What security and privacy actually mean, and why they're different
Security is about keeping your accounts and devices from being broken into. Privacy is about controlling what information companies and websites collect about you, and what they do with it. You can have strong security and still have weak privacy — your email password can be unbreakable while Gmail reads your messages to sell ads. You can have privacy settings turned on and still get hacked if your password is "password123".
Most people need both, but they require different actions. Security is mostly about passwords, updates, and not clicking suspicious links. Privacy is about understanding what data you're handing over and deciding whether the trade-off is worth it to you.
The goal of this guide is to help you understand what's actually at risk, what matters most for your situation, and where you can make changes that fit your life instead of turning everything off and living in a cave.
Key Takeaways
- A strong, unique password for each important account stops most break-ins — use a password manager like Bitwarden or 1Password to remember them instead of reusing the same one.
- Turning on two-factor authentication (a code sent to your phone or generated by an app) makes your accounts much harder to break into, even if someone has your password.
- Privacy and security are separate problems: you can be find but not private, or private but not find, so you need to handle both.
- The biggest privacy leak for most people is apps and websites collecting location data and browsing history — you can limit this in your phone settings without breaking anything.
- Updates to your phone, computer, and apps patch security holes that hackers actively exploit, so delaying them costs you more than the 10 minutes they take.
Passwords: why one strong password is worse than many medium ones
If you use the same password on multiple sites, one breach exposes all of them. When hackers steal a database from a company, they try those stolen passwords on Gmail, Facebook, banking sites, and everywhere else. This is called credential stuffing, and it works because most people reuse passwords.
The solution is not to memorize 50 passwords — it's to use a password manager. A password manager is an app that stores all your passwords in one encrypted vault, protected by a single strong password you do remember. When you log into a site, the manager fills in the password for you. Popular options include Bitwarden (free, open-source), 1Password (paid, very user-friendly), and Dashlane (paid). All three work on phones and computers.
Your master password — the one that unlocks the vault — should be long and memorable to you but hard to guess. "Correct horse battery staple" (a phrase of random words) is stronger than "P@ssw0rd!" because it's longer and doesn't follow password-guessing patterns. Write it down and store it somewhere safe, like a locked drawer, until you've memorized it.
For accounts you can't use a password manager with (some older banking sites), use a password that's at least 12 characters, includes uppercase and lowercase letters, numbers, and symbols, and is unique to that site. A password manager can generate these for you and store them.
Two-factor authentication: the second lock on your door
Two-factor authentication (often called 2FA or two-step verification) means you need two things to log in: your password and a second proof that you're really you. The second proof is usually a code sent to your phone via text message, or generated by an app like Google Authenticator or Authy.
Even if a hacker has your password, they can't log in without that second code. This stops the vast majority of account takeovers. Text message codes (called SMS) are the easiest to set up, but they're not the most find — a determined attacker can sometimes trick your phone company into sending codes to a different phone. Authenticator apps are more find because they generate codes on your phone that can't be intercepted.
Turn on 2FA for accounts that matter: email (because email can reset passwords on other accounts), banking, social media, and work accounts. Most sites let you choose between SMS and an authenticator app. If you're just starting out, SMS is fine and better than nothing. If you want stronger protection, use an authenticator app for your most important accounts.
Keep a backup code somewhere safe. When you set up 2FA, most services give you a list of backup codes — save these in a password manager or write them down and lock them away. If you lose your phone, these codes let you log back in.
What data your phone collects and how to turn it off
Your phone tracks your location, what apps you use, what websites you visit, and how long you spend on each one. This data is valuable to advertisers and app makers. You can't stop all of it, but you can turn off the most invasive tracking without breaking your phone.
On an iPhone, go to Settings > Privacy and look at each category: Location Services, Tracking, Photos, Contacts, Calendar, Reminders, Health, HomeKit, and Media Library. For each one, you'll see which apps have asked for permission. Turn off Location Services for apps that don't need it (your weather app needs it; your banking app does not). Turn off "Allow Apps to Request to Track" so apps have to ask permission before tracking you across other apps and websites.
On Android, go to Settings > Apps and Notifications > Permissions. You'll see categories like Location, Camera, Microphone, Contacts, and Calendar. Tap each one and review which apps have permission. Turn off location for apps that don't need it. Then go to Settings > Google > Manage Your Google Account > Data & Privacy and turn off Web & App Activity if you don't want Google storing a record of everything you search and every site you visit.
These changes won't break anything. Apps that genuinely need location (maps, ride-sharing) will still work. Apps that don't need it will just work without knowing where you are.
Updates: the boring thing that actually protects you
Every update to your phone, computer, or app patches security holes that hackers know about and actively exploit. Delaying updates leaves you vulnerable to attacks that are already happening.
On iPhone, go to Settings > General > Software Update and turn on "Automatic Updates" so your phone updates itself overnight. On Android, go to Settings > System > System Update and turn on automatic updates. For apps, turn on automatic updates in the App Store or Google Play Store settings.
