Learning
Digital privacy and account security
Also known as
password manager · passkeys · two-factor authentication · privacy settings · account recovery · private browsing · VPN
Named sources. May contain inaccuracies or be incomplete. Not medical, legal, financial, or other professional advice.
Digital privacy concerns who can collect, use and share your information. Account security concerns who can get into your accounts. Start with the accounts that unlock the others, use distinct credentials and stronger sign-in, keep recovery available, and choose privacy controls for the specific information you want to protect.
Understand what each protection does
An account can have a strong password while its provider still collects activity you would prefer to keep private. Security asks whether access and use are authorized; privacy also asks what information is collected, for what purpose and with whom it is shared. The FTC describes collection through accounts, cookies, device identifiers and other mechanisms. In an ordinary example, a shopping account may be well protected against another person signing in while still retaining your purchase history. Decide which problem you are trying to solve before choosing a setting or buying a tool.
Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab) · Electronic Frontier Foundation — Your Security Plan (opens in a new tab)
EFF calls this a security plan: name what matters, who might gain access and what consequences matter to you. You do not need an elaborate adversary diagram for routine personal accounts. A lost phone, a reused password exposed elsewhere and an unnecessarily public profile are already three different problems. A screen lock helps with the first, unique credentials with the second and audience settings with the third. This guide supplies a practical starting order, not a calculation that those threats have the same likelihood or seriousness for every reader.
Electronic Frontier Foundation — Your Security Plan (opens in a new tab) · Julie Haney — Usable Security: A Human-Centric Approach (NIST, 2021) (opens in a new tab)
Start with your situation
When many settings feel urgent, start by finding which email or identity account receives your password-reset messages. Losing access there can make other accounts harder to recover. EFF’s planning approach begins with what matters and how it can be lost; NIST treats recovery as part of authentication, not an afterthought. Open the service through its known app or address, inspect its sign-in and recovery options, and make one improvement you can complete. Record a private reminder of the recovery method without putting passwords or recovery codes into an ordinary to-do list.
Electronic Frontier Foundation — Your Security Plan (opens in a new tab) · NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Reusing a password means that a disclosure at one service can expose access elsewhere. A password manager stores distinct credentials in a protected vault and can generate long, unpredictable passwords for you. EFF’s manager guide explains the practical choices, while NIST supports password managers and autofill rather than forcing people to memorize many complicated strings. Start with one important account, save the replacement correctly and confirm access before continuing. Protect the vault itself with a strong unique unlock secret and the additional authentication it supports; its recovery instructions deserve the same attention as its convenience.
Electronic Frontier Foundation — Choosing the Password Manager That’s Right for You (opens in a new tab) · NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
A private browser window mainly changes what that browser keeps after the private session. Mozilla explains that it does not make browsing invisible to websites, a workplace network or an internet provider, and downloaded files can remain on the device. Logging into an account still identifies you to that service. First name the goal: avoiding saved local history differs from reducing advertising tracking or protecting an account. Then use the corresponding browser, device, app or account control and read its scope. No single privacy label promises that every participant in the connection stops seeing information.
Mozilla Support — Private Browsing: Use Firefox Without Saving History (opens in a new tab) · Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab)
A phone can hold a passkey, run an app that generates sign-in codes, or receive messages needed during sign-in. An authenticator is a device or software that holds a credential and helps prove you can use it; the phone or an app can perform that role. Moving to a new phone can therefore affect more than the device itself. NIST distinguishes normal authentication from account recovery, and FIDO explains that passkeys may synchronize through a provider or remain on one authenticator. Check each important service’s transfer and recovery instructions while your current access works. Verify the new method before retiring the old one, and keep recovery material somewhere you can reach without that phone. Avoid deliberately locking yourself out as a test.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · FIDO Alliance — Passkeys (opens in a new tab) · Electronic Frontier Foundation — How to Enable Two-Factor Authentication (opens in a new tab)
Understand the main findings
Credential reuse is the use of the same secret at several services. An attacker who obtains that secret from one source may try it elsewhere, even if the second service had no breach. NIST recommends screening out compromised passwords and enabling managers; these measures address different parts of the problem. A long unique password at the second service breaks that particular reuse path. It does not prevent a fake login page, malicious software or misuse of an already signed-in device, so password quality belongs alongside other protections.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
A passkey uses a pair of cryptographic keys instead of a reusable password sent to a website. The service holds the public part, and the authenticator proves possession of the private part after the required user verification. FIDO explains why that service binding resists ordinary credential phishing: a lookalike domain cannot simply receive the same reusable secret. A phone’s face, fingerprint or PIN check can unlock the process without giving that biometric to the website. Device compromise, insecure recovery and misleading requests to authorize other actions still need separate attention.
