8 iPhone Privacy Settings to Change Right Now

Review these 8 iPhone privacy settings to change right now — limit location tracking, block ad targeting, and hide lock screen previews in under 10 minutes.

Most iPhones ship with privacy settings that quietly share your location, usage habits, and Siri interactions with Apple and third-party apps by default. I audited my own device recently and found six apps still holding “Always” location access — including a food delivery app and a weather widget I had completely forgotten about. The core insight about iphone privacy settings to change: Apple’s defaults lean toward convenience and data collection, not user privacy — every adjustment in this guide is something you have to opt out of yourself.

The good news is that none of these changes require technical expertise, and most take under a minute each. You can back up your iPhone first if you want peace of mind, though none of these tweaks touch your photos or personal files.

Quick Answer

Open Settings → Privacy & Security and work through eight changes: limit Location Services to “While Using,” block all app tracking requests, disable Siri learning and audio sharing, revoke unneeded camera and microphone access, opt out of Analytics, hide lock screen notification previews, and confirm Safari’s cross-site tracking prevention is active.

Which iPhone Privacy Settings Leak the Most Data?

1. Location Services — Per-App Controls

Go to Settings → Privacy & Security → Location Services. Every app with location permission is listed here. Change anything set to “Always” to “While Using the App” unless it’s a navigation app that needs background access. A setting of “Always” lets an app log your physical location even when you’re not actively using it — there is no good reason for most apps to have this.

2. App Tracking Transparency — Block All Requests

Go to Settings → Privacy & Security → Tracking. Toggle off “Allow Apps to Request to Track.” This prevents apps from asking to follow your behavior across other apps and websites for advertising. Scroll down on the same screen to see which apps already have permission — I found three from years ago still active and revoked all of them.

Pro tip: After revoking tracking for old apps, force-close those apps once so the change takes effect immediately rather than at the next launch.

3. Siri & Search — Stop Siri From Profiling Your Habits

Go to Settings → Siri & Search → scroll down and disable “Improve Siri & Dictation” and “Share Audio with Apple.” These options send voice recordings to Apple for human review. I also turn off “Show Suggestions” for apps I rarely open — it limits how much Siri learns about my daily routines.

Limiting location access, blocking tracking requests, and reining in Siri learning together close off the three biggest passive data flows on a default iPhone.

How Do I Protect My Camera and Microphone Privacy?

4. Camera Access — Review Every App

Go to Settings → Privacy & Security → Camera. Revoke access for any app without an obvious need — a news reader, finance tool, or shopping app, for example. If an app truly needs camera access for a feature, it will ask again when you trigger that feature. Removing access now costs you nothing.

5. Microphone Access — The Same Audit Applies

Go to Settings → Privacy & Security → Microphone. I found a fitness tracking app on my phone with microphone access it had never explained in context — I revoked it immediately. If an app has no voice input, recording, or calling feature, it has no legitimate reason to hear you.

Auditing camera and microphone permissions takes under two minutes and eliminates the risk of apps recording audio or video in the background.

What Lock Screen Setting Should I Change First?

6. Notification Previews — Hide Them Until Unlocked

Go to Settings → Notifications → Show Previews → change “Always” to “When Unlocked.” Anyone who picks up your phone now sees only a generic badge, not your actual message or email content. This is the setting I recommend first to anyone who works in a shared office or takes public transit.

Troubleshooting tip: If you stop seeing expected alerts after this change, check whether your iPhone Focus mode is silencing specific apps independently — that’s a separate toggle from notification previews.

Which Analytics and Browser Settings Need Adjusting?

7. Analytics & Improvements — Opt Out Completely

Go to Settings → Privacy & Security → Analytics & Improvements. Disable “Share iPhone Analytics,” “Share iCloud Analytics,” and “Share with App Developers.” This stops your usage patterns from being uploaded to Apple and third-party developers. It has no effect on speed, battery life, or any app functionality.

8. Safari — Confirm Cross-Site Tracking Is Active

Go to Settings → Safari and verify “Prevent Cross-Site Tracking” is toggled on. Safari turns this on by default, but I’ve seen it disabled on phones restored from older backups. Apple’s privacy page explains exactly what this blocks if you want to understand the underlying mechanism.

Opting out of analytics and confirming Safari’s tracker blocker address the data your phone shares passively — no further action required once they’re set.

What Mistakes Undermine iPhone Privacy Settings?

  • Turning off Location Services entirely. This breaks Maps, Find My, and weather. Set each app individually to “While Using” instead — you keep useful features without the background tracking.
  • Only auditing recently installed apps. Permissions granted years ago are still active. Review the full list in each Privacy & Security category, not just apps you remember installing recently.
  • Assuming iOS defaults are already privacy-friendly. They’re not — Apple’s defaults favor data collection and product improvement. Privacy requires explicit opt-outs.
  • Skipping the review after a major iOS update. New iOS versions sometimes introduce new sharing options toggled on by default. Re-check Privacy & Security after each major update.
  • Revoking permissions without thinking through app needs. Removing microphone access from a voice-memo app breaks it. Think through what each app does before revoking.

Frequently Asked Questions

Will blocking app tracking break any features I rely on?

Almost never. App tracking is used for cross-app ad targeting — it’s not connected to core features like payments, navigation, or messaging. I’ve had tracking blocked for over a year with no noticeable impact on any app I use daily.

How often should I review my iPhone privacy settings?

I do a quick audit every three to four months and always after a major iOS update. New apps request permissions when installed, and iOS updates sometimes introduce new data-sharing options. A ten-minute check twice a year covers most people’s needs.

Can I see which apps recently accessed my microphone or camera?

Yes — iOS shows a green dot for active camera use and an orange dot for microphone use in the status bar. For a full access log, go to Settings → Privacy & Security → App Privacy Report. Enable it first if prompted; it then shows every app that accessed your hardware sensors and the domains each app contacted.

Does disabling Siri learning make Siri noticeably worse?

Slightly, over the long term. Siri may be marginally less tailored to your patterns without the feedback data. In practice, I’ve had Siri learning disabled for months and noticed no meaningful difference in everyday use — the privacy tradeoff is worth it.

Conclusion

These eight iphone privacy settings to change take about ten minutes and meaningfully reduce what your device shares by default. Start with Location Services and App Tracking Transparency — those two deliver the biggest gains with the least effort. Work through the remaining six at your own pace.

Once your privacy settings are locked down, take five minutes to set up Find My iPhone — it’s the security safety net that makes all the difference if your phone is ever lost or stolen.

Set Up Find My iPhone Before You Actually Need It

Set up Find My iPhone in under two minutes. Enable Offline Finding and Send Last Location so you can track, lock, or erase a missing phone from anywhere.

Losing your iPhone is one of those gut-drop moments you don’t forget. One minute it’s in your pocket; the next you’re retracing your steps across a parking lot — or realizing someone walked off with it. The key insight: Find My iPhone only works if you enable it before the phone goes missing.

I turn this on the same day I take any new iPhone out of the box. It takes under two minutes, costs nothing, and requires nothing beyond a free Apple ID. Here’s the complete setup, plus how to use it the moment disaster strikes.

Quick Answer

Go to Settings, tap your name at the top, select Find My, then enable Find My iPhone, Offline Finding, and Send Last Location. That’s the full setup. Once active, locate your device from any browser at icloud.com or from the Find My app on another Apple device.

Three toggles, under two minutes, and your iPhone is trackable even when the battery is nearly dead.

Does Find My Come Turned On Automatically?

