Security Myths
18 widespread assumptions about IT security that don't hold up on closer inspection.
Last updated: September 1, 2026
I have nothing to hide, I don't need security.
It's not about hiding something. Your data, photos, messages and accounts still have value, both to you and to attackers. Protection means deciding for yourself what happens with your data.
WhatsApp is end to end encrypted, that's enough for me.
The encryption of the actual message content is correct, but WhatsApp as a Meta service still collects significantly more metadata, who communicates with whom and when, contacts, device information, than more privacy friendly alternatives like Signal. Being end to end encrypted isn't the same as collecting little data overall.
A free VPN protects me just as well as a paid one.
Running a VPN costs servers and bandwidth, someone pays for that. With free providers that's often the user themselves, through ads, selling usage data, or weaker encryption. Paid providers like Proton VPN or Mullvad instead finance themselves directly through the subscription fee, that's not an ad, just a different, more transparent business model that usually comes with fewer compromises on privacy and security.
I can reuse a very long password everywhere.
Length protects against guessing, not against a data breach at a single service. If it's stolen there, every account using the same password is immediately at risk.
I always recognize phishing emails right away, that won't happen to me.
Modern phishing emails are often deceptively well made and deliberately exploit stress or time pressure. Even experienced people fall for it when they're distracted or not paying attention, that's not a question of being careless.
An update can wait, it only changes small things anyway.
Many updates close actively exploited security holes. The longer a system stays unpatched, the longer that door stays open.
Changing my password often automatically makes me safer.
Forced, regular changes without a reason often lead in practice to weaker, slightly modified passwords. One single strong, unique password with two factor sign in is more effective.
Two factor sign in via SMS is just as secure as an app.
SMS codes can be intercepted through SIM swapping. An authenticator app or a hardware key are considered far more resilient.
An antivirus program protects me completely.
Antivirus software lowers the risk, but doesn't replace your own behavior. Updates, strong passwords and caution with links remain just as important.
A website with HTTPS and a padlock icon is automatically trustworthy.
HTTPS only encrypts the connection between you and the server, it says nothing about who runs that server. Well made phishing sites have long since used HTTPS as a matter of course too.
Firewalls only matter for companies.
Private routers and computers benefit from an active firewall too, it blocks unwanted connection attempts from the internet, regardless of network size.
My small, private website isn't a target.
Automated attacks and scans search the entire internet indiscriminately for known vulnerabilities, regardless of how well known or small a site is.
A password with special characters like @ or ! is automatically secure.
Predictable patterns like a capital letter at the start and an exclamation mark at the end barely add extra protection. What matters most is length and that the password isn't guessable, not a single special character in a familiar spot.
My cloud syncs everything, I don't need a separate backup.
Syncing is not a backup. If you accidentally delete or encrypt a file, for example through ransomware, that's usually immediately synced to the cloud too. A real backup is offset in time and independent of that.
Incognito mode makes me invisible on the internet.
It only avoids saving history on your own device. Your internet provider and visited websites still see your activity regardless.
Public Wi-Fi is fine as long as the website uses HTTPS.
HTTPS protects the content of the connection, but doesn't automatically reveal everything. Metadata like visited domains can still be visible on insecure networks, a VPN closes that gap additionally.
An app from the official app store is always safe.
Official app stores review apps, but that doesn't completely rule out malicious or poorly secured apps. Problematic apps keep slipping through regardless, a look at permissions and reviews remains worthwhile.
Apple devices can't be hacked.
No system is unbreakable. Mac and iPhone get attacked less often because they have a smaller market share, not because they're technically invulnerable.