Our forum talks about the built-in firewall plenty often, including how to tweak it to allow SSH over wifi for root shell on the kindles. As we explain, you need the real root password when doing that, which indicates that the firewall is more strict for wifi than it is for USBnet, so your fears are unfounded in this case (but not in all cases, as Edward Snowden has demonstrated).
However, I am curious why you want to "borrow" wifi bandwidth from potentially compromised wifi hotspots. You can be tracked and identified anyway, because wifi protocols leak your MAC address.