Total Defense

Security & Safety Resource Center

Learn about today's current internet threats and how to stay safe and secure.

Security Tip of the Day

Daily tips to create awareness of cyber threats and empower Total Defense users to be safer and more secure online with our security tips and resources..


September 2026
09.08.26

Stop auto-connecting to Wi‑Fi and Bluetooth to make your devices safer

Most people think cybersecurity starts with strong passwords and antivirus software. While those are important, one of the easiest ways to improve your digital security is hiding in your smartphone settings: turning off automatic Wi‑Fi and Bluetooth connections.

Many smartphones and tablets constantly search for nearby networks and devices. This feature is convenient, but it can also create opportunities for cybercriminals to intercept data, track devices, or trick users into connecting to malicious networks.

If you’re looking for a simple security setting that can immediately reduce your exposure to online threats, disabling auto-connect for Wi‑Fi and Bluetooth is a smart place to start.

Why do phones automatically connect to Wi‑Fi and Bluetooth?

Device manufacturers enable these features to make life easier. Your phone remembers previously used networks, wireless earbuds, speakers, smartwatches, and vehicle infotainment systems so you can reconnect automatically.

While convenient, automatic connections can create security risks when your device connects without your knowledge.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends disabling wireless features such as Bluetooth and Wi‑Fi when they are not needed because they can increase a device’s attack surface and create unnecessary exposure to threats.

What are the risks of auto-connecting to public Wi‑Fi?

Public Wi‑Fi remains one of the most common attack vectors for travelers and remote workers.

According to the FBI, cybercriminals frequently exploit public wireless networks to steal information, monitor activity, and conduct phishing attacks through fake hotspots.

Common Wi‑Fi risks include:

  • Fake “evil twin” hotspots designed to mimic legitimate networks
  • Unencrypted connections that expose data
  • Man-in-the-middle attacks
  • Device tracking and profiling
  • Malware delivery through compromised networks

Imagine walking into an airport and your phone automatically reconnects to a network it remembers from a previous visit. If an attacker creates a fake version of that network, your device could connect without you realizing it.

What are the risks of leaving Bluetooth on?

Bluetooth is incredibly useful, but it also broadcasts information that can potentially be discovered by nearby devices.

Security researchers and government agencies such as the U.S. National Security Agency (NSA) have long recommended disabling Bluetooth when it isn’t actively being used.

Potential Bluetooth threats include:

  • Unauthorized device pairing attempts
  • Bluetooth tracking
  • Data interception
  • Bluejacking spam messages
  • Exploitation of Bluetooth vulnerabilities

Most modern Bluetooth implementations are much safer than older versions, but reducing exposure remains a cybersecurity best practice.

How does turning off auto-connect make you safer online?

This is one of the most common questions people ask.

The answer is simple: you gain control over when and where your device connects.

When your phone automatically joins networks and devices, it makes decisions without your direct approval.

By manually controlling connections, you:

  • Reduce exposure to rogue networks
  • Prevent accidental connections
  • Lower the risk of wireless attacks
  • Improve location privacy
  • Increase visibility into your device activity

Cybersecurity is fundamentally about reducing unnecessary risk. Disabling automatic connections removes opportunities that attackers often exploit.

How to disable Wi‑Fi auto-connect

Most smartphones have a similar process.

On Android

  1. Open Settings
  2. Select Network & Internet or Connections
  3. Tap Wi‑Fi
  4. Choose a saved network
  5. Disable Auto Connect or Connect Automatically

On iPhone

  1. Open Settings
  2. Tap Wi‑Fi
  3. Select the information icon next to a saved network
  4. Disable Auto‑Join

Review your saved networks regularly and remove any you no longer use.

How to manage Bluetooth securely

You don’t necessarily need to disable Bluetooth permanently.

Instead, follow these best practices:

  • Turn Bluetooth off when not in use
  • Remove old paired devices
  • Reject unexpected pairing requests
  • Keep your phone updated
  • Avoid pairing in crowded public locations

These simple actions significantly reduce your wireless exposure.

Additional mobile security tips

While you’re updating settings, consider strengthening your device security with these steps:

  • Enable automatic operating system updates
  • Use multifactor authentication whenever available
  • Install apps only from trusted app stores
  • Review app permissions regularly
  • Use a strong screen lock
  • Enable Find My Device features

When multiple security controls work together, attackers have a much harder time compromising your information.

Final takeaway

Disabling automatic Wi‑Fi and Bluetooth connections won’t dramatically change how you use your phone, but it can significantly reduce your exposure to unnecessary security risks.

Every automatic connection is a potential opportunity for a cybercriminal to exploit a trusted relationship between your device and a network or peripheral. By choosing when your device connects, you put yourself back in control.

The next time you review your smartphone settings, take a few minutes to disable auto-connect features. It’s a quick security win that helps protect your privacy, data, and online safety every day.

