Wipe Your Device Before Selling: Step-by-Step for Phones and Laptops

Learn how to wipe your device before selling — sign out first, then reset. Step-by-step guide for iPhone, Android, and Windows with no data left behind.

If you sell or give away a phone or laptop without wiping it properly, the buyer inherits everything on it — saved passwords, banking apps, personal photos, and years of browsing history. The single most important step is signing out of every linked account before you reset, because skipping it triggers Activation Lock on iPhones or Factory Reset Protection on Android, leaving the next owner with a device they simply can’t use.

I know this from experience. I once sold an Android phone without removing my Google account, and the buyer called two days later — Factory Reset Protection had blocked them at setup and they couldn’t get past the credentials screen. Ten minutes of prep would have fixed it. Here’s exactly how to wipe your device before selling so that doesn’t happen to you.

Quick Answer

Sign out of Apple ID, Google, or Microsoft account first — then factory reset. On iPhone: Settings > General > Transfer or Reset > Erase All Content and Settings. On Android: Settings > System > Reset > Factory Data Reset. On Windows: Settings > System > Recovery > Reset PC > Remove Everything with Clean data enabled. Remove your SIM before handing over any phone.

What Do You Need to Do Before Resetting?

Three steps must happen before the reset. Skip any one of them and you’ll create a problem that’s harder to fix after the handoff.

Device Sign-Out Step Reset Path Time
iPhone / iPad Settings > [Your Name] > Sign Out Settings > General > Transfer or Reset > Erase All Content 5–15 min
Android Settings > Accounts > Google > Remove account Settings > System > Reset > Factory Data Reset 4–10 min
Windows PC Settings > Accounts > Your Info > Sign out Settings > System > Recovery > Reset PC 1–2 hours

Step 1: Back Up Your Data

Move everything you want to keep off the device before resetting. On iPhone: Settings > [Your Name] > iCloud > iCloud Backup > Back Up Now. On Android: Settings > System > Backup. On Windows, copy your Documents, Desktop, and Pictures folders to an external drive or cloud storage.

Step 2: Sign Out of Your Main Account

  • iPhone/iPad: Settings > [Your Name] > Sign Out — this also disables Find My iPhone automatically.
  • Android: Settings > Accounts > Google, tap your account, then Remove account.
  • Windows: Settings > Accounts > Your Info, then Sign out next to your Microsoft account.

Step 3: Remove Your SIM Card

Remove the SIM from any phone before handing it over — it stores your phone number and carrier info, and you’ll need it in your next device. Use the SIM eject pin or a straightened paperclip on the side tray.

Pro tip: After removing your Google account from Android, visit android.com/find and confirm the device no longer appears in your account. If it does, select it and click Sign out — this clears Factory Reset Protection before you reset.

These three steps — in this order — prevent every common post-sale activation problem buyers run into across all platforms.

How Do You Wipe an iPhone or iPad?

Once your Apple ID is signed out, the erase takes about 30 seconds to start and 5–15 minutes to complete.

  1. Go to Settings > General > Transfer or Reset iPhone.
  2. Tap Erase All Content and Settings.
  3. Enter your passcode, confirm the warnings, and tap Continue.
  4. The device erases itself and restarts to the “Hello” setup screen.

I’ve done this on every iPhone I’ve sold — the “Hello” screen confirms Activation Lock is off and the buyer can set up the device normally. If the phone prompts for an Apple ID password on restart instead, sign out of your account and run the erase again.

The “Hello” welcome screen before handoff is the only reliable sign that Activation Lock is cleared and the device is ready for a new owner.

How Do You Factory Reset an Android Phone?

The menu path varies by manufacturer, but the core steps are consistent across Samsung, Pixel, and most other Android devices.

  1. Go to Settings > General Management > Reset (Samsung) or Settings > System > Reset options (Pixel / stock Android).
  2. Tap Factory Data Reset, review the deletion list, then tap Reset.
  3. Enter your PIN or password and tap Delete All.
  4. The phone reboots to a language-selection welcome screen.

On my Pixel 7, the reset finished in about 4 minutes. Samsung devices typically take 7–10 minutes.

Troubleshooting tip: If setup asks for your previous Google account password, Factory Reset Protection is active. Sign back into the device, go to Settings > Accounts > Google, remove the account, then reset again.

A clean Android reset ends at the language-selection screen — a credentials prompt on startup means the Google account wasn’t removed before resetting.

How Do You Wipe a Windows PC Before Selling?

Windows 11 includes a built-in reset that reinstalls the OS without a USB drive. The option most people miss is “Clean data,” which overwrites storage so recovery software can’t read deleted files.

  1. Go to Settings > System > Recovery.
  2. Click Reset PC under Recovery options.
  3. Choose Remove everything — not “Keep my files.”
  4. Choose Cloud download for a clean Windows installation.
  5. Click Change settings and set Clean data to On.
  6. Click Reset. With both options enabled, expect 1–2 hours.

Cloud download plus Clean data gives the buyer a fresh install and prevents your files from being retrieved with recovery tools. For more on protecting data going forward, see my guide on encrypting your backups on any device.

Enabling “Clean data” is the difference between a deleted file and an unrecoverable one — always turn it on when resetting a Windows PC before selling.

What Are the Most Common Mistakes When Wiping a Device?

  1. Resetting an iPhone without signing out of Apple ID. Activation Lock stays on. The buyer can’t activate the phone, and removing the lock remotely at appleid.apple.com requires your password and sometimes proof of purchase.
  2. Choosing “Keep my files” on Windows Reset. Apps are removed, but your personal files stay fully readable on the drive. Always choose “Remove everything.”
  3. Skipping Google account removal on Android. Factory Reset Protection activates on the buyer’s first boot and the phone shows “This device is protected by Google.” Fix: remove your account via Settings > Accounts > Google before resetting.
  4. Forgetting MDM or work profiles. Corporate apps and VPN certificates installed via Mobile Device Management can survive a factory reset. On iPhone, check Settings > General > VPN & Device Management and remove any profiles before wiping.

Frequently Asked Questions

Does a factory reset permanently delete my photos?

Yes — all locally stored photos are removed when you reset. That’s why Step 1 (backing up to iCloud, Google Photos, or your computer) is essential. Once the reset runs, local copies can’t be recovered from the device itself.

Can someone recover my data after a factory reset?

On devices sold since 2016, hardware encryption makes recovery effectively impossible after a proper reset. On Windows, enabling “Clean data” adds a critical overwrite pass. For older Android phones (pre-2015), enable full-disk encryption in Settings before resetting — the reset then destroys the encryption key along with the data.

What if I forgot my Apple ID password before selling?

Reset it at iforgot.apple.com before wiping. Don’t hand over an iPhone with Activation Lock still on — the buyer can’t activate it, and you’ll still need to log in remotely to remove it anyway.

Should I factory reset even after deleting everything manually?

Yes. Manual deletion leaves login tokens and cached data on the device — only a factory reset removes those completely. For a broader security checklist, my guide on protecting your identity after a data breach covers what to do when personal data is already at risk.

Conclusion

Wiping your device before selling takes 20–30 minutes and protects years of personal data. Back up first, sign out of your main account, remove the SIM, then factory reset — and confirm the welcome screen before handing anything over. If you’re setting up a new device next, my guide on spotting fake apps before you install them will help you keep that fresh start secure.

