Security Myths

18 widespread assumptions about IT security that don't hold up on closer inspection.

Last updated: September 1, 2026

Myth

I have nothing to hide, I don't need security.

Actually

It's not about hiding something. Your data, photos, messages and accounts still have value, both to you and to attackers. Protection means deciding for yourself what happens with your data.

Myth

WhatsApp is end to end encrypted, that's enough for me.

Actually

The encryption of the actual message content is correct, but WhatsApp as a Meta service still collects significantly more metadata, who communicates with whom and when, contacts, device information, than more privacy friendly alternatives like Signal. Being end to end encrypted isn't the same as collecting little data overall.

Myth

A free VPN protects me just as well as a paid one.

Actually

Running a VPN costs servers and bandwidth, someone pays for that. With free providers that's often the user themselves, through ads, selling usage data, or weaker encryption. Paid providers like Proton VPN or Mullvad instead finance themselves directly through the subscription fee, that's not an ad, just a different, more transparent business model that usually comes with fewer compromises on privacy and security.

Myth

I can reuse a very long password everywhere.

Actually

Length protects against guessing, not against a data breach at a single service. If it's stolen there, every account using the same password is immediately at risk.

Myth

I always recognize phishing emails right away, that won't happen to me.

Actually

Modern phishing emails are often deceptively well made and deliberately exploit stress or time pressure. Even experienced people fall for it when they're distracted or not paying attention, that's not a question of being careless.

Myth

An update can wait, it only changes small things anyway.

Actually

Many updates close actively exploited security holes. The longer a system stays unpatched, the longer that door stays open.

Myth

Changing my password often automatically makes me safer.

Actually

Forced, regular changes without a reason often lead in practice to weaker, slightly modified passwords. One single strong, unique password with two factor sign in is more effective.

Myth

Two factor sign in via SMS is just as secure as an app.

Actually

SMS codes can be intercepted through SIM swapping. An authenticator app or a hardware key are considered far more resilient.

Myth

An antivirus program protects me completely.

Actually

Antivirus software lowers the risk, but doesn't replace your own behavior. Updates, strong passwords and caution with links remain just as important.

Myth

A website with HTTPS and a padlock icon is automatically trustworthy.

Actually

HTTPS only encrypts the connection between you and the server, it says nothing about who runs that server. Well made phishing sites have long since used HTTPS as a matter of course too.

Myth

Firewalls only matter for companies.

Actually

Private routers and computers benefit from an active firewall too, it blocks unwanted connection attempts from the internet, regardless of network size.

Myth

My small, private website isn't a target.

Actually

Automated attacks and scans search the entire internet indiscriminately for known vulnerabilities, regardless of how well known or small a site is.

Myth

A password with special characters like @ or ! is automatically secure.

Actually

Predictable patterns like a capital letter at the start and an exclamation mark at the end barely add extra protection. What matters most is length and that the password isn't guessable, not a single special character in a familiar spot.

Myth

My cloud syncs everything, I don't need a separate backup.

Actually

Syncing is not a backup. If you accidentally delete or encrypt a file, for example through ransomware, that's usually immediately synced to the cloud too. A real backup is offset in time and independent of that.

Myth

Incognito mode makes me invisible on the internet.

Actually

It only avoids saving history on your own device. Your internet provider and visited websites still see your activity regardless.

Myth

Public Wi-Fi is fine as long as the website uses HTTPS.

Actually

HTTPS protects the content of the connection, but doesn't automatically reveal everything. Metadata like visited domains can still be visible on insecure networks, a VPN closes that gap additionally.

Myth

An app from the official app store is always safe.

Actually

Official app stores review apps, but that doesn't completely rule out malicious or poorly secured apps. Problematic apps keep slipping through regardless, a look at permissions and reviews remains worthwhile.

Myth

Apple devices can't be hacked.

Actually

No system is unbreakable. Mac and iPhone get attacked less often because they have a smaller market share, not because they're technically invulnerable.