09.07.26

Turn off your phone’s always-on display to protect your privacy

Most smartphone users focus on strong passwords, biometric logins, and software updates. Those are important security habits, but many people overlook a surprisingly common privacy risk: the always-on display (AOD) feature.

Many Android smartphones and some other devices show the time, date, battery status, and notifications on the screen even when the phone is locked. While that convenience can save a few taps, it can also expose sensitive information to anyone nearby.

If you’re looking for a simple way to strengthen your mobile security today, turning off your phone’s always-on display or limiting notification previews is a smart place to start.

What is an always-on display?

An always-on display is a feature that keeps a portion of your screen active while the device remains locked. Depending on your settings, it may show:

  • Text messages
  • Email notifications
  • Calendar reminders
  • Authentication codes
  • Social media alerts
  • Banking app notifications

The feature is designed for convenience, but convenience and privacy don’t always go hand in hand.

Why can an always-on display be a security risk?

The biggest risk is information exposure.

The U.S. National Institute of Standards and Technology (NIST) specifically warns that sensitive information contained in notifications may be displayed even when a mobile device is locked, allowing someone with physical proximity to gain unauthorized access to that information through lock screen notifications.

Think about everyday situations:

  • Sitting in a crowded coffee shop
  • Waiting at an airport gate
  • Working in a shared office
  • Leaving your phone on a restaurant table
  • Charging your device during a meeting

In each scenario, someone nearby may be able to view information without ever touching your phone.

What kind of information could be exposed?

Many users assume lock screens only show notification icons. In reality, devices can display much more depending on configuration.

Sensitive information commonly exposed includes:

  • One-time verification codes
  • Password reset notifications
  • Email subjects
  • Meeting details
  • Delivery notifications containing addresses
  • Financial transaction alerts
  • Personal text message previews

Even small details can help cybercriminals conduct phishing attacks or social engineering scams.

How does this help someone become safer online?

Cybersecurity is often about reducing the amount of information available to attackers.

When you hide notification content or disable your always-on display:

  • Fewer personal details are visible to strangers
  • Sensitive account information stays private
  • Verification codes are less likely to be exposed
  • Social engineering attacks become harder
  • You gain greater control over your personal data

In other words, you reduce opportunities for criminals to gather information about you.

What should you do instead?

You don’t have to eliminate convenience completely.

A better approach is to limit what appears on your lock screen.

Recommended security settings

Consider making these changes:

  • Turn off the always-on display entirely
  • Hide notification previews on the lock screen
  • Show notification icons only
  • Require biometric authentication before displaying message content
  • Disable lock screen visibility for banking and financial apps
  • Hide email previews while the device is locked

These small adjustments can dramatically improve your privacy without affecting everyday usability.

How to turn off always-on display

The exact steps vary by manufacturer, but generally:

On Android devices

  1. Open Settings
  2. Tap Display or Lock Screen
  3. Select Always-On Display
  4. Toggle the feature Off

On Samsung Galaxy devices

  1. Open Settings
  2. Tap Lock Screen and AOD
  3. Select Always On Display
  4. Turn the feature Off

Review notification privacy settings

While you’re updating security settings, also:

  1. Open Settings
  2. Select Notifications
  3. Tap Lock Screen Notifications
  4. Choose Hide Sensitive Content or Show Icons Only

This provides a balance between awareness and privacy.

Additional smartphone privacy tips

For even stronger protection:

  • Enable automatic software updates
  • Use a strong PIN alongside biometrics
  • Install apps only from trusted sources
  • Remove unused applications
  • Turn on Find My Device capabilities
  • Review app permissions regularly

The National Institute of Standards and Technology’s mobile security guidance emphasizes the importance of securing mobile devices because they routinely store and access sensitive personal and business information.

Final takeaway

Turning off your phone’s always-on display may seem like a small change, but it can have a meaningful impact on your privacy. Every notification preview, authentication code, and message snippet visible on a locked screen represents information that others may see.

By disabling the always-on display or limiting lock screen notification content, you make it harder for strangers, scammers, and opportunistic attackers to gather information about you. It’s one of the quickest mobile security improvements you can make today, and it’s a simple step toward a safer digital life.

09.06.26

Why you should review online privacy policies: A simple habit that helps protect your personal data

Every day, we click “I Agree” without thinking twice.

Whether you’re signing up for a new social media platform, downloading an app, creating an online shopping account, or using a streaming service, you’re likely accepting a privacy policy that explains exactly how your information will be collected, stored, shared, and used.

Most people skip these policies because they’re long and filled with legal language. Unfortunately, that’s where companies often disclose some of the most important details about your personal information.

Reviewing privacy policies may not sound exciting, but it is one of the easiest ways to take more control of your digital life.

What is a privacy policy and why does it matter?

A privacy policy explains how a company handles your data.