Not always. Apple prompts you during the initial setup wizard, but many people tap through quickly and skip it. iPhones restored from backups sometimes arrive with it off. I check this setting with anyone who hands me a new iPhone — it’s a ten-second verification that prevents enormous stress later.

Find My status is a one-screen check, yet most people never verify it until after something goes wrong.

How Do I Set Up Find My iPhone?

Make sure your iPhone is signed into an Apple ID before you start.

Step 1: Open Apple ID Settings

Open Settings and tap your name at the very top. This panel controls iCloud, Apple ID, and every Apple device tied to your account.

Step 2: Enable Find My

Tap Find My > Find My iPhone, then flip the main toggle to green. Also enable both sub-options:

  • Offline Finding — uses Apple’s encrypted crowd network to locate your phone via nearby Apple devices, even without Wi-Fi or cellular.
  • Send Last Location — sends your GPS coordinates to Apple the moment the battery reaches critical, giving you one final location clue before the phone powers off.

Step 3: Confirm Location Services Are On

Go to Settings > Privacy & Security > Location Services and verify the main toggle is on. Find My cannot function without it.

Pro tip: Open the Find My app right after setup, tap Devices, and confirm your iPhone appears with a green dot and a live map pin. If you see “Location Not Available,” toggle Find My off, wait 30 seconds, and toggle it back on — this usually refreshes the connection. That quick test is the troubleshooting step most people skip until the phone is already missing.

With all three options active, Find My tracks your phone across the offline Bluetooth network and captures one final GPS ping before the battery dies.

How Do I Find My iPhone When It’s Lost?

From the Find My App

On another Apple device, open the Find My app, tap Devices, and select your iPhone. The map shows its current or last known location. From here you can play a sound, enable Lost Mode, or remotely erase the device as a last resort.

From iCloud.com

Visit icloud.com on any computer or Android phone, sign in with your Apple ID, and open Find My. The web interface has the same controls as the app — the best option when you’re borrowing a non-Apple device.

Via Siri on Apple Watch

If the phone is somewhere nearby, say “Hey Siri, play a sound on my iPhone” from your Apple Watch. The chime overrides silent mode for two minutes.

All three methods pull from the same location data — use whichever device is in your hand fastest.

What Does Lost Mode Do?

Lost Mode is a one-tap lockdown you should activate the moment you suspect theft. Trigger it from the Find My app or iCloud.com by tapping Mark As Lost.

Feature Effect in Lost Mode
Screen Displays your custom message and callback number
Apple Pay Suspends all cards automatically
Notifications Hidden so a finder can’t read them
Location alerts Sends you a notification when the phone moves
Activation Lock Requires your Apple ID password to reactivate

Lost Mode is reversible — enter your Apple ID on the recovered device to disable it.

Enable Lost Mode early rather than waiting to be certain; it’s easy to undo, and it starts logging location changes the moment you turn it on.

What Are the Most Common Find My Mistakes?

  1. Skipping “Send Last Location.” This free option takes one toggle. Without it, a dead battery ends your tracking completely — you get no final location clue.
  2. Turning off Location Services to save battery. Find My stops working entirely. If battery life is a concern, reduce screen brightness or disable Background App Refresh instead. For iCloud storage issues that can affect backup options, read my guide on freeing up iCloud storage for free.
  3. Erasing the device too quickly. A remote erase removes the iPhone from Find My permanently and cannot be undone. Always try playing a sound and enabling Lost Mode first — treat erase as an absolute last resort.
  4. Not testing after setup. Confirm your iPhone shows on the Find My map while you’re still at home. Silent failures — stale location, wrong Apple ID signed in — are far easier to diagnose when the device isn’t actually gone.

Most people discover these gaps only after something goes wrong; a two-minute check today prevents all of them.

Frequently Asked Questions

Does Find My work without an internet connection?

Yes, in limited fashion. With Offline Finding on, your iPhone broadcasts an encrypted Bluetooth signal that nearby Apple devices pick up and relay to Apple anonymously — without those bystander devices knowing what they relayed. I’ve seen this surface a location in a busy shopping mall even after the phone’s SIM card was removed.

Can someone turn off Find My to steal my phone?

Disabling Find My requires your Apple ID password — there’s no shortcut around it. Without the password, Activation Lock prevents a thief from setting the iPhone up as their own device, making it much less useful to steal. For broader account security, see my guide on removing unknown logins from your Apple, Google, and Microsoft accounts.

Does Find My drain my iPhone’s battery?

No, not noticeably. In my experience running it continuously on multiple iPhones, the impact is well under 1% of daily battery life. Keep Location Services on for Find My and restrict precise location only for apps that genuinely don’t need it.

What if my iPhone’s location isn’t updating in Find My?

First confirm your Apple ID is signed in and Find My is still enabled under Settings. A toggle off-and-on usually refreshes the connection within a minute. If the location still shows “Not Available,” the phone is likely powered off — the last recorded location is your starting point while you work through additional iPhone troubleshooting steps.

Conclusion

Setting up Find My iPhone takes under two minutes and delivers outsized peace of mind. Enable it now, turn on Send Last Location, and confirm your device appears on the Find My map — all three steps, today. It’s the one setup task you genuinely don’t want to leave until after you actually need it.

Move Saved Passwords Between Browsers: Chrome, Edge, Firefox, and Safari

Move saved passwords between browsers in five minutes — export a CSV, import it in the new browser, then delete the file immediately to stay secure.

Moving to a new browser is painless until you realize hundreds of saved logins are stranded inside the old one. I have switched browsers three times in the past two years, and the password question stops most people before they even begin.

The answer is simpler than it looks. Chrome, Edge, Firefox, and Safari all export saved passwords as a CSV file in about two minutes. The one thing you must know before you start: delete that CSV the moment your import finishes, because it stores every password in plain, readable text with zero encryption.

Quick Answer

Export your saved passwords from the old browser’s settings as a CSV file, then import that file in the new browser’s password manager. The whole process takes about five minutes. Delete the CSV immediately after — it stores every password in plain text and is a serious security risk if left on your device.

How Do I Export Passwords from My Old Browser?

Here is what each browser supports before you start:

Browser Export to CSV Import from CSV Where to Find It
Google Chrome Yes Yes Settings → Google Password Manager → gear icon
Microsoft Edge Yes Yes edge://settings/passwords → three-dot menu
Mozilla Firefox Yes (v79+) Yes Menu → Passwords → three-dot menu
Safari No Yes (Mac only) File → Import From → Passwords CSV file

Export from Google Chrome

  1. Click the three-dot menu → SettingsAutofill and passwordsGoogle Password Manager.
  2. Click the Settings gear in the upper right corner.
  3. Select Export passwords and confirm when prompted.
  4. Enter your computer login password if asked, then save the file to your Desktop.

Export from Microsoft Edge

  1. Type edge://settings/passwords in the address bar and press Enter.
  2. Click the three-dot icon next to “Saved passwords” → Export passwordsExport passwords.
  3. Save the file to your Desktop.

Export from Mozilla Firefox

This requires Firefox version 79 or later. Update first via Help → About Firefox if needed. If you run into trouble with an older version, Mozilla’s official export documentation covers the steps in detail.

  1. Click the hamburger menu → Passwords.
  2. In the Passwords window, click the three-dot menu in the upper right → Export logins.
  3. Confirm the warning, then save the file to your Desktop.

Pro tip: Save the CSV to your Desktop, not your Downloads folder. It is harder to forget to delete when it is sitting right in front of you.

All three browsers bury the export option inside password manager settings — once you know where to look, the export takes under a minute.

How Do I Import Passwords Into the New Browser?