Encrypt Your Backups on Any Device: iPhone, Windows, and External Drives

Learn how to encrypt your backups on iPhone, Windows, and external drives in minutes — keep your data unreadable even if a drive is lost or stolen.

Most people set up a backup and assume their data is safe. But I learned that an unencrypted backup is almost as risky as losing the device itself: anyone who gets the external drive or accesses an exposed archive can browse your files without a login or any special software. The backup you created to protect yourself can become the biggest vulnerability in your setup.

Encrypting your backups is a one-time, ten-minute setup on every major platform. Once it is done, a stolen drive gives a thief nothing but scrambled data they cannot use.

Quick Answer

To encrypt your backups: on iPhone, connect to a Mac or PC, open Finder or iTunes, and tick Encrypt local backup before clicking Back Up Now. On Windows, enable BitLocker on your backup drive. Android’s Google backup is encrypted by default. For external drives, use VeraCrypt (free) or your operating system’s built-in encryption tool.

Why Does Encrypting Your Backups Matter?

A backup is a complete copy of your device — contacts, photos, saved passwords, and banking app data. Without encryption, anyone who physically accesses that backup can open your files in minutes using standard software. No hacking, no special skills required.

Encryption converts your files into ciphertext that is only readable with the correct passphrase. I keep my Windows backup on an encrypted external drive, and when it once slipped out of my bag at a coffee shop, I knew the contents were unreadable to whoever picked it up.

Encrypting a backup adds almost zero overhead but turns a stolen drive from a catastrophe into a minor inconvenience.

How Do You Encrypt an iPhone Backup?

Apple’s local iPhone backup is not encrypted by default. You have to turn it on manually. Here’s how, on a Mac or Windows PC:

  1. Connect your iPhone with a USB cable. Open Finder on Mac or iTunes on Windows.
  2. Select your device. In Finder, click the iPhone in the left sidebar. In iTunes, click the device icon near the top left. Navigate to the General tab.
  3. Tick Encrypt local backup in the Backups section. You’ll be prompted to set a password. Save it in a password manager immediately — Apple has no way to recover it for you.
  4. Click Back Up Now. The encrypted backup now includes Health data, saved Wi-Fi passwords, and keychain credentials that Apple excludes from unencrypted copies.

Pro tip: After the backup finishes, go to iTunes > Preferences > Devices. A padlock icon next to the backup confirms encryption is active.

If you have not set up iPhone backups yet, my guide on backing up your iPhone to iCloud and your computer covers the two-layer strategy I use every week.

An encrypted iPhone backup also gives you a more complete backup — Apple withholds Health history and keychain data from unencrypted copies, so encryption is an upgrade in both security and completeness.

How Do You Encrypt Windows Backups?

The fastest way to protect a Windows backup drive is BitLocker, which encrypts the entire drive at the operating system level.

  1. Plug in your backup drive. Open File Explorer, right-click the drive, and select Turn on BitLocker. On Windows 11 Home, look for Device Encryption under Settings > Privacy & Security instead.
  2. Choose a password to unlock the drive, then save the recovery key to your Microsoft account or print it and store it somewhere other than the drive itself.
  3. Run your backup normally — via Settings > System > Storage > Backup or a tool like Macrium Reflect Free. Every file written to the drive is encrypted automatically from this point forward.

Troubleshooting tip: If BitLocker asks for the recovery key unexpectedly after a Windows Update, sign in to your Microsoft account and look under Devices > [your PC name] > BitLocker to find the saved key.

BitLocker encrypts at the drive level, so every backup you run — now and in the future — is protected without any extra steps after the initial setup.

Which Tool Should You Use for an External Drive?

If your Windows edition does not include BitLocker, or you back up to drives shared between Windows and Mac, VeraCrypt is the best free cross-platform alternative.

Tool Platforms Free Best For
BitLocker Windows Pro/Enterprise Yes (built-in) Windows whole-drive encryption
VeraCrypt Windows, Mac, Linux Yes Cross-platform or portable drives
macOS FileVault Mac Yes (built-in) Mac whole-drive + Time Machine backups
7-Zip (AES-256) Windows, Mac, Linux Yes One-off encrypted archive files

For ongoing backups, built-in tools are the simplest choice — encryption happens in the background with no extra steps. Use VeraCrypt when you need a portable encrypted container that opens on any operating system.

Start with the tool built into your OS; reach for VeraCrypt only when you need cross-platform access or your Windows edition lacks BitLocker.

Are Cloud Backups Already Encrypted?

Yes and no. Most major cloud services encrypt your data in transit and at rest — but the provider holds the encryption key. That means Google, Apple, or another service can technically read your files if compelled by law or in a security incident.

For sensitive documents like tax returns or medical records, use a zero-knowledge service such as Proton Drive or Backblaze Personal Backup (which lets you set a private key only you hold), or encrypt files locally with Cryptomator (free, open-source) before uploading them to Google Drive or iCloud.

Cloud encryption protects your data in transit; zero-knowledge encryption protects it from the provider itself — a meaningful distinction if you store financial or medical files.

What Mistakes Should You Avoid When Encrypting Backups?

  1. Forgetting the encryption password. Without it, you cannot restore the backup. Fix: save it in a password manager the moment you create it.
  2. Storing the recovery key on the encrypted drive. If you lose access to the drive, the key is gone too. Fix: save it to your Microsoft account or store a printed copy somewhere separate.
  3. Assuming cloud storage equals encrypted backup. Most providers hold the keys. Fix: use a zero-knowledge service or encrypt locally with Cryptomator before uploading.
  4. Never testing a restore. An encrypted backup you cannot successfully restore is useless. Fix: do a test restore to a spare folder every few months to confirm everything works.
  5. Using a weak passphrase. Encryption is only as strong as the password protecting it. Fix: use a random 16-character passphrase generated by a password manager.

Frequently Asked Questions

Does encrypting a backup slow down my computer?

Barely. Modern processors handle AES encryption in hardware. I back up a 300 GB drive with BitLocker enabled regularly, and the speed difference is negligible after the initial encryption pass completes. For example, my backup runs at roughly the same pace — around 120 MB/s — whether BitLocker is on or off.

Can I encrypt a backup I already made?

For iPhone, enabling the setting and running a new backup creates a fresh encrypted copy that replaces the old one. For Windows drives, BitLocker encrypts the whole drive in the background — you do not need to delete existing backup files first.

What happens if I forget my iPhone backup password?

Apple cannot reset it. You would need to factory-reset the device, set it up as new, and start a fresh encrypted backup. There is no recovery path without the original password — I save mine in my password manager the same day I create it.

Is VeraCrypt hard for a beginner?

It has more setup steps than BitLocker, but the documentation is thorough and the community forums are helpful. For most Windows users, BitLocker or Device Encryption is simpler and just as effective. Reach for VeraCrypt only if you genuinely need cross-platform access between Windows and Mac.

Conclusion

Encrypting your backups takes ten minutes and protects you permanently. Start with the two highest-risk items: your iPhone local backup and any external drive you carry outside the house. If either is ever stolen, you’ll be glad encryption was already on.

For the next step in locking down your digital life, read my guide on how to protect your identity after a data breach — it covers what to do when a service you use gets compromised.

Stay Safe on Public Wi-Fi: Your VPN Setup Guide for Any Device

Stay safe on public Wi-Fi with a VPN in under 5 minutes: pick an audited free option, enable the kill switch, and always connect before joining the network.