It typically outlines:

  • What information is collected
  • How the information is used
  • Whether data is shared with third parties
  • How long information is retained
  • How advertising and tracking work
  • What privacy controls are available
  • How users can delete or request access to their data

Many organizations update their privacy policies regularly as they introduce new products, features, advertising partnerships, or AI-powered services.

When a company sends you a notification about a privacy policy update, don’t ignore it. That update may significantly change how your data is collected or shared.

What personal data do companies typically collect?

Many services collect far more than basic account information.

Depending on the platform, they may gather:

  • Name and email address
  • Phone number
  • Device information
  • Location data
  • Browsing activity
  • Purchase history
  • Search history
  • Advertising interactions
  • Contacts and social connections
  • Photos and uploaded files

Mozilla notes that online services and advertising technologies often collect information about user activity across websites and applications, which can be used to build advertising and behavioral profiles. The organization’s guidance on privacy tools such as Facebook Container highlights how companies may associate activity across multiple websites with a user identity.

Why should you read privacy policy updates?

Privacy policies can change at any time.

A company may update its policy to:

  • Expand data collection
  • Introduce AI features
  • Partner with advertisers
  • Share data with additional vendors
  • Enable new tracking technologies
  • Modify account retention practices

Even a small update can change how much information a business gathers about you.

Instead of deleting the update email immediately, spend a few minutes reviewing the key sections.

Focus on what has changed.

Which sections of a privacy policy are most important?

You do not need to read every word.

Look for these high-impact areas first.

Information collected

This section explains exactly what data is gathered.

Pay attention to:

  • Location tracking
  • Contact access
  • Browsing activity
  • Device details
  • Biometric information
  • Usage analytics

Data sharing and third parties

This section often reveals whether your information may be shared with:

  • Advertising partners
  • Analytics companies
  • Affiliates
  • Data processors
  • Business partners

The more organizations that receive your information, the less control you ultimately have over it.

User controls and privacy settings

Look for tools that allow you to:

  • Opt out of targeted ads
  • Restrict tracking
  • Delete data
  • Download account information
  • Manage consent settings

Data retention

Check whether the company explains:

  • How long it keeps your information
  • What happens after account deletion
  • Whether backup copies remain

How does reviewing privacy policies make someone safer online?

Reviewing privacy policies helps someone become safer online because it reduces surprises.

When you understand how a company handles your information, you can make informed decisions about:

  • What you share
  • Which permissions you grant
  • Which services you trust
  • Whether you want to continue using a platform

This protects:

  • Personal information
  • Browsing habits
  • Location data
  • Financial information
  • Contacts
  • Photos
  • Online identities

Privacy and cybersecurity are closely connected. The less unnecessary information exposed, the less information available to advertisers, scammers, data brokers, and cybercriminals.

How can you review privacy policies without spending hours reading them?

Use this simple process:

Privacy policy review checklist

When a policy changes:

✅ Read the summary of changes

✅ Search the document for “collect”

✅ Search for “share”

✅ Search for “third parties”

✅ Search for “advertising”

✅ Search for “retention”

✅ Search for “location”

✅ Review privacy settings afterward

✅ Disable unnecessary permissions

✅ Decide whether you’re comfortable with the changes

Most privacy policies can be reviewed in less than 10 minutes using this method.

What should you do after reviewing a privacy policy?

Take action when necessary.

You may decide to:

  • Adjust account privacy settings
  • Turn off ad personalization
  • Disable location sharing
  • Remove third-party app access
  • Limit profile visibility
  • Delete old accounts
  • Move to a more privacy-friendly service

Reading the policy is only useful if it informs your decisions afterward.

Red flags to watch for

Pay closer attention if a policy indicates:

  • Extensive third-party sharing
  • Automatic location tracking
  • Broad data retention periods
  • Collection of unnecessary information
  • Vague descriptions of data use
  • Limited user control options

These don’t automatically mean a service is unsafe, but they may influence how much information you choose to provide.

Privacy policies are often treated like internet fine print, but they contain valuable information about how your personal data is handled.

You don’t need to become a legal expert. You simply need to understand the basics: what information is collected, who receives it, how long it’s retained, and what controls are available to you.

09.05.26

5 browser security tips that can stop cyberattacks before they start

Most people think of cybersecurity in terms of antivirus software, firewalls, or password protection. But one of the most targeted applications on your device is the one you use every day: your web browser.

Whether you’re shopping online, managing bank accounts, checking email, working remotely, or scrolling social media, your browser serves as the front door to your digital life. If cybercriminals can trick you through that browser, they may gain access to sensitive accounts, financial information, and personal data.

That’s why browser security matters more than ever.

Why do hackers target web browsers?

Your browser connects you to nearly everything you do online. Attackers know that compromising a browser is often easier than attacking a device directly.