Import into Google Chrome

  1. Go to SettingsAutofill and passwordsGoogle Password Manager → the gear icon.
  2. Click Import passwordsSelect file, choose the CSV, and click Open.
  3. Chrome shows how many entries were added and flags any duplicates.

Import into Microsoft Edge

  1. Go to edge://settings/passwords.
  2. Click the three-dot icon → Import passwordsFrom a CSV file.
  3. Select the CSV and click Import. Edge shows a summary count when finished.

Import into Mozilla Firefox

  1. Open the Passwords window (menu → Passwords).
  2. Click the three-dot menu → Import from a File → select the CSV.

Import into Safari (Mac only)

  1. In Safari, go to FileImport FromPasswords CSV file.
  2. Authenticate with your Mac password or Touch ID, select the CSV, and click Import.

After importing, test two or three logins you use every day. When I moved about 340 passwords from Chrome to Firefox, three entries had imported with an extra space appended to the password — a quirk caused by a special character in the original entry. Testing right away caught it before it turned into a lockout.

If you use multiple Chrome profiles for work and personal browsing, see my guide on setting up Chrome profiles before exporting, so you know which profile’s passwords you are moving.

Spot-checking five key logins right after import catches nearly all character-encoding issues before they become a problem.

Why Should I Delete the CSV File Right Away?

The CSV file has no password and no encryption. Any person or piece of malware that opens it can read every username and password instantly. Treat it like a sticky note with your bank PIN — use it once, then destroy it.

  1. Right-click the file on your Desktop → Delete (Windows) or Move to Trash (Mac).
  2. Empty the Recycle Bin or Trash immediately.
  3. On Windows, open File Explorer and check Quick Access → Recent files to confirm no auto-saved copy exists elsewhere.

Troubleshooting tip: If Chrome reports “0 passwords imported,” open the CSV in Notepad and check the first row. Chrome requires the headers to read exactly name,url,username,password. Edge sometimes exports with slightly different column labels that Chrome rejects — rename the headers, save the file, and try the import again.

The unencrypted CSV is the single biggest security risk in this entire process — deleting it is not optional.

What Are the Most Common Password Migration Mistakes?

  1. Leaving the CSV on your device. It is completely unencrypted. Fix: set a two-minute phone timer the moment you save the file.
  2. Skipping the post-import test. Special characters in passwords can cause silent import errors. Fix: manually test five key logins right after importing.
  3. Creating duplicates. Importing into a browser that already has some passwords saved adds them twice. Fix: clear the existing password list first, or use the browser’s built-in duplicate finder afterward.
  4. Leaving sync on in the old browser. Chrome and Edge keep syncing passwords to your Google or Microsoft account unless you turn it off. Fix: sign out of sync in the old browser’s settings once migration is confirmed complete.
  5. Doing this repeatedly when you switch browsers often. A free password manager like Bitwarden removes the migration problem permanently — credentials follow the extension, not the browser. Before switching, check my comparison of Chrome vs Edge vs Firefox privacy defaults to pick the right browser from the start.

Most migration headaches come from two sources: leaving the CSV on the device too long, and skipping the post-import test — both take under two minutes to prevent.

Frequently Asked Questions

Is it safe to export browser passwords as a CSV file?

Safe only if you delete the file immediately after importing. The CSV is unencrypted plain text — no password, no protection. I always delete it and empty the Trash within five minutes of finishing the import.

Will importing passwords overwrite what is already saved in the new browser?

No. Imports add entries rather than replace them. Browsers flag duplicates and skip them, so existing passwords stay intact. If you see duplicates afterward, use the browser’s built-in password manager to clean them up.

Can I transfer Chrome passwords to Safari on iPhone?

Not directly via CSV on mobile. The cleanest path is to import the CSV into Safari on a Mac first, then let iCloud Keychain sync those credentials to your iPhone automatically — no cable required.

Why does Firefox show no export option?

CSV export was added in Firefox version 79. Go to Help → About Firefox to check and trigger an update. Once current, the Export logins option appears in the Passwords window’s three-dot menu.

Should I use a dedicated password manager instead of browser-saved passwords?

For most people, yes. A free tool like Bitwarden stores credentials independently of any browser, eliminating migrations entirely. It also pairs naturally with two-factor authentication for a much stronger overall account security setup.

Conclusion

Moving saved passwords between browsers takes about five minutes: export a CSV from the old browser, import it in the new one, and delete the file immediately. The only real danger is leaving that unencrypted file sitting on your device.

Not sure which browser to land in? My side-by-side look at Chrome, Edge, and Firefox privacy defaults shows which one protects your data right out of the box — choose the right browser first and you may never need to migrate again.

What Browser Cookies Really Do — and Which Ones to Block

What browser cookies do on your device — and why blocking third-party tracking cookies is the single most effective browser privacy setting you can enable.

If you’ve ever clicked “Accept All Cookies” without reading the banner, you’re not alone — most people just want the dialog to disappear. But understanding what browser cookies do underneath is worth two minutes, because not every cookie is created equal. The real split is between first-party cookies that make sites work and third-party tracking cookies that build advertising profiles of your browsing habits.

I noticed this firsthand when a pair of running shoes I browsed once appeared in ads across four completely unrelated websites for days afterward. One browser toggle stopped it immediately, and I’ve kept it on ever since.

Quick Answer

Browser cookies are small text files websites save on your device to remember logins, preferences, and activity. First-party cookies, set by the site you’re visiting, are mostly harmless. Third-party cookies from ad networks follow you across sites to build behavioral profiles. Block third-party cookies; leave first-party ones enabled.

Enabling “block third-party cookies” in your browser’s privacy settings is the one toggle that addresses most cookie-based tracking.

What Are Browser Cookies, Exactly?

A cookie is a tiny text file — usually a few hundred bytes — saved in your browser by a website. It stores a name, value, expiration date, and the domain that owns it. When your browser revisits that domain, it sends the cookie back so the server can recognize you without asking you to sign in again.

A cookie cannot run code or access your files. It only identifies your browser to the server that set it. Mozilla’s HTTP cookies documentation covers the full technical specification if you want to go deeper.

Session Cookies vs. Persistent Cookies

Session cookies disappear the moment you close the browser window. They handle temporary state: shopping carts, multi-step forms, one-time logins. Persistent cookies carry an expiration date — sometimes years away — and keep you signed in between visits or remember your language preference.

Persistent cookies accumulate quietly over time; clearing them periodically resets any trackers that slipped past your blocking settings.

How Do Cookies Track You Across Websites?

First-party cookies are set by the exact domain you’re visiting. If you’re on example.com, only example.com’s server can read them — they don’t leave that site.

Third-party cookies come from a different domain embedded in the page: an ad-network script, a social share button, or an analytics tag. Because that same network domain appears on thousands of sites, it links your activity across all of them. That’s how a shoe retailer ends up serving you ads on a cooking blog an hour after you browsed.

Cookie Type Set By Typical Use Block It?
Session (first-party) Site you’re visiting Cart, form state No
Persistent (first-party) Site you’re visiting Login state, preferences No
Third-party tracking Ad networks, data brokers Cross-site behavioral profiles Yes
Third-party functional Embedded services YouTube embeds, Google Maps Optional

First-party cookies identify you to the site you’re on; third-party tracking cookies identify you everywhere else on the web.

Which Cookies Are Safe to Allow?

First-party cookies from sites you use are safe. They keep you logged in, save settings, and make shopping carts persist. Without them, every page reload treats you as a stranger.

Functional third-party cookies — YouTube embeds, Google Maps widgets — are low risk. They’re tied to a specific feature you invoked, not a sweeping tracking network.