Every time I set up at a coffee shop or airport gate, I notice people nearby on the same open network with nothing protecting their traffic. Unencrypted public Wi-Fi lets anyone in range — using free software on any laptop — intercept login sessions, capture session cookies, and read unencrypted requests as they flow by. The single most effective way to stay safe on public Wi-Fi is to run a VPN, which encrypts your connection before it ever touches the router.

A VPN (Virtual Private Network) routes your traffic through an encrypted tunnel, turning readable data into scrambled noise for anyone snooping on the same network. Reliable options start at free, and setup takes under five minutes on any device you own.

Quick Answer

To stay safe on public Wi-Fi with a VPN: download Proton VPN (free, no data cap), enable the kill switch in Settings, then connect to the VPN before joining any public network. Keep it running the whole session. The kill switch blocks all traffic if the VPN drops, so you are never accidentally exposed.

Connect the VPN first, then join the network — that single sequence closes the most common exposure window.

Why Is Public Wi-Fi Risky?

Most café, hotel, and airport hotspots are unencrypted. Anyone on the same network can run a packet capture tool and record every byte flowing through. The two attacks I see most in security writing are packet sniffing — passively recording all traffic — and evil twin attacks, where a rogue access point mimics a legitimate-sounding name like “Airport-Free-WiFi” to lure nearby devices into connecting.

Even on HTTPS sites, your local network operator can see which domains you visit and when. A VPN encrypts that metadata too, not just the page contents.

Public Wi-Fi is dangerous not because attacks are constant, but because the effort cost for an attacker is near zero — one tool captures everything on the network at once.

Which VPN Should You Use for Public Wi-Fi?

The most important thing to verify is whether the provider’s no-logs policy has been independently audited by a third party. Marketing claims without an audit are meaningless. I always check the audit record before recommending any provider.

VPN Free Tier Data Cap Kill Switch Audited
Proton VPN Yes None Yes Yes (Securitum, 2022)
Windscribe Yes 10 GB/month Yes Partial
Tunnelbear Yes 500 MB/month Yes Yes
Mullvad No (€5/month) None Yes Yes

I use Proton VPN on public networks because the free tier has no data cap and a verified no-logs policy. For a paid option with strong privacy credentials, Mullvad’s flat monthly rate and clean audit history make it my second choice.

A free VPN with an audited no-logs policy beats a paid one with vague privacy terms — the audit matters more than the price tag.

How Do You Set Up a VPN on Your Phone or Laptop?

The steps below use Proton VPN as the example. Every major provider follows the same sequence: create an account, download the official app, enable the kill switch, and connect before joining the network.

Step 1: Create an Account

Go to protonvpn.com and sign up for the free plan. You only need an email address — no payment information required for the free tier.

Step 2: Download the Official App

Proton VPN has native apps for Windows, macOS, Android, and iOS. Download it from the official site or your device’s app store. Never install a VPN from an unofficial source or a sideloaded APK.

Step 3: Enable the Kill Switch

Open Settings in the app and turn on Kill Switch. This blocks all internet traffic if the VPN connection drops, so your real IP address and unencrypted traffic are never accidentally exposed mid-session.

Step 4: Connect Before Joining Public Wi-Fi

While still on mobile data, open the VPN app and tap Connect. Then join the café or hotel network. This closes the brief gap where your traffic is unprotected — a gap that opens when people activate the VPN only after they are already online.

Step 5: Verify You Are Protected

Open a browser and check whatismyipaddress.com. The location shown should match your VPN server, not your real city. If your actual location appears, disconnect and reconnect the VPN before continuing.

Pro tip: Enable auto-connect for unfamiliar networks in the app settings. On iOS go to Settings > VPN; on Android enable Always-on VPN under Settings > Network & Internet > VPN. You will never accidentally browse a public network without protection again.

Troubleshooting tip: If the hotel or café captive portal will not load, temporarily disable the VPN, complete the network login page, then immediately re-enable it. The portal needs your real IP to authenticate you first.

The full setup takes five minutes, and with auto-connect configured you will not need to think about it again.

What Else Can You Do to Stay Safer on Public Wi-Fi?

A VPN handles the biggest risk, but a few habits add meaningful depth to your protection.

  • Stick to HTTPS sites. Check for the padlock in your browser’s address bar before entering any data. For an extra layer, enable DNS over HTTPS in your browser to encrypt your DNS lookups as well.
  • Set your Windows network type to Public. Open Settings > Network & Internet > Wi-Fi > Properties and set the profile to Public. This disables file sharing and device discovery automatically.
  • Avoid sensitive logins on public Wi-Fi. Even over a VPN, I keep banking and medical accounts for home. The VPN protects transit — it cannot fix a session that was already compromised.
  • Log out when you are done. Session cookies remain a target even after you close a tab, so sign out explicitly on any shared or public machine.

Pair these habits with locking down your home router so the network you trust most is equally protected.

A VPN encrypts your transit; these habits close the gaps a VPN cannot seal on its own.

What VPN Mistakes Should You Avoid?

  • Grabbing a random free VPN from the app store. Most unreviewed free VPNs log and sell your browsing data — the opposite of what you want. Fix: use only providers with independently audited no-logs policies.
  • Turning on the VPN after connecting to public Wi-Fi. There is a brief unprotected window while the VPN negotiates its connection. Fix: always connect the VPN first, then join the public network.
  • Skipping the kill switch. If the VPN drops mid-session, your real IP and traffic are immediately visible. Fix: enable the kill switch in settings and leave it permanently on.
  • Trusting a network because the name sounds official. “Hotel_Secure” or “Airport-Official-WiFi” can be evil twin hotspots designed to capture credentials. Fix: ask staff for the exact network name and use your VPN regardless of what you find.

Configure the VPN correctly once — auto-connect and the kill switch handle the rest from there.

Frequently Asked Questions

Is a free VPN safe enough for public Wi-Fi?

Yes, if the provider has an independently audited no-logs policy. Proton VPN’s free tier is what I use when traveling — no data cap, no cost, and a verified privacy record. Most generic app-store freebies are the product being sold, not the user they protect.

Does a VPN slow down my connection?

In my experience, by about 10 to 20 percent. On a typical café connection that is barely noticeable for email and video calls — I have run Zoom calls on Proton VPN’s free tier without a single quality drop.

Can the coffee shop see what I am doing if I use a VPN?

No. Their router only sees encrypted packets flowing to your VPN server — it cannot read the contents or the destination URLs. The entire session looks like a stream of noise to anyone monitoring the local network.

Do I need a VPN if every site I visit uses HTTPS?

HTTPS protects the contents of each individual request, but your network operator can still see which domains you visit and how often. A VPN hides that metadata too — they protect different things and both matter on public Wi-Fi. Also pair your VPN habit with strong, unique passwords so any captured credential does minimal damage.

Conclusion

Staying safe on public Wi-Fi comes down to one decision: connect a VPN before you join the network. Proton VPN’s free tier removes every excuse — no data cap, no cost, independently audited. Enable the kill switch, turn on auto-connect, and you have closed the biggest vulnerability most travelers carry. For your next security step, learn how passkeys can replace your passwords entirely and cut another major attack surface.

Secure Home Wi-Fi Router Settings in 7 Steps

Secure home wi-fi router settings in 20 minutes: change your default admin password, enable WPA3, disable WPS, and isolate IoT devices on a guest network.

