access to your computers, printers, and file shares.
- Smart home gadgets — cameras, doorbells, bulbs, and cheap smart plugs have a poor security track record. If one of them gets compromised, isolation keeps it away from your laptop and your banking.
- Kids' friends' devices — same logic as visitors, more frequent.
Give the guest network its own password (it doesn't have to be as precious as your main one), and leave it running. It's the cheapest meaningful upgrade in this entire guide.
4. Keep the router's firmware updated
Router manufacturers patch security holes through firmware updates, and most routers do not install them on their own. Check the admin page for a firmware or software update section — some routers offer an automatic-update toggle, which is worth enabling. If your router hasn't been updated in years (or the manufacturer no longer offers updates for your model), that's a sign worth noting: an unpatchable router is a liability. This alone is a common reason people end up replacing old hardware.
5. Turn off features you don't use
A few router features are convenient but expand the attack surface:
- WPS (the push-button connect feature) — convenient for adding devices without typing a password, but its PIN mode has known weaknesses. Disable it and type passwords instead.
- Remote administration — lets you manage the router from anywhere on the internet. Unless you genuinely use this, turn it off; it exposes the admin login to the whole world.
- UPnP — lets devices automatically open ports in your router. Some game consoles and apps want it, but if you don't need it, disabling it removes a classic attack path.
None of these will break normal browsing, streaming, or smart devices. They just remove doors you weren't using.
6. Know what's connected
Once in a while, glance at the connected-devices list in the router's admin page. You should recognize everything on it. An unfamiliar device is worth investigating — it could be a forgotten gadget, a neighbor who guessed the old password, or something more serious. If anything looks wrong, change the Wi-Fi password; every device will have to rejoin with the new one, which boots off anything that shouldn't be there.
None of this takes more than an afternoon, and most of it is set-and-forget. Security on a home network isn't about paranoia — it's about not leaving the defaults in place.