Pro tip: Look for a “Block third-party cookies” toggle specifically — not “Block all cookies.” Chrome, Firefox, and Edge each have this under Settings → Privacy and Security. You get the full privacy benefit without breaking site features you use daily.

Allowing first-party cookies and blocking third-party ones is the balance that gives you a working web without the retargeted ads following you around.

Which Cookies Should You Block?

Enable third-party cookie blocking in your browser using these paths:

  • Chrome: Settings → Privacy and security → Third-party cookies → Block third-party cookies
  • Firefox: Settings → Privacy & Security → Enhanced Tracking Protection → Strict
  • Edge: Settings → Cookies and site permissions → Block third-party cookies
  • Safari (iOS): Settings → Safari → Prevent Cross-Site Tracking (on by default)

For a deeper layer, uBlock Origin (free, available for Chrome, Firefox, and Edge) blocks tracking scripts before they can set a cookie at all.

Troubleshooting tip: If a login or embedded widget breaks after enabling the block, open Site Settings and add only that domain to an exception list. Don’t disable blocking globally — whitelist the one site that needs it.

Clearing your cookie store periodically sweeps up anything that slipped through. I do a full clear every couple of months — the guide to clearing browser cache and cookies covers exact steps for every major browser. To compare how aggressively each browser blocks trackers out of the box, the Chrome vs Edge vs Firefox privacy breakdown scores them all.

Third-party cookie blocking takes under a minute to enable and eliminates most cross-site ad tracking without disrupting sites you rely on.

What Common Cookie Mistakes Should You Avoid?

  1. Clicking “Accept All” on every banner. Most banners have a “Manage” or “Customize” option. Spending ten extra seconds lets you reject tracking categories. In EU and UK jurisdictions, sites are legally required to honor that choice.
  2. Assuming incognito mode blocks cookies. Private browsing deletes cookies when the window closes — it doesn’t prevent tracking during the session. For the full picture, what incognito mode actually hides covers exactly where the protection ends.
  3. Blocking all cookies entirely. This logs you out on every page load and breaks most site features. Block third-party cookies specifically — not the whole category.
  4. Thinking HTTPS means no tracking. The padlock encrypts your connection. It says nothing about whether the site uses cookies to profile and share your behavior.
  5. Ignoring mobile browsers. Safari and Chrome on your phone have the same cookie controls as the desktop versions. Check both — most people harden the laptop and forget the device in their pocket.

The most common cookie privacy mistake is behavioral — clicking “Accept All” on reflex instead of taking 10 seconds on the consent screen.

Frequently Asked Questions

Are cookies the same as trackers?

Cookies are the mechanism; tracking is the use. A first-party login cookie isn’t a tracker. A third-party ad-network cookie that links your activity across dozens of sites is. The cookie file itself is neutral — who set it and why determines whether it’s a privacy concern. For example, a retailer’s retargeting network sets a third-party cookie that follows you to unrelated sites, while a login cookie from your bank stays put.

Can I delete one site’s cookies without logging out of everything?

Yes. In Chrome or Edge, go to Settings → Privacy and security → Site Settings → View permissions and data stored across sites, find the domain, and delete it. You’ll lose only that site’s login. I used this recently to force a streaming service to reset my account state without touching any other sessions.

Do cookie consent banners actually protect my privacy?

In EU and UK regions (GDPR), sites must honor your selection before activating tracking cookies. In the US, protections vary by state. Either way, enabling third-party cookie blocking directly in your browser is more reliable than trusting any individual banner — it applies automatically on every site you visit.

What is the difference between cookies and browser cache?

Cache stores page assets — images, scripts, stylesheets — so repeat visits load faster. Cookies store identifiers or preferences a site or third party wants to read back later. Clearing cache fixes a slow or broken-looking page; clearing cookies logs you out and resets stored settings. They are separate stores with separate clearing controls.

Cookies identify you; cache speeds up pages — they’re stored separately and cleared by different browser controls.

Conclusion

Most browser cookies are harmless — they’re what makes login persistence and saved preferences possible. The ones worth stopping, third-party tracking cookies, take under a minute to block with one toggle in any major browser. Add a periodic cookie clear and a few extra seconds on consent banners, and you’ve closed the biggest privacy gap most people never address. Open your browser’s Privacy settings and flip that switch today.

Enable DNS over HTTPS in Any Browser — Chrome, Firefox, and Edge

Enable DNS over HTTPS in Chrome, Firefox, or Edge in about 60 seconds to encrypt your browser’s DNS queries and stop ISPs from tracking the sites you visit.

Every time you visit a site, your browser sends a DNS request to translate the domain name into an IP address. That request travels in plain text by default — your ISP, a coffee shop Wi-Fi operator, or anyone else watching the network can see exactly which domains you’re looking up. Enabling DNS over HTTPS (DoH) encrypts those lookups so only you and your chosen DNS provider can read them.

Chrome, Firefox, and Edge all support DoH natively today — no extension, no app, and no router change required. I’ve had it running across all three browsers for over a year without a single compatibility issue. Here’s how to turn it on in each one.

Quick Answer

To enable DNS over HTTPS, open your browser’s security settings and turn on Secure DNS (Chrome/Edge) or DNS over HTTPS (Firefox), then pick Cloudflare or Google as your resolver. The whole process takes about 60 seconds and encrypts every DNS query your browser makes from that point on.

What Is DNS over HTTPS — and Why Should I Enable It?

Standard DNS sends lookup queries unencrypted over port 53. Anyone with access to your network traffic can log every domain you request — even when the sites themselves use HTTPS. DoH wraps each query in an encrypted HTTPS connection, so it blends in with normal web traffic and can’t be read in transit.

The practical result: your ISP loses the ability to build a detailed map of your browsing habits from DNS alone. On public Wi-Fi, that’s especially valuable since you can’t trust who controls the network.

Does it slow my browser down?

Not in practice. Cloudflare’s 1.1.1.1 resolver is among the fastest globally, and the added encryption adds only a few milliseconds on the first query per session — nothing you’d notice while browsing.

DoH encrypts your browser’s domain lookups so ISPs and public-network operators can no longer log which sites you’re requesting.

How Do I Enable DNS over HTTPS in Chrome?

  1. Click the three-dot menu in the top-right corner, then click Settings.
  2. In the left sidebar, select Privacy and security, then click Security.
  3. Scroll to the Advanced section and find Use secure DNS.
  4. Toggle it on. From the dropdown, choose a provider — I use Cloudflare (1.1.1.1) for its speed and strict no-logging policy.
  5. Changes save immediately. No restart needed.

Pro tip

If the toggle is grayed out, a work or school admin policy is locking the setting. You won’t be able to override it from the browser — ask your IT department to enable DoH at the network level instead.

Chrome’s Secure DNS toggle takes under 30 seconds to flip on and needs no extensions or account sign-in.

How Do I Enable DNS over HTTPS in Firefox?

Firefox gives you three protection levels — more granular control than any other major browser.

  1. Click the hamburger menu (≡), then Settings.
  2. Select Privacy & Security in the left panel and scroll down to the DNS over HTTPS section.
  3. Under Enable DNS over HTTPS using, choose a protection level:
    • Default Protection — uses DoH when available, falls back to standard DNS if not.
    • Increased Protection — DoH only, with fallback to standard DNS if the resolver fails.
    • Max Protection — DoH only; Firefox blocks the page entirely rather than falling back. This is what I run on my personal laptop.
  4. Select a provider from the dropdown. Cloudflare is the default; NextDNS lets you build a custom filtering dashboard for free (300,000 queries per month on the free tier).