Most people plug in a router, connect a device, and never open the admin panel again. That leaves the default admin password unchanged, firmware unpatched, and encryption standards from 2003 still active. The single most effective step you can take to secure home wi-fi router settings is logging in right now and changing that default admin password — every other improvement builds on that first move.

I walked through this process recently on my own TP-Link router and found firmware 14 months out of date with three unpatched CVEs. Twenty minutes fixed all of it, and I’ll show you exactly what to do.

Quick Answer

To secure home wi-fi router settings: change the default admin password, update firmware, enable WPA3 or WPA2-AES encryption, rename your SSID, disable WPS, turn on the firewall with remote management off, and create a guest network for visitors and smart home devices. Takes about 20 minutes.

How Do I Access My Router’s Admin Panel?

Before changing any setting, you need to reach the admin interface. On Windows, open Command Prompt and type ipconfig. Look for Default Gateway under your Wi-Fi adapter — usually 192.168.1.1 or 192.168.0.1. On a Mac, go to System Settings → Network → Wi-Fi → Details and check the Router field. Type that IP address into your browser’s address bar.

Most routers use “admin” as both the username and password by default, or the credentials are printed on a label on the device itself. If neither works, a web search for your router model plus “default login” will find them.

Bookmark the admin panel URL once you’re in — you’ll return to it during these steps.

What Router Settings Matter Most for Security?

Work through these seven changes in order. Each one takes two to five minutes.

1. Change the Default Admin Password

Go to Administration → Password (exact label varies by brand). Replace the default with a strong, unique password and store it somewhere secure. I cover how to build passwords that are both strong and memorable in this guide: Create Strong Passwords You Can Actually Remember.

Pro tip: Use three random words joined by a symbol — “grape$ladder!orbit” is longer than “P@ssw0rd1” and orders of magnitude harder to crack.

2. Update Firmware

Firmware updates patch known security holes. Find Administration → Firmware Update (or equivalent on your brand) and check for available updates. Enable automatic firmware updates if your router supports it — most routers added this option after 2020.

3. Enable WPA3 or WPA2-AES Encryption

Under Wireless Settings → Security Mode, select WPA3-Personal if available. If not listed, choose WPA2-Personal with AES. Avoid anything labeled WEP, WPA (version 1), or TKIP — those are crackable with free tools that run on a laptop. See the comparison table in the next section.

4. Rename Your Network (SSID)

Change your Wi-Fi name away from the factory default. A default SSID broadcasts your router brand, giving an attacker a ready shortlist of default credentials and known vulnerabilities. Any generic name works — you don’t need to hide the network completely.

5. Disable WPS

Wi-Fi Protected Setup was built for easy device pairing, but its PIN method has a documented brute-force vulnerability exploitable in under four hours on unpatched routers. Disable it under Wireless Settings → WPS. Connecting devices by typing a password works equally well and carries none of the risk.

6. Enable the Firewall and Disable Remote Management

Under Security or Advanced settings, confirm the SPI firewall is enabled. Then find Remote Management (also called Remote Access) and turn it off. Remote management lets anyone on the internet attempt to log in to your admin panel — there’s no reason to leave that exposure open for a home network.

Troubleshooting tip: If a smart device stops responding after enabling the firewall, it may need UPnP. Enable UPnP for that device category only, not globally, if your router allows per-rule control.

7. Create a Guest Network for Visitors and IoT Devices

Enable a guest network under Wireless → Guest Network with its own separate password. Then move all smart home devices — cameras, thermostats, smart bulbs, locks — onto it. IoT firmware is notoriously slow to update, so isolating these devices means a compromised smart bulb can’t reach your laptops and phones on the main network.

Moving eight smart home devices off my main network and onto the guest network took five minutes and is the single change I’d recommend to any friend setting up a new router.

Which Wi-Fi Security Protocol Is Safest?

Here’s what you’ll find in the encryption dropdown and what to do with each option:

Protocol Year Status Action
WEP 1997 Broken — crackable in minutes Disable
WPA (TKIP) 2003 Deprecated Disable
WPA2-AES 2004 Still solid Use if WPA3 unavailable
WPA3-Personal 2018 Current gold standard Enable this
WPA2/WPA3 Mixed 2020 Good transitional mode Use when older devices need WPA2

WPA3 uses SAE (Simultaneous Authentication of Equals), meaning captured Wi-Fi handshakes cannot be cracked offline — a real improvement over WPA2. The Wi-Fi Alliance publishes the full certification specs if you want to verify your router’s protocol support.

If WPA3 doesn’t appear in your dropdown, check for a firmware update first — many routers added WPA3 support in a post-release patch rather than at launch.

What Common Mistakes Leave Home Networks Wide Open?

  • Skipping the admin password change. Default credentials for every major router brand are publicly listed. This is the most exploited router weakness — change it before anything else.
  • Choosing WPA2-TKIP instead of AES. Routers still offer TKIP as a fallback. Select AES explicitly every time you configure encryption.
  • Leaving remote management on. Unless you actively manage the router from outside the home, disable it. The attack surface isn’t worth it.
  • Putting IoT devices on the main network. A compromised camera or thermostat gets full LAN access to your computers. The guest network fix takes two minutes.
  • Ignoring firmware for years. Set a calendar reminder every 90 days to check for updates, or enable auto-update today and skip the reminder entirely.

Frequently Asked Questions

Does changing my Wi-Fi password help if the admin password is still the default?
Only partly. Someone already on your network can reach the admin panel using default credentials and change anything they want. Change both passwords. I’ve seen setups with a 20-character Wi-Fi password but “admin/admin” still active as the router login — the Wi-Fi password gives false confidence.

Will enabling WPA3 break my older devices?
Some devices made before 2019 don’t support WPA3. Set the router to WPA2/WPA3 Mixed Mode — newer devices negotiate WPA3 automatically while older ones fall back to WPA2 without any extra setup.

How do I know if my router has been compromised?
Log into the admin panel and check the DHCP client list under LAN or Status. Any device you don’t recognize is a red flag. Also look at the DNS server addresses in your WAN settings — attackers sometimes replace these with their own servers to intercept traffic. If you suspect a breach, the steps in How to Protect Your Identity Online After a Data Breach are a solid starting point.

My ISP provided the router — do these settings still apply?
Yes. Log in using the credentials on the router’s label. If the ISP has locked the admin panel, call support and ask them to apply the security settings — most will do it. An ISP-provided router with all defaults intact is just as exposed as one you bought yourself and never configured.

Ready to Lock Down Your Router?

Seven settings, one admin panel, about 20 minutes. Start right now: type 192.168.1.1 into your browser, log in, and change that default admin password. Work through the list from there and your home network will be better protected than most households. Once your router is locked down, learning about passkeys is the next smart step for protecting your online accounts.

What Is a Passkey? How the New Login Standard Replaces Passwords

What is a passkey and why does it beat passwords? Learn how passkeys stop phishing cold, set one up in 90 seconds, and avoid the top setup mistakes.

Every few months I get an email from a site I joined years ago telling me my password turned up in a breach. It is exhausting — and it is the same problem billions of people face daily. Passwords can be guessed, phished, or leaked, and most people reuse the same few across dozens of accounts. The single most powerful shift you can make right now is switching to passkeys, a login standard that works without any shareable secret.

Passkeys have been rolling out across Google, Apple, Microsoft, and hundreds of major sites since 2022. If you have used Face ID to sign into an app recently, you may have already used one without realising it. This guide explains exactly what is a passkey, how the technology works, and how to create your first one in about 90 seconds today.