FIDO Alliance — Passkeys (opens in a new tab) · NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Multi-factor authentication combines different kinds of evidence, such as a password you know and a device you possess. Two passwords are still two examples of the same kind of factor. NIST distinguishes phishing-resistant cryptographic methods from codes a person can be tricked into entering at a false site. Where a supported stronger method is workable, use it and retain recovery. If a service offers only a less resistant additional method, understand the limit rather than assuming it provides no value. Never approve a sign-in request you did not initiate.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — How to Enable Two-Factor Authentication (opens in a new tab)
A software update can change features, fix ordinary defects or close a security vulnerability: a weakness someone could exploit. The NCSC recommends installing current legitimate updates and using automatic updating where practical. Obtain them through the device’s settings or the software’s official update mechanism. An alarming advertisement claiming that your computer urgently needs a tool is a different thing. For a device managed by work or school, follow its support process. If a product no longer receives security fixes, repeated checks cannot manufacture support that its maker has ended.
UK National Cyber Security Centre — Install the Latest Software and App Updates (opens in a new tab)
Encryption makes stored information unreadable without the appropriate key or unlock process. A backup is another recoverable copy when the original is lost, damaged or changed. EFF treats protecting data and preserving access as connected tasks. An encrypted laptop may protect files on a stolen, locked device, yet provide no way to retrieve them after physical loss unless a usable copy exists elsewhere. Conversely, an unprotected backup can expose everything it preserves. Check both how a copy is protected and whether you can recover a harmless sample file from it.
Electronic Frontier Foundation — Keeping Your Data Safe (opens in a new tab)
The FTC distinguishes several ways services recognize browsers and devices; cookies are only one of them. Blocking a category of cookies does not necessarily stop a signed-in service from keeping account activity, and removing an app’s permission does not by itself erase information it already received. Read the control’s description and the provider’s data options together. In a simple example, limiting future location permission, deleting stored location history and changing a post’s audience are three different actions. A useful review asks which of those outcomes the chosen setting actually changes.
Recognize the limits and open questions
Cloud-synchronized and local-only vaults place responsibility in different places. EFF describes the convenience of access across devices alongside questions about provider trust, encryption and recovery; a local vault puts more backup and transfer work on its owner. There is no evidence here that one storage arrangement wins for every person. Compare supported devices, accessibility, recovery and the effort you can sustain before choosing. A technically attractive setup that leaves you regularly reusing passwords or unable to recover the vault has failed an important part of your practical goal.
Electronic Frontier Foundation — Choosing the Password Manager That’s Right for You (opens in a new tab) · Cormac Herley — So Long, and No Thanks for the Externalities: The Rational Rejection of Security Advice by Users (2009) (opens in a new tab)
An authenticator is a device or software that holds a credential and proves you can use it. A synchronized passkey can be available on multiple authorized devices through a provider; a device-bound passkey stays on one authenticator. NIST distinguishes these arrangements because their protection and recovery needs differ. Synchronization can help after losing a device, but the provider account and its recovery also need protection. A physical security key needs secure custody and a usable backup method. Read the service’s options and recovery instructions, then choose around the consequences of losing access or allowing someone else in.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · FIDO Alliance — Passkeys (opens in a new tab)
Ion and colleagues found differences between expert and non-expert reported practices in 2015. Ortloff and colleagues’ 2025 replication found changed practices and continuing differences, with expert interviews emphasizing usability and context. Neither survey directly measures how many attacks a particular checklist prevents. Herley also argues that advice has a cost when it consumes a person’s time. Routine accounts can sensibly start with credentials, stronger sign-in, updates and recovery, while an unusual targeted risk may require specialist planning. A survey majority is useful context, not a personalized guarantee.