Firefox’s Max Protection mode guarantees DNS never travels unencrypted — at the cost of blocking pages outright if your DoH resolver goes offline.

How Do I Turn On Secure DNS in Microsoft Edge?

  1. Click the three-dot menu (…), then Settings.
  2. Open Privacy, search, and services in the sidebar.
  3. Scroll to the Security section and toggle on Use secure DNS to specify how to look up the network address for websites.
  4. Select Choose a service provider and pick Cloudflare, Google, or another option from the list.

Troubleshooting tip

If Edge reverts to unencrypted DNS after a reboot, a third-party antivirus or VPN client is likely overriding DNS at the OS level. The browser-level DoH setting has no effect in that case — you’ll need to set DoH in Windows network settings or on your router directly.

Edge’s Secure DNS steps mirror Chrome’s almost exactly, so you can configure both browsers in under two minutes total.

Which DNS over HTTPS Provider Should I Use?

Provider Logs queries? Best for
Cloudflare 1.1.1.1 No (purged in 24 h) Speed and strong privacy
Google Public DNS Limited (purged in 48 h) High reliability
NextDNS Optional Custom filtering dashboard
OpenDNS Yes (anonymized) Family and content filtering
AdGuard DNS No Ad blocking at the DNS layer

For most people, Cloudflare is the right default — it’s fast, independently audited, and publicly committed to not selling your data. If you want per-device filtering controls, NextDNS’s free plan is worth setting up. For a broader comparison of how Chrome, Firefox, and Edge handle your privacy overall, see Chrome vs Edge vs Firefox: Which Browser Respects Your Privacy Most.

Cloudflare 1.1.1.1 is the best default for most users — independently audited, free, and consistently the fastest resolver in global benchmarks.

What Mistakes Should I Avoid With DNS over HTTPS?

  1. Thinking DoH covers all your apps. Browser DoH encrypts DNS only inside the browser. Email clients, games, and other apps still use OS-level DNS. For whole-device protection, also set DoH in Windows network settings — my guide on changing your DNS server for faster, safer browsing walks through that step.
  2. Picking an obscure provider. Your DoH resolver sees all your browser DNS queries in plain text. Stick to providers with published privacy policies and third-party audits rather than a random resolver you found online.
  3. Confusing DoH with a VPN. DoH encrypts only the DNS lookup. Your IP address and the server names in TLS handshakes are still visible to your ISP. Use a VPN if you need to hide the connection itself, not just the lookup.
  4. Breaking work or parental filters. Corporate networks and parental controls often rely on DNS interception to enforce filtering. DoH bypasses those filters. Disable it on work-managed devices unless your IT team has approved it.
  5. Forgetting mobile browsers. Chrome and Firefox on Android support DoH in the exact same settings locations as their desktop counterparts. Public Wi-Fi on mobile carries the same risk — enable DoH there too.

Frequently Asked Questions

Does DNS over HTTPS affect how fast pages load?

Not noticeably. Cloudflare 1.1.1.1 responds in under 20 ms from most locations — on par with or faster than the average ISP resolver. I’ve run speed tests before and after enabling DoH and never measured a meaningful difference in page load times.

Is DoH the same as a VPN?

No. A VPN encrypts all your traffic and hides your IP address. DoH only encrypts the DNS lookup step — think of it as one privacy layer rather than a full anonymity solution. For public Wi-Fi safety you ideally want both, but DoH alone is still a worthwhile upgrade.

What is the difference between DNS over HTTPS and DNSSEC?

DoH encrypts DNS queries in transit so no one can eavesdrop on them. DNSSEC signs DNS responses cryptographically so you know the answer wasn’t tampered with. They solve different problems and can run at the same time — enabling one doesn’t interfere with the other.

Will enabling DoH break my parental controls?

It can, if your parental controls work by intercepting DNS at the router or ISP level. The fix is to set your DoH provider to your parental control service’s own DoH endpoint — for example, CleanBrowsing’s family filter — so queries stay filtered even when encrypted.

How do I check that DoH is actually working?

Visit 1.1.1.1/help — Cloudflare’s official check page — immediately after enabling the setting. It shows whether your DNS queries are encrypted and confirms which resolver is handling them. Takes about five seconds.

Can I enable DoH on my router instead of browser by browser?

Yes, and it’s more thorough. Router-level DoH protects every device on your network automatically, without touching individual browsers. Many Asus and Netgear routers support it natively in the DNS settings — look for a “DNS over HTTPS” or “Encrypted DNS” option in your router’s admin panel.

Conclusion

Enabling DNS over HTTPS is one of the quickest privacy upgrades you can make — under a minute, completely free, and nothing breaks. Start with Chrome or Edge’s Secure DNS toggle and pick Cloudflare as your resolver. If you want filtering control on top of encryption, set up NextDNS in Firefox. Open your browser settings right now and lock down your DNS queries.

Chrome vs Edge vs Firefox: Which Browser Respects Your Privacy Most

Chrome vs Edge vs Firefox privacy compared — learn which browser blocks the most trackers by default and the exact settings to harden whichever you use.

Chrome, Edge, and Firefox each have a different relationship with your browsing data — and if you’re using whichever came pre-installed, you may be sharing more than you realize. The gap between these three browsers on chrome vs edge vs firefox privacy is wider than most users expect.

Your browser is open dozens of times a day, which means the company behind it has a front-row seat to your habits — and each of the three handles that access very differently.

Quick Answer

Firefox is the most private browser out of the box, blocking cross-site trackers by default and sending minimal data to Mozilla. Edge is a middle-ground option with a useful tiered tracking prevention mode. Chrome collects the broadest behavioral data because Google’s advertising revenue depends on it. All three can be meaningfully tightened with a few targeted settings changes.

For default privacy with no configuration, Firefox leads; Edge is a solid compromise inside the Windows ecosystem.

What Does “Browser Privacy” Really Mean?

Browser privacy covers two distinct things: what the browser reports back to its own company, and how well it blocks third-party trackers from advertisers while you browse. These are not the same concern.

When I switched from Chrome to Firefox for a month, third-party tracking dropped noticeably in my network logs — but I still had to open Firefox’s settings and uncheck its own usage telemetry boxes. A browser can protect you from advertisers while still sending detailed usage reports to its maker.

Knowing which concern matters more to you — advertiser tracking or vendor data collection — points you to the right browser and the settings that actually move the needle.

How Do Chrome, Edge, and Firefox Compare on Privacy?

The table below covers the defaults that drive your real-world privacy exposure across all three browsers.

Feature Chrome Edge Firefox
Default tracker blocking None Balanced mode Standard ETP (on)
Third-party cookies Partial/delayed Follows Chromium Blocked by default
Fingerprinting protection None Basic (Strict mode only) Built-in, all modes
Data sent to vendor Google — extensive Microsoft — moderate Mozilla — minimal
Open-source codebase Chromium core only Chromium core only Fully open source

Firefox leads on every row; Chrome needs extensions and settings changes to close the gap.

Which Browser Blocks the Most Trackers?

Firefox’s Enhanced Tracking Protection (ETP) is active from the moment you install it. Standard mode blocks social trackers, cross-site tracking cookies, fingerprinters, and cryptominers. Switching to Strict mode extends that protection to tracking content in all windows — not just private ones.

Edge defaults to Balanced tracking prevention, which stops trackers from domains you haven’t visited. Strict mode blocks more aggressively but occasionally breaks layouts — I noticed it causing blank content blocks on certain media sites until I added a site-specific exception.

