Total Defense

Security & Safety Resource Center

Learn about today's current internet threats and how to stay safe and secure.

Security Tip of the Day

Daily tips to create awareness of cyber threats and empower Total Defense users to be safer and more secure online with our security tips and resources..


September 2026
09.20.26

New gaming console privacy settings: What to change before you start playing online

A new gaming console makes it tempting to jump straight into a game, but spend five minutes reviewing the privacy settings first. Modern consoles function like social networks: profiles can reveal when you are online, what you are playing, your gaming history, friends, achievements, and shared content.

Setting your profile to Friends Only is a smart starting point. It limits what strangers can learn about you and reduces unwanted messages, friend requests, invitations, and other distractions.

Why should you check a new console’s privacy settings?

Default settings may prioritize social discovery and multiplayer features instead of maximum privacy. Depending on the console and account type, other players may be able to see:

  • Your online status
  • The game or app you are using
  • Your gaming history and achievements
  • Your friends and social connections
  • Screenshots, clips, and other shared media
  • Your profile details
  • Whether you are available for messages or invitations

Limiting this information can reduce unwanted attention. Research from the Anti-Defamation League found hate or harassment in almost half of the online multiplayer sessions it tested, illustrating why communication, blocking, and privacy controls matter in online gaming.

Which gaming privacy settings should you change?

Start with the settings that control profile visibility and communication.

Set profile visibility to friends only

Restrict your profile so strangers cannot automatically view personal details or gaming activity. A friends-only profile creates a boundary between people you intentionally add and everyone else on the network.

On PlayStation, the Friend Focused preset allows only friends to see profile information and send chat invitations. The stricter Solo and Focused preset prevents everyone, including friends, from seeing profile information or sending invitations. You can compare these choices in the official PlayStation privacy-settings guide.

On Xbox, open:

  1. Profile & system
  2. Settings
  3. Account
  4. Privacy & online safety
  5. Xbox privacy
  6. View details & customize

The official Xbox privacy instructions let players choose preset privacy levels or customize who can see profile details and interact with content.

Hide your online status and game activity

Other players do not always need to know when you are online, what you are playing, or which apps you have used.

On Xbox, you can control whether others see:

  • When you are online
  • What you are watching or listening to
  • Your game and app history

The Xbox activity visibility guide also explains how to appear offline or use Do Not Disturb.

On PlayStation, privacy controls cover online status, current games, gaming history, and games hidden from other players.

Limit messages and friend requests

Spam often arrives through open messaging and friend-request settings. Restrict these features to friends, friends of friends, or nobody, depending on how social you want the account to be.

Review who can:

  • Send messages
  • Start voice chats
  • Invite you to a game
  • Send friend requests
  • Follow your profile
  • View your friends list
  • See shared screenshots or clips

Do not accept a friend request simply because the account shares mutual connections. Look at the profile carefully and confirm the person through another trusted channel when necessary.

Can you hide your friends list?

On supported platforms, you can restrict who sees your connections. This helps prevent strangers from browsing your social circle, contacting your friends, or using mutual connections to appear trustworthy.

PlayStation includes friends and connections among its customizable privacy categories. Its controls let users manage friend requests, followers, and who can see account connections.

Nintendo also lets account holders disable friend suggestions across supported services. The official Nintendo friend-suggestion instructions explain how to turn suggestions off for the whole account or individual services.

Be aware that hiding your friends list does not necessarily remove your profile from every discovery system. Review friend suggestions, linked social accounts, real-name sharing, and discovery options separately.

What account-security settings should you enable?

Privacy controls limit visibility, but they will not stop someone who steals your credentials. Protect the underlying gaming account too.

Use this checklist:

  • Create a strong password used only for the gaming account.
  • Enable multifactor authentication or a passkey.
  • Add current account-recovery information.
  • Require a password or PIN before purchases.
  • Avoid displaying your real name publicly.
  • Remove payment methods you no longer need.
  • Review active sessions and connected devices.
  • Keep the console and controller firmware updated.

Never share login codes, recovery codes, or one-time verification codes with another player. Gaming support representatives should not need your password or authentication code.

What should parents and caregivers review?

Family settings may allow an adult organizer to manage privacy, purchases, screen time, age-rated content, and communication for supervised accounts.

The Xbox support guidance says an organizer in an Xbox family group can manage a member’s online-safety and privacy settings.

PlayStation similarly allows family managers to manage child privacy settings, communication, spending, content restrictions, and playtime.

Before a younger player goes online, review:

  • Who can send messages and invitations
  • Whether voice and text chat are allowed
  • Who can view the player’s profile and activity
  • Purchase approval and spending limits
  • Friend-request controls
  • Blocking, muting, and reporting tools
  • Real-name and location disclosures

How does this help someone become safer online?

Tightening console privacy settings reduces the information strangers can use to contact, manipulate, impersonate, or target a player.

These changes help someone become safer online by:

  • Reducing spam and unwanted messages
  • Limiting exposure of gaming habits and schedules
  • Preventing strangers from browsing social connections
  • Restricting who can send invitations or start chats
  • Protecting personal details from unnecessary visibility
  • Giving players better control over online interactions

Privacy settings cannot prevent every harmful interaction, but they reduce the number of unknown people who can reach you and the amount of information those people can see.

New console privacy checklist

Before starting your first online game:

  • Set profile visibility to Friends Only.
  • Limit messages, chats, and invitations.
  • Hide your friends list where possible.
  • Restrict online status and game activity.
  • Disable unnecessary friend suggestions.
  • Use a unique password.
  • Enable multifactor authentication or a passkey.
  • Add a purchase PIN.
  • Review parental controls for younger players.
  • Learn how to block, mute, and report users.

A new console should not broadcast your activity to everyone by default. Before joining multiplayer games, open the privacy settings and decide who can see your profile, status, games, friends, and shared content.

Start with Friends Only, then tighten individual settings based on your comfort level. That quick privacy review can reduce spam, limit unwanted contact, and keep your gaming activity within the audience you actually chose.

09.19.26

Sign in to smart TV media apps with your smartphone for safer streaming

Typing a long password into a smart TV is slow, awkward, and easy for someone nearby to watch. A safer option is to authenticate through the media app on your smartphone, then link the television with an on-screen code, QR code, or device connection.

This approach keeps your actual password on a personal device you control while still letting you enjoy YouTube, Spotify, and other media on the big screen.

Why is smartphone sign-in safer than typing on a TV?

Entering credentials directly on a television can expose them to people in the room. You might also accidentally save the password on a shared, rented, or unfamiliar device.

A phone-based activation process can reduce that risk because you authenticate through the provider’s official app or website on your smartphone. The TV receives authorization without displaying your password.

This helps protect:

  • Your username and password
  • Subscription and billing settings
  • Personal profiles and viewing history
  • Saved payment details
  • Other accounts that could be affected by password reuse

The risk of account theft is real. A 2025 consumer survey found that 29% of respondents had experienced an account takeover, according to Security.org’s account takeover report. The report also found that 70% of affected respondents said the compromised accounts lacked unique passwords. [security.org]

How does smart TV activation with a phone work?

Many media apps display a short activation code or QR code on the television. You then use your smartphone to authorize that TV.

For example, YouTube’s official TV activation page lets users enter the code displayed on a television.

On Spotify, you can open the app on your phone and select a compatible TV through Spotify Connect. You can also choose Log in with PIN, visit Spotify’s pairing page on a separate device, and enter the displayed PIN, as described in Spotify’s official TV instructions.

Exact steps vary by app, but the general process is:

  1. Open the official media app on your smart TV.
  2. Select Sign in with phone, Log in with code, or a similar option.
  3. Scan the QR code or note the activation code.
  4. Open the provider’s official app or website on your smartphone.
  5. Confirm that the displayed web address belongs to the real provider.
  6. Enter the code and approve the television.
  7. Verify that the correct profile appears on-screen.

Are QR codes and activation codes always safe?

No. Treat both as temporary credentials.

A scammer could replace a legitimate QR code with one that opens a phishing website, particularly on a TV in a rental property, hotel, or public space. Someone nearby could also photograph the activation code and attempt to use it before it expires.

Protect yourself by following these precautions:

  • Scan only a code displayed inside the official TV app.
  • Preview the website address before opening it.
  • Check the domain carefully before entering credentials.
  • Never send an activation code to another person.
  • Do not enter a code from an unexpected email or text.
  • Cancel the process if the phone opens an unfamiliar website.

Can you connect without signing the TV into your account?

Often, yes. Spotify Connect, Google Cast, and Apple AirPlay can send or control playback from your phone without requiring you to type a password with the television remote.

Spotify explains that Spotify Connect lets users choose a compatible TV and control playback from a phone, typically when both devices use the same Wi-Fi network or another supported connection.

This can be especially useful at a friend’s home because it reduces the chance of leaving your account signed in after you leave.

What should you do on a shared or unfamiliar smart TV?

If the TV does not belong to you:

  • Prefer casting or device connection over permanent sign-in.
  • Use a phone-based code instead of typing the password.
  • Avoid selecting Remember me or Stay signed in.
  • Keep activation codes out of view.
  • Sign out when viewing ends.
  • Remove the television from your account’s device list.
  • Forget the local Wi-Fi network if you no longer need it.

For YouTube, Google explains how to remove an account from a TV or sign out remotely through Google Account device activity or connected-app permissions.

What if you forgot to sign out?

Open the media provider’s account settings from your smartphone and look for Manage devices, Authorized devices, or Device activity.

Then:

  1. Find the unfamiliar television.
  2. Sign it out or remove its access.
  3. Review other recently active devices.
  4. Change your password if someone may have seen it.
  5. Replace that password anywhere you reused it.
  6. Enable two-factor authentication when available.

The FTC recommends using strong, unique passwords and two-factor authentication because online accounts may contain valuable personal and financial information. [consumer.ftc.gov], [consumer.ftc.gov]

How does this help someone become safer online?

Phone-based activation limits password exposure by keeping your credentials on a device you own and control. It also reduces the chance that someone sees your password while you slowly enter it with a remote.

This practice helps you become safer online by:

  • Reducing shoulder-surfing risks
  • Keeping passwords off shared televisions
  • Limiting persistent account access
  • Making sign-in destinations easier to verify
  • Encouraging reviews of connected devices
  • Reducing the damage caused by forgotten logins

The bottom line

When a smart TV offers smartphone sign-in, an activation code, or a QR option, use it instead of typing your password directly on the television. Verify the website or app before approving access, and remember that pairing codes should remain private.

On shared TVs, casting may be even better because it keeps account control on your phone. Whatever method you choose, disconnect or sign out when playback ends.

09.18.26

Signing in to a smart TV? Protect your password from people nearby

Movie night should not create an account-security headache. When you sign in to a streaming app on a smart TV, anyone nearby may see your email address, password, activation code, or account details.

That exposure matters because streaming accounts can connect to saved payment methods, subscription settings, viewing history, and personal profiles. If you need to sign in on a shared or unfamiliar television, do it privately and remove your account when you finish.

Why is signing in to a smart TV a security risk?

Entering a password with a television remote is slow and highly visible. Someone sitting nearby could watch what you type, record the screen, photograph an activation code, or later reopen the app if you leave the account signed in.

A streaming password becomes an even bigger risk if you reuse it. Netflix explains in its official account-security guidance that an attacker who obtains a reused email-and-password combination may try it on other websites and apps.

The broader identity-theft problem is significant. The Federal Trade Commission reports that more than one million people reported identity theft in 2025. Streaming-account exposure does not automatically cause identity theft, but protecting credentials helps close one potential route into your wider digital life. [consumer.ftc.gov]

What could someone access through your streaming account?

The exact information varies by provider, but a signed-in television may expose:

  • Your name, email address, or phone number
  • Viewing history and recommendations
  • Household profiles
  • Subscription and billing settings
  • Partial payment information
  • Parental controls or profile PIN settings
  • Options to upgrade a plan or make purchases
  • Other devices connected to the account

Someone who knows your password may also test it against your email, shopping, gaming, or social media accounts. That is why every streaming service should have a unique password.

How should you sign in around other people?

The safest option is to sign in before guests arrive. If that is not possible, ask everyone to step away while you complete the process. You are not being rude. You are treating your password like the private security credential it is.

Follow these steps:

  1. Confirm that you are using the streaming provider’s official app.
  2. Ask other people to leave the room or turn away.
  3. Shield the remote or screen while entering information.
  4. Never say your password aloud.
  5. Decline any option to display the password on-screen.
  6. Avoid saving the password on a television you do not own.
  7. Confirm that nobody photographed an activation code.
  8. Sign out before leaving if the television is not yours.

Is a QR code or activation code safer?

It can be. Many streaming services let you scan a QR code or enter a short activation code through a website on your phone. This keeps your actual password on a device you control.

However, activation codes can still be sensitive. Anyone who scans or copies the code before it expires may be able to connect the television to an account.

Use activation features safely:

  • Scan the code with your own phone.
  • Verify the website address before signing in.
  • Avoid QR codes that appear on stickers placed over the screen.
  • Do not text the code to another person.
  • Complete activation privately.
  • Cancel the process if the destination website looks unfamiliar.

Is casting safer than signing in directly?

Casting from your phone, tablet, or laptop is often the better choice because your password normally remains inside the authenticated app on your personal device. You simply choose the television as the playback destination.

When casting is available:

  • Connect to the host’s verified Wi-Fi network.
  • Open the official streaming app on your device.
  • Select the correct television.
  • Start playback.
  • Disconnect the casting session when viewing ends.
  • Forget the Wi-Fi network if you do not need it saved.

Casting reduces credential exposure, but it does not remove every privacy concern. Other people on the same network may discover compatible devices, and the television may retain limited viewing information.

What should you do before leaving a shared television?