Quick Answer

A passkey is a login credential stored on your device — phone, laptop, or tablet — that uses your biometrics or PIN to prove it is really you. There is no password to type, steal, or forget. The site never receives a secret; it only confirms your device approved the login.

Passkeys work by combining a device-held private key with biometric approval, so there is nothing for a phisher or data-breach to steal.

What Is a Passkey, Exactly?

A passkey is a pair of cryptographic keys. One half — the private key — lives on your device and never leaves it. The other half — the public key — is stored on the website’s server. When you log in, your device uses your fingerprint or face scan to unlock the private key, signs a unique challenge from the server, and sends the signature back. The server verifies the math against the public key. If it matches, you are in.

Nothing sensitive crosses the internet. The site cannot leak your passkey because it was never sent to them in the first place.

How Is a Passkey Different From a Password?

With a password you invent a secret and hand a copy to the website. If that site is breached, your secret can leak — and if you reused it, attackers try it everywhere else. With a passkey the private key stays on your device. Even a complete server breach gives attackers nothing usable.

Where Are Passkeys Stored?

Device Storage location Syncs to
iPhone / iPad iCloud Keychain All your Apple devices
Android Google Password Manager All signed-in Android devices
Windows PC Windows Hello Local only (or via 1Password)
Hardware key (YubiKey) The key itself Not synced — physical device only

Your private key and biometrics never leave the device’s secure chip — local storage is the feature, not a limitation.

How Does a Passkey Keep You Safe?

Passkeys neutralise the three biggest password attack types at once.

Phishing: A passkey is cryptographically tied to the real site’s domain. A fake login page triggers a failed handshake automatically — there is nothing for the attacker to capture.

Credential stuffing: Attackers buy leaked password databases and replay them across thousands of sites. There is no passkey equivalent of a leaked password list.

Weak passwords: A passkey is a 256-bit key generated by your device. There is no equivalent of “Summer2025!” or any other guessable string.

Pro Tip

Enable a passkey on an account the moment the option appears, even if you keep the old password as a fallback. You get the security benefit immediately and can delete the password later once you are comfortable with the new flow.

Passkeys eliminate phishing, credential stuffing, and weak-password risks in a single step — the three vectors behind the majority of account takeovers.

Which Websites and Apps Accept Passkeys?

As of mid-2026, major services with passkey support include Google, Apple ID, Microsoft, GitHub, PayPal, eBay, Shopify, Uber, and WhatsApp, among hundreds more. The FIDO Alliance maintains an official passkey directory you can search by service name. If a service you use is not listed, check Settings → Security — many sites quietly add passkey support with routine app updates.

Troubleshooting Tip

If the passkey option is missing in your account settings, sign out and sign back in, then look under Settings → Security → Sign-in methods. Some services show passkey enrollment only after a recent authentication step.

Passkey adoption is accelerating fast — if a service does not support it today, check again in a few months and it likely will.

How Do I Set Up and Use a Passkey?

The setup flow is nearly identical on every service. Here is Google as an example — it takes about 90 seconds.

  1. Go to myaccount.google.com and sign in normally.
  2. Click Security in the left sidebar.
  3. Under “How you sign in to Google,” click Passkeys and security keys.
  4. Click Create a passkey.
  5. Approve the prompt with your fingerprint, Face ID, or device PIN.
  6. Done — the passkey syncs to your other signed-in Apple or Android devices automatically.

Next time you sign in to Google, enter your email, choose Try another way, then Use your passkey. Your device prompts for biometrics and you are in within two seconds. I noticed the first login felt strange because I kept waiting for a password field that never came.

On Windows

Windows uses Windows Hello — your PIN, fingerprint reader, or face recognition. The passkey creation steps are the same; just approve with your Hello method when prompted. I set mine up on a laptop in under a minute.

Passkey creation on any major platform takes under two minutes and walks you through every step with on-screen prompts.

Are Passkeys Safe if You Lose Your Device?

Yes — with one caveat. If your passkeys sync to iCloud Keychain or Google Password Manager, losing your phone does not mean losing access. Sign into your Apple or Google account on any new device and your passkeys are waiting there already.

If you stored a passkey only locally on a Windows PC, that credential is tied to that machine. Best practice: enrol a second passkey on a backup device or a hardware security key for critical accounts. Pair this with a strong, unique master password for your Apple or Google account — the guide on creating strong passwords you can actually remember covers a reliable method for exactly that.

Synced passkeys survive a lost or reset device; device-local passkeys need a recovery backup before you rely on them as your only login method.

What Mistakes Should You Avoid With Passkeys?

  1. Skipping account recovery setup before creating a passkey. If your Apple or Google account is compromised, an attacker could delete your passkeys. Lock down recovery options first. A quick data breach check confirms whether your master credentials have already leaked.
  2. Treating a passkey as a replacement for two-factor authentication. A passkey replaces your password — it is one strong factor. For banking or primary email, add an authenticator app on top for extra protection.
  3. Creating a passkey on only one device. Enrol on at least two devices so you have a working fallback if one is lost, stolen, or factory-reset.
  4. Assuming cross-platform sync is automatic. Apple passkeys sync across Apple devices; Google passkeys sync across Android. If you switch ecosystems, re-enrol passkeys on the new platform — they do not transfer automatically.
  5. Abandoning your password manager during the transition. You will not migrate every account overnight. Keep existing passwords in a dedicated manager like Bitwarden while you work through your list — our password manager setup guide walks through the free installation.

The most common slip-up is skipping account recovery setup — fix that first and the rest of the passkey transition is straightforward.

Frequently Asked Questions

Can a passkey be phished?

No. A passkey is cryptographically bound to the legitimate site’s domain, so a fake login page gets nothing usable — the handshake fails silently. I tested this on a cloned login page and the passkey prompt never even appeared.

What happens if I lose my phone and my passkeys are not synced?

You regain access through the account’s standard recovery options such as backup codes or a recovery email, then enrol a fresh passkey on your replacement device. This is exactly why configuring recovery options before creating passkeys is step one.

Are passkeys free?

Yes. Passkeys are built into iOS 16+, Android 9+, and Windows 10/11 with Windows Hello — no extra app or paid subscription required on any major platform.

Can I keep a password and a passkey on the same account?

Yes, and that is the recommended transition approach. Keep the existing password as a fallback while you get comfortable with the passkey flow, then remove it later on services that support fully passwordless login.

The four questions above cover the concerns most people have before switching — passkeys are simpler in practice than they sound in theory.

Conclusion

Passkeys make signing in faster and dramatically more secure — no phishing risk, no credential leaks, nothing to memorise or type. Start with one high-value account like Google or Apple ID, confirm the experience feels natural, then roll out to other accounts over a few weeks.

While you transition, a free password manager keeps your remaining accounts under control. The Bitwarden setup guide takes about ten minutes and bridges the gap perfectly until every account supports passkeys.

Create Strong Passwords You Can Actually Remember

Create strong memorable passwords using the passphrase method, sentence abbreviation trick, and a free password manager — so you stop reusing passwords for good.

Most people know they should use strong, unique passwords — yet reusing the same password across multiple accounts remains the norm. I did it for years. The cycle is predictable: you create a genuinely random password, forget it within a week, reset it to something you can recall, then use that familiar string on every new site you join.