Ion, Reeder and Consolvo — “No one can hack my mind”: Comparing Expert and Non-Expert Security Practices (SOUPS 2015) (opens in a new tab) · Ortloff and colleagues — Replication: “No one can hack my mind” — 10 Years Later (SOUPS 2025) (opens in a new tab) · Cormac Herley — So Long, and No Thanks for the Externalities: The Rational Rejection of Security Advice by Users (2009) (opens in a new tab)
Schaub and colleagues’ design review explains why timing, format and context can make notices more or less usable. It does not establish that simply showing more text produces informed control, or that individuals can resolve all collection practices through repeated consent clicks. A reader can inspect the purpose, recipient and available alternative while recognizing that service design constrains the choices. If an optional feature needs information disproportionate to its value for you, leaving that feature unused is one possible response. The provider still carries responsibility for its own collection and protections.
Schaub, Balebako, Durity and Cranor — A Design Space for Effective Privacy Notices (SOUPS 2015) (opens in a new tab) · Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab)
Take one useful next step
Choose your main email or identity account and open it through a known route. Look at the available passkey or additional-authentication option, the recovery details and any listed signed-in devices. Follow the service’s instructions, confirm that the recovery destination belongs to you and save required recovery material securely. Finish by confirming that you can use the new method while your existing access remains available. This is a practical adaptation of NIST’s authentication-and-recovery distinction: an unfinished security setting that causes avoidable lockout is not the desired outcome.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — How to Enable Two-Factor Authentication (opens in a new tab)
Select an ordinary account you own, open its official settings and use your manager’s password generator if the service accepts it. Save the exact replacement under the correct service before ending the session, then confirm normal access. Do not paste the password into a chat, document or unprotected note to keep track of it. EFF’s manager guidance supports making distinct credentials practical; this exercise is an editorial way to learn the workflow on one account before repeating it. Stop and use official support if the process behaves unexpectedly.
Pick one app and read the operating system’s permission settings and the app’s own account controls. Ask what feature requires the requested information and whether a narrower choice is offered. A navigation feature and a decorative theme do not have the same reason to request location. The FTC’s tracking explanation supplies the distinction between limiting collection and changing stored data. Make one supported adjustment you understand, then check that the function you need still works. This is a review exercise, not a universal instruction to deny every permission.
Write down which approved method you would use if your main phone stopped working, keeping secret codes out of the ordinary note. Read the provider’s instructions and verify that any backup contact information is yours and current. When instructions permit, confirm a spare authenticator or restore a harmless backed-up file while the original remains available. NIST and EFF distinguish recovery from daily login. You are checking that a path exists and is understood; you do not need to remove working access or destroy an original file to prove the point.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — Keeping Your Data Safe (opens in a new tab)
Keep the useful habits
A new phone number, replaced device or closed email address can make an old recovery path unusable. Put a short account-access review into those transitions rather than relying on memory during a later problem. NIST treats the binding and removal of authenticators as account lifecycle events, each with its own implications. Confirm a new authorized method first, then follow the provider’s process for retiring an old one. Record that the review happened without recording secrets in a shared calendar or task list.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Automatic updates reduce how often you must remember individual releases, but a device may still need power, storage or a restart to finish. The NCSC’s recommendation concerns installing legitimate fixes, not merely downloading an update. Check the device’s own status if installation keeps failing, and use official support where necessary. For equipment managed by an organization, report the problem through its support route. A recurring warning deserves resolution; dismissing the same failure repeatedly is not equivalent to maintaining the software.
UK National Cyber Security Centre — Install the Latest Software and App Updates (opens in a new tab)
Recovery material may grant access when normal sign-in fails, so treat it as sensitive. NIST includes saved recovery codes among recovery mechanisms and requires services to protect that process. Consider the actual loss scenario: a code stored only inside the account you cannot open may be unavailable just when needed. Follow the provider’s storage advice, protect any physical copy and avoid casual screenshots sent through messaging. Replace or update saved material when the provider invalidates old codes, and keep its purpose clear enough to recognize later.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
A focused review is easier to finish than trying to understand every setting in one sitting. Start with a feature involving information you care about and inspect who can see it or receive it. The FTC explains why app, browser and account controls cover different collection paths. After a service changes a feature, revisit the relevant choice rather than assuming the old label retains the same meaning. An occasional useful review helps maintain your chosen arrangement; constant checking is not the aim.
Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab) · Julie Haney — Usable Security: A Human-Centric Approach (NIST, 2021) (opens in a new tab)
Usable security treats people’s tasks and limits as part of the system. Julie Haney’s NIST work explains that a technically strong control can still fail if its design makes correct use impractical. Notice the points where your setup repeatedly creates confusion: finding the right account, unlocking a vault or locating recovery instructions. Resolve one of those frictions with official help or a better-supported workflow. The purpose is reliable protection you can continue using, not accumulating the largest possible collection of tools or feeling at fault for a difficult interface.
Julie Haney — Usable Security: A Human-Centric Approach (NIST, 2021) (opens in a new tab) · Ortloff and colleagues — Replication: “No one can hack my mind” — 10 Years Later (SOUPS 2025) (opens in a new tab)
Take a closer look
Authentication answers whether a person has the required proof to sign in now. Recovery handles the case where the usual proof is no longer available. If someone can misuse the recovery channel, the strength of the ordinary password alone cannot settle the account’s protection. NIST therefore discusses recovery separately, including saved codes, issued codes and other approved mechanisms. For your account, identify the service’s actual process and the destinations it trusts. Do not assume that every provider offers the same rescue route or that support can recover an account without adequate proof.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
A short PIN used to unlock a properly designed authenticator has different controls and a different job from a password checked by a distant website. NIST’s requirements distinguish these cases; quoting a website password-length rule does not by itself evaluate a local unlock mechanism. FIDO passkeys can use local user verification while the service receives cryptographic proof. The practical question is what you are unlocking and where the secret is checked. Follow the device and service instructions rather than trying to make every credential look alike.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · FIDO Alliance — Passkeys (opens in a new tab)
A private session can discard particular local browsing records when the session ends, but the file you deliberately saved to Downloads remains a file. A bookmark you created can also remain. Mozilla separates those persistent objects from private-window session data. Imagine using a shared computer to retrieve a document: closing the window does not necessarily remove the downloaded document or log out of another open application. Follow the device’s permitted use and the service’s sign-out process. The browser label is only one part of what the device retains.
Mozilla Support — Private Browsing: Use Firefox Without Saving History (opens in a new tab)
A VPN carries traffic through its provider. It can conceal some traffic information from a local network while exposing different information to that provider, depending on encryption and the connection. EFF cautions that this is not a universal anonymity arrangement. Imagine signing into the same named account before and after enabling a VPN: the account still supplies a direct identifier to the service. Ask what observer the tunnel addresses, what the provider can see and what information remains visible at the destination before deciding whether it serves a real need.
Electronic Frontier Foundation — Choosing a VPN That’s Right for You (opens in a new tab)
Encryption can prevent unauthorized reading of stored data, but it does not create another copy. A backup can preserve a copy while still leaving questions about who can open it. EFF’s data guidance makes both access and recovery relevant. A simple practice check is to recover a non-sensitive sample into a separate location and confirm it opens, leaving the original intact. If a backup needs a key, know where its authorized recovery information is kept. The useful outcome is protected information that its owner can still retrieve when a device fails.
Electronic Frontier Foundation — Keeping Your Data Safe (opens in a new tab)
A survey can tell researchers what people say they do or recommend. It cannot by itself show how many account takeovers those actions prevent in current conditions. Ion’s study and Ortloff’s later replication are valuable because they reveal priorities, gaps and changing practices across groups. They are not a race in which the most popular expert answer automatically wins every scenario. Use current technical standards for what a method does, professional guidance for practical setup and research on usability for whether people can reliably carry it out.