Chrome has no built-in tracker blocking at all. The fastest fix is adding uBlock Origin, which works across all three browsers with filter lists that update daily.

Pro Tip

Install uBlock Origin regardless of which browser you use. It is the highest-impact privacy step available — free, lightweight, and effective out of the box. Paired with Firefox’s ETP in Strict mode, it blocks the broadest range of trackers with near-zero friction.

Out of the box, Firefox blocks the most; adding uBlock Origin to Chrome or Edge narrows the practical gap considerably.

Does Signing Into Your Browser Expose More of My Data?

Yes — especially in Chrome. Signing in with your Google account links your browsing history to your advertising profile, the one Google uses to target you across every site that runs Google Ads. This is by design; it is the core of how Google’s business model works.

Edge syncs to your Microsoft account with a lower ad-targeting incentive — Microsoft’s revenue comes primarily from software and cloud subscriptions. Firefox sync stores encrypted data on Mozilla’s servers, and Mozilla has no advertising business.

If you need to sync bookmarks and passwords across devices, a standalone password manager like Bitwarden handles that without connecting your browsing history to any vendor account.

Signing in amplifies the privacy gap between browsers — signed-in Chrome is substantially more exposed than signed-in Firefox.

What Privacy Settings Should You Change Today?

In Firefox

Open Settings → Privacy & Security. Set Enhanced Tracking Protection to Strict. Scroll to Firefox Data Collection and uncheck all telemetry boxes. Under Address Bar, disable suggestions that “improve Firefox” — these send your partial searches to Mozilla servers.

In Edge

Go to Settings → Privacy, search, and services. Set Tracking prevention to Strict. Under “Personalization & advertising,” disable the advertising ID toggle. Under Optional Diagnostic Data, uncheck all boxes.

In Chrome

Go to Settings → Privacy and security → Third-party cookies and choose “Block third-party cookies.” Under Privacy Sandbox, disable all active trials. Visit myaccount.google.com/data-and-privacy to review what your signed-in Google account collects beyond what Chrome itself sends.

Troubleshooting Tip

If Strict mode breaks a site — login failures, missing images, blank content — right-click the lock icon in the address bar and add a site-specific exception. Lowering your global setting is never the right fix for one problem site.

These settings take under ten minutes and deliver more benefit than switching browsers without changing any defaults.

Is Firefox Worth Switching to From Chrome?

For most people, yes. Popular extensions — uBlock Origin, Bitwarden, Grammarly — all have direct equivalents at addons.mozilla.org. Google Docs, Drive, and Meet all work identically in Firefox.

I made the switch in about twenty minutes and found only one Chrome extension I used regularly had no Firefox equivalent — and a built-in Firefox feature covered the same workflow. The setup time is low; the privacy improvement starts immediately.

Switching from Chrome to Firefox takes under thirty minutes; the ongoing privacy benefit requires nothing extra to install or maintain afterward.

Common Mistakes to Avoid

  1. Thinking Incognito or Private mode protects you from tracking. It only prevents local history from saving on your device. Websites, advertisers, and your ISP still see your activity in real time.
  2. Staying signed into Chrome for all general browsing. Sign out of your Google account during non-Google sessions, or use separate browser profiles. My guide on setting up Chrome profiles for work and personal browsing walks through keeping sessions properly isolated.
  3. Installing too many browser extensions. Every extension can read your browsing data. Keep your toolbar short and stick to widely-reviewed tools — a crowded extension list is a real privacy exposure, not just clutter.
  4. Dismissing the browser update notification. Privacy patches ship in nearly every release. The “relaunch to update” prompt in all three browsers is worth acting on the day it appears.

Frequently Asked Questions

Is Firefox more secure than Chrome against malware?

They address different threats. Firefox leads on tracker blocking and vendor data collection by default. Chrome and Edge use Google’s Safe Browsing database for phishing and known-bad-site detection, which is very broad. I keep Safe Browsing enabled in Firefox — the two protections complement each other rather than compete.

Can I make Chrome as private as Firefox without switching?

Mostly. Add uBlock Origin, block third-party cookies, and sign out of your Google account while browsing. The remaining gap is the usage data Chrome sends to Google that Firefox does not send to Mozilla — that part cannot be closed with settings alone. For everyday browsing, the extension approach covers the most visible gap.

Does switching to Firefox mean losing my Chrome extensions?

Rarely. uBlock Origin, Bitwarden, 1Password, and Grammarly all have Firefox equivalents. A handful of niche Chrome-only tools have no equivalent. Check addons.mozilla.org for any extension you depend on before committing to the switch.

Which browser is safest for online banking?

All three are safe when updated. Firefox in Strict mode reduces the chance of a compromised third-party script running alongside your banking session — a real attack vector, not a theoretical one. I use Firefox for all finance-related browsing because the built-in isolation is one less thing to configure manually.

Conclusion

For privacy with the least setup, Firefox is the clear answer. For good-enough privacy inside the Windows ecosystem, Edge in Strict mode is a practical starting point. Chrome requires extra steps — install uBlock Origin and block third-party cookies — before it approaches either option. Those two changes are the highest-impact place to start regardless of which browser you are using today.

For more browser tips, see my guides on syncing your bookmarks across every device and reading any article distraction-free with browser reader mode.

Windows 11 TPM 2.0 Requirement: What It Is and How to Check Yours

Windows 11 TPM 2.0 requirement explained: what the chip does, how to check your version with tpm.msc, and how to enable fTPM or PTT in BIOS in minutes.

When I tried upgrading an older Dell laptop to Windows 11, Microsoft’s setup tool flagged one blocker: the windows 11 tpm 2.0 requirement. It sounded like obscure jargon, but ten minutes in BIOS later the upgrade was running. The chip was there all along — just switched off.

TPM 2.0, or Trusted Platform Module version 2, is a hardware security chip — or a firmware module inside the CPU — that Windows 11 uses to protect encryption keys, login credentials, and boot integrity. Most PCs built after 2016 already have it; the challenge is knowing where to find and enable it.

Quick Answer

TPM 2.0 is a security chip Windows 11 requires to verify your system and protect encrypted data. Check yours now: press Win + R, type tpm.msc, press Enter. A “Ready for use” message with Specification Version 2.0 means you’re all set. If you see “Compatible TPM cannot be found,” the module is likely disabled — enable fTPM (AMD) or PTT (Intel) in BIOS and the problem is usually solved in five minutes.

What Is TPM 2.0?

TPM stands for Trusted Platform Module. It is either a physical chip soldered onto the motherboard or a firmware module embedded inside the processor. AMD calls their version fTPM (firmware TPM); Intel calls theirs PTT (Platform Trust Technology). Both satisfy the Windows 11 requirement and behave identically from the operating system’s perspective.

What Does TPM Actually Do on Windows 11?

The chip acts as a tamper-resistant safe for cryptographic keys, operating independently of the main CPU. Windows 11 relies on it for four core features:

  • BitLocker — stores the drive encryption key so your disk auto-unlocks at boot without a USB recovery drive.
  • Windows Hello — anchors your fingerprint, face, or PIN to a hardware-backed key that never leaves the device.
  • Secure Boot — works with TPM to verify that bootloaders and drivers are signed before Windows loads.
  • Credential Guard — isolates Windows login tokens from malware running inside the OS, blocking pass-the-hash attacks.

Once I enabled fTPM on a Lenovo ThinkCentre, Windows Hello face recognition enrolled in under 30 seconds and BitLocker activated silently — no USB key required at boot. That one experience made the requirement click for me.

TPM 2.0 is a hardware-backed security vault that Windows 11 uses for drive encryption, biometric sign-in, and boot integrity — a genuine security baseline, not an arbitrary upgrade checkbox.