Do not assume that closing the app signs you out. Open the streaming service’s settings and select Sign Out, Remove Account, or the equivalent option.

Then:

  • Restart the app and confirm that it displays the sign-in screen.
  • Remove any personal profile left on the television.
  • Review account activity from your phone.
  • Confirm that the television no longer appears as an authorized device.
  • Check for subscription or profile changes.

Netflix lets subscribers use its Manage Access and Devices page to review recently active devices and remotely sign out of one or all devices. Netflix notes that some devices may take up to 48 hours to appear and that the list may not include every device.

YouTube also provides instructions for removing an account from a television or game console, including a remote option through Google Account device activity when you no longer have physical access to the television.

What if you forgot to sign out?

Act as soon as you remember:

  1. Open the streaming provider’s account settings.
  2. Review recently used or authorized devices.
  3. Remove the unfamiliar television.
  4. Choose Sign out of all devices if you cannot identify it.
  5. Change your password if anyone may have seen it.
  6. Replace that password on every account where you reused it.
  7. Enable two-factor authentication when the service supports it.
  8. Review billing and account activity.

If someone is using your account without permission, Netflix recommends changing the password and signing out devices you do not recognize.

How does this help someone become safer online?

Private sign-in protects more than a streaming subscription. It prevents nearby people from learning a password that might unlock other parts of your digital life.

These precautions help you become safer online by:

  • Keeping passwords out of sight
  • Reducing access from shared televisions
  • Protecting billing and profile settings
  • Preventing password reuse from causing wider damage
  • Encouraging reviews of connected devices
  • Keeping authentication on devices you control

The Federal Trade Commission recommends using strong passwords and two-factor authentication because online accounts can contain valuable personal and financial information. Its consumer account-protection guidance also recommends password managers for creating and storing unique passwords.

Smart TV sign-in safety checklist

Before the movie starts:

  • Sign in before guests arrive.
  • Use casting when practical.
  • Keep passwords and activation codes private.
  • Use a unique streaming password.
  • Avoid saving credentials on someone else’s television.
  • Sign out when viewing ends.
  • Confirm the account is gone before leaving.
  • Review connected devices afterward.
  • Enable two-factor authentication when available.

Only enter streaming credentials around people you trust, and even then, keep the password private. A better option is to sign in ahead of time, use a phone-based activation process privately, or cast from a device you control.

When you use someone else’s smart TV, sign out before leaving and verify the logout. That small cleanup step helps protect your subscription, payment access, personal information, and other accounts.

09.17.26

Cast streaming apps at a friend’s house instead of signing in on their TV

Watching a movie or game at a friend’s house should not end with your streaming account permanently logged into someone else’s television. When the TV supports casting, you can often control playback through an authenticated app on your own phone, tablet, or laptop instead.

Casting generally reduces the need to type or save your username and password on a device you do not own. It also lowers the chance that someone will continue using your account after you leave.

Is casting safer than signing into a smart TV?

Casting can be safer because your login usually stays within the app on your personal device. You select the television as the playback destination instead of manually entering credentials with a shared remote.

For example, Google explains in its official Google TV casting instructions that users can cast from a phone, tablet, or laptop when both devices are connected to the same Wi-Fi network. To end the session, select the Cast control and choose Disconnect.

Casting helps you avoid several risks associated with signing in directly:

  • Accidentally saving your password on another person’s television
  • Forgetting to sign out before leaving
  • Exposing your password while typing it with a remote
  • Leaving profiles, recommendations, and account settings accessible
  • Allowing future viewers to make changes or purchases

Casting is not a guarantee of complete privacy. The television may still display viewing information, and anyone with access to the same trusted home network may be able to discover compatible Cast devices. Google notes that multiple users on the same home network can cast to a supported television.

Why do saved streaming logins create a security risk?

Streaming accounts can hold personal details, profile information, viewing history, and payment data. A person with continued access might alter the subscription, view account details, or lock the owner out by changing credentials.

The risk becomes more serious when people reuse passwords. Netflix warns in its account security guidance that if the same email and password combination is used across multiple services, an attacker who obtains it from one service may try it on the others. The company recommends a password unique to Netflix and advises users to sign out of unused or unrecognized devices.

Account takeover is a significant concern across digital services. A 2025 consumer study found that 29% of surveyed internet users had experienced an account takeover, up from 22% in 2021. The Security.org account takeover report also found that 70% of affected respondents said the compromised accounts did not have unique passwords.

How do you cast safely at a friend’s house?

Connect only to a trusted network

Ask your friend for the exact Wi-Fi network name and password. Avoid similarly named networks that could belong to a neighbor or an unauthorized access point.

Casting normally requires your device and television to share the same network. Google also notes that guest or public networks using client isolation may prevent casting because connected devices cannot discover one another.

Use the official streaming app

Open the verified app already installed on your device. Do not install a “casting helper,” unknown browser extension, or unofficial media player because a website says it is required.

Then:

  1. Confirm that the phone and television use the same trusted Wi-Fi.
  2. Open the official media app.
  3. Select the Cast icon.
  4. Choose the correct television by name.
  5. Start the content from your device.
  6. Select Cast > Disconnect when viewing ends.

Disconnect before leaving

Stopping a video does not always end the casting connection. Use the app’s disconnect command, close the media session, and check that the television has returned to its normal screen.

If you joined your friend’s Wi-Fi only for casting, consider selecting Forget network afterward. That prevents your phone or laptop from trying to reconnect automatically during a future visit.

What if the television does not support casting?

If casting is unavailable, consider safer alternatives before entering your credentials:

  • Use an official sign-in code or QR process that authenticates through your phone.
  • Connect your own streaming device or laptop if the host permits it.
  • Use a temporary or guest profile where the service supports one.
  • Sign in directly only as a last resort, then sign out and verify the logout.

Never read your password aloud or send it to another person. A password manager can help you enter a unique password without exposing or memorizing it.

The Federal Trade Commission recommends strong, unique passwords and two-factor authentication to protect online accounts. Its two-factor authentication guidance explains that a second factor helps protect an account when a password is stolen or guessed.

What should you do if you forgot to sign out?

Do not wait until your next visit. Open the streaming provider’s account settings from your own device and look for Manage devices, Device activity, or a similar option.

For example, Netflix lets subscribers use its Manage Access and Devices tools to review recently active devices and sign out of one device or all devices remotely. Netflix notes that some devices may take up to 48 hours to appear and that the list does not necessarily show every device.

Take these steps:

  • Sign out of the television remotely.
  • Review other connected devices.
  • Change your password if you exposed or shared it.
  • Replace that password anywhere you reused it.
  • Enable two-factor authentication if the service offers it.
  • Review payment activity and account changes.

How does casting help someone become safer online?

Casting reduces the number of shared or unfamiliar devices that store your account credentials. That limits opportunities for another person to reopen your account, change settings, or keep streaming after you leave.

It also builds a broader safety habit: keep authentication on devices you own and control.

Casting helps someone become safer online by:

  • Reducing password exposure
  • Preventing forgotten television logins
  • Limiting persistent access to streaming accounts
  • Keeping account control on a trusted personal device
  • Making it easier to end access when viewing is finished
  • Encouraging regular reviews of connected devices

Your safe casting checklist

Before movie night:

  • Update your streaming app and device.
  • Verify the host’s Wi-Fi network.
  • Use the official app’s Cast button.
  • Select the correct television.
  • Avoid unknown plug-ins or casting apps.
  • Disconnect when playback ends.
  • Forget the Wi-Fi network if you do not need it saved.
  • Review connected devices if you signed in directly.

When you visit a friend, casting from your own phone or laptop is often a cleaner security choice than entering your credentials on the television. Your password stays on a device you control, and you can disconnect when the show, movie, or game ends.

Casting does not remove every privacy risk, so use only a trusted Wi-Fi network, verify the receiving television, and end the session before leaving. If you signed in directly, log out and review connected devices afterward.

09.17.26

Using a shared computer? Turn on private browsing to protect your accounts and history

A shared computer can be convenient when you are traveling, visiting a library, staying at a hotel, or borrowing a friend’s laptop. It can also expose your browsing history, login sessions, and personal information to the next person who uses it.

Private browsing, called Incognito in Google Chrome, InPrivate in Microsoft Edge, and Private Browsing in Firefox and Safari, reduces the information the browser keeps after your session ends. It is a useful privacy tool, but it is not an invisibility shield.

What does private browsing do on a shared computer?

Private browsing opens a separate browser session. After you close every private window, the browser generally removes the session’s browsing history, cookies, site data, and information entered into forms.

According to Google Chrome’s official Incognito guidance, Chrome does not retain a record of visited sites or new site data after all Incognito windows close. Google specifically identifies shared computers as a situation where Incognito can be useful.

Similarly, Microsoft explains that Edge InPrivate deletes browsing history, cookies, passwords, addresses, and form data when you close all InPrivate windows.

Private browsing can help prevent the next computer user from:

  • Seeing websites in the browser history
  • Reopening an authenticated session through retained cookies
  • Viewing information entered into forms
  • Finding credentials accidentally saved during the session
  • Seeing searches through the browser’s local history

Does private browsing save passwords or account logins?

Private browsing is designed not to retain new passwords or login cookies after the session closes. However, you still need to sign out manually before closing the browser.

Microsoft’s guidance for public computers recommends using a private window, signing out when finished, and closing every browser window. Closing only one tab may not end the private session if another private window remains open.

Never select options such as:

  • Remember me
  • Keep me signed in
  • Save password
  • Trust this device
  • Stay signed in

If the shared computer asks to save your password, select Never or decline the request.

What does private browsing not protect?

Private browsing primarily protects against local browser history remaining on the device. It does not make your online activity anonymous.

Google states that Incognito does not make users invisible. Websites, schools, employers, and internet service providers may still observe activity. Downloads and bookmarks also remain on the computer unless you remove them yourself.

Firefox explains that private browsing does not protect against malware, hide physical location from websites, or prevent an internet provider from seeing online activity.

Private browsing also cannot protect you from:

  • Keylogging malware that records keystrokes
  • Screen-capture software
  • Fake login pages
  • Someone watching over your shoulder
  • Network monitoring
  • Files you download and leave behind
  • Bookmarks created during the session
  • Activity saved to an account after you sign in

This distinction matters because users may feel safer than they actually are. The FTC reported that more than one million people reported identity theft in 2025, reinforcing the importance of protecting login credentials and personal data wherever you sign in, according to the agency’s online security resources.

Should you access banking or email on a public computer?

Avoid it whenever possible. A private window cannot tell you whether the computer has malware, a keylogger, or unauthorized monitoring software.

The United Nations Office of Information and Communications Technology advises against entering sensitive information on public computers, including logging into work email, banking, or other accounts containing sensitive data.

Use your own phone and cellular connection instead for:

  • Online banking
  • Credit card accounts
  • Medical portals
  • Government services
  • Password managers
  • Work systems
  • Tax information
  • Account recovery

If you absolutely must use a shared computer, enable multifactor authentication and never approve a prompt asking you to trust that device permanently.

How do you open a private browsing window?

Google Chrome

Select the three-dot menu and choose New Incognito window.

Keyboard shortcut:

  • Windows, Linux, or ChromeOS: Ctrl + Shift + N
  • Mac: Command + Shift + N

Microsoft Edge

Select the three-dot menu and choose New InPrivate window.

Keyboard shortcut:

  • Windows: Ctrl + Shift + N
  • Mac: Command + Shift + N

Mozilla Firefox

Open the menu and select New private window.

Keyboard shortcut:

  • Windows or Linux: Ctrl + Shift + P
  • Mac: Command + Shift + P

Confirm the private-browsing indicator appears before entering any information.

What should you do before leaving a shared computer?

Use this step-by-step cleanup routine:

  1. Sign out of every website and app.
  2. Close every private browsing window.
  3. Delete downloaded files from the computer.
  4. Empty the recycle bin or trash if permitted.
  5. Remove files from the browser’s download folder.
  6. Disconnect any USB drive or external device.
  7. Confirm that no account remains visible.
  8. Restart the computer if that option is available.

The FTC recommends logging out when you finish using an account instead of remaining permanently signed in, particularly when using an unfamiliar network or device.

How does private browsing help someone become safer online?

Private browsing reduces the amount of account and browsing information left for the next person using the computer. That limits casual exposure from retained cookies, form entries, account sessions, and browser history.

It helps someone become safer online by:

  • Reducing locally stored browsing data
  • Preventing new login cookies from remaining after closure
  • Lowering the chance of accidentally saving credentials
  • Separating a temporary session from the regular browser profile
  • Encouraging deliberate sign-out and cleanup
  • Protecting searches from other people who use the same device

Private browsing works best as one layer of protection, not the only layer. Avoid sensitive accounts, use multifactor authentication, watch for shoulder surfing, and prefer a personal device whenever possible.

Private browsing is the right tool when your goal is to leave less information behind on a shared computer. It can remove local history, cookies, and session data after every private window closes.

However, it cannot detect malware, stop keyloggers, hide activity from websites or network operators, or protect files left in the Downloads folder. Use a private window, sign out manually, close every window, and avoid high-value accounts on computers you do not control.

09.16.26

Only donate directly to online charities? How to give safely and avoid donation scams

Giving online makes it easy to support causes you care about, but it also gives scammers opportunities to exploit generosity. Criminals create copycat charity websites, impersonate legitimate organizations, launch misleading crowdfunding campaigns, and send urgent donation requests after disasters.

When possible, start at the charity’s official website instead of clicking a donation link in an email, text, advertisement, or social media post. Direct navigation gives you more control over where your money and personal information go.

Is donating directly to a charity safer?

Donating through a charity’s verified website reduces the number of organizations handling your payment and personal information. It also helps you avoid fraudulent links that imitate a legitimate organization.