The problem isn’t laziness. Standard password advice treats memorability and security as opposites, and that framing makes the advice unworkable. The real danger isn’t a weak password — it’s any password you’ve reused across more than one account. Attackers don’t crack passwords one by one; they take credentials from one leaked database and test them automatically across every major site. Here’s how I broke the cycle for good.

Quick Answer

Build a passphrase from four random, unrelated words — for example, “cobalt fence eleven grape.” At 26 characters, it’s far stronger than an 8-character random string and takes about five repetitions to memorize. For every other account, use a free password manager like Bitwarden to generate unique passwords you’ll never need to type or remember.

Why Is Standard Password Advice So Hard to Follow?

Rules like “include uppercase letters, numbers, and symbols” were designed for security systems, not human memory. When you’re forced to memorize “Xk$9!mQz,” your brain shortcuts to “Password1!” — and then you reuse that everywhere. That predictable shortcut is exactly what credential-stuffing attacks rely on: grab a password from one breach and test it on every other site automatically.

The real measure of password strength is length combined with unpredictability. A 26-character passphrase made of four random unrelated words is mathematically stronger than an 8-character “complex” password. It also takes far less mental effort to memorize, because your brain stores sequences of real words as images rather than random character strings.

Complexity requirements backfire by driving reuse — length and randomness are what actually protect your accounts.

How Do I Create a Strong, Memorable Password?

Method 1: The Passphrase

This is the method I use for my password manager’s master password — anything I need to type from memory on a regular basis.

  1. Pick four words that share no logical connection. Avoid personal details: your pet’s name, hometown, birth year, or anything tied to your public identity.
  2. String them together, optionally adding a number or symbol to satisfy site requirements: “cobalt-fence-eleven-grape7”
  3. Picture each word as a frame in a short comic strip. If you can see all four images in sequence, you’ll recall them after about five repetitions.

A passphrase like “cobalt fence eleven grape” sits at 26 characters. Brute-force cracking it would take longer than the age of the universe. I had my current master passphrase memorized within the first day — the visual association trick genuinely shortens the learning curve.

Pro tip: Use the EFF’s free Diceware wordlist at eff.org/dice to pick your words at true random. Words you choose yourself cluster around common phrases far more than you’d expect.

Method 2: The Sentence Abbreviation Trick

Take a sentence only you’d know and use the first letter of each word. “My first dog Bella was born October 3rd, 2010” becomes “MfdBwbO3,2010” — 13 characters with mixed case, a number, and punctuation already built in naturally.

To make it unique per site, add the site’s first two letters at the end: “MfdBwbO3,2010gm” for Gmail, “MfdBwbO3,2010am” for Amazon. I used this approach for several years before switching to a manager, and you can still recreate any password anywhere just by remembering your original sentence.

Method 3: One Passphrase, a Manager for Everything Else

This is what I recommend to everyone today. Use Method 1 to create one strong master passphrase, then let a free manager like Bitwarden generate unique 20-character random passwords for every other account. You memorize exactly one thing; the manager handles the rest. I made this switch two years ago and haven’t reused a password since.

Troubleshooting tip: If you’re ever locked out of your password manager, recovery depends on setup. In Bitwarden, go to Settings > Emergency Access before you need it — designate a trusted contact as a backup so you’re never permanently locked out of your vault.

If you ever switch browsers later, moving your saved passwords between browsers takes about five minutes and doesn’t require retyping anything by hand.

One strong passphrase unlocks a vault of unique credentials — the only setup that makes password reuse impossible without taxing your memory.

How Strong Is “Strong Enough”?

Length is the dominant variable. The table below shows how crack resistance scales with password type, assuming dedicated hardware and known attack patterns such as dictionary mutations and brute force.

Password Type Example Length Estimated Crack Resistance
Common word sunshine 8 chars Under 1 second
Symbol substitution $uNsh!N3 8 chars Under 1 minute
Random alphanumeric Xk9mQzRpL2 10 chars Days to weeks
4-word passphrase cobalt fence eleven grape 26 chars Billions of years
Manager-generated random qY7#kRzPm2@Lv9nXw 17 chars Effectively impossible

The bigger real-world threat isn’t brute force anyway — it’s database breaches. Even a strong password causes damage if you’ve reused it. Pair strong passwords with the two-factor authentication steps in these iPhone privacy settings or these Android privacy settings for a complete security upgrade.

Length and uniqueness together are what actually protect accounts — short complexity without length gives you a false sense of security.

What Common Mistakes Should You Avoid?

  1. Reusing any password across sites. One breach hands attackers access to every account that shares it. Fix: use a manager so every site gets its own unique string, automatically.
  2. Using personal information. Your dog’s name, birth year, or hometown appear in data broker records and are easily guessable. Fix: choose words or phrases with no connection to your life.
  3. Appending “1!” to a familiar base word. Attackers run this mutation pattern first in any brute-force sequence. Fix: use a passphrase or a manager-generated string instead.
  4. Storing passwords in a plain notes app. An unlocked phone or laptop exposes everything at once. Fix: use a dedicated password manager that requires its own authentication to open.
  5. Believing short complexity beats long simplicity. “P@$$w0rd” cracks in seconds on modern hardware. Fix: start with length — 16 or more characters makes any password exponentially harder to attack, even without symbols.

Every one of these mistakes trades a few seconds of convenience for a systemic vulnerability — fix the method once and you stop making the same trade-off on every new account.

Frequently Asked Questions

Should I change my passwords on a regular schedule?

Only when you have a specific reason — a breach notification, a shared account you’re revoking, or suspicious login activity. Forced rotation drives predictable increments like “Password1,” “Password2.” I check haveibeenpwned.com a few times a year instead, which gives me a real signal rather than an arbitrary 90-day reminder.

What is the best free password manager available right now?

Bitwarden is open-source, independently audited, and free for personal use across every device and browser. The built-in managers in Chrome and Safari are also solid if your device stays with you. I use Bitwarden because it follows me across operating systems and browsers without locking me into one ecosystem.

Is a passphrase really stronger than a short complex password?

Yes — length is the dominant factor in brute-force resistance. “Cobalt fence eleven grape” at 26 characters beats “Xk$9!mQz” at 8 characters by an enormous computational margin. The passphrase also defeats dictionary attacks because the specific combination of four random unrelated words is effectively unique in any attack database.

What should I do if my password shows up in a data breach?

Change it on the affected site immediately, then check whether you’ve reused that password anywhere else and change those too. A breach is only catastrophic if the password wasn’t unique to that site. Going forward, a password manager keeps each account isolated — a future breach stays contained to one login.

Do I really need a different password for every account?

Yes, every account. With a password manager, this is effortless — it generates and fills unique passwords automatically so you never type them. If you prefer the sentence abbreviation method, a site-specific suffix makes each login distinct. I manage over 200 unique passwords now and only remember one: my master passphrase.

Every FAQ about passwords points to the same answer: use a passphrase, use a manager, and never reuse — the three habits that cover nearly every attack vector most people face.

Conclusion

Creating strong passwords you can actually remember comes down to one shift in approach: use a four-word passphrase for anything you type from memory, and a free password manager for everything else. Start today by setting up Bitwarden and updating your five most important accounts — email, banking, and social media first. That one hour of setup protects you from the credential-stuffing attacks that catch most people off guard long after a breach they never heard about.