Ion, Reeder and Consolvo — “No one can hack my mind”: Comparing Expert and Non-Expert Security Practices (SOUPS 2015) (opens in a new tab) · Ortloff and colleagues — Replication: “No one can hack my mind” — 10 Years Later (SOUPS 2025) (opens in a new tab) · NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
A request for information is easier to assess when the purpose is concrete. Schaub and colleagues describe how context and timing affect privacy notices; a long policy far from the decision can be hard to use. In an ordinary example, supplying an address to receive a parcel has an understandable purpose, while an unrelated optional profile field may not contribute to that task. Read what is required, what is optional and how the information will be used. You can choose a smaller set of features when that meets your needs.
If a service reports an unfamiliar sign-in or you lose access, independently open its known app or account-help address rather than following an unsolicited message. NIST explains the importance of recovery and notifications, while the details of containment differ by provider and incident. Follow that service’s process for securing access and reviewing authorized devices. Work or school accounts belong with the organization’s support team. This article does not diagnose whether a particular device is compromised; targeted incidents can need specialist help beyond ordinary settings.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — Your Security Plan (opens in a new tab)
A safeguard can consume time, attention, money or access to a needed service. Herley’s economic argument brings those costs into the discussion; it does not imply that all advice is wasteful. For a routine setup, ask whether a proposed extra tool protects something your existing controls do not, and whether you can maintain its updates and recovery. A manageable improvement that closes a concrete gap can be more useful than an elaborate arrangement you cannot operate. This is practical reasoning about your constraints, not a numerical estimate of your personal attack risk.
Cormac Herley — So Long, and No Thanks for the Externalities: The Rational Rejection of Security Advice by Users (2009) (opens in a new tab) · Julie Haney — Usable Security: A Human-Centric Approach (NIST, 2021) (opens in a new tab)
Check familiar claims
Does private browsing make me anonymous?
The claim is not supported. Mozilla describes private browsing as limiting particular local session records, not hiding activity from every website or network. A logged-in account can still identify you to its service, and downloads or saved bookmarks can remain. Use the feature for its stated purpose, then choose separate controls for tracking, account access or the audience of a post. Closing the window cannot undo everything you intentionally shared.
Mozilla Support — Private Browsing: Use Firefox Without Saving History (opens in a new tab) · Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab)
Does a VPN hide everything I do online?
The claim is not supported. EFF explains that a VPN changes the path and trust arrangement of a connection. The VPN provider becomes relevant, while your account login and information you give a website can still identify you there. Decide what network observation you are trying to limit and read the provider’s scope. Complete anonymity is not a property to infer from the presence of a VPN icon.
Electronic Frontier Foundation — Choosing a VPN That’s Right for You (opens in a new tab)
Must every password change every month?
The claim is not supported. NIST’s current guidance tells verifiers not to require arbitrary periodic password changes, but to require a change when compromise is indicated. Distinct credentials prevent a disclosure at one service from directly exposing the same secret elsewhere. Follow actual incident instructions rather than making a predictable monthly edit to a reused password. A service can still have its own requirements, and a local device PIN is a different kind of credential.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Do ordinary accounts need protection?
Supported within the stated scope. EFF’s planning method starts with information and consequences: email access, documents and the ability to recover other accounts can matter even without a public profile. Choose protections around those ordinary needs. You do not have to imagine exceptional threats to use unique credentials, supported stronger sign-in and a workable recovery method. The goal is proportionate, usable protection rather than constant worry.
Electronic Frontier Foundation — Your Security Plan (opens in a new tab) · NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Do all forms of two-factor authentication resist phishing equally?
The claim is not supported. NIST distinguishes cryptographic authentication bound to the legitimate service from codes a person can be persuaded to type into a false page. Passkeys and suitable security-key methods can provide that binding. Code-based additional authentication can still improve on reliance on a password alone, but its limits differ. Use the strongest supported method you can maintain, and check recovery before retiring another method.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · FIDO Alliance — Passkeys (opens in a new tab)
Does encryption mean I no longer need a backup?
The claim is not supported. Encryption protects readability under specified access conditions; a backup preserves another recoverable copy. EFF’s data guidance addresses both. A securely encrypted device can still be lost, damaged or unavailable, and an unprotected backup can expose the information it saves. Check the protection of both copies and test recovery with a harmless sample while keeping the original intact.