Cybercriminals commonly use:

  • Fake websites
  • Phishing pages
  • Malicious browser extensions
  • Fake software updates
  • Dangerous downloads
  • Session hijacking attacks
  • Stolen browser cookies
  • Malicious advertisements
  • Credential theft campaigns

According to CISA’s guidance on phishing, most online attacks begin with a single click, often involving a malicious link, attachment, or deceptive website.

That makes your browser one of the most important security tools you own.

How can a browser become a security risk?

Many attacks don’t exploit software flaws. Instead, they exploit human behavior.

For example:

  • Clicking a fake login page
  • Downloading a fake PDF reader
  • Installing an unsafe extension
  • Reusing a password
  • Entering credentials into a fraudulent website

The browser itself may be secure, but unsafe browsing habits can create opportunities for attackers.

The joint phishing guidance from CISA, NSA, FBI, and MS-ISAC explains that attackers commonly use phishing websites to steal credentials and deploy malware.

What browser threats should consumers watch for?

Fake websites and phishing pages

Modern phishing websites often look identical to legitimate brands.

Watch for:

  • Misspelled domains
  • Extra words in web addresses
  • Unexpected login prompts
  • Urgent warnings
  • Requests for passwords or verification codes

Always manually verify the website URL before signing in.

Malicious browser extensions

Extensions can improve productivity, but they can also access:

  • Browsing history
  • Website content
  • Saved passwords
  • Cookies
  • Account information

Install extensions only from official browser stores and reputable developers.

Stolen cookies and session hijacking

Cookies help websites remember your login status.

However, criminals sometimes target browser cookies to:

  • Bypass passwords
  • Hijack sessions
  • Access accounts without logging in again

Keeping your browser updated helps reduce this risk.

Fake downloads

Attackers frequently disguise malware as:

  • Browser updates
  • PDF readers
  • Video codecs
  • Tax forms
  • Invoice attachments

If you weren’t planning to download it before seeing the popup, don’t install it without independent verification.

Malicious pop-ups

Fake security warnings often claim:

  • Your computer is infected
  • A virus was detected
  • Immediate action is required

Legitimate operating systems and browsers do not typically use random webpages to demand emergency security actions.

How does browser security help someone become safer online?

Improving browser security helps someone become safer online by reducing exposure to the most common attack methods used by cybercriminals.

Strong browser security helps prevent:

  • Identity theft
  • Account takeovers
  • Financial fraud
  • Malware infections
  • Ransomware attacks
  • Credential theft
  • Social engineering scams
  • Unauthorized account access

Think of your browser as your digital front door. The stronger that door is, the harder it becomes for attackers to get inside.

5 browser security tips everyone should follow

1. Keep your browser updated

  • Browser updates often contain critical security patches.
  • Enable automatic updates whenever possible.
  • An outdated browser may contain vulnerabilities attackers already know how to exploit.

2. Install extensions only from trusted sources

Before installing an extension:

  • Read recent reviews
  • Check the developer
  • Review requested permissions
  • Avoid unnecessary extensions
  • Remove extensions you no longer use.

3. Check website URLs before entering passwords

Before entering credentials:

  • Verify the domain name
  • Look for spelling errors
  • Confirm you’re on the site’s legitimate address
  • Never trust a login page simply because it looks authentic.

4. Avoid downloading files from unknown websites

Only download software from:

  • Official vendor websites
  • Trusted app stores
  • Verified business portals

Avoid downloads promoted through pop-ups, ads, or unsolicited messages.

5. Use a password manager and multifactor authentication

Strong passwords remain essential.

Use:

Microsoft notes in its latest Digital Defense Report that security systems process enormous volumes of modern threats, including blocking approximately 4.5 million new malware files every day.

That statistic highlights the scale of the threats consumers face daily.

Browser security checklist

Use this quick checklist:

✅ Keep browsers updated

✅ Use MFA

✅ Use a password manager

✅ Verify URLs carefully

✅ Remove unused extensions

✅ Review extension permissions

✅ Avoid suspicious downloads

✅ Block pop-ups when possible

✅ Sign out of shared devices

✅ Monitor browser security settings regularly

Your browser is more than a tool for accessing websites. It’s one of the primary battlegrounds between consumers and cybercriminals.

By keeping your browser updated, verifying website URLs, avoiding suspicious downloads, limiting extensions, and using MFA, you can dramatically reduce your exposure to online threats.

09.04.26

Back-to-school scams are surging: How families can protect themselves from cybercriminals this school year

Back-to-school season means shopping for supplies, paying activity fees, setting up student accounts, and helping kids prepare for a new year. Unfortunately, it also marks one of the busiest times of year for scammers.

Cybercriminals know that parents are rushing, students are distracted, and schools are sending a flood of legitimate emails and messages. That creates the perfect environment for fraud.

The IRS Criminal Investigation division (IRS-CI) recently warned that back-to-school season brings spikes in online shopping scams, impersonation schemes, scholarship fraud, and scams targeting children through gaming platforms and social media. Even more alarming, IRS-CI reported identifying more than $24 million in cyber-related crime during fiscal year 2025.