Cast Your Android Screen to Any TV: 4 Methods Step by Step

Cast your Android screen to any TV in under two minutes — Chromecast, Smart View, Miracast, and HDMI methods explained step by step with troubleshooting tips.

Watching a video or showing photos on your phone works fine one-on-one, but the moment you want to cast your Android screen to a TV for a group, squinting at a 6-inch display gets old fast. The detail most guides skip is that you probably already own the hardware you need — the right method depends on your setup, not on buying anything new. I’ve used all four methods below in real situations, from a hotel room with a Miracast adapter to my living room Chromecast to a USB-C cable in a pinch.

Whether you have a Chromecast, a smart TV, or just an Android phone and an HDMI port, there’s a method that works. Setup takes under two minutes once you know which option matches your hardware.

Quick Answer

To cast your Android screen to a TV, swipe down twice to open Quick Settings and tap Cast or Screen Cast. Select your Chromecast, Google TV, or compatible smart TV from the list. If the Cast tile is missing, open the Google Home app and tap Cast my screen. Your display mirrors to the TV within seconds.

What Methods Can You Use to Cast an Android Screen to a TV?

Android supports four casting approaches, each suited to different hardware. Here’s a quick overview before diving into steps.

Method What You Need Wi-Fi Required Typical Cost
Chromecast / Google TV Chromecast device or Google TV dongle Yes Free (device already owned)
Smart TV built-in Samsung, LG, Roku, or Android TV Yes Free
Miracast adapter Wireless display adapter No $20–$40
USB-C HDMI cable USB-C to HDMI cable + video-out port No $10–$15

Matching the method to hardware you already own keeps the cost at zero in most cases.

How Do I Cast to a Chromecast or Google TV?

This is the method I use most often. As long as your phone and Chromecast are on the same Wi-Fi network, setup takes about 90 seconds and works with any app on your phone — not just streaming services.

Step 1: Open Quick Settings

Swipe down from the top of your screen twice to reveal the full Quick Settings panel. Look for a Cast or Screen Cast tile. On some phones it sits in the second row and requires swiping left to find it.

Step 2: Tap Cast

Tap the tile. Your phone scans for nearby devices automatically. If the tile is missing, open the Google Home app, tap your Chromecast device, then select Cast my screen. Unsure what access Google Home actually needs? This guide to Android app permissions breaks down every permission category clearly.

Step 3: Select Your Device

Tap your Chromecast or Google TV name from the list. The TV flashes blue briefly, then mirrors your Android display. Everything on your phone — apps, photos, video — appears on the TV within 3–5 seconds. Google’s official Cast from Android guide covers additional troubleshooting by device model if your Chromecast generation isn’t listed here.

Pro tip: Keep your phone screen on while casting — if it locks, casting pauses on most Android versions. Extend the timeout under Settings > Display > Screen timeout before starting any session longer than a few minutes.

Chromecast casting is the most reliable wireless method because the TV fetches the stream from your router rather than directly from your phone.

How Do I Cast to a Samsung or Other Smart TV?

Many smart TVs support wireless screen mirroring natively — no Chromecast required. Samsung calls the feature Smart View, LG uses Screen Share, and Roku TVs have Screen Mirroring built in.

Step 1: Enable Screen Mirroring on the TV

On a Samsung TV, press Home, then go to Settings > General > External Device Manager > Device Connection Manager and enable Screen Mirroring. On 2022+ Samsung models, look under Settings > Connection > Screen Mirroring. On LG and Roku TVs, the option is usually under Input > Screen Share.

Step 2: Cast From Your Android Phone

Swipe down to open Quick Settings and tap Smart View (Samsung phones) or Cast (all other Android phones). Your TV should appear in the device list within 5–10 seconds.

Step 3: Accept the Connection

The TV shows a prompt asking you to allow the connection. Select Allow with your remote. Your phone mirrors to the TV in about 3 seconds, with audio routing through the TV speakers by default.

Troubleshooting tip: If your TV doesn’t appear in the Cast list, confirm both devices are on the same Wi-Fi band — 2.4 GHz or 5 GHz. I’ve had Samsung TVs on 5 GHz completely miss Android phones sitting on 2.4 GHz. Switching both to 5 GHz fixed discovery in under a minute.

Smart TV mirroring is the easiest zero-cost option — no extra hardware, no Google account, and no app download required.

How Does a Miracast Adapter Work for Casting?

A Miracast adapter — such as the Microsoft Wireless Display Adapter — plugs into your TV’s HDMI port and creates a direct wireless link with your Android phone. No router is required, which makes it useful in hotels, conference rooms, and offices where you can’t join the local Wi-Fi network.

Step 1: Set Up the Adapter

Insert the adapter into an HDMI port on the TV and connect its USB power cable. Switch the TV to that HDMI input using your remote.

Step 2: Connect From Android

Open Quick Settings, tap Cast, then look for an Enable wireless display toggle at the top of the Cast screen. Turn it on. Your adapter appears in the device list within 10 seconds — tap it to connect. On some phones this toggle is hidden in the three-dot overflow menu inside the Cast panel.

Miracast builds a peer-to-peer connection with no internet involved — the go-to option when you can’t join the venue’s Wi-Fi or would rather not.

When Should I Use an HDMI Cable Instead?

If your Android phone has a USB-C port that supports DisplayPort Alternate Mode (video output), a USB-C to HDMI cable delivers wired casting with essentially zero lag. I reach for this when gaming or watching anything where even 100ms of wireless latency would be distracting. Connect the cable to your phone and any TV HDMI port, switch the TV input, and your phone mirrors immediately — no app, no Wi-Fi, no pairing step needed. Not every USB-C port supports video output, so verify in your phone’s spec sheet before buying the cable.

Wired casting is the most stable option for low-latency needs and works even when your home network is down.

What Mistakes Should I Avoid When Casting?

Using different Wi-Fi networks. Your phone and Chromecast or smart TV must be on the same network. Guest Wi-Fi is isolated by design — devices on the guest side can’t see devices on the main network. Fix: connect both to the main Wi-Fi.

Leaving a VPN active. A VPN often routes traffic through a different subnet, making your TV invisible to the Cast feature. Disconnect the VPN, cast, then reconnect. Your Android privacy settings can help you decide when the VPN is actually necessary versus habit.

Ignoring screen timeout. Most Android phones sleep after 30–60 seconds. Casting pauses the moment the screen locks. Set a longer timeout or keep the phone plugged in during any session longer than a few minutes.

Selecting the wrong TV input. A black screen after tapping Cast almost always means the TV is set to the wrong HDMI input. Cycle through inputs with your remote until the mirrored display appears.

Running an outdated Google Home app. An old version can silently fail to discover Chromecast devices. Open the Play Store, search Google Home, and tap Update if the button is available.

Most casting failures trace back to a network mismatch or a locked screen — check those two things before anything else.

Frequently Asked Questions

Does casting drain my phone battery?

Yes — casting keeps the screen on and the processor active the entire time. I always plug my phone in for sessions longer than 20 minutes; I once ran from 40% battery to completely dead during a 45-minute photo slideshow before I started doing this consistently.

Can I cast Netflix or Disney+ to the TV this way?

Yes, but use the Cast icon inside the app itself rather than the Quick Settings Cast tile. DRM (digital rights management) often blocks system-level screen mirroring on Android. I hit a black screen my first time trying to screen-mirror a Prime Video film — switching to the in-app Cast button fixed it immediately.

Why is the TV showing a black screen when I cast?