The Charity and Disaster Fraud guidance from the FBI recommends giving to established charities whose work you know and trust. The FBI also advises donors to manually type website addresses instead of clicking unfamiliar links.

However, donating directly is not an automatic guarantee of safety. A professional-looking website can still belong to a fake organization. You should verify the charity independently before entering a card number, address, or other personal information.

Why do charity scams work so well?

Charity scams exploit emotion and urgency. A request may mention disaster victims, children, veterans, medical care, animals, or another cause that encourages immediate action.

Scammers may contact potential donors through:

  • Emails and text messages
  • Social media posts and advertisements
  • Crowdfunding campaigns
  • Telephone calls
  • Direct messages
  • Copycat charity websites
  • QR codes at events or in public places

The FTC’s charity scam resources warn that scammers often take advantage of major disasters and popular giving seasons when people feel motivated to help quickly.

The financial consequences can be significant. In one charity enforcement matter highlighted by the Federal Trade Commission, a sham cancer charity collected more than $18 million from donors between 2017 and 2022, while the complaint alleged that only about one penny from every donated dollar supported the assistance described to donors.

How can you verify an online charity before donating?

Pause before paying and complete a few independent checks.

Confirm the charity’s legal identity

Use the IRS Tax Exempt Organization Search to review an organization’s federal tax-exempt status, eligibility to receive tax-deductible contributions, and available filings. The IRS tool lets you search by the organization’s name or Employer Identification Number.

Confirm that the name and location match the organization you intend to support. Copycat charities may use names that differ from established organizations by only one or two words.

Tax-exempt status confirms a legal classification, but it does not automatically tell you whether the charity uses donations effectively. Continue researching before giving.

Review independent charity information

The BBB Wise Giving Alliance publishes free reports based on standards covering governance, finances, effectiveness reporting, transparency, and fundraising practices. You can use BBB charity reports and donor resources to research organizations before making a contribution.

Candid’s GuideStar nonprofit database also provides information about IRS-recognized tax-exempt organizations, including financial details, leadership, mission information, and available Form 990 filings.

Use more than one source if you are unfamiliar with the charity.

Navigate to the website independently

Do not use the donation button in an unexpected message. Search for the organization independently, compare the address with trusted listings, and type the verified web address into your browser.

The FBI warns donors to watch for copycat names and avoid providing personal information in response to unsolicited emails, calls, or text messages.

Are third-party donation platforms safe?

Some third-party platforms serve a legitimate purpose. They may process donations for smaller nonprofits, combine contributions to multiple charities, support anonymous giving, or provide centralized receipts.

For example, Charity Navigator describes its Giving Basket as a tool for donating to multiple eligible charities while controlling how much personal information is shared.

Before using any intermediary, check:

  • Whether the charity is eligible to receive the donation
  • Whether the charity recognizes or recommends the platform
  • How much the platform charges in processing or transaction fees
  • Whether an optional tip is added automatically
  • How long the platform takes to distribute funds
  • What personal information the platform collects
  • Whether you will receive an appropriate donation receipt
  • Whether recurring contributions are clearly disclosed

Do not rely on an old list of recommended platforms. Services merge, close, change ownership, or modify their policies. Verify a platform’s current identity, fees, privacy policy, and disbursement process at the time of donation.

Which payment methods are safest for online donations?

The FBI recommends donating by credit card or check and warns that a charity asking for cash, gift cards, cryptocurrency, or wire transfers is probably a scam.

A credit card generally provides a payment record and a way to dispute fraudulent charges. Avoid donation requests that demand:

  • Gift card numbers
  • Cryptocurrency
  • Wire transfers
  • Cash sent to an individual
  • Access to your bank account
  • A verification code
  • Your online banking password

No legitimate charity needs your password or multifactor authentication code to accept a donation.

What should you check on the donation page?

Before submitting payment:

  1. Confirm the charity’s exact name.
  2. Inspect the website address for misspellings.
  3. Make sure the connection uses HTTPS.
  4. Review the donation amount and processing fees.
  5. Check whether the donation is one-time or recurring.
  6. Read how your personal information will be used.
  7. Save the confirmation and receipt.
  8. Monitor your card statement afterward.

HTTPS encrypts information sent to the website, but it does not prove that the organization operating the site is legitimate. Independent charity verification remains essential.

How does donating directly help someone become safer online?

Direct, independently verified giving reduces opportunities for scammers and unknown intermediaries to control the transaction.

This approach helps someone become safer online by:

  • Avoiding phishing links in emotional appeals
  • Reducing unnecessary sharing of payment and personal data
  • Confirming that the organization exists before paying
  • Limiting surprise fees and unwanted recurring donations
  • Creating a reliable transaction record
  • Preventing criminals from redirecting generosity to fake campaigns

These habits apply beyond charitable giving. Independent verification can also protect you from fake invoices, fraudulent payment pages, impersonation scams, and misleading crowdfunding requests.

What should you do if you donated to a scam?

Act quickly:

  • Contact your card issuer or bank.
  • Ask whether the payment can be stopped or disputed.
  • Change any passwords entered on the fraudulent page.
  • Monitor financial accounts for unauthorized activity.
  • Save emails, texts, receipts, screenshots, and website details.
  • Report the incident through the FTC’s official fraud-reporting service.
  • Report charity or disaster fraud to the FBI through the reporting options identified in its charity-fraud guidance

Your safe online donation checklist

Before giving:

  • Research the charity independently.
  • Check its status through the IRS.
  • Review independent charity reports.
  • Type the verified website address yourself.
  • Prefer the charity’s official donation page.
  • Review fees and distribution policies on third-party platforms.
  • Pay by credit card or check.
  • Avoid rushed requests and unusual payment methods.
  • Save the donation receipt.
  • Review your financial statement afterward.

The bottom line

Giving directly through a verified charity website is often the simplest and safest option, but the word “direct” does not replace research. Confirm the organization through the IRS, review independent reports, inspect the payment page, and use a traceable payment method.

A reputable third-party platform can also be appropriate when the charity recognizes it and the platform clearly explains its fees, privacy practices, and distribution process. The safest donation is not simply the fastest one. Pause, verify, and make sure your generosity reaches the cause you intended.

09.15.26

Disconnect smart devices from public Wi-Fi when not in use to reduce online security risks

Free Wi-Fi at airports, hotels, cafés, libraries, and shopping centers can be convenient, especially when cellular coverage is weak. But once you finish checking directions, messages, or travel details, your device may remain connected longer than necessary.

Disconnecting from public Wi-Fi when you are not actively using it reduces unnecessary exposure to a network you do not control. For stronger protection, disable automatic reconnection or forget the network entirely.

Is public Wi-Fi always dangerous?

No. Public Wi-Fi is not automatically unsafe.

The Federal Trade Commission explains that most websites now encrypt traffic, so connecting through a public network is generally safer than it was during the early days of the internet. Look for https or a lock symbol in your browser’s address bar to confirm that your connection to a website is encrypted.

However, encryption does not make every network or website trustworthy. The FTC also warns that scammers can create encrypted fake websites. Encryption may protect your information while it travels to a site, but it cannot protect you from criminals operating the site.

The Federal Communications Commission also warns about imposter Wi-Fi hotspots and recommends confirming the correct network name with an employee before connecting. [fcc.gov]

Why should you disconnect Wi-Fi when you are finished?

Leaving Wi-Fi connected gives your phone, laptop, tablet, smartwatch, or other smart device more time to remain associated with an unfamiliar network.

The National Security Agency recommends disabling Wi-Fi, Bluetooth, and NFC when they are not in use. Its public wireless guidance notes that attackers can use malicious access points, redirects, proxies, and network eavesdropping to target devices and information.

Disconnecting does not erase every risk from a previous session, but it stops the device from continuing to use that hotspot. It also prevents apps from sending or receiving information through the public network while you are not paying attention.

What is the difference between disconnecting and forgetting a Wi-Fi network?

These options solve slightly different problems:

  • Disconnect ends the current Wi-Fi session but usually keeps the network saved.
  • Forget network removes the saved network details, so your device will not reconnect using the stored configuration.
  • Disable auto-connect keeps the network saved but requires you to select it manually later.
  • Turn off Wi-Fi disables all Wi-Fi connections until you switch the feature back on.

For a one-time airport, restaurant, or café hotspot, forgetting the network is often the cleanest choice. For hotel Wi-Fi that you will use throughout a trip, disabling automatic connection may be more convenient.

The FCC recommends adjusting your phone settings so it does not automatically connect to nearby networks outside your list of trusted Wi-Fi connections.

How do you disconnect safely from public Wi-Fi?

The exact menu names vary by device, but you can follow this general process:

  1. Finish the task that required the Wi-Fi connection.
  2. Log out of any websites or apps you opened.
  3. Open your device’s Wi-Fi settings.
  4. Disconnect from the public hotspot.
  5. Turn off automatic connection for that network.
  6. Select Forget network if you will not use it again.
  7. Turn Wi-Fi off completely when you do not need a wireless connection.

The FTC’s public Wi-Fi security recommendations also advise users to log out when they finish using an account instead of staying permanently signed in.

What should you do before using public Wi-Fi?

Verify the real network

Ask an employee for the exact hotspot name and sign-in process. Do not choose a network based only on the strongest signal or a familiar name such as “Hotel Guest” or “Airport Free Wi-Fi.”

An attacker can create an imposter network with a convincing name. The FCC recommends checking with staff when more than one hotspot appears to belong to the same establishment.

Use mobile data for sensitive activity

Whenever possible, use your cellular connection for:

  • Online banking
  • Credit card payments
  • Medical portals
  • Tax or government accounts
  • Password resets
  • Other accounts containing sensitive information

The FCC says a cellular data plan may be more secure than an unfamiliar Wi-Fi network when transmitting sensitive information.

Consider using a trusted VPN

A virtual private network encrypts the connection between your device and the VPN service. The FCC recommends considering a VPN if you regularly rely on public Wi-Fi, while the NSA also recommends using a personal or organization-provided VPN when public Wi-Fi cannot be avoided.

Remember that a VPN does not make a fraudulent site safe. You must still inspect links, verify websites, and avoid unexpected login or payment requests.

Which public Wi-Fi mistakes should you avoid?

Avoid these common mistakes:

  • Automatically joining any network with “free Wi-Fi” in its name
  • Ignoring browser certificate or security warnings
  • Entering passwords through unexpected pop-ups
  • Leaving file sharing or device discovery enabled
  • Accessing financial accounts when cellular data is available
  • Keeping unfamiliar networks saved with auto-connect enabled
  • Assuming https proves that a website itself is legitimate
  • Leaving Bluetooth turned on when you are not using it

How does disconnecting help someone become safer online?

Disconnecting unused Wi-Fi reduces the amount of time your device remains attached to a network you do not control. Disabling auto-connect also restores an important moment of choice because your device must ask before joining again.

This habit helps you become safer online by:

  • Reducing unnecessary network exposure
  • Preventing automatic reconnection to saved public hotspots
  • Encouraging you to verify networks before joining
  • Limiting opportunities for imposter hotspots
  • Moving sensitive activity to cellular data
  • Building the habit of logging out and closing active sessions

The broader cybercrime environment makes these precautions worthwhile. According to the FBI’s 2025 Internet Crime Report, the Internet Crime Complaint Center received more than one million complaints of suspected internet crime, with reported losses exceeding $20 billion. That figure is not specific to public Wi-Fi, but it demonstrates the scale of the threats consumers face online.

Your public Wi-Fi safety checklist

Before walking away from a public hotspot:

  • Log out of active accounts.
  • Disconnect from the network.
  • Disable automatic reconnection.
  • Forget networks you will not use again.
  • Turn Wi-Fi off when it is not needed.
  • Use cellular data for sensitive tasks.
  • Keep your device and browser updated.
  • Review and remove old saved networks regularly.

09.14.26

How to customize your Snapchat location settings and use Ghost Mode safely

Snap Map can make meeting friends and discovering places convenient, but sharing your location also reveals sensitive information about where you are and, potentially, your daily routine.

Fortunately, Snapchat provides controls that let you hide your location completely or share it only with selected friends. Reviewing these settings takes only a few minutes and helps you decide who, if anyone, needs access to your whereabouts.

Who can see your location on Snapchat?

Snapchat lets users control location visibility through Snap Map. The official My Location and Ghost Mode support section includes options for sharing a location with all friends, sharing with selected friends, and turning on Ghost Mode.

Your available audience options may include:

  • My Friends: Shares your location with eligible Snapchat friends.
  • My Friends, Except: Lets you exclude selected friends.
  • Only These Friends: Shares your location only with people you select.
  • Ghost Mode: Hides your location from other Snapchat users.

Choose the smallest audience that genuinely needs your location. A person being on your friends list does not automatically mean that person needs ongoing location access.

How do you turn on Ghost Mode?

Ghost Mode is Snapchat’s primary control for hiding your location on Snap Map. Snapchat’s official support center identifies Ghost Mode as one of its dedicated location controls. [help.snapchat.com]

To review the setting:

  1. Open Snapchat.
  2. Open Snap Map.
  3. Tap the gear icon at the top of the Map screen.
  4. Find Ghost Mode.
  5. Turn Ghost Mode on.
  6. If Snapchat presents duration choices, select the option that fits your needs.

After enabling it, return to Snap Map and confirm that Ghost Mode remains active. App menus can change, so use the current labels displayed on your device.

How do you share your location with only selected friends?

If hiding your location from everyone feels too restrictive, use a selected-friends option instead.

From Snap Map’s settings:

  1. Turn off Ghost Mode only if you intend to share your location.
  2. Select the option for sharing with specific friends.
  3. Carefully review each selected contact.
  4. Remove anyone who no longer needs access.
  5. Recheck the list periodically.