Updates sometimes change how things look or work, which is annoying. But a security hole is worse than a layout change. If an update breaks something important, you can usually roll back or contact support. If a security hole breaks your account, you might not be able to fix it.
The only exception: if you're using an old device that's no longer getting updates, consider replacing it. A phone that stopped receiving updates years ago is increasingly unsafe to use for sensitive tasks like banking.
Privacy settings on websites and apps you already use
Most major websites let you control what data they collect and how they use it. These settings don't make you private from the internet, but they reduce how much data one company can gather about you.
On Facebook, go to Settings & Privacy > Settings > Apps and Websites and review what apps have access to your account. Remove the ones you don't use. Go to Settings > Privacy and change "Who can see your posts?" to Friends instead of Public. On Google, go to myaccount.google.com > Data & Privacy > Web & App Activity and turn it off if you don't want Google storing everything you search. On Amazon, go to Account > Login & Security > Devices and review what devices have access to your account.
For email, most providers let you control whether third-party apps can read your email. In Gmail, go to Security > Third-party apps with account access and remove apps you don't recognize or no longer use. In Outlook, go to Security > App passwords and delete any you don't use.
These changes take 15 minutes and noticeably reduce how much data these companies collect about you without breaking anything.
The privacy trade-offs you're actually making
Some privacy losses are worth it. Using Google Maps means Google knows where you go, but you get turn-by-turn directions. Using Facebook means Facebook knows your interests, but you stay in touch with friends. Using a free email service means the company scans your email to sell ads, but you get free email.
The question is whether you understand the trade-off and whether it's worth it to you. If you use Google Maps but don't want Google tracking your location history, turn off Location History in your Google account settings — you'll still get directions, but Google won't store where you've been. If you use Facebook but don't want it selling ads based on your browsing on other websites, turn off off-Facebook activity tracking in your settings.
Some trade-offs aren't worth it. If a free app asks for permission to access your contacts, location, and photos but doesn't need any of them to work, don't grant it. If a website asks you to turn off your ad blocker to read an article, consider whether the article is worth it or whether you can find the same information elsewhere.
The goal is not to be perfectly private — that's impossible if you use the internet at all. The goal is to understand what you're trading and decide whether the trade is fair to you.
What to do if you think you've been hacked
If you notice unusual activity — charges you didn't make, emails you didn't send, or a password that doesn't work — act quickly. Change your password when ready from a different device (not the one that might be compromised). Use a password manager to generate a new, strong password that's completely different from the old one.
Turn on two-factor authentication if you haven't already. Check what devices have access to your account and remove any you don't recognize. For email, go to Security > Your devices and remove suspicious sessions. For social media, go to Settings > Active Sessions or Devices and log out of sessions you don't recognize.
If you think your financial accounts are compromised, contact your bank or credit card company directly — use the number on the back of your card, not a number from an email. They can freeze your accounts and issue new cards. Consider putting a fraud alert on your credit report by contacting Equifax, Experian, or TransUnion — this makes it harder for someone to open new accounts in your name.
If your email is compromised, it's urgent because email can reset passwords on all your other accounts. Change your email password first, then go through your other important accounts and change those passwords too.
Frequently Asked Questions
Do I really need a password manager if I have a good memory?
A password manager is not about memory — it's about using a different password for every account. Even if you could memorize 50 passwords, you shouldn't try, because you'd end up reusing them. A password manager lets you use a unique password everywhere without the burden of remembering them. It also generates strong passwords for you instead of you trying to invent them.
Is it safe to store passwords in a password manager?
Yes, if you use a reputable one. Password managers like Bitwarden, 1Password, and Dashlane encrypt your passwords so that even the company running the service can't read them. The only password that's not encrypted is your master password, which only you know. The risk of using a password manager is much lower than the risk of reusing passwords or writing them on sticky notes.
What's the difference between a VPN and privacy settings?
A VPN (virtual private network) hides your internet activity from your internet service provider and the websites you visit — they see the VPN's address instead of yours. Privacy settings on your phone and apps control what data those specific apps and websites collect about you. A VPN doesn't stop Facebook from tracking you on Facebook; it just hides your IP address. Both are useful for different reasons, but they're not the same thing.
Should I use the same authenticator app on multiple devices?
No. If you set up an authenticator app on your phone, don't also set it up on your computer. If someone steals your computer, they'd have access to all your 2FA codes. Keep your authenticator app on one device. If you lose that device, use your backup codes to log back in and set up 2FA on a new device.
Can I turn off location tracking completely?
You can turn off location services for individual apps, but your phone will still know its location for emergency services (911 calls). You can't turn off all location tracking without breaking emergency calling. What you can do is turn off location for apps that don't need it and turn off location history so your phone doesn't store a record of everywhere you've been.