DRM-protected content blocks screen mirroring at the OS level on most Android phones. Switch to the streaming app’s own Cast button instead of the system Cast feature. This applies to Netflix, Disney+, Prime Video, and Max — they all have a Cast icon built into the player controls.

Do I need a Google account to cast from Android?

For Chromecast and Google TV, yes — a Google account is required to complete initial device setup through the Google Home app. For Samsung Smart View or a Miracast adapter, no account is needed at all; I’ve mirrored to a hotel TV’s Miracast adapter in under 30 seconds without signing into anything.

What if the Cast tile isn’t in my Quick Settings panel?

Long-press any existing tile and tap the pencil icon to enter edit mode. Drag the Cast or Screen Cast tile from the hidden tiles section up into the active row. On a Pixel I configured recently, the tile was buried three rows deep in the hidden section and easy to miss.

The DRM black screen issue is the most common first-time surprise — the fix is always the in-app Cast button, not a settings change.

Conclusion

Casting your Android screen to a TV takes under two minutes once you match the right method to your hardware. Start with the Quick Settings Cast tile — it handles Chromecast and most smart TVs with a single tap. Use a Miracast adapter when there’s no shared Wi-Fi, and reach for a USB-C HDMI cable when zero-lag output matters. Open Quick Settings and tap Cast right now — your Android screen can fill the big screen in seconds.

Android Split Screen: Multitask With Two Apps Open at Once

Learn how to use android split screen to multitask with two apps at once — step-by-step setup, tips for every Android brand, and fixes for common problems.

Switching back and forth between two apps is one of those small frustrations that adds up fast — you’re referencing notes while writing an email, or watching a tutorial while trying to follow steps yourself. The fix is already built into your Android phone: android split screen multitask mode lets you run two apps side by side without constant toggling.

I use split screen almost every workday — typically with Chrome on top and my notes app below. Once I got the activation gesture down, it became second nature within a day. Here’s exactly how to set it up.

Quick Answer

To use android split screen, open recent apps (swipe up and hold, or tap the square button). Long-press the app icon at the top of any recent card and tap “Split screen.” Pick a second app from recents or your home screen. Both apps run simultaneously, separated by a draggable divider you can slide up or down.

What Is Android Split Screen Mode?

Android split screen divides your display into two independent app windows, each taking roughly half the screen. The feature has been built into Android since version 7.0 (Nougat), so any phone from around 2016 onward supports it — though the exact activation method varies by brand. If you’ve just switched phones, our step-by-step guide to transferring data to a new Android phone is a good starting point before exploring features like split screen.

Brand / OS How to Open Recent Apps Split Screen Trigger
Google Pixel (Android 12+) Swipe up + hold Long-press app icon → Split screen
Samsung One UI 4+ Swipe up + hold Long-press icon → Open in split screen view
3-button navigation (any brand) Tap the square button Long-press app icon → Split screen
Android Go edition Not supported

The wording differs by brand, but the core method is always the same: get into recent apps, long-press the app icon, and choose “Split screen.”

How Do You Enable Split Screen on Android?

These steps work on most Android phones running Android 9 or later with gesture navigation.

Step 1: Open Your Recent Apps

Swipe up from the bottom edge and hold for about one second. On a 3-button navigation phone, tap the square Overview button instead. Your recent apps appear as a scrollable stack of cards.

Step 2: Pin Your First App

Scroll to the app you want on top. Tap the small circular icon at the very top of its card — not the card body itself. A short menu appears. Tap “Split screen.” That app locks to the top half of the screen.

Step 3: Open Your Second App

The bottom half of the screen now shows your recent apps or your home screen. Tap the second app you want there. Both apps are now live simultaneously.

Pro tip: If the app you need isn’t in your recent apps, tap the Home icon that appears inside the split-screen picker, find the app on your home screen, and tap it — it drops straight into the lower pane without any extra steps.

The most common mistake is tapping the card body rather than the small circular icon at its very top — the card body triggers “Remove” or “App info,” not “Split screen.”

How Do You Adjust and Exit Split Screen?

Resizing the Panes

Drag the thick divider bar up or down to give one app more screen space. On a standard 6-inch phone, I usually pull the divider slightly below center so the bottom pane has more room for reading or typing.

Exiting Split Screen

Drag the divider bar all the way to the top or bottom edge of the screen. The app on the “swallowed” side closes and the surviving app expands to fill the full display. On Samsung devices, tapping the center of the divider bar also reveals a “Close Split Screen View” button.

Troubleshooting tip: If “Split screen” is grayed out or missing from the menu entirely, that app has disabled multi-window support — Netflix, most streaming apps, and many games block it by policy. Open the content in a browser tab instead, or switch to a compatible app. Chrome, Gmail, Google Maps, and most productivity apps all work fine in split screen.

Exiting split screen takes one gesture — drag the divider to either edge — and the remaining app fills the screen immediately.

What Mistakes Do People Make With Android Split Screen?

  1. Tapping the card instead of the icon. You must tap the small circular app icon at the very top of the recent-apps card. Tapping anywhere else on the card opens “Remove” or “App info” — neither leads to split screen.
  2. Expecting every app to cooperate. Netflix, full-screen YouTube, and most mobile games block split screen by design. Use a browser tab pointing to the same content as a workaround, or accept that some apps simply won’t support it.
  3. Trying it on Android Go. Android Go — the lightweight version of Android for budget devices — removes split screen entirely. Go to Settings > About phone to confirm whether you’re running Android Go.
  4. Overlooking Samsung’s pop-up window option. On Samsung One UI, “Pop-up view” floats an app in a resizable overlay above your split-screen pair, giving you three apps visible at once. It’s a hidden productivity gain worth knowing about on Samsung devices.

Most split screen frustrations trace back to two root causes: tapping the wrong part of the card, or trying to use an app that has disabled multi-window support.

Frequently Asked Questions

Does Android split screen work on tablets?

Yes, and tablets handle it better than phones because of the larger display. On Android 12L and later, tablets include a persistent taskbar at the bottom, letting you drag app icons directly into a split view. The activation steps are the same as on phones.

Will split screen drain my battery faster?

Running two active apps increases power draw. In my testing, I noticed roughly 15–20% faster battery drain during extended split screen sessions compared to single-app use. Close split screen when you don’t need both panes visible to preserve battery life.

Can I save a split screen pair as a shortcut?

On Samsung One UI 5.1 and later, tap the divider icon and choose “Add to Home screen” to create a shortcut that reopens the exact same app pair in one tap. Stock Android doesn’t offer this natively, though some third-party launchers add the feature.

What is the difference between split screen and picture-in-picture on Android?

Split screen gives each app a full interactive half of the display. Picture-in-picture (PiP) overlays a small floating video window on top of a full-screen app — you can’t fully interact with the PiP content beyond basic playback controls. Use PiP for background video; use split screen when you need both apps fully active.

Split screen and picture-in-picture solve different problems — the right choice depends on whether you need to interact with both apps or just monitor one passively in the background.

Conclusion

Android split screen multitasking is one of those built-in features that genuinely changes how you use your phone once it becomes a habit. Start with a simple pair — Chrome on top, your notes app below — and you’ll quickly discover other combinations that save real time every day.

To get even more from your Android device, see how Android Digital Wellbeing can help you manage screen time, or review the Android privacy settings worth changing today. For the full technical background, Google’s official multi-window documentation covers every supported device and API detail.