Electronic Frontier Foundation — Keeping Your Data Safe (opens in a new tab)
Use this knowledge in its proper scope
This topic explains routine personal privacy and account protection. A targeted compromise, disputed account ownership or a work-managed device needs the provider’s or organization’s authorized support process. Make changes only to accounts and devices you are permitted to manage. Protect recovery material and confirm replacement access before retiring working methods. General explanations cannot determine whether a particular incident has been contained.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — Your Security Plan (opens in a new tab)
Named sources. Honest paraphrase of the finding. Not medical, legal, or financial advice.
NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab) · Electronic Frontier Foundation — Your Security Plan (opens in a new tab)
Sources and further reading
- Electronic Frontier Foundation — Your Security Plan (opens in a new tab)
Identify information to protect, plausible threats, consequences, resources and manageable safeguards. Expert practice framework; no guarantee and no universal ranking of every safeguard.
- NIST — SP 800-63B-4: Authentication and Authenticator Management (2025) (opens in a new tab)
Password uniqueness and verifier requirements, phishing resistance, recovery, syncable versus device-bound authenticators. Federal digital-identity standard; normative service requirements are not blanket consumer law. Local unlock PINs differ from centrally verified passwords.
- Electronic Frontier Foundation — Choosing the Password Manager That’s Right for You (opens in a new tab)
Generated unique passwords, vault protection, recovery, cloud versus local tradeoffs and practical selection. Expert guidance last reviewed March 6, 2025; specific product interfaces and security can change.
- FIDO Alliance — Passkeys (opens in a new tab)
Passkeys use public-key credentials bound to a service; device unlock, phishing resistance and sync or device-bound forms. Standards-industry explanation; passkeys do not prevent every compromise, and availability/recovery differ by provider.
- Electronic Frontier Foundation — How to Enable Two-Factor Authentication (opens in a new tab)
Additional authentication factors, security keys and the need to retain usable recovery methods. Expert practice source; code-based methods are not all phishing resistant.
- UK National Cyber Security Centre — Install the Latest Software and App Updates (opens in a new tab)
Timely legitimate updates address security weaknesses; automatic updates reduce repeated manual work. General public guidance, not instructions for unsupported work devices or proof every update is flawless.
- Electronic Frontier Foundation — Keeping Your Data Safe (opens in a new tab)
Device encryption, access protection and backups address different data risks. Expert practice guidance; an unlocked or compromised device and recovery-key loss remain limits.
- Federal Trade Commission — How Websites and Apps Collect and Use Your Information (opens in a new tab)
Cookies, pixels, device identifiers, fingerprinting and available tracking controls. U.S. consumer explanation of technical practices; controls reduce particular collection, not every observation or legal use.
- Mozilla Support — Private Browsing: Use Firefox Without Saving History (opens in a new tab)
Private windows limit locally retained session history; downloads, saved bookmarks and network visibility have separate rules. Firefox-specific support; private modes differ and are not anonymity tools.
- Electronic Frontier Foundation — Choosing a VPN That’s Right for You (opens in a new tab)
VPN tunnel scope and trust in the VPN provider; a VPN does not remove account or browser identification. Expert practice source, not a tested ranking or endorsement of a commercial provider.
- Ion, Reeder and Consolvo — “No one can hack my mind”: Comparing Expert and Non-Expert Security Practices (SOUPS 2015) (opens in a new tab)
Experts and non-experts reported different security priorities; experts emphasized updates, managers and additional authentication. Self-reported practices, 231 experts and 294 non-experts; not a trial measuring prevented attacks.
- Ortloff and colleagues — Replication: “No one can hack my mind” — 10 Years Later (SOUPS 2025) (opens in a new tab)
Replication with 990 non-experts, 75 experts and 35 expert interviews; context, usability and changes in practices and advice. Survey/interview evidence does not establish one best universal checklist or a causal reduction in harm.
- Schaub, Balebako, Durity and Cranor — A Design Space for Effective Privacy Notices (SOUPS 2015) (opens in a new tab)
Privacy-notice effectiveness depends on timing, presentation, context and meaningful controls. Design review and framework, not proof every notice works or that individual consent solves structural privacy risks.
