Guides Mobile
Phone security without the theatre
Phones are attacked differently from computers, so the advice that works is different too - and it mostly is not about installing a scanner.
Why scanners do less here
Both major mobile systems isolate applications from each other. On iOS, an app simply cannot inspect the system or other apps, so a mobile "antivirus" cannot scan in any meaningful sense. What these apps actually provide is usually web filtering, a VPN, or alerts when your address appears in a breach.
Those can be worth having. They are just not the thing the name implies.
What actually goes wrong on phones
- Applications installed from outside the official stores.
- Permissions granted without thought - an app with no need for it reading contacts, location or messages.
- Phishing through SMS, messaging apps and the browser, which works the same as on a computer but is harder to inspect on a small screen.
- A lost or stolen device that was not locked.
- Accounts compromised elsewhere, with the phone merely the place you notice.
What to actually do
- Keep the system updated. Mobile updates frequently contain security fixes.
- Install from the official store, and look at the developer before installing.
- Review permissions occasionally and revoke what an app does not need.
- Use a passcode of reasonable length along with biometrics, and turn on automatic locking.
- Enable the remote find-and-erase feature, before you need it.
- Use a second factor on your accounts - your phone is often the recovery route for everything else.
Public Wi-Fi, honestly
Traffic to sites using HTTPS - which is now nearly all of them - is already encrypted between your device and the site, so the old picture of someone reading your passwords from the next table is largely out of date.
A VPN on public networks still hides which sites you visit from the network operator and protects the smaller amount of traffic that is not encrypted. That is a real benefit, and a narrower one than the marketing suggests.