Snapchat’s official location support resources confirm that users can share a location with only selected friends.

Never select someone simply because the account appears familiar. Confirm that you know and trust the person behind the account first.

Can you turn off Snapchat location requests?

Older versions of Snapchat and some third-party instructions reference a separate control for location requests. However, the current official Snapchat support pages found for this article document Ghost Mode and location-audience controls but do not specify a current standalone switch named Allow Friends to Request My Location.

If that option appears in your version of the app, review it inside Snap Map’s settings and disable it if you do not want requests. If it does not appear, use the privacy controls Snapchat currently documents:

  • Enable Ghost Mode.
  • Limit sharing to selected friends.
  • Decline unwanted location requests.
  • Remove or block accounts that repeatedly request access.
  • Restrict Snapchat’s location permission through your phone.

Do not rely on an outdated menu path if the setting is absent from your current app.

Should you also change your phone’s location permission?

Ghost Mode controls whether other Snapchat users can see your location through Snap Map. Your phone’s operating-system permissions separately determine whether Snapchat can access location data.

For stricter privacy, open the privacy or app-permission settings on your phone and review Snapchat’s location access. Depending on the device, the choices displayed may include access only while using the app, precise-location controls, or no location access.

Turning off device-level location access may affect Snapchat features that depend on location. This is a privacy tradeoff rather than a requirement, so choose the narrowest access that still supports the features you actually use.

Why does Snapchat location privacy matter?

Snapchat remains widely used. The Pew Research Center’s 2025 teen social media report found that 55% of U.S. teens ages 13 to 17 use Snapchat, based on a survey of 1,458 teens conducted from September 25 through October 9, 2025.

Location data can reveal more than your current position. Repeated visibility may expose patterns such as:

  • Where you live or attend school
  • When you leave home
  • Frequently visited locations
  • Travel and commuting routines
  • Where you spend evenings or weekends
  • Which friends or places you visit regularly

A trusted friend may also lose control of an account. Limiting location access reduces the effect of a compromised or impersonated account.

How does this help someone become safer online?

Customizing Snapchat’s location controls reduces unnecessary exposure of your physical movements. It also builds a valuable digital-safety habit: access to sensitive information should be limited to the people who need it.

This makes someone safer online by helping to:

  • Prevent strangers or casual contacts from seeing a location
  • Reduce exposure of home, school, and travel routines
  • Limit the impact of a compromised friend account
  • Discourage unwanted monitoring
  • Keep location sharing intentional instead of automatic

Ghost Mode does not make an account completely private, and friends can still learn a location from Stories, messages, landmarks, or shared plans. Location safety therefore depends on both settings and careful posting.

Snapchat location privacy checklist

Review these items today:

  • Turn on Ghost Mode if nobody needs your location.
  • Otherwise, share only with selected, trusted friends.
  • Remove unfamiliar or outdated contacts.
  • Review Snapchat’s location permission on your phone.
  • Avoid posting real-time travel details.
  • Check photos for visible street signs, addresses, or landmarks.
  • Revisit Snap Map settings after app updates.
  • Block accounts that pressure you to share your location.

Snap Map location sharing should always be a deliberate choice. Open the Map settings, enable Ghost Mode for maximum visibility control, or limit sharing to a small group of trusted friends.

Then review your phone’s location permissions and the information visible in your Stories. These simple changes reduce exposure of your whereabouts and make it harder for unwanted contacts to follow your routine.

09.13.26

Football season streaming scams: How to avoid fake sites, apps, and malware

Football season brings packed schedules, exclusive broadcasts, and fans scrambling to find the right stream before kickoff. Scammers exploit that urgency with fake “free game” sites, counterfeit streaming apps, misleading search ads, and malicious pop-ups.

An illegal stream may cost nothing upfront, but it can expose your passwords, payment information, device, and even other equipment connected to your home Wi-Fi.

Why do football streaming scams increase during the season?

Fans often search minutes before a game starts, especially when broadcast rights are spread across several networks and subscription services. That time pressure makes phrases such as “free football livestream” and “watch tonight’s game now” powerful bait.

Criminals create sites and apps that imitate legitimate streaming platforms. Some ask for payment information to start a fake trial. Others display misleading download buttons, trigger endless redirects, or claim that you need a special video player, browser extension, or software update.

The FTC’s guidance about illegal streaming apps warns that pirated video apps and add-ons can spread malware. The FTC says that malware may steal credit card information, shopping credentials, or bank logins, and it may attempt to infect other devices on the same wireless network.

How dangerous are unofficial sports streaming sites?

The risk is more than theoretical. In March 2025, Microsoft Threat Intelligence’s malvertising investigation reported that a large-scale campaign starting on illegal streaming websites affected nearly one million devices globally. Malicious advertising redirects led users through intermediary websites to malware designed to collect system information and steal documents and data.

The U.S. government continues to warn about illicit streaming risks. In July 2026, the U.S. Department of Justice announced the seizure of more than 1,000 domains that were illegally streaming World Cup matches. The announcement specifically warned that some illicit streaming services embed malicious software and may attempt to steal payment information.

What do fake football streaming sites look like?

Counterfeit streaming pages often copy team colors, league imagery, countdown clocks, and familiar video-player controls. A polished design does not prove that a site is safe.

Watch for these warning signs:

  • The site promises every game free without explaining its licensing.
  • Several “Play” or “Download” buttons appear around the video.
  • Clicking the player opens unrelated tabs or redirects.
  • The page says your browser, codec, or media player is outdated.
  • A pop-up claims your device has a virus.
  • The site asks you to install a browser extension.
  • A “free verification” page requests credit card information.
  • The page asks you to disable security software.
  • The website address misspells a known streaming brand.

The FTC advises people to avoid pirated content entirely because illegal streaming apps and add-ons may carry malware.

Can a fake streaming app infect other devices?

Yes. A suspicious app can affect more than the television or streaming box where you install it. The FTC says malware inside a pirate app may try to infect other devices connected to the same wireless network, potentially putting computers used for banking or shopping at risk.

The FBI has also warned that compromised TV streaming devices and other internet-connected products can become part of criminal botnets. Its BADBOX 2.0 public service announcement says devices may arrive with malicious software or become infected after downloading apps with backdoors during setup. [fbi.gov]

Potential warning signs include:

  • An unfamiliar device brand
  • Unofficial app marketplaces
  • Instructions to disable Google Play Protect
  • A device that is not Play Protect certified
  • “Unlocked” access to paid content
  • Unexpected or unexplained internet traffic

The FBI advises consumers to evaluate suspicious devices and consider disconnecting them from their networks.

How can you stream football safely?

Start with the official schedule

Use the NFL’s official Ways to Watch page to identify the network or authorized service carrying a game. The page lists national, local, and out-of-market viewing options and allows viewers to check availability through their existing television or streaming provider.

Then follow these steps:

  1. Open the broadcaster’s official app or type the service’s address into the browser yourself.
  2. Download apps only through an official device store.
  3. Verify the developer and app name before installing.
  4. Avoid links posted in forums, social comments, group chats, or unsolicited messages.
  5. Reject prompts to install unknown players, codecs, extensions, or “security updates.”
  6. Keep the streaming device, browser, and operating system updated.
  7. Use a unique password and multifactor authentication for each streaming account.
  8. Remove old or unrecognized devices from account settings.

Treat sponsored search results carefully

A paid search result can resemble an official listing. Check the destination address before clicking, especially when signing up, entering payment information, or downloading a streaming app.

A safer habit is to navigate through the league, team, network, or streaming provider’s official site. Bookmark the verified page before game day so you do not have to search under kickoff pressure.

What should you do after visiting a suspicious stream?

If the page only opened and you entered nothing:

  • Close the page and unexpected tabs.
  • Do not accept notification requests.
  • Delete files that downloaded unexpectedly without opening them.
  • Update your browser and security software.
  • Run a full malware scan.

If you installed an app, extension, or player:

  1. Disconnect the suspicious device from your network.
  2. Remove the unfamiliar software or extension.
  3. Run an updated security scan.
  4. Change important passwords from a clean device.
  5. Enable multifactor authentication.
  6. Review streaming, email, and financial accounts for unknown activity.
  7. Contact your card issuer if you entered payment information.

Consumers can submit suspected fraud through the FTC’s official reporting service. The FTC says reports help law enforcement identify patterns and investigate scams.

How does this help someone become safer online?

Choosing an authorized stream does more than protect entertainment subscriptions. It prevents unknown operators from controlling the website, app, download, or payment form you use.

These habits help you become safer online by reducing the chance that criminals can:

  • Install malware on your device
  • Steal saved passwords or card details
  • Enroll a streaming box in a botnet
  • Spread malware across your home network
  • Hijack email or streaming accounts
  • Charge you for a fake subscription

Football streaming scams thrive on urgency. Scammers know fans want immediate access and may overlook warning signs when kickoff is seconds away.

Plan before game day. Check the official schedule, use authorized apps, bookmark legitimate services, and never install software demanded by a streaming page. If a site promises every game free but asks you to ignore security warnings, the real cost could be your password, payment information, or device.

09.12.26

What is malvertising? How dangerous ads can infect or redirect your device

Online ads can help you discover products, services, and useful information. Unfortunately, some advertisements hide a more dangerous purpose.

Malvertising, short for malicious advertising, uses compromised or deceptive online ads to distribute malware, redirect people to fraudulent websites, or steal sensitive information. These ads may appear on questionable sites, legitimate websites, social media platforms, and even search results.

What is malvertising and how does it work?

The Cybersecurity and Infrastructure Security Agency’s malvertising guidance defines malvertising as the use of malicious or hijacked advertisements to spread malware. Criminals may insert harmful ads into legitimate advertising networks, allowing the ads to appear on websites that have no idea they are serving dangerous content.

A malicious ad can attack in several ways:

  • Redirect you to a fake login, shopping, or tech support scam page
  • Promote a fraudulent software download
  • Display a fake virus or browser-update warning
  • Send you through several websites before reaching a malware download
  • Exploit an unpatched browser vulnerability
  • Trick you into copying and running a malicious command

Some attacks require a click. Others may use hidden scripts or unpatched vulnerabilities to deliver a harmful payload when the advertisement loads. CISA specifically warns that certain malvertising can compromise a network even if the user does not click the ad.

How dangerous is malvertising?

Malvertising can affect consumers at scale. In March 2025, Microsoft Threat Intelligence reported that one large malvertising campaign affected nearly one million devices worldwide. The campaign started on illegal streaming websites and redirected users through intermediary sites to malicious files hosted on several platforms.

Microsoft found that the campaign used multiple stages to collect system information, deploy more malicious files, and steal documents and data. It affected both consumer and enterprise devices across multiple industries.

That scale shows why an online ad should not automatically earn your trust just because it looks professional or appears on a familiar website.

Can malvertising infect a device without a click?

Yes, under some circumstances. CISA says malicious ads can run hidden scripts, force redirects, or interact directly with users. Unsecure configurations and outdated browsers increase the opportunity for attackers to exploit a device. [

However, not every malicious advertisement automatically causes an infection. The outcome depends on factors that include the ad’s design, the website, browser protections, software vulnerabilities, and whether the user follows additional instructions.

Modern attacks also combine malvertising with social engineering. Microsoft’s analysis of the ClickFix technique describes campaigns that use malvertising and fake verification prompts to persuade people to copy, paste, and run malicious commands themselves.

What does a malicious ad look like?

Malvertising often imitates something familiar or urgent. Watch for ads that:

  • Claim your device has a virus
  • Demand an immediate browser or software update
  • Offer expensive software or subscriptions for free
  • Impersonate a known retailer, antivirus company, or technology brand
  • Place a “Download” button beside unrelated content
  • Ask you to disable security software
  • Instruct you to open PowerShell, Terminal, or the Windows Run dialog
  • Redirect you repeatedly or open unexpected tabs
  • Request passwords, card numbers, or cryptocurrency payments

The Federal Trade Commission advises consumers to be cautious of appealing websites and desirable downloads that lead to malware. The FTC also notes that spyware may redirect computers, monitor browsing, or record keystrokes.

How can you protect yourself from malvertising?

Keep browsers and devices updated

Install browser, operating-system, and security updates promptly. CISA identifies outdated browsers and insecure configurations as common weaknesses associated with malvertising. [cisa.gov]

Avoid sponsored links for sensitive tasks

When downloading software or signing in to a financial account, type the known website address yourself or use a trusted bookmark. Do not assume a sponsored result is the official website.

Use reputable security protections

Enable built-in browser protections and use reputable anti-malware software. CISA also recommends advertising-blocking controls and protective DNS technologies as potential organizational defenses against malicious advertising.

Treat fake updates as a warning sign

Close the page if an advertisement says you must install an urgent browser update. Use your browser’s built-in update menu or visit the developer’s official website instead.

Never run commands supplied by a webpage

A legitimate CAPTCHA or verification check should not require you to paste commands into PowerShell, Terminal, or a Run box. Microsoft says ClickFix campaigns exploit seemingly harmless verification and troubleshooting prompts to persuade victims to execute malicious instructions.

What should you do after clicking a suspicious ad?

If you clicked but entered nothing:

  1. Close the page and unexpected tabs.
  2. Do not accept notifications or download files.
  3. Update your browser and operating system.
  4. Run a full security scan.
  5. Review recently installed apps and browser extensions.

If you downloaded or ran something:

  • Disconnect the device from the internet.
  • Run an updated anti-malware scan.
  • Change important passwords from a clean device.
  • Enable multifactor authentication.
  • Check banking, email, and shopping accounts.
  • Report deceptive advertisements through the platform where they appeared.
  • Report scams through the FTC’s official fraud-reporting service.

How does this help someone become safer online?

Understanding malvertising changes a risky habit: trusting an advertisement because a search engine, website, or social network displayed it.