- Cormac Herley — So Long, and No Thanks for the Externalities: The Rational Rejection of Security Advice by Users (2009) (opens in a new tab)
Security advice has time/attention costs; task context and the burden of advice matter. Economic argument from 2009, not current numerical risk estimates or permission to skip essential protections.
- Julie Haney — Usable Security: A Human-Centric Approach (NIST, 2021) (opens in a new tab)
Security design must consider human tasks, knowledge, usability and burden. Professional presentation summary, not an intervention effectiveness trial.
- Georgetown Computer Science — Elissa Redmiles Joins as Assistant Professor (opens in a new tab)
Public explanation of Redmiles’s research on how people make digital-safety decisions and how systems can support them. Institutional introduction establishes public education and research relevance; it is not outcome evidence for a safeguard.
- Public question — A beginner asks where to start with digital privacy (opens in a new tab)
Beginner confusion informs the first situation and manageable starting point. A single public thread; not representative demand, factual security evidence or product advice.
- Lorrie Faith Cranor — verified professional role (opens in a new tab)
Professor of Computer Science and Engineering and Public Policy; Carnegie Mellon usable privacy and security researcher. Public usefulness: CUPS education, public talks and explanations of passwords and privacy notices. Academic research does not certify an individual product or account.
- Jason Hong — verified professional role (opens in a new tab)
Professor Emeritus, Human-Computer Interaction Institute, Carnegie Mellon University. Public usefulness: Public research explanations, teaching and accessible work on smartphone privacy. Use the current emeritus designation; no vendor endorsement is implied.
- Sauvik Das — verified professional role (opens in a new tab)
Assistant Professor, Human-Computer Interaction Institute, Carnegie Mellon University. Public usefulness: Public lab research and teaching on usable and social cybersecurity. Research context matters; no assumption that peer pressure improves every security decision.
- Lujo Bauer — verified professional role (opens in a new tab)
Professor of Electrical and Computer Engineering and Computer Science, Carnegie Mellon University. Public usefulness: Open publications and courses explain authentication and access control. Technical findings apply to specified systems and threat models.
- Florian Schaub — verified professional role (opens in a new tab)
Associate Professor of Information and Electrical Engineering and Computer Science, University of Michigan. Public usefulness: Public privacy research, media explanations and teaching on meaningful choice. A notice design is not proof that data collection is minimal or harmless.
- Blase Ur — verified professional role (opens in a new tab)
Associate Professor of Computer Science, University of Chicago. Public usefulness: Public education and outreach listed in his faculty profile bring usable security to non-specialists. Study participants and interfaces bound any reported result.
- Elissa Redmiles — verified professional role (opens in a new tab)
Clare Boothe Luce Assistant Professor of Computer Science, Georgetown University. Public usefulness: Georgetown’s public introduction explains research intended to make safety tools work for real people. Empirical priorities are context-sensitive, not a universal personal threat assessment.
- Julie Haney — verified professional role (opens in a new tab)
Computer scientist and usable cybersecurity researcher, National Institute of Standards and Technology. Public usefulness: NIST public presentations and practitioner explanations, including Usable Security: A Human-Centric Approach. Professional education is not a guarantee about a particular service.
- Karen Renaud — verified professional role (opens in a new tab)
Reader, University of Strathclyde; human-centered cybersecurity researcher. Public usefulness: Public outreach and accessible explanations connect security with everyday comprehension. Avoid interpreting noncompliance as a personal character failure.
- M. Angela Sasse — verified professional role (opens in a new tab)
Professor of Human-Centred Security with a University College London appointment. Public usefulness: Public research and professional teaching explain security friction and user effort. The profile includes historical appointments; no current directorship is asserted.
- Serge Egelman — verified professional role (opens in a new tab)
Senior research scientist and usable privacy/security group lead at ICSI; Berkeley research scientist. Public usefulness: Public mobile-app privacy research and measurement tools make hidden data flows more visible. AppCensus commercial involvement is disclosed in the official profile; no product promotion here.
- L. Jean Camp — verified professional role (opens in a new tab)
Indiana University professor; named Provost Professor in 2025. Public usefulness: Books and public research connect trust, risk and privacy in consumer technologies. Broad research perspective does not replace account-specific support.