How Do I Check Whether My PC Has TPM 2.0?

Three built-in tools give you the answer in under two minutes, no download required.

Method 1: TPM Management Console (Fastest)

  1. Press Win + R, type tpm.msc, and press Enter.
  2. Read the Status section — it should say “The TPM is ready for use.”
  3. Under TPM Manufacturer Information, confirm Specification Version: 2.0.

If the right pane shows no manufacturer data, the chip is either disabled in firmware or not present at all.

Method 2: Device Manager

  1. Right-click Start and choose Device Manager.
  2. Expand the Security Devices node.
  3. Look for Trusted Platform Module 2.0. Its presence confirms Windows has loaded the chip’s driver.

Method 3: System Information

  1. Press Win + R, type msinfo32, press Enter.
  2. Select System Summary in the left panel.
  3. Scroll to TPM Spec Version — a value of 2.0 confirms you meet the requirement.

Pro tip: tpm.msc is always my first stop. It shows version and health on one screen and doesn’t require administrator rights to open.

All three methods query the same chip — tpm.msc is fastest because version and status appear together without navigating sub-menus.

How Do I Enable TPM 2.0 in BIOS?

If tpm.msc reports “Compatible TPM cannot be found,” the module is almost certainly present but disabled in firmware. Three steps fix it.

Step 1: Enter UEFI Firmware Settings

Restart and press the key shown at boot — commonly Del, F2, or F10 depending on your brand. From inside Windows you can go to Settings → System → Recovery → Advanced startup → Restart now, then choose Troubleshoot → Advanced options → UEFI Firmware Settings.

Step 2: Locate and Enable TPM

The menu path varies by manufacturer. This table covers most systems:

Brand / CPU Type BIOS Menu Path Setting to Enable
AMD systems (most brands) Advanced → CPU Configuration AMD fTPM switch → Enabled
Intel systems (most brands) Advanced → PCH-FW Configuration PTT → Enabled
HP Security → TPM Device TPM State: Available
Dell Security → TPM 2.0 Security TPM On (tick the checkbox)
Lenovo ThinkPad Security → Security Chip Security Chip: TPM 2.0

Step 3: Save and Verify

Press F10 (or the labelled save key) and confirm the reboot. After Windows loads, open tpm.msc again to confirm the status now reads “Ready for use” with version 2.0.

Troubleshooting tip: If you switch TPM type — say from a discrete hardware chip to fTPM — BitLocker will demand the recovery key on the very next boot. Retrieve your key before touching any BIOS setting at Microsoft’s BitLocker recovery key page. Skipping this step can lock you out of your own drive.

Flipping fTPM or PTT from Disabled to Enabled is a single BIOS toggle — and it resolves “Compatible TPM cannot be found” on the vast majority of PCs built after 2016.

What If My PC Does Not Have TPM 2.0 at All?

Machines from 2013 and earlier may have no TPM hardware — not even a firmware module. Two realistic options exist:

  • Add a discrete TPM 2.0 module — Many desktop motherboards have a physical TPM header (labelled TPM_1 or similar in the manual). A compatible module typically costs $15–30 and plugs directly onto the board.
  • Stay on Windows 10 and plan a hardware upgrade — Windows 10 receives security patches until October 14, 2025. While you plan, make sure automatic file backups are in place so no data is lost during the eventual transition.

Truly TPM-less PCs need a discrete module or a hardware upgrade — there is no reliable software workaround for the Windows 11 requirement on a production machine.

What Mistakes Should I Avoid With TPM?

  • Switching TPM type without saving the BitLocker recovery key first — Changing from dTPM to fTPM invalidates the stored key and triggers a recovery screen at next boot. Always export the key beforehand.
  • Assuming “Not found” means the chip is missing — In my experience this almost always means the module is disabled, not absent. Run tpm.msc before concluding your hardware lacks TPM 2.0.
  • Enabling TPM but skipping Secure Boot — Both are required for Windows 11. Enable them together during the same BIOS session to avoid a second reboot cycle.
  • Confusing TPM 1.2 with TPM 2.0 — Windows 11 requires version 2.0 specifically. Some Lenovo and Dell BIOS menus let you switch from 1.2 to 2.0 mode — check before assuming you need new hardware.
  • Expecting Windows 11 to install automatically after enabling TPM — You still need to launch Windows 11 Setup or wait for the Windows Update offer to appear; enabling the chip does not trigger the upgrade on its own.

Frequently Asked Questions

Does enabling TPM 2.0 erase my files?

No. Enabling the module in BIOS does not touch your data or Windows installation. The only data risk is if you switch TPM type while BitLocker is active without saving the recovery key first — that can lock you out of your drive, not erase it, but recovery without the key is effectively impossible.

My PC shows TPM 1.2 in tpm.msc — can I upgrade it?

Sometimes, yes. Some Lenovo, Dell, and HP BIOS menus include a “Security Chip” setting that lets you choose between 1.2 and 2.0 mode in firmware. If no such option appears, the chip is physically limited to 1.2 and cannot be upgraded without new hardware. Check your manufacturer’s support page for a BIOS update that might add the option.

Will enabling TPM 2.0 slow down my PC?

No measurable impact in everyday use. The chip handles lightweight cryptographic operations independently of the CPU, so tasks like browsing, gaming, and video calls are completely unaffected. I have never seen a benchmark shift after toggling fTPM on any AMD or Intel system I have worked on.

Can I install Windows 11 without TPM 2.0?

Microsoft has published a registry workaround that bypasses the TPM check at setup, but machines using it are flagged as unsupported and may stop receiving Windows 11 feature updates. For any PC you use for banking, work email, or personal data, the five-minute BIOS change is a far better path than running an unsupported configuration.

Conclusion

The windows 11 tpm 2.0 requirement almost never points to missing hardware — it points to a disabled setting. Open tpm.msc first, identify whether you need fTPM or PTT using the table above, enable it in BIOS, and verify the status in under ten minutes.

Once TPM is active and Windows 11 is running smoothly, the OS has a lot more to offer. A great next step is learning to use Snap Layouts and Virtual Desktops to keep your workspace organized from day one.

Signs Your Phone Has Been Hacked and How to Take Back Control

Worried your phone has been hacked? I walk through the warning signs and an exact Android and iPhone cleanup plan so you can lock things down today.

Last winter a friend handed me her iPhone because it was “acting possessed” — dead by lunch, random Portuguese-language ads on the home screen, and a password-reset email from her bank she never asked for. Twenty minutes later we found a configuration profile she had been tricked into installing, and the picture snapped into focus. The earlier you catch a compromised phone, the difference between a fifteen-minute cleanup and months of identity-theft cleanup.

I have walked dozens of people through this exact panic, and the pattern is always the same: a few small symptoms that each look innocent until you line them up. Below I cover what a hacked phone actually looks like and the precise steps I use to clean one up on both Android and iPhone.

Quick Answer

The clearest signs your phone has been hacked are sudden battery drain, apps you never installed, unexpected mobile-data spikes, messages sent from your accounts that you didn’t write, pop-up ads, sluggish performance, and password-reset emails you didn’t request. If two or more apply, run a malware scan and change your passwords today.

What Are the Warning Signs Your Phone Has Been Hacked?

Spyware and adware leave fingerprints. Each sign below can have an innocent explanation on its own, but when several appear together I treat the phone as compromised until proven otherwise. Here are the seven I check first.

Is your battery draining far faster than normal?