When you verify destinations independently, keep software patched, reject fake updates, and avoid webpage-supplied commands, you reduce opportunities for attackers to:

  • Install information-stealing malware
  • Capture passwords and payment information
  • Redirect you to impersonation sites
  • Gain remote access to your device
  • Use one compromised account to attack others

Malvertising turns ordinary online advertising into a delivery channel for redirects, scams, and malware. A polished ad is not proof of safety, and a familiar website cannot guarantee that every third-party advertisement is trustworthy.

Pause before clicking sponsored results. Visit official websites directly, keep your browser updated, and treat unexpected downloads or technical instructions as warning signs. These small habits make digital advertising much less useful to cybercriminals.

09.11.26

Fake package delivery texts: Why these scams keep getting harder to spot

Your phone buzzes with a delivery update. The message says your package is delayed because of an incomplete address, unpaid postage, or a customs fee. Since you recently ordered something, the text feels believable. 

That sense of familiarity is exactly what scammers count on. 

Fake package delivery texts, also called smishing attacks, impersonate USPS, UPS, FedEx, DHL, Amazon, and other recognizable brands. The messages direct recipients to look-alike websites that capture payment details, passwords, Social Security numbers, and other personal information. 

How common are fake package delivery texts? 

Delivery scams are not rare or isolated. According to the Federal Trade Commission’s analysis of the top text scams of 2024, consumers reported $470 million in losses from scams that started with text messages in 2024, more than five times the amount reported in 2020. Fake package delivery problems were the most commonly reported type of text scam.

The FTC also notes that reported losses probably represent only a portion of the actual harm because many fraud incidents go unreported. 

Why are package delivery scams getting harder to spot? 

People regularly receive real delivery notifications, so a fake one does not immediately feel unusual. Scammers strengthen the illusion by copying logos, colors, shipping terminology, and website layouts from legitimate carriers. 

Recent variations have also adapted to current events. The Federal Communications Commission’s package delivery scam guidance warns that criminals may send texts claiming a shipment is stuck in customs or requires a tariff payment before delivery. 

Common scam messages claim: 

  • Your address is incomplete. 
  • A delivery attempt failed. 
  • Your package needs to be rescheduled. 
  • You owe a small redelivery or postage fee. 
  • Your order is stuck in customs. 
  • Your package will be returned unless you act immediately. 

The small fee is often bait. The real goal may be to obtain your full credit card number, billing address, security code, login credentials, or Social Security number. 

What is smishing and how does it work? 

Smishing combines “SMS” and “phishing.” The U.S. Postal Inspection Service’s smishing guidance explains that scammers send deceptive text messages designed to persuade recipients to provide personal or financial information. 

The scam usually follows this sequence: 

  1. You receive an unexpected delivery text. 
  2. The message creates urgency or curiosity. 
  3. A link opens a fake carrier website. 
  4. The website requests information or a small payment. 
  5. The scammer captures everything you enter. 

The website may look legitimate on a phone’s smaller screen. A familiar logo and convincing page design can distract you from a misspelled or unrelated web address. 

How can you tell if a delivery text is fake? 

Look for several warning signs instead of relying on grammar alone: 

  • The message arrived unexpectedly. 
  • It contains a shortened, unusual, or misspelled link. 
  • It asks for a password, card number, or Social Security number. 
  • It pressures you to act immediately. 
  • It demands a redelivery fee. 
  • The tracking details do not match your actual order. 
  • It comes from an unfamiliar number or email address. 
  • It asks you to reply, including with the word “STOP.” 

The FCC advises consumers not to reply to suspicious messages, even when a text asks them to respond with “STOP,” because some scammers seek engagement or want to confirm that a phone number is active. 

For USPS specifically, the Postal Inspection Service says customers must first request tracking for a particular package before receiving USPS tracking texts. Those requested messages will not contain a link, and USPS does not charge for its tracking service. 

What should you do when you receive a delivery text? 

Follow one rule: Leave the message and verify independently. 

  • Do not click the link. 
  • Do not reply to the sender. 
  • Open the retailer’s official app or website. 
  • Check the order directly in your purchase history. 
  • Type the carrier’s website address into your browser yourself. 
  • Compare the tracking number with your order confirmation. 
  • Contact the retailer or carrier through verified contact information. 

The FTC recommends contacting the company through a phone number or website you know is real, rather than using information contained in an unexpected text. 

How does this help someone become safer online? 

Independent verification breaks the scam’s chain. You prevent the criminal from controlling where you go, what website you visit, and what information you provide. 

This habit protects more than one package. It trains you to handle bank alerts, toll notices, password warnings, account problems, and other urgent messages with the same healthy caution. 

Safer online behavior means: 

  • Pausing before clicking 
  • Navigating to official websites independently 
  • Questioning unexpected requests for payment 
  • Protecting login credentials and verification codes 
  • Reporting scams so providers can improve filtering 

What should you do if you clicked the link? 

If you clicked but entered nothing, close the page and avoid downloading files. Update your device and security software, then run a security scan if the site initiated a download. 

If you entered information: 

  1. Contact your card issuer or bank immediately if you provided payment information. 
  2. Change exposed passwords from a trusted device. 
  3. Replace reused passwords on other accounts. 
  4. Enable multifactor authentication wherever available. 
  5. Monitor bank, credit card, email, and shopping accounts. 
  6. Save screenshots and transaction details for reporting. 

The Postal Inspection Service advises contacting your financial institution if you interacted with a suspicious USPS-related link. 

How do you report a fake delivery text? 

Forward unwanted texts to 7726, which spells SPAM. The FTC says this helps wireless providers identify and block similar messages. 

For USPS impersonation, forward the message to [email protected] and include a screenshot, the sender’s number, the date, and details about any interaction or loss. The Postal Inspection Service provides complete USPS scam-reporting instructions

You can also report delivery scams through the FTC’s official fraud-reporting system. 

Fake package delivery texts are getting harder to spot because they blend into everyday shopping and shipping activity. Logos, polished language, believable tracking problems, and small payment requests can make a scam feel routine. 

Do not judge the message by appearance alone. Avoid the link, open the retailer or carrier’s official site yourself, and confirm the shipment independently. That brief pause can prevent a fake delivery update from turning into payment fraud, password theft, or identity theft. 

09.10.26

How to turn off ad tracking on Windows and improve your online privacy

Windows includes an advertising ID that allows supported apps and advertising networks to associate information about your activity with a unique identifier. Turning it off will not eliminate advertisements, but it can reduce one way apps build a profile to personalize the ads and recommendations you see.

Here is how the setting works, how to disable it, and which additional privacy controls provide broader protection.

What is the Windows advertising ID?

Windows generates a unique advertising ID for each user on a device. Supported Windows apps can access that identifier and use it alongside information they collect to deliver personalized advertisements and other tailored experiences. Microsoft compares the identifier to the unique IDs websites store in browser cookies.

For example, an app or its advertising partners might associate the ID with:

  • Your activity inside participating Windows apps
  • Topics or products that appear to interest you
  • Advertisements you viewed or interacted with
  • Information collected under the app provider’s privacy policy

This setting is specific to the Windows advertising identifier. It does not control every form of data collection or personalized advertising on your computer. Browser cookies, website trackers, account-based personalization, mobile advertising IDs, and third-party applications may use separate tracking methods.

Why should you turn off ad tracking on Windows?

Turning off the advertising ID limits supported apps’ access to a common identifier used for cross-app personalization. This makes it harder for participating apps and advertising networks to connect activity to the same Windows advertising profile. [

Privacy concerns surrounding commercial data collection are widespread. In a survey of 5,101 U.S. adults, 67% said they understood little to nothing about what companies do with their personal data, according to the Pew Research Center’s data privacy report.

Turning this setting off helps someone become safer online by reducing an unnecessary identifier available to supported apps. It will not prevent malware, phishing, or account theft, but privacy and cybersecurity overlap. The less unnecessary data companies and apps can associate with you, the smaller the profile that may be exposed, misused, or used to target persuasive advertising.

How do you turn off the advertising ID in Windows 11?

Microsoft is replacing the General privacy page with a Recommendations & offers page in newer versions of Windows 11. The wording you see will depend on your installed Windows version.

On newer versions of Windows 11

  1. Select Start.
  2. Open Settings.
  3. Select Privacy & security.
  4. Open Recommendations & offers.
  5. Find Advertising ID.
  6. Turn the switch Off.

If your Windows 11 PC still shows the General page

  1. Go to Start > Settings.
  2. Select Privacy & security.
  3. Select General.
  4. Turn off Let apps show me personalized ads by using my advertising ID.

Microsoft confirms that the older General page may still appear on devices that have not received the newest Settings layout.

The change should take effect without a restart. If you later switch the feature back on, Microsoft says Windows will reset the advertising ID.

How do you turn off the advertising ID in Windows 10?

On Windows 10:

  1. Open Start.
  2. Select Settings.
  3. Open Privacy.
  4. Select General.
  5. Turn off the option that allows apps to use your advertising ID for personalized or relevant ads.

Labels may vary slightly by Windows build, but the switch should mention apps using the advertising ID to make advertisements more relevant. Microsoft’s general privacy guidance covers privacy controls for both Windows 10 and Windows 11.

Will turning off the advertising ID block ads?

No. Turning off this feature does not function as an ad blocker, and it does not reduce the total number of advertisements you see. Microsoft says the ads may simply become less personalized or relevant.

It also does not automatically:

  • Block browser cookies
  • Stop website fingerprinting
  • Clear your browsing history
  • Disable advertisements in every Microsoft product
  • Change privacy settings in third-party apps
  • Stop account-based personalization
  • Remove existing data held by an advertiser

The FTC explains that websites and apps can also track activity through cookies, pixels, device fingerprinting, and advertising identifiers. Companies may use that information for analytics, personalization, and targeted advertising.

What other Windows and browser privacy settings should you review?

Disabling the Windows advertising ID is a good start, but broader protection requires a few more steps.

Review Windows permissions

Open Settings > Privacy & security and review which apps can access:

  • Your location
  • Camera and microphone
  • Contacts and calendar
  • Notifications
  • Files and downloads
  • Diagnostics and activity data

Microsoft provides these settings so users can decide how much information they want to share.

Manage browser tracking

The Windows advertising ID does not control tracking inside Chrome, Edge, Firefox, or another browser. The FTC recommends reviewing browser privacy settings and clearing cookies and browsing history if you do not want advertising based on past activity.

Consider taking these actions:

  • Block or limit third-party cookies
  • Clear old cookies and browsing data
  • Review location permissions
  • Remove extensions you no longer use
  • Turn off personalized advertising within major online accounts
  • Use private browsing for temporary sessions

Private browsing can remove local history after a session, but the FTC notes that it does not stop websites from seeing your online activity while you browse.

Your Windows privacy checklist

For a quick privacy tune-up:

  • Turn off the Windows advertising ID.
  • Review Windows app permissions.
  • Disable location access for apps that do not need it.
  • Limit third-party cookies in your browser.
  • Clear old cookies and search history.
  • Remove unused apps and browser extensions.
  • Review advertising preferences in your online accounts.
  • Recheck privacy settings after major Windows updates.

Turning off ad tracking in Windows takes less than a minute and reduces one way supported apps can connect your activity to a personalized advertising profile. It will not make you anonymous or block every advertisement, but it gives you more control over an identifier you may not need.

Use it as the first step in a wider privacy cleanup. Review app permissions, browser tracking, connected accounts, and personalized advertising settings regularly. Each change limits unnecessary data collection and helps create a safer, more private online experience.

09.09.26

Why every home should have a guest Wi‑Fi network for better security

When friends, family members, contractors, or delivery technicians visit your home, someone will eventually ask for your Wi‑Fi password. While sharing your primary network may seem harmless, it’s not the safest option.

A better alternative is creating a guest Wi‑Fi network. Most modern routers support this feature, and it helps protect your devices by separating visitor traffic from your primary network. In today’s connected homes, where laptops, smartphones, security cameras, smart TVs, and voice assistants all share the same network, segmentation can significantly improve your cybersecurity posture.

If you’re looking for a simple security improvement that takes only a few minutes to set up, a guest Wi‑Fi network should be near the top of your list.

What is a guest Wi‑Fi network?

A guest Wi‑Fi network is a separate wireless network that provides internet access to visitors without granting access to devices connected to your primary network.

This separation can help protect:

  • Personal computers
  • Smartphones and tablets
  • Network storage devices
  • Smart home hubs
  • Security cameras
  • Printers
  • Connected IoT devices

The Federal Communications Commission (FCC) recommends securing home wireless networks and managing access carefully to protect personal data and connected devices. Learn more in the FCC’s guidance on protecting your wireless network.

Think of a guest network as a separate entrance to your home. Visitors can use the internet, but they can’t freely access the devices and information connected to your primary network.

Why is sharing your primary Wi‑Fi network a security risk?

Every device connected to your main Wi‑Fi network becomes part of your trusted environment.

The challenge is that you rarely know the security status of another person’s device. Their laptop or smartphone may contain:

  • Malware
  • Spyware
  • Adware
  • Vulnerable software
  • Outdated operating systems
  • Infected browser extensions

The Cybersecurity and Infrastructure Security Agency (CISA) recommends adopting layered security practices and reducing unnecessary access to critical systems because limiting access can reduce the impact of cyber threats. Review CISA’s cybersecurity best practices.

Potential risks of sharing your main network

  • Malware spreading to other connected devices
  • Unauthorized access to shared resources
  • Increased exposure of smart home devices
  • Network reconnaissance by attackers
  • Reduced visibility into who is using your network

A guest network creates an extra layer of protection by isolating visitor traffic from your primary devices.

How does a guest Wi‑Fi network help someone become safer online?

This is one of the most common questions homeowners ask.