The good news? Most of these scams share common warning signs that families can learn to recognize before becoming victims.

Why do scammers target families during back-to-school season?

Back-to-school shopping creates a perfect storm for cybercriminals:

  • Parents are making frequent online purchases
  • Schools send numerous emails and payment requests
  • Students use social media, gaming platforms, and messaging apps
  • Families may apply for scholarships or financial aid
  • New devices are being purchased and configured
  • People are multitasking and making quick decisions

According to an IRS-CI warning reported by CPA Practice Advisor, fraudsters frequently exploit this season through fake e-commerce sites, school impersonation scams, scholarship scams, and digital exploitation targeting minors.

What are the most common back-to-school scams right now?

Fake online shopping websites

One of the fastest-growing fraud trends involves websites offering massive discounts on school supplies, backpacks, laptops, tablets, and clothing.

Watch for:

  • Prices that seem too good to be true
  • Websites with little contact information
  • Pressure to purchase immediately
  • Requests for cryptocurrency or gift card payments
  • Poorly written product descriptions

The IRS warns that fraudulent online stores frequently lure shoppers with unusually steep discounts and pressure buyers into using difficult-to-trace payment methods.

School impersonation scams

Criminals may impersonate:

  • School administrators
  • District officials
  • PTA organizations
  • Scholarship providers
  • Government agencies

Their goal is often to trick parents into:

The IRS advises families to independently verify any payment requests by contacting schools through known contact information rather than using links provided in emails or texts.

Scholarship and financial aid scams

Students may receive messages promising:

  • Guaranteed scholarships
  • Exclusive grants
  • Fast-track financial aid
  • Free college assistance

Red flags include:

  • Upfront fees
  • Requests for Social Security numbers
  • Pressure to act immediately
  • Unsolicited offers

Legitimate scholarship providers generally do not demand payment to apply.

Gaming and social media scams targeting students

Children and teenagers increasingly face scams through:

  • Gaming platforms
  • Social apps
  • Discord servers
  • Messaging platforms
  • Livestream communities

These scams may promise:

  • Free game currency
  • Exclusive rewards
  • Influencer giveaways
  • Contest prizes

They often seek personal information, account credentials, or payment details. IRS investigators specifically warn that scammers use gaming platforms and social media to target minors during back-to-school season.

How can parents protect their children online?

Children often don’t recognize fraud tactics as quickly as adults.

Teach these online safety rules

  • Never share passwords
  • Don’t click links from strangers
  • Avoid downloading unknown files
  • Never reveal home addresses
  • Be suspicious of “free” offers
  • Tell a parent about unusual messages
  • Verify requests for personal information

Parents should regularly discuss scams just like they discuss stranger danger in the physical world.

How does this help someone become safer online?

Understanding seasonal scam tactics helps families recognize fraud before money or personal information is stolen.

This awareness helps protect:

  • School payment accounts
  • Banking information
  • Children’s identities
  • Email accounts
  • Social media profiles
  • Student records
  • Family finances
  • Personal data

The biggest cybersecurity advantage isn’t technology. It’s knowing when something feels suspicious and taking a moment to verify it.

What should families do before making purchases?

Back-to-school cybersecurity checklist

Before buying supplies or paying school-related fees:

✅ Shop with established retailers

✅ Verify website addresses carefully

✅ Read recent reviews

✅ Pay with credit cards when possible

✅ Avoid gift card payments

✅ Avoid wire transfers

✅ Enable multifactor authentication

✅ Keep devices updated

✅ Verify all school communications independently

✅ Monitor children’s online activity

✅ Teach children to report suspicious messages

✅ Freeze a child’s credit if appropriate

The IRS notes that credit freezes can help prevent criminals from opening fraudulent accounts using a child’s identity.

What should you do if you suspect a scam?

Act quickly:

  1. Stop communicating with the suspected scammer.
  2. Save screenshots and emails.
  3. Contact your bank if payment information was shared.
  4. Change passwords on affected accounts.
  5. Enable multifactor authentication.
  6. Notify your school if scammers are impersonating staff.
  7. Report fraud through official government reporting channels.

Timely reporting helps investigators identify broader fraud campaigns and may prevent additional victims.

Back-to-school season should be about learning, not losing money to scammers. Criminals know families are busy, and they use urgency, fake discounts, and impersonation tactics to exploit that pressure.

The safest approach is simple: slow down, verify before you pay, and teach children to question unexpected messages and offers.

09.03.26

App permissions explained: Why reviewing app permissions is one of the easiest ways to protect your privacy

Smartphone apps make life easier. They help us navigate, communicate, shop, bank, stream content, and stay productive. But every app you install may request access to sensitive parts of your device, including your camera, microphone, contacts, photos, location, calendar, and files.