Malicious apps run silently in the background — tracking location, uploading contacts, streaming the microphone — and all of that burns battery fast. If a phone that once lasted all day now dies by mid-afternoon for no obvious reason, I open Settings > Battery on iPhone or Settings > Battery > Battery Usage on Android and look for an unfamiliar app near the top of the list. On iOS 14+ and Android 12+, a colored dot in the status bar means the camera or microphone is active right now — seeing it while you’re doing neither is a red flag.

Unexplained battery drain plus a live camera or mic dot is one of the strongest early warning signs.

Are there apps you don’t recognize?

I scroll through every home screen and app drawer. Attackers love disguising apps as bland utilities like “System Service” or “Phone Manager” so they blend in. Uninstall anything you don’t remember adding. On Android, also open Settings > Security > Device Admin Apps and revoke admin access for anything you didn’t authorize. Rogue browser add-ons work the same way on desktop, and my guide on browser extensions that spy on you covers that angle in detail.

If an app is on your phone and you can’t recall installing it, treat it as hostile until you confirm otherwise.

Has your mobile data usage spiked?

Spyware exfiltrates messages, photos, and call logs to remote servers, and that traffic shows up in your data totals. I check Settings > Mobile Data on iPhone or Settings > Network & Internet > Data Usage on Android. An app you barely touch sitting at the top of the data list is worth acting on immediately.

A rarely-used app burning large amounts of background data usually means something is shipping your information out.

Are messages going out that you didn’t write?

If contacts say they’re getting strange links or odd messages from you, act right away. Hijacked phones get used to spread phishing links and run premium-rate SMS scams. I open the Sent folder in both Messages and email and scan for anything I didn’t send.

Outgoing messages you never wrote mean your accounts are already being used against your contacts.

Is the phone sluggish or overheating for no reason?

A phone running hot while idle or freezing often is busy with hidden background processes. On its own this could be a software bug or aging hardware, but paired with any other sign here it points to compromise and warrants a scan.

Heat and lag alone are inconclusive, but combined with another symptom they tip the scales toward malware.

Are pop-up ads showing up outside of apps?

Ads on your home screen, or inside apps that never had ads before, are a hallmark of adware that pays attackers to force advertisements onto your screen. When I see ads appearing where they have no business being, a rogue app is almost always the cause.

Ads outside of an app you opened are a near-certain sign of an adware infection.

Are you getting password resets you never asked for?

Password-reset emails you didn’t request, login alerts from unfamiliar places, or sudden lockouts all point to someone methodically taking over your accounts — often starting from access gained through your phone. This escalates within hours, so I act the same day every time. The fastest way to confirm it is to find and remove unknown logins on Google, Microsoft, and Apple.

Unrequested password resets are the loudest alarm on this list — never ignore them.

How Do You Clean Up a Hacked Phone Step by Step?

Once I’m confident the phone is compromised, I work through these five steps in order. Doing them out of sequence — for example, resetting passwords on the infected device before removing the malware — can hand your new credentials straight back to the attacker.

Step 1: Run a malware scan

On Android, I install Malwarebytes (free) and run a full device scan. On iPhone, I go to Settings > General > VPN & Device Management and delete any configuration profile I didn’t install — those profiles are the main way attackers bypass Apple’s protections without a jailbreak, and they were exactly what my friend had been tricked into adding.

Step 2: Remove every app you don’t recognize

Uninstall unfamiliar apps right away. On Android: Settings > Apps. On iPhone: press and hold the icon, then Remove App. If an Android app refuses to uninstall, it likely holds Device Administrator privileges — revoke those at Settings > Security > Device Admin Apps first, then remove it. When an app still resists, I boot into Safe Mode by holding the Power button, then long-pressing “Power off” until the Safe Mode prompt appears; third-party apps are disabled there, so they come off cleanly.

Step 3: Change your passwords, email first

Email is the master key to every other account, so I change it first, then banking, social media, and anything with saved payment details. Use a unique, strong password for each one, and turn on two-factor authentication everywhere it’s offered — my walkthrough on setting up two-factor authentication makes that quick. It’s also worth checking whether your password was already exposed in a data breach.

Step 4: Audit your signed-in devices

I open myaccount.google.com > Security > Your devices for Google and Android, or appleid.apple.com > Devices for iPhone, and remove anything I don’t recognize. Reviewing sign-in times and locations usually surfaces the intruder fast.

Step 4 follow-up: Confirm 2FA is active

Before moving on, I verify two-factor authentication is genuinely enabled and not just half-configured. A single missed account is all an attacker needs to walk back in.

Step 5: Factory reset as a last resort

If malware survives the steps above, a factory reset is the most reliable fix. Back up photos and contacts to the cloud first, then restore from a backup dated before your symptoms began — restoring a post-compromise backup just reinstalls the problem you removed.

Work these steps in order and most phones are fully clean within two hours.

Which Security Tools Should You Use on Android vs. iPhone?

When three or four tools all claim to help, I find a side-by-side comparison settles it fastest. Here’s what I actually reach for, all free or built in.

Tool Platform Purpose Cost
Malwarebytes Android Malware scan and removal Free
Google Play Protect Android Real-time app scanning Built-in
Apple ID Security iPhone Device audit and remote wipe Built-in
Have I Been Pwned Both Check email against breach databases Free

You don’t need to pay for anything — the built-in and free tools above cover the whole cleanup.

Common Mistakes to Avoid

These are the slip-ups I see most often, each with the fix I give people.

  1. Waiting to act. Symptoms don’t resolve on their own, and every hour gives attackers more time to harvest data. Fix: act the same day you notice something off.
  2. Changing only one password. Attackers usually target several accounts at once. Fix: change all important passwords, not just the obvious one.
  3. Restoring a backup without checking its date. A post-compromise backup reinstalls the malware. Fix: restore the most recent backup from before symptoms started.
  4. Skipping permission reviews after a reset. A clean phone can still leak data through over-permissioned apps. Fix: review each app’s permissions before granting them — a flashlight has no business reading your contacts.
  5. Resetting passwords on the still-infected phone. Active spyware can capture the new ones. Fix: remove the malware first, then change credentials from a clean device.

Most of the damage I see comes from rushing the order, not from the malware itself.

Frequently Asked Questions

Can iPhones get hacked?

Yes, iPhones can be hacked, though their closed ecosystem makes it harder. The friend I helped was compromised through a rogue configuration profile she installed after tapping a link in a fake “delivery” text — no jailbreak required.

Does a factory reset remove all malware?

In nearly all cases, yes — a factory reset wipes the device back to its original state. The one exception is firmware-level malware, which is extraordinarily rare; in years of helping people I’ve never seen it outside of news reports about state-sponsored attacks on high-value targets.

How do I check whether my email was exposed in a data breach?

Use Have I Been Pwned, a free and reputable service that checks your address against hundreds of known breaches. I ran my own email through it and found it in two old breaches, which is exactly why I now use unique passwords everywhere.

What is SIM swapping and should I worry about it?

SIM swapping is when an attacker convinces your carrier to move your number to a SIM they control, intercepting your SMS codes. I had a reader hit by this; the fix was calling the carrier directly and adding a SIM-lock PIN to the account, which blocks the transfer.

How long does it take to fully secure a hacked phone?

Most people finish a scan, password change, and account audit in under two hours. When I helped my friend it took about ninety minutes, and adding a factory reset would have added roughly another half hour.

Conclusion

A hacked phone is stressful but very recoverable — the real risk is waiting, because every hour a compromised device sits in your pocket adds to the damage. Work through the steps above the moment you spot two or more warning signs, then make two-factor authentication your permanent first line of defense. Start your scan today.