The answer is simple: network segmentation reduces risk.

Businesses, government agencies, and security teams frequently use network segmentation to help contain threats. The National Institute of Standards and Technology (NIST) recognizes network segmentation as a valuable security practice that helps reduce the spread of cyber threats across connected systems.

Benefits of using a guest network

  • Limits access to personal devices
  • Reduces malware propagation risks
  • Protects smart home ecosystems
  • Improves privacy
  • Strengthens overall network security
  • Gives homeowners greater control over connected devices

The fewer pathways attackers have into your network, the safer your digital environment becomes.

Are smart home devices safer on a guest network?

In many cases, yes.

Modern households commonly contain dozens of internet-connected devices, including:

  • Smart TVs
  • Streaming devices
  • Smart thermostats
  • Video doorbells
  • Voice assistants
  • Connected appliances
  • Security cameras

The FBI has warned consumers that insecure Internet of Things (IoT) devices can create opportunities for cybercriminals to gain access to networks and personal information.

Separating guest devices from critical household systems can help reduce the likelihood that a compromised device affects the rest of the network.

You may also want to read:

  • How to protect smart home devices from cyberattacks
  • Why you should change your router’s default password
  • Stop auto-connecting to Wi‑Fi and Bluetooth
  • How to stay safe on public Wi‑Fi

What does the data say about network security?

According to the 2024 Verizon Data Breach Investigations Report (DBIR), system intrusion continued to be one of the leading breach patterns observed across industries, reinforcing the importance of limiting unnecessary access and reducing attack surfaces.

While a guest network alone won’t stop every cyberattack, reducing unnecessary connectivity and isolating devices are proven security principles used throughout the cybersecurity industry.

How do you set up a guest Wi‑Fi network?

Most modern routers make the process straightforward.

Step 1: Sign in to your router

Open a web browser and navigate to your router’s management portal.

Common router addresses include:

  • 192.168.0.1
  • 192.168.1.1

Step 2: Locate guest network settings

Look for settings labeled:

  • Guest Network
  • Guest Wi‑Fi
  • Wireless Settings

Step 3: Create the network

Configure:

  • A unique network name (SSID)
  • A strong password
  • WPA3 encryption when available
  • WPA2 encryption if WPA3 is unavailable

Step 4: Enable device isolation

If available, enable:

  • Guest Isolation
  • Client Isolation
  • Disable access to local network resources

These settings prevent guest devices from communicating directly with devices on your primary network.

Step 5: Test connectivity

Verify that:

  • Guests can access the internet
  • Personal devices remain inaccessible
  • Security settings work properly

Frequently asked questions

Should a guest Wi‑Fi network have a password?

Yes. Password protection helps prevent unauthorized users from consuming bandwidth or attempting attacks against connected devices.

Can guests access my personal devices?

Typically no. Properly configured guest networks isolate visitor traffic from your computers, phones, and smart home systems.

Does a guest network slow down internet speeds?

Most modern routers handle guest traffic efficiently. Some even allow administrators to set bandwidth limits for guest users.

Is a guest network worth setting up even if I rarely have visitors?

Absolutely. Many homeowners use guest networks to isolate IoT and smart home devices as an additional security measure.

Final takeaway

A guest Wi‑Fi network is one of the easiest and most effective cybersecurity upgrades for any household. It allows visitors to access the internet without exposing your personal devices, files, and smart home technology.

By separating guest traffic from your primary network, you reduce opportunities for malware spread, improve your privacy, and create another layer of defense against cyber threats.

If your router supports guest networking, take a few minutes today to enable it. It’s a small change that can make a meaningful difference in your online safety.

09.08.26

Stop auto-connecting to Wi‑Fi and Bluetooth to make your devices safer

Most people think cybersecurity starts with strong passwords and antivirus software. While those are important, one of the easiest ways to improve your digital security is hiding in your smartphone settings: turning off automatic Wi‑Fi and Bluetooth connections.

Many smartphones and tablets constantly search for nearby networks and devices. This feature is convenient, but it can also create opportunities for cybercriminals to intercept data, track devices, or trick users into connecting to malicious networks.

If you’re looking for a simple security setting that can immediately reduce your exposure to online threats, disabling auto-connect for Wi‑Fi and Bluetooth is a smart place to start.

Why do phones automatically connect to Wi‑Fi and Bluetooth?

Device manufacturers enable these features to make life easier. Your phone remembers previously used networks, wireless earbuds, speakers, smartwatches, and vehicle infotainment systems so you can reconnect automatically.

While convenient, automatic connections can create security risks when your device connects without your knowledge.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends disabling wireless features such as Bluetooth and Wi‑Fi when they are not needed because they can increase a device’s attack surface and create unnecessary exposure to threats.

What are the risks of auto-connecting to public Wi‑Fi?

Public Wi‑Fi remains one of the most common attack vectors for travelers and remote workers.

According to the FBI, cybercriminals frequently exploit public wireless networks to steal information, monitor activity, and conduct phishing attacks through fake hotspots.

Common Wi‑Fi risks include:

  • Fake “evil twin” hotspots designed to mimic legitimate networks
  • Unencrypted connections that expose data
  • Man-in-the-middle attacks
  • Device tracking and profiling
  • Malware delivery through compromised networks

Imagine walking into an airport and your phone automatically reconnects to a network it remembers from a previous visit. If an attacker creates a fake version of that network, your device could connect without you realizing it.

What are the risks of leaving Bluetooth on?

Bluetooth is incredibly useful, but it also broadcasts information that can potentially be discovered by nearby devices.

Security researchers and government agencies such as the U.S. National Security Agency (NSA) have long recommended disabling Bluetooth when it isn’t actively being used.

Potential Bluetooth threats include:

  • Unauthorized device pairing attempts
  • Bluetooth tracking
  • Data interception
  • Bluejacking spam messages
  • Exploitation of Bluetooth vulnerabilities

Most modern Bluetooth implementations are much safer than older versions, but reducing exposure remains a cybersecurity best practice.

How does turning off auto-connect make you safer online?

This is one of the most common questions people ask.

The answer is simple: you gain control over when and where your device connects.

When your phone automatically joins networks and devices, it makes decisions without your direct approval.

By manually controlling connections, you:

  • Reduce exposure to rogue networks
  • Prevent accidental connections
  • Lower the risk of wireless attacks
  • Improve location privacy
  • Increase visibility into your device activity

Cybersecurity is fundamentally about reducing unnecessary risk. Disabling automatic connections removes opportunities that attackers often exploit.

How to disable Wi‑Fi auto-connect

Most smartphones have a similar process.

On Android

  1. Open Settings
  2. Select Network & Internet or Connections
  3. Tap Wi‑Fi
  4. Choose a saved network
  5. Disable Auto Connect or Connect Automatically

On iPhone

  1. Open Settings
  2. Tap Wi‑Fi
  3. Select the information icon next to a saved network
  4. Disable Auto‑Join

Review your saved networks regularly and remove any you no longer use.

How to manage Bluetooth securely

You don’t necessarily need to disable Bluetooth permanently.

Instead, follow these best practices:

  • Turn Bluetooth off when not in use
  • Remove old paired devices
  • Reject unexpected pairing requests
  • Keep your phone updated
  • Avoid pairing in crowded public locations

These simple actions significantly reduce your wireless exposure.

Additional mobile security tips

While you’re updating settings, consider strengthening your device security with these steps:

  • Enable automatic operating system updates
  • Use multifactor authentication whenever available
  • Install apps only from trusted app stores
  • Review app permissions regularly
  • Use a strong screen lock
  • Enable Find My Device features

When multiple security controls work together, attackers have a much harder time compromising your information.

Final takeaway

Disabling automatic Wi‑Fi and Bluetooth connections won’t dramatically change how you use your phone, but it can significantly reduce your exposure to unnecessary security risks.

Every automatic connection is a potential opportunity for a cybercriminal to exploit a trusted relationship between your device and a network or peripheral. By choosing when your device connects, you put yourself back in control.

The next time you review your smartphone settings, take a few minutes to disable auto-connect features. It’s a quick security win that helps protect your privacy, data, and online safety every day.

09.07.26

Turn off your phone’s always-on display to protect your privacy

Most smartphone users focus on strong passwords, biometric logins, and software updates. Those are important security habits, but many people overlook a surprisingly common privacy risk: the always-on display (AOD) feature.

Many Android smartphones and some other devices show the time, date, battery status, and notifications on the screen even when the phone is locked. While that convenience can save a few taps, it can also expose sensitive information to anyone nearby.

If you’re looking for a simple way to strengthen your mobile security today, turning off your phone’s always-on display or limiting notification previews is a smart place to start.

What is an always-on display?

An always-on display is a feature that keeps a portion of your screen active while the device remains locked. Depending on your settings, it may show:

  • Text messages
  • Email notifications
  • Calendar reminders
  • Authentication codes
  • Social media alerts
  • Banking app notifications

The feature is designed for convenience, but convenience and privacy don’t always go hand in hand.

Why can an always-on display be a security risk?

The biggest risk is information exposure.

The U.S. National Institute of Standards and Technology (NIST) specifically warns that sensitive information contained in notifications may be displayed even when a mobile device is locked, allowing someone with physical proximity to gain unauthorized access to that information through lock screen notifications.

Think about everyday situations:

  • Sitting in a crowded coffee shop
  • Waiting at an airport gate
  • Working in a shared office
  • Leaving your phone on a restaurant table
  • Charging your device during a meeting

In each scenario, someone nearby may be able to view information without ever touching your phone.

What kind of information could be exposed?

Many users assume lock screens only show notification icons. In reality, devices can display much more depending on configuration.

Sensitive information commonly exposed includes:

  • One-time verification codes
  • Password reset notifications
  • Email subjects
  • Meeting details
  • Delivery notifications containing addresses
  • Financial transaction alerts
  • Personal text message previews

Even small details can help cybercriminals conduct phishing attacks or social engineering scams.

How does this help someone become safer online?

Cybersecurity is often about reducing the amount of information available to attackers.

When you hide notification content or disable your always-on display:

  • Fewer personal details are visible to strangers
  • Sensitive account information stays private
  • Verification codes are less likely to be exposed
  • Social engineering attacks become harder
  • You gain greater control over your personal data

In other words, you reduce opportunities for criminals to gather information about you.

What should you do instead?

You don’t have to eliminate convenience completely.

A better approach is to limit what appears on your lock screen.

Recommended security settings

Consider making these changes:

  • Turn off the always-on display entirely
  • Hide notification previews on the lock screen
  • Show notification icons only
  • Require biometric authentication before displaying message content
  • Disable lock screen visibility for banking and financial apps
  • Hide email previews while the device is locked

These small adjustments can dramatically improve your privacy without affecting everyday usability.

How to turn off always-on display

The exact steps vary by manufacturer, but generally:

On Android devices

  1. Open Settings
  2. Tap Display or Lock Screen
  3. Select Always-On Display
  4. Toggle the feature Off

On Samsung Galaxy devices

  1. Open Settings
  2. Tap Lock Screen and AOD
  3. Select Always On Display
  4. Turn the feature Off

Review notification privacy settings

While you’re updating security settings, also:

  1. Open Settings
  2. Select Notifications
  3. Tap Lock Screen Notifications
  4. Choose Hide Sensitive Content or Show Icons Only

This provides a balance between awareness and privacy.

Additional smartphone privacy tips

For even stronger protection:

  • Enable automatic software updates
  • Use a strong PIN alongside biometrics
  • Install apps only from trusted sources
  • Remove unused applications
  • Turn on Find My Device capabilities
  • Review app permissions regularly

The National Institute of Standards and Technology’s mobile security guidance emphasizes the importance of securing mobile devices because they routinely store and access sensitive personal and business information.

Final takeaway

Turning off your phone’s always-on display may seem like a small change, but it can have a meaningful impact on your privacy. Every notification preview, authentication code, and message snippet visible on a locked screen represents information that others may see.

By disabling the always-on display or limiting lock screen notification content, you make it harder for strangers, scammers, and opportunistic attackers to gather information about you. It’s one of the quickest mobile security improvements you can make today, and it’s a simple step toward a safer digital life.

09.06.26

Why you should review online privacy policies: A simple habit that helps protect your personal data

Every day, we click “I Agree” without thinking twice.

Whether you’re signing up for a new social media platform, downloading an app, creating an online shopping account, or using a streaming service, you’re likely accepting a privacy policy that explains exactly how your information will be collected, stored, shared, and used.

Most people skip these policies because they’re long and filled with legal language. Unfortunately, that’s where companies often disclose some of the most important details about your personal information.

Reviewing privacy policies may not sound exciting, but it is one of the easiest ways to take more control of your digital life.

What is a privacy policy and why does it matter?

A privacy policy explains how a company handles your data.

It typically outlines:

  • What information is collected
  • How the information is used
  • Whether data is shared with third parties
  • How long information is retained
  • How advertising and tracking work
  • What privacy controls are available
  • How users can delete or request access to their data

Many organizations update their privacy policies regularly as they introduce new products, features, advertising partnerships, or AI-powered services.

When a company sends you a notification about a privacy policy update, don’t ignore it. That update may significantly change how your data is collected or shared.

What personal data do companies typically collect?

Many services collect far more than basic account information.

Depending on the platform, they may gather:

  • Name and email address
  • Phone number
  • Device information
  • Location data
  • Browsing activity
  • Purchase history
  • Search history
  • Advertising interactions
  • Contacts and social connections
  • Photos and uploaded files

Mozilla notes that online services and advertising technologies often collect information about user activity across websites and applications, which can be used to build advertising and behavioral profiles. The organization’s guidance on privacy tools such as Facebook Container highlights how companies may associate activity across multiple websites with a user identity.

Why should you read privacy policy updates?

Privacy policies can change at any time.