Many users tap “Allow” without a second thought. Unfortunately, that convenience can expose more personal information than necessary.

The good news is that reviewing app permissions takes only a few minutes and can dramatically improve your privacy and security.

Why do app permissions matter?

App permissions determine what an application can access on your device. Some permissions are necessary. For example, a video conferencing app needs camera and microphone access to function properly.

Problems arise when apps request permissions that don’t match their purpose.

For example:

  • A flashlight app requesting contacts access
  • A calculator asking for your location
  • A wallpaper app requesting microphone access
  • A game requesting access to text messages
  • A photo editor requesting full contact-list access

According to Google’s https://blog.google/products-and-platforms/platforms/google-play/how-we-kept-google-play-safe-in-2025/, Google prevented more than 1.75 million policy-violating apps from reaching Google Play in 2025 and scans over 350 billion Android apps daily through Google Play Protect. These numbers highlight why users should not assume every app is automatically safe. Security screening helps, but users still play an important role in protecting their own devices.

What app permissions deserve extra attention?

Some permissions create greater privacy risks because they provide access to personal information or sensitive device functions.

Contacts

Contact lists often contain:

  • Family members
  • Friends
  • Work colleagues
  • Phone numbers
  • Email addresses

If an app doesn’t need your contacts to perform its core function, deny the request.

Microphone

Microphone access allows apps to capture audio.

Before approving:

  • Ask why the app needs it.
  • Check whether microphone use makes sense.
  • Remove access when it is no longer needed.

Camera

Camera permissions can be legitimate for:

  • Video calls
  • Document scanning
  • QR code scanning

However, many apps request camera access without a clear business need.

Location

Location data can reveal:

  • Home address
  • Workplace
  • Daily routines
  • Travel habits
  • Frequently visited places

The NSA’s guidance on location privacy notes that location data can expose daily routines, movements, and behavioral patterns. Limiting unnecessary location access reduces exposure.

Photos and files

Many apps request access to your entire photo library when they only need access to a single image.

Whenever possible:

  • Choose “Selected Photos”
  • Use one-time access
  • Avoid granting permanent full-library access

How does reviewing permissions make someone safer online?

Reviewing permissions helps someone become safer online by reducing unnecessary access to personal information.

This protects:

  • Private conversations
  • Contacts
  • Photos
  • Location data
  • Financial information
  • Work documents
  • Family information
  • Authentication information

The less access unnecessary apps receive, the smaller the risk if the app becomes compromised or behaves improperly.

Think of each permission as a key. Only hand out the keys an app genuinely needs.

How can you evaluate whether an app is trustworthy?

Before installing a new app, take a few minutes to investigate.

Check recent reviews

Focus on:

  • Current reviews
  • Complaints about privacy issues
  • Reports of excessive permissions
  • Sudden changes after updates

Recent reviews often reveal issues that older ratings may miss.

Verify the developer

Look for:

  • Established company websites
  • Contact information
  • Published privacy policies
  • Consistent app history

Review permissions before installing

Most app stores show permissions before download.

Ask:

  • Does this permission make sense?
  • Is it necessary?
  • Would I be comfortable sharing this information?

Step-by-step app permission audit

Audit your apps every few months.

Android

  1. Open Settings
  2. Select Privacy
  3. Tap Permission Manager
  4. Review each permission category
  5. Remove unnecessary access

iPhone

  1. Open Settings
  2. Select Privacy & Security
  3. Review categories such as:
    • Location Services
    • Microphone
    • Camera
    • Photos
    • Contacts
  4. Disable permissions you no longer need

Red flags that an app may be requesting too much

Watch for apps that:

  • Request permissions unrelated to their purpose
  • Frequently ask for additional permissions
  • Have poor or suspicious reviews
  • Come from unknown developers
  • Require accessibility permissions without explanation
  • Ask for administrator-level device access

If something feels excessive, trust your instincts and investigate further.

Additional protection tips

Use these best practices:

✅ Install apps only from official app stores
✅ Read recent reviews before downloading
✅ Keep apps updated
✅ Remove apps you no longer use
✅ Enable Google Play Protect or Apple security protections
✅ Run mobile security scans when appropriate
✅ Review permissions after major updates
✅ Deny permissions that don’t support app functionality
✅ Use “Only While Using the App” when available
✅ Remove permissions from dormant apps

App stores perform extensive security screening, but no system catches everything. Cybersecurity ultimately works best when technology and smart user behavior work together.

Before granting access, ask one simple question:

“Does this app really need this permission to do its job?”

If the answer isn’t obvious, deny the request until you’ve done more research.

09.02.26

How to limit Facebook tracking and protect your online privacy across the web

Facebook can be a great way to stay connected with friends, family, local groups, and businesses. What many people don’t realize, however, is that Facebook’s data collection can extend beyond what happens on Facebook itself.