- Cormac Herley — verified professional role (opens in a new tab)
Security researcher; documented as a Microsoft Research principal researcher in 2011. Public usefulness: Public Microsoft Research explanation and the accessible 2009 paper explain the costs of security advice. Historical role verified; current employment was not established and is not claimed.
- Eva Galperin — verified professional role (opens in a new tab)
Director of Cybersecurity, Electronic Frontier Foundation. Public usefulness: Public digital-security education, training and Surveillance Self-Defense work. General guidance cannot substitute for specialist help with a targeted compromise.
- Thorin Klosowski — verified professional role (opens in a new tab)
Senior Security and Privacy Activist, Electronic Frontier Foundation. Public usefulness: Public consumer explanations and Surveillance Self-Defense guides. Professional public educator; not represented as a clinician or academic researcher.
Professional perspectives
- Lorrie Faith Cranor (opens in a new tab)
Professor of Computer Science and Engineering and Public Policy; Carnegie Mellon usable privacy and security researcher. Makes the usability of passwords, notices and privacy choices part of the security question. Academic research does not certify an individual product or account.
- Jason Hong (opens in a new tab)
Professor Emeritus, Human-Computer Interaction Institute, Carnegie Mellon University. Shows how everyday mobile services and interfaces affect privacy decisions. Use the current emeritus designation; no vendor endorsement is implied.
- Sauvik Das (opens in a new tab)
Assistant Professor, Human-Computer Interaction Institute, Carnegie Mellon University. Connects protective behavior with real social and usability constraints. Research context matters; no assumption that peer pressure improves every security decision.
- Lujo Bauer (opens in a new tab)
Professor of Electrical and Computer Engineering and Computer Science, Carnegie Mellon University. Contributes research on passwords, authentication and usable access decisions. Technical findings apply to specified systems and threat models.
- Florian Schaub (opens in a new tab)
Associate Professor of Information and Electrical Engineering and Computer Science, University of Michigan. Studies how notices and interfaces make privacy choices understandable. A notice design is not proof that data collection is minimal or harmless.
- Blase Ur (opens in a new tab)
Associate Professor of Computer Science, University of Chicago. Studies password use and everyday privacy/security decision making. Study participants and interfaces bound any reported result.
- Elissa Redmiles (opens in a new tab)
Clare Boothe Luce Assistant Professor of Computer Science, Georgetown University. Studies how people evaluate digital safety and which advice is usable. Empirical priorities are context-sensitive, not a universal personal threat assessment.
- Julie Haney (opens in a new tab)
Computer scientist and usable cybersecurity researcher, National Institute of Standards and Technology. Centers human needs and workload when evaluating protective behavior. Professional education is not a guarantee about a particular service.
- Karen Renaud (opens in a new tab)
Reader, University of Strathclyde; human-centered cybersecurity researcher. Investigates mental models, authentication and why advice can be difficult to follow. Avoid interpreting noncompliance as a personal character failure.
- M. Angela Sasse (opens in a new tab)
Professor of Human-Centred Security with a University College London appointment. Examines the costs of systems that demand impractical behavior. The profile includes historical appointments; no current directorship is asserted.
- Serge Egelman (opens in a new tab)
Senior research scientist and usable privacy/security group lead at ICSI; Berkeley research scientist. Studies app tracking, disclosure and usable privacy controls. AppCensus commercial involvement is disclosed in the official profile; no product promotion here.
- L. Jean Camp (opens in a new tab)
Indiana University professor; named Provost Professor in 2025. Examines how people understand trust and manage security risks. Broad research perspective does not replace account-specific support.
- Cormac Herley (opens in a new tab)
Security researcher; documented as a Microsoft Research principal researcher in 2011. Challenges advice that ignores the user’s time and actual risks. Historical role verified; current employment was not established and is not claimed.
- Eva Galperin (opens in a new tab)
Director of Cybersecurity, Electronic Frontier Foundation. Contributes practical safety planning for people with differing risks. General guidance cannot substitute for specialist help with a targeted compromise.
- Thorin Klosowski (opens in a new tab)
Senior Security and Privacy Activist, Electronic Frontier Foundation. Translates privacy tools and their limits into ordinary practical choices. Professional public educator; not represented as a clinician or academic researcher.