A company may update its policy to:

  • Expand data collection
  • Introduce AI features
  • Partner with advertisers
  • Share data with additional vendors
  • Enable new tracking technologies
  • Modify account retention practices

Even a small update can change how much information a business gathers about you.

Instead of deleting the update email immediately, spend a few minutes reviewing the key sections.

Focus on what has changed.

Which sections of a privacy policy are most important?

You do not need to read every word.

Look for these high-impact areas first.

Information collected

This section explains exactly what data is gathered.

Pay attention to:

  • Location tracking
  • Contact access
  • Browsing activity
  • Device details
  • Biometric information
  • Usage analytics

Data sharing and third parties

This section often reveals whether your information may be shared with:

  • Advertising partners
  • Analytics companies
  • Affiliates
  • Data processors
  • Business partners

The more organizations that receive your information, the less control you ultimately have over it.

User controls and privacy settings

Look for tools that allow you to:

  • Opt out of targeted ads
  • Restrict tracking
  • Delete data
  • Download account information
  • Manage consent settings

Data retention

Check whether the company explains:

  • How long it keeps your information
  • What happens after account deletion
  • Whether backup copies remain

How does reviewing privacy policies make someone safer online?

Reviewing privacy policies helps someone become safer online because it reduces surprises.

When you understand how a company handles your information, you can make informed decisions about:

  • What you share
  • Which permissions you grant
  • Which services you trust
  • Whether you want to continue using a platform

This protects:

  • Personal information
  • Browsing habits
  • Location data
  • Financial information
  • Contacts
  • Photos
  • Online identities

Privacy and cybersecurity are closely connected. The less unnecessary information exposed, the less information available to advertisers, scammers, data brokers, and cybercriminals.

How can you review privacy policies without spending hours reading them?

Use this simple process:

Privacy policy review checklist

When a policy changes:

✅ Read the summary of changes

✅ Search the document for “collect”

✅ Search for “share”

✅ Search for “third parties”

✅ Search for “advertising”

✅ Search for “retention”

✅ Search for “location”

✅ Review privacy settings afterward

✅ Disable unnecessary permissions

✅ Decide whether you’re comfortable with the changes

Most privacy policies can be reviewed in less than 10 minutes using this method.

What should you do after reviewing a privacy policy?

Take action when necessary.

You may decide to:

  • Adjust account privacy settings
  • Turn off ad personalization
  • Disable location sharing
  • Remove third-party app access
  • Limit profile visibility
  • Delete old accounts
  • Move to a more privacy-friendly service

Reading the policy is only useful if it informs your decisions afterward.

Red flags to watch for

Pay closer attention if a policy indicates:

  • Extensive third-party sharing
  • Automatic location tracking
  • Broad data retention periods
  • Collection of unnecessary information
  • Vague descriptions of data use
  • Limited user control options

These don’t automatically mean a service is unsafe, but they may influence how much information you choose to provide.

Privacy policies are often treated like internet fine print, but they contain valuable information about how your personal data is handled.

You don’t need to become a legal expert. You simply need to understand the basics: what information is collected, who receives it, how long it’s retained, and what controls are available to you.

09.05.26

5 browser security tips that can stop cyberattacks before they start

Most people think of cybersecurity in terms of antivirus software, firewalls, or password protection. But one of the most targeted applications on your device is the one you use every day: your web browser.

Whether you’re shopping online, managing bank accounts, checking email, working remotely, or scrolling social media, your browser serves as the front door to your digital life. If cybercriminals can trick you through that browser, they may gain access to sensitive accounts, financial information, and personal data.

That’s why browser security matters more than ever.

Why do hackers target web browsers?

Your browser connects you to nearly everything you do online. Attackers know that compromising a browser is often easier than attacking a device directly.

Cybercriminals commonly use:

  • Fake websites
  • Phishing pages
  • Malicious browser extensions
  • Fake software updates
  • Dangerous downloads
  • Session hijacking attacks
  • Stolen browser cookies
  • Malicious advertisements
  • Credential theft campaigns

According to CISA’s guidance on phishing, most online attacks begin with a single click, often involving a malicious link, attachment, or deceptive website.

That makes your browser one of the most important security tools you own.

How can a browser become a security risk?

Many attacks don’t exploit software flaws. Instead, they exploit human behavior.

For example:

  • Clicking a fake login page
  • Downloading a fake PDF reader
  • Installing an unsafe extension
  • Reusing a password
  • Entering credentials into a fraudulent website

The browser itself may be secure, but unsafe browsing habits can create opportunities for attackers.

The joint phishing guidance from CISA, NSA, FBI, and MS-ISAC explains that attackers commonly use phishing websites to steal credentials and deploy malware.

What browser threats should consumers watch for?

Fake websites and phishing pages

Modern phishing websites often look identical to legitimate brands.

Watch for:

  • Misspelled domains
  • Extra words in web addresses
  • Unexpected login prompts
  • Urgent warnings
  • Requests for passwords or verification codes

Always manually verify the website URL before signing in.

Malicious browser extensions

Extensions can improve productivity, but they can also access:

  • Browsing history
  • Website content
  • Saved passwords
  • Cookies
  • Account information

Install extensions only from official browser stores and reputable developers.

Stolen cookies and session hijacking

Cookies help websites remember your login status.

However, criminals sometimes target browser cookies to:

  • Bypass passwords
  • Hijack sessions
  • Access accounts without logging in again

Keeping your browser updated helps reduce this risk.

Fake downloads

Attackers frequently disguise malware as:

  • Browser updates
  • PDF readers
  • Video codecs
  • Tax forms
  • Invoice attachments

If you weren’t planning to download it before seeing the popup, don’t install it without independent verification.

Malicious pop-ups

Fake security warnings often claim:

  • Your computer is infected
  • A virus was detected
  • Immediate action is required

Legitimate operating systems and browsers do not typically use random webpages to demand emergency security actions.

How does browser security help someone become safer online?

Improving browser security helps someone become safer online by reducing exposure to the most common attack methods used by cybercriminals.

Strong browser security helps prevent:

  • Identity theft
  • Account takeovers
  • Financial fraud
  • Malware infections
  • Ransomware attacks
  • Credential theft
  • Social engineering scams
  • Unauthorized account access

Think of your browser as your digital front door. The stronger that door is, the harder it becomes for attackers to get inside.

5 browser security tips everyone should follow

1. Keep your browser updated

  • Browser updates often contain critical security patches.
  • Enable automatic updates whenever possible.
  • An outdated browser may contain vulnerabilities attackers already know how to exploit.

2. Install extensions only from trusted sources

Before installing an extension:

  • Read recent reviews
  • Check the developer
  • Review requested permissions
  • Avoid unnecessary extensions
  • Remove extensions you no longer use.

3. Check website URLs before entering passwords

Before entering credentials:

  • Verify the domain name
  • Look for spelling errors
  • Confirm you’re on the site’s legitimate address
  • Never trust a login page simply because it looks authentic.

4. Avoid downloading files from unknown websites

Only download software from:

  • Official vendor websites
  • Trusted app stores
  • Verified business portals

Avoid downloads promoted through pop-ups, ads, or unsolicited messages.

5. Use a password manager and multifactor authentication

Strong passwords remain essential.

Use:

Microsoft notes in its latest Digital Defense Report that security systems process enormous volumes of modern threats, including blocking approximately 4.5 million new malware files every day.

That statistic highlights the scale of the threats consumers face daily.

Browser security checklist

Use this quick checklist:

✅ Keep browsers updated

✅ Use MFA

✅ Use a password manager

✅ Verify URLs carefully

✅ Remove unused extensions

✅ Review extension permissions

✅ Avoid suspicious downloads

✅ Block pop-ups when possible

✅ Sign out of shared devices

✅ Monitor browser security settings regularly

Your browser is more than a tool for accessing websites. It’s one of the primary battlegrounds between consumers and cybercriminals.

By keeping your browser updated, verifying website URLs, avoiding suspicious downloads, limiting extensions, and using MFA, you can dramatically reduce your exposure to online threats.

09.04.26

Back-to-school scams are surging: How families can protect themselves from cybercriminals this school year

Back-to-school season means shopping for supplies, paying activity fees, setting up student accounts, and helping kids prepare for a new year. Unfortunately, it also marks one of the busiest times of year for scammers.

Cybercriminals know that parents are rushing, students are distracted, and schools are sending a flood of legitimate emails and messages. That creates the perfect environment for fraud.

The IRS Criminal Investigation division (IRS-CI) recently warned that back-to-school season brings spikes in online shopping scams, impersonation schemes, scholarship fraud, and scams targeting children through gaming platforms and social media. Even more alarming, IRS-CI reported identifying more than $24 million in cyber-related crime during fiscal year 2025.

The good news? Most of these scams share common warning signs that families can learn to recognize before becoming victims.

Why do scammers target families during back-to-school season?

Back-to-school shopping creates a perfect storm for cybercriminals:

  • Parents are making frequent online purchases
  • Schools send numerous emails and payment requests
  • Students use social media, gaming platforms, and messaging apps
  • Families may apply for scholarships or financial aid
  • New devices are being purchased and configured
  • People are multitasking and making quick decisions

According to an IRS-CI warning reported by CPA Practice Advisor, fraudsters frequently exploit this season through fake e-commerce sites, school impersonation scams, scholarship scams, and digital exploitation targeting minors.

What are the most common back-to-school scams right now?

Fake online shopping websites

One of the fastest-growing fraud trends involves websites offering massive discounts on school supplies, backpacks, laptops, tablets, and clothing.

Watch for:

  • Prices that seem too good to be true
  • Websites with little contact information
  • Pressure to purchase immediately
  • Requests for cryptocurrency or gift card payments
  • Poorly written product descriptions

The IRS warns that fraudulent online stores frequently lure shoppers with unusually steep discounts and pressure buyers into using difficult-to-trace payment methods.

School impersonation scams

Criminals may impersonate:

  • School administrators
  • District officials
  • PTA organizations
  • Scholarship providers
  • Government agencies

Their goal is often to trick parents into:

The IRS advises families to independently verify any payment requests by contacting schools through known contact information rather than using links provided in emails or texts.

Scholarship and financial aid scams

Students may receive messages promising:

  • Guaranteed scholarships
  • Exclusive grants
  • Fast-track financial aid
  • Free college assistance

Red flags include:

  • Upfront fees
  • Requests for Social Security numbers
  • Pressure to act immediately
  • Unsolicited offers

Legitimate scholarship providers generally do not demand payment to apply.

Gaming and social media scams targeting students

Children and teenagers increasingly face scams through:

  • Gaming platforms
  • Social apps
  • Discord servers
  • Messaging platforms
  • Livestream communities

These scams may promise:

  • Free game currency
  • Exclusive rewards
  • Influencer giveaways
  • Contest prizes

They often seek personal information, account credentials, or payment details. IRS investigators specifically warn that scammers use gaming platforms and social media to target minors during back-to-school season.

How can parents protect their children online?

Children often don’t recognize fraud tactics as quickly as adults.

Teach these online safety rules

  • Never share passwords
  • Don’t click links from strangers
  • Avoid downloading unknown files
  • Never reveal home addresses
  • Be suspicious of “free” offers
  • Tell a parent about unusual messages
  • Verify requests for personal information

Parents should regularly discuss scams just like they discuss stranger danger in the physical world.

How does this help someone become safer online?

Understanding seasonal scam tactics helps families recognize fraud before money or personal information is stolen.

This awareness helps protect:

  • School payment accounts
  • Banking information
  • Children’s identities
  • Email accounts
  • Social media profiles
  • Student records
  • Family finances
  • Personal data

The biggest cybersecurity advantage isn’t technology. It’s knowing when something feels suspicious and taking a moment to verify it.

What should families do before making purchases?

Back-to-school cybersecurity checklist

Before buying supplies or paying school-related fees:

✅ Shop with established retailers

✅ Verify website addresses carefully

✅ Read recent reviews

✅ Pay with credit cards when possible

✅ Avoid gift card payments

✅ Avoid wire transfers

✅ Enable multifactor authentication

✅ Keep devices updated

✅ Verify all school communications independently

✅ Monitor children’s online activity

✅ Teach children to report suspicious messages

✅ Freeze a child’s credit if appropriate

The IRS notes that credit freezes can help prevent criminals from opening fraudulent accounts using a child’s identity.

What should you do if you suspect a scam?

Act quickly:

  1. Stop communicating with the suspected scammer.
  2. Save screenshots and emails.
  3. Contact your bank if payment information was shared.
  4. Change passwords on affected accounts.
  5. Enable multifactor authentication.
  6. Notify your school if scammers are impersonating staff.
  7. Report fraud through official government reporting channels.

Timely reporting helps investigators identify broader fraud campaigns and may prevent additional victims.

Back-to-school season should be about learning, not losing money to scammers. Criminals know families are busy, and they use urgency, fake discounts, and impersonation tactics to exploit that pressure.

The safest approach is simple: slow down, verify before you pay, and teach children to question unexpected messages and offers.

09.03.26

App permissions explained: Why reviewing app permissions is one of the easiest ways to protect your privacy

Smartphone apps make life easier. They help us navigate, communicate, shop, bank, stream content, and stay productive. But every app you install may request access to sensitive parts of your device, including your camera, microphone, contacts, photos, location, calendar, and files.

Many users tap “Allow” without a second thought. Unfortunately, that convenience can expose more personal information than necessary.

The good news is that reviewing app permissions takes only a few minutes and can dramatically improve your privacy and security.

Why do app permissions matter?

App permissions determine what an application can access on your device. Some permissions are necessary. For example, a video conferencing app needs camera and microphone access to function properly.

Problems arise when apps request permissions that don’t match their purpose.