Many websites contain Facebook tracking technologies, such as embedded content, social sharing buttons, advertising pixels, and login tools. These technologies can help Facebook understand parts of your browsing activity even after you leave the platform.

The good news? You can take practical steps to reduce how much information Facebook can connect to your identity online.

How does Facebook track activity outside of Facebook?

When you visit websites that use Facebook technology, information about those visits may be shared with Meta for advertising, analytics, and personalization purposes.

Facebook tracking can occur through:

  • Social sharing buttons
  • Facebook “Like” buttons
  • Embedded Facebook content
  • Advertising pixels
  • Third-party cookies
  • Facebook Login integrations
  • Mobile app tracking technologies

According to Mozilla’s official Facebook Container extension documentation, Facebook Container works by isolating your Facebook identity into a separate browser container, making it more difficult for Facebook to track visits to other websites through third-party cookies.

This does not eliminate all data collection, but it can significantly reduce the connection between your Facebook account and your broader web browsing activity.

Why should you care about online tracking?

Many people assume online tracking only affects advertising. In reality, tracking contributes to detailed profiles that can influence:

  • Advertisements you see
  • Content recommendations
  • Shopping suggestions
  • Marketing campaigns
  • Political messaging
  • Consumer profiling
  • Behavioral analytics

Mozilla explains that Facebook Container helps separate Facebook activity from browsing activity on other websites, helping users maintain greater privacy while continuing to use Facebook normally.

The goal isn’t necessarily to stop using Facebook. The goal is to increase your control over who collects information about your online behavior.

How does Facebook Container work?

Mozilla developed Facebook Container specifically for Firefox users who want stronger privacy protections.

After installation:

  • Facebook opens in an isolated browser container
  • Facebook cookies are separated from other websites
  • Non-Facebook websites open outside the container
  • Facebook has a harder time associating other browsing activity with your Facebook identity

Mozilla states that the extension logs users out of Facebook, clears tracking cookies, then reloads Facebook within a dedicated container environment.

This separation limits how easily Facebook can follow your activity across the web.

How does limiting tracking make someone safer online?

Reducing online tracking helps someone become safer online by limiting how much information large platforms, advertisers, and potentially malicious actors can associate with their browsing habits.

This helps protect:

  • Personal browsing habits
  • Shopping behavior
  • Interests and preferences
  • Device information
  • Advertising profiles
  • Location-related browsing patterns
  • Personal research activities
  • Sensitive searches

Privacy and security are closely related. The less information that gets collected and shared, the fewer opportunities exist for misuse, profiling, or manipulation.

Think of privacy as reducing your digital footprint before attackers or data brokers can use it.

What are the best ways to reduce Facebook tracking?

Install Facebook Container for Firefox

Mozilla’s Facebook Container extension remains one of the easiest tools for Firefox users. It helps isolate Facebook from other browsing activity.

Review Facebook privacy settings

Regularly review:

  • Ad personalization settings
  • Activity permissions
  • Connected apps
  • Off-platform activity controls
  • Facial recognition settings (where applicable)
  • Location-sharing permissions

Limit social logins

Many websites allow users to sign in with Facebook.

Instead:

  • Create separate accounts
  • Use a password manager
  • Sign in with email when practical

This reduces cross-site tracking opportunities.

Use privacy-focused browser settings

Enable:

  • Third-party cookie blocking
  • Enhanced tracking protection
  • Private browsing when appropriate
  • Browser security updates

Mozilla also recommends combining Facebook Container with additional privacy protections such as Firefox’s built-in tracking protections and cookie controls.

Step-by-step privacy checklist

Use this simple checklist:

✅ Install Facebook Container if you use Firefox
✅ Review Facebook privacy settings quarterly
✅ Limit Facebook Login usage on third-party websites
✅ Block third-party cookies where possible
✅ Remove unused connected apps
✅ Restrict location permissions
✅ Audit your ad preferences
✅ Keep your browser updated
✅ Use unique passwords and multifactor authentication
✅ Think before sharing personal information publicly

What misconceptions do people have about tracking?

One common misconception is:

“I logged out of Facebook, so Facebook can’t track me.”

Tracking technologies can function independently of active sessions in some situations. That’s why browser-level tools and privacy settings matter.

Another misconception:

“I have nothing to hide.”

Privacy isn’t about hiding wrongdoing. It’s about maintaining control over personal information, browsing habits, and digital autonomy.

Facebook provides valuable ways to stay connected, but it also gathers significant amounts of user data. By using tools such as Mozilla’s Facebook Container, reviewing privacy settings, limiting social logins, and reducing unnecessary tracking, you can take back more control over your online footprint.

09.01.26

Don’t install software you didn’t intend to download: How to avoid fake updates, malware, and phishing traps

One of the easiest ways cybercriminals infect computers is by convincing people to install something they never planned to install.

A pop-up claims your browser is outdated. An ad warns that your computer is infected. An email says you must open an attachment immediately. A fake update promises better performance or security. These tactics rely on one thing: getting you to click before you think.

A simple cybersecurity habit can dramatically reduce your risk: Never install software, apps, browser extensions, updates, or attachments unless you intended to download them beforehand and verified the source.

Why do scammers want you to install software?

Malicious software gives cybercriminals access to devices, accounts, passwords, and sensitive information. Attackers often disguise malware as legitimate software updates, productivity tools, security programs, invoices, or document attachments.

According to the FBI’s https://www.fbi.gov/file-repository/2025_ic3report.pdf/view, the agency received more than 1 million cybercrime complaints with reported losses exceeding $20 billion, demonstrating the massive scale of online threats facing consumers. The FBI also notes that phishing, spoofing, and malware delivery remain among the most common tactics used by cybercriminals.

The goal is simple: trick users into doing the attacker’s work.

What are the most common fake download scams?

Cybercriminals use many different approaches to convince people to install malware.

Fake software updates

You may see alerts claiming:

  • Your browser is outdated
  • Flash Player needs updating
  • Your PDF software is insecure
  • Your media player needs a critical patch
  • Your operating system requires an emergency update

Legitimate updates typically arrive through the software itself or through your device’s official update system, not random advertisements or pop-up windows.

Malicious email attachments

The FTC’s guidance on https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams warns that scammers frequently send attachments disguised as:

  • Invoices
  • Shipping notifications
  • Tax documents
  • Resumes
  • Receipts
  • Payment confirmations
  • Legal notices
  • Account verification forms

Opening the attachment may install malware or direct victims to credential-stealing websites.

Fake antivirus alerts

Many fraudulent websites display alarming messages such as:

  • “Your computer is infected!”
  • “15 viruses detected!”
  • “Click here to clean your device!”

These messages often create urgency to pressure users into downloading fake security software.

Browser extension scams

Some malicious browser extensions promise:

  • Coupons and discounts
  • Productivity improvements
  • Streaming enhancements
  • Security tools
  • Free downloads

Instead, they may collect browsing data, steal credentials, or inject advertisements.

How can you tell whether a download is legitimate?

Before installing anything, ask yourself one important question:

Did I intentionally go looking for this software?

If the answer is “no,” stop and verify before proceeding.

Check the source

Only download software from:

  • Official vendor websites
  • Trusted app stores
  • Verified enterprise portals
  • Reputable software publishers

Avoid downloads from:

  • Pop-up advertisements
  • Random search results
  • Unsolicited emails
  • Chat messages
  • Social media posts
  • Unknown websites

CISA’s phishing prevention guidance recommends verifying suspicious requests independently rather than using links included in messages.

How does this help someone become safer online?

Avoiding unexpected downloads protects users from many of the most common forms of cybercrime.

This habit helps prevent:

  • Malware infections
  • Ransomware attacks
  • Identity theft
  • Account takeovers
  • Banking fraud
  • Data theft
  • Browser hijacking
  • Spyware infections
  • Credential theft

The safest users are often not the most technical users. They’re the users who pause before clicking.

What should you do when software claims it needs updating?

Use this safer process:

Safe update checklist

  1. Close the pop-up.
  2. Do not click the update button.
  3. Open the application directly.
  4. Check for updates within the software.
  5. Visit the vendor’s official website.
  6. Install updates only from verified sources.
  7. Enable automatic updates whenever possible.

This approach eliminates the risk of downloading malware disguised as a security update.

What should you do if you accidentally installed something suspicious?

Act quickly.

Emergency response steps

  • Disconnect from the internet if malware is suspected.
  • Run a full antivirus or endpoint security scan.
  • Uninstall suspicious software.
  • Change important passwords from a clean device.
  • Enable multifactor authentication.
  • Review banking and online accounts for unusual activity.
  • Remove unknown browser extensions.
  • Monitor financial statements.
  • Contact IT support if it involves a work device.

The FTC warns that phishing attacks often attempt to steal passwords, account numbers, and personal information through fake links and downloads.

Best practices to prevent unwanted installations

Build these habits into your daily routine:

  • Keep automatic updates enabled.
  • Download software only from trusted sources.
  • Use reputable security software.
  • Verify every attachment before opening it.
  • Avoid clicking unexpected links.
  • Review browser extensions regularly.
  • Remove software you no longer use.
  • Use multifactor authentication.
  • Keep operating systems updated.
  • Think before clicking.

The bottom line

Most malware infections begin with a single click. Cybercriminals know that fear, urgency, and curiosity can convince people to install software they never intended to download.

The safest approach is also the simplest: If you weren’t planning to install it before you saw the pop-up, don’t install it until you’ve independently verified it’s legitimate.

Security tip of the day: Unexpected downloads are one of the most common paths to malware. Trust your plan, not the pop-up.