For example:

  • A flashlight app requesting contacts access
  • A calculator asking for your location
  • A wallpaper app requesting microphone access
  • A game requesting access to text messages
  • A photo editor requesting full contact-list access

According to Google’s https://blog.google/products-and-platforms/platforms/google-play/how-we-kept-google-play-safe-in-2025/, Google prevented more than 1.75 million policy-violating apps from reaching Google Play in 2025 and scans over 350 billion Android apps daily through Google Play Protect. These numbers highlight why users should not assume every app is automatically safe. Security screening helps, but users still play an important role in protecting their own devices.

What app permissions deserve extra attention?

Some permissions create greater privacy risks because they provide access to personal information or sensitive device functions.

Contacts

Contact lists often contain:

  • Family members
  • Friends
  • Work colleagues
  • Phone numbers
  • Email addresses

If an app doesn’t need your contacts to perform its core function, deny the request.

Microphone

Microphone access allows apps to capture audio.

Before approving:

  • Ask why the app needs it.
  • Check whether microphone use makes sense.
  • Remove access when it is no longer needed.

Camera

Camera permissions can be legitimate for:

  • Video calls
  • Document scanning
  • QR code scanning

However, many apps request camera access without a clear business need.

Location

Location data can reveal:

  • Home address
  • Workplace
  • Daily routines
  • Travel habits
  • Frequently visited places

The NSA’s guidance on location privacy notes that location data can expose daily routines, movements, and behavioral patterns. Limiting unnecessary location access reduces exposure.

Photos and files

Many apps request access to your entire photo library when they only need access to a single image.

Whenever possible:

  • Choose “Selected Photos”
  • Use one-time access
  • Avoid granting permanent full-library access

How does reviewing permissions make someone safer online?

Reviewing permissions helps someone become safer online by reducing unnecessary access to personal information.

This protects:

  • Private conversations
  • Contacts
  • Photos
  • Location data
  • Financial information
  • Work documents
  • Family information
  • Authentication information

The less access unnecessary apps receive, the smaller the risk if the app becomes compromised or behaves improperly.

Think of each permission as a key. Only hand out the keys an app genuinely needs.

How can you evaluate whether an app is trustworthy?

Before installing a new app, take a few minutes to investigate.

Check recent reviews

Focus on:

  • Current reviews
  • Complaints about privacy issues
  • Reports of excessive permissions
  • Sudden changes after updates

Recent reviews often reveal issues that older ratings may miss.

Verify the developer

Look for:

  • Established company websites
  • Contact information
  • Published privacy policies
  • Consistent app history

Review permissions before installing

Most app stores show permissions before download.

Ask:

  • Does this permission make sense?
  • Is it necessary?
  • Would I be comfortable sharing this information?

Step-by-step app permission audit

Audit your apps every few months.

Android

  1. Open Settings
  2. Select Privacy
  3. Tap Permission Manager
  4. Review each permission category
  5. Remove unnecessary access

iPhone

  1. Open Settings
  2. Select Privacy & Security
  3. Review categories such as:
    • Location Services
    • Microphone
    • Camera
    • Photos
    • Contacts
  4. Disable permissions you no longer need

Red flags that an app may be requesting too much

Watch for apps that:

  • Request permissions unrelated to their purpose
  • Frequently ask for additional permissions
  • Have poor or suspicious reviews
  • Come from unknown developers
  • Require accessibility permissions without explanation
  • Ask for administrator-level device access

If something feels excessive, trust your instincts and investigate further.

Additional protection tips

Use these best practices:

✅ Install apps only from official app stores
✅ Read recent reviews before downloading
✅ Keep apps updated
✅ Remove apps you no longer use
✅ Enable Google Play Protect or Apple security protections
✅ Run mobile security scans when appropriate
✅ Review permissions after major updates
✅ Deny permissions that don’t support app functionality
✅ Use “Only While Using the App” when available
✅ Remove permissions from dormant apps

App stores perform extensive security screening, but no system catches everything. Cybersecurity ultimately works best when technology and smart user behavior work together.

Before granting access, ask one simple question:

“Does this app really need this permission to do its job?”

If the answer isn’t obvious, deny the request until you’ve done more research.

09.02.26

How to limit Facebook tracking and protect your online privacy across the web

Facebook can be a great way to stay connected with friends, family, local groups, and businesses. What many people don’t realize, however, is that Facebook’s data collection can extend beyond what happens on Facebook itself.

Many websites contain Facebook tracking technologies, such as embedded content, social sharing buttons, advertising pixels, and login tools. These technologies can help Facebook understand parts of your browsing activity even after you leave the platform.

The good news? You can take practical steps to reduce how much information Facebook can connect to your identity online.

How does Facebook track activity outside of Facebook?

When you visit websites that use Facebook technology, information about those visits may be shared with Meta for advertising, analytics, and personalization purposes.

Facebook tracking can occur through:

  • Social sharing buttons
  • Facebook “Like” buttons
  • Embedded Facebook content
  • Advertising pixels
  • Third-party cookies
  • Facebook Login integrations
  • Mobile app tracking technologies

According to Mozilla’s official Facebook Container extension documentation, Facebook Container works by isolating your Facebook identity into a separate browser container, making it more difficult for Facebook to track visits to other websites through third-party cookies.

This does not eliminate all data collection, but it can significantly reduce the connection between your Facebook account and your broader web browsing activity.

Why should you care about online tracking?

Many people assume online tracking only affects advertising. In reality, tracking contributes to detailed profiles that can influence:

  • Advertisements you see
  • Content recommendations
  • Shopping suggestions
  • Marketing campaigns
  • Political messaging
  • Consumer profiling
  • Behavioral analytics

Mozilla explains that Facebook Container helps separate Facebook activity from browsing activity on other websites, helping users maintain greater privacy while continuing to use Facebook normally.

The goal isn’t necessarily to stop using Facebook. The goal is to increase your control over who collects information about your online behavior.

How does Facebook Container work?

Mozilla developed Facebook Container specifically for Firefox users who want stronger privacy protections.

After installation:

  • Facebook opens in an isolated browser container
  • Facebook cookies are separated from other websites
  • Non-Facebook websites open outside the container
  • Facebook has a harder time associating other browsing activity with your Facebook identity

Mozilla states that the extension logs users out of Facebook, clears tracking cookies, then reloads Facebook within a dedicated container environment.

This separation limits how easily Facebook can follow your activity across the web.

How does limiting tracking make someone safer online?

Reducing online tracking helps someone become safer online by limiting how much information large platforms, advertisers, and potentially malicious actors can associate with their browsing habits.

This helps protect:

  • Personal browsing habits
  • Shopping behavior
  • Interests and preferences
  • Device information
  • Advertising profiles
  • Location-related browsing patterns
  • Personal research activities
  • Sensitive searches

Privacy and security are closely related. The less information that gets collected and shared, the fewer opportunities exist for misuse, profiling, or manipulation.

Think of privacy as reducing your digital footprint before attackers or data brokers can use it.

What are the best ways to reduce Facebook tracking?

Install Facebook Container for Firefox

Mozilla’s Facebook Container extension remains one of the easiest tools for Firefox users. It helps isolate Facebook from other browsing activity.

Review Facebook privacy settings

Regularly review:

  • Ad personalization settings
  • Activity permissions
  • Connected apps
  • Off-platform activity controls
  • Facial recognition settings (where applicable)
  • Location-sharing permissions

Limit social logins

Many websites allow users to sign in with Facebook.

Instead:

  • Create separate accounts
  • Use a password manager
  • Sign in with email when practical

This reduces cross-site tracking opportunities.

Use privacy-focused browser settings

Enable:

  • Third-party cookie blocking
  • Enhanced tracking protection
  • Private browsing when appropriate
  • Browser security updates

Mozilla also recommends combining Facebook Container with additional privacy protections such as Firefox’s built-in tracking protections and cookie controls.

Step-by-step privacy checklist

Use this simple checklist:

✅ Install Facebook Container if you use Firefox
✅ Review Facebook privacy settings quarterly
✅ Limit Facebook Login usage on third-party websites
✅ Block third-party cookies where possible
✅ Remove unused connected apps
✅ Restrict location permissions
✅ Audit your ad preferences
✅ Keep your browser updated
✅ Use unique passwords and multifactor authentication
✅ Think before sharing personal information publicly

What misconceptions do people have about tracking?

One common misconception is:

“I logged out of Facebook, so Facebook can’t track me.”

Tracking technologies can function independently of active sessions in some situations. That’s why browser-level tools and privacy settings matter.

Another misconception:

“I have nothing to hide.”

Privacy isn’t about hiding wrongdoing. It’s about maintaining control over personal information, browsing habits, and digital autonomy.

Facebook provides valuable ways to stay connected, but it also gathers significant amounts of user data. By using tools such as Mozilla’s Facebook Container, reviewing privacy settings, limiting social logins, and reducing unnecessary tracking, you can take back more control over your online footprint.

09.01.26

Don’t install software you didn’t intend to download: How to avoid fake updates, malware, and phishing traps

One of the easiest ways cybercriminals infect computers is by convincing people to install something they never planned to install.

A pop-up claims your browser is outdated. An ad warns that your computer is infected. An email says you must open an attachment immediately. A fake update promises better performance or security. These tactics rely on one thing: getting you to click before you think.

A simple cybersecurity habit can dramatically reduce your risk: Never install software, apps, browser extensions, updates, or attachments unless you intended to download them beforehand and verified the source.

Why do scammers want you to install software?

Malicious software gives cybercriminals access to devices, accounts, passwords, and sensitive information. Attackers often disguise malware as legitimate software updates, productivity tools, security programs, invoices, or document attachments.

According to the FBI’s https://www.fbi.gov/file-repository/2025_ic3report.pdf/view, the agency received more than 1 million cybercrime complaints with reported losses exceeding $20 billion, demonstrating the massive scale of online threats facing consumers. The FBI also notes that phishing, spoofing, and malware delivery remain among the most common tactics used by cybercriminals.

The goal is simple: trick users into doing the attacker’s work.

What are the most common fake download scams?

Cybercriminals use many different approaches to convince people to install malware.

Fake software updates

You may see alerts claiming:

  • Your browser is outdated
  • Flash Player needs updating
  • Your PDF software is insecure
  • Your media player needs a critical patch
  • Your operating system requires an emergency update

Legitimate updates typically arrive through the software itself or through your device’s official update system, not random advertisements or pop-up windows.

Malicious email attachments

The FTC’s guidance on https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams warns that scammers frequently send attachments disguised as:

  • Invoices
  • Shipping notifications
  • Tax documents
  • Resumes
  • Receipts
  • Payment confirmations
  • Legal notices
  • Account verification forms

Opening the attachment may install malware or direct victims to credential-stealing websites.

Fake antivirus alerts

Many fraudulent websites display alarming messages such as:

  • “Your computer is infected!”
  • “15 viruses detected!”
  • “Click here to clean your device!”

These messages often create urgency to pressure users into downloading fake security software.

Browser extension scams

Some malicious browser extensions promise:

  • Coupons and discounts
  • Productivity improvements
  • Streaming enhancements
  • Security tools
  • Free downloads

Instead, they may collect browsing data, steal credentials, or inject advertisements.

How can you tell whether a download is legitimate?

Before installing anything, ask yourself one important question:

Did I intentionally go looking for this software?

If the answer is “no,” stop and verify before proceeding.

Check the source

Only download software from:

  • Official vendor websites
  • Trusted app stores
  • Verified enterprise portals
  • Reputable software publishers

Avoid downloads from:

  • Pop-up advertisements
  • Random search results
  • Unsolicited emails
  • Chat messages
  • Social media posts
  • Unknown websites

CISA’s phishing prevention guidance recommends verifying suspicious requests independently rather than using links included in messages.

How does this help someone become safer online?

Avoiding unexpected downloads protects users from many of the most common forms of cybercrime.

This habit helps prevent:

  • Malware infections
  • Ransomware attacks
  • Identity theft
  • Account takeovers
  • Banking fraud
  • Data theft
  • Browser hijacking
  • Spyware infections
  • Credential theft

The safest users are often not the most technical users. They’re the users who pause before clicking.

What should you do when software claims it needs updating?

Use this safer process:

Safe update checklist

  1. Close the pop-up.
  2. Do not click the update button.
  3. Open the application directly.
  4. Check for updates within the software.
  5. Visit the vendor’s official website.
  6. Install updates only from verified sources.
  7. Enable automatic updates whenever possible.

This approach eliminates the risk of downloading malware disguised as a security update.

What should you do if you accidentally installed something suspicious?

Act quickly.

Emergency response steps

  • Disconnect from the internet if malware is suspected.
  • Run a full antivirus or endpoint security scan.
  • Uninstall suspicious software.
  • Change important passwords from a clean device.
  • Enable multifactor authentication.
  • Review banking and online accounts for unusual activity.
  • Remove unknown browser extensions.
  • Monitor financial statements.
  • Contact IT support if it involves a work device.

The FTC warns that phishing attacks often attempt to steal passwords, account numbers, and personal information through fake links and downloads.

Best practices to prevent unwanted installations

Build these habits into your daily routine:

  • Keep automatic updates enabled.
  • Download software only from trusted sources.
  • Use reputable security software.
  • Verify every attachment before opening it.
  • Avoid clicking unexpected links.
  • Review browser extensions regularly.
  • Remove software you no longer use.
  • Use multifactor authentication.
  • Keep operating systems updated.
  • Think before clicking.

The bottom line

Most malware infections begin with a single click. Cybercriminals know that fear, urgency, and curiosity can convince people to install software they never intended to download.

The safest approach is also the simplest: If you weren’t planning to install it before you saw the pop-up, don’t install it until you’ve independently verified it’s legitimate.

Security tip of the day: Unexpected downloads are one of the most common paths to malware. Trust your plan, not the pop-up.