Encrypting Your Devices
How long this takes: about 10 minutes.
I already have a password for my computer. Do I need this?
Yes, if you use a PC. A password alone doesn't stop someone who gets physical access to your hard drive, there are ways around it. Full disk encryption closes that gap.
If you have a Mac, turn on FileVault, a built-in feature. Go to the Apple menu, System Settings, Privacy & Security, and turn on FileVault.
What is full disk encryption? It sounds complicated.
It's simpler than it sounds. It encrypts everything on your computer, so if it's lost or stolen, whoever has it can't get at your files.
I have a PC. What do I do?
If you have Windows Pro or Enterprise, turn on BitLocker, it's already built into Windows (Settings, Privacy & Security, Device Encryption). If you're on Windows Home, or want an open source option, use VeraCrypt instead.
What about my phone?
Both iPhones and Android phones encrypt your data automatically, but only if you have a passcode set. No passcode means no encryption, so this is the single most important phone setting you have.
- Use a real passcode (6 digits minimum), not a pattern or a 4-digit PIN.
- Turn on auto-erase after 10 failed attempts if your phone supports it (Settings, Face ID/Touch ID & Passcode on iPhone; Settings, Security on most Android phones).
- Biometrics (Face ID, fingerprint) are convenient, but a passcode can't be forced out of you by holding your phone up to your face. Know that distinction if you're ever in a situation where someone might physically compel you to unlock it.
Protecting Yourself with an Anti-Virus
Viruses can be dangerous for LGBTQ+ organizations. Think of this as your digital immune system.
What is phishing?
Emails or messages designed to trick you into handing over private information. It's more convincing than it used to be, some phishing messages are now written or even voiced by AI, so bad grammar isn't a reliable warning sign anymore. Treat any unexpected request for login info, payment, or personal details with suspicion, no matter how polished it looks.
What is ransomware, and what's the risk?
Ransomware is a virus that locks your files and demands payment to unlock them. It's a serious threat, especially if you're not out, since attackers sometimes threaten to leak what they've locked.
How do I get free antivirus software?
Malwarebytes, for Windows, Mac, and Android. If you're on Linux, ClamAV is a solid free option.
Multi factor authentication is one of the most effective protections against phishing, see Two-Factor Authentication below. Keep your operating system and browser updated, security patches matter.
5 common ways people get a virus, and how to avoid it
- Infected email attachments. Only open attachments from senders you know and trust.
- Be cautious with PDFs, they're a common target.
- Don't click links in emails or messages unless you're sure they're legitimate.
- Check URLs carefully, phishing often uses lookalike domains (like fac3book.com, or a capital I swapped for a lowercase l).
- Use VirusTotal to scan a file before opening it if you're unsure.
- Be careful with removable drives, scan them when you plug them in.
- Only download apps from official app stores.
- Keep your software up to date.
I think I've been hit by ransomware. What do I do?
- Disconnect the device from the internet and any shared drives right away, this can stop it from spreading.
- Don't pay the ransom. There's no guarantee you'll get your files back, and paying funds the people doing this to more people.
- Report it, to your IT contact if you have one, and to a local cybercrime authority if that's safe to do in your country.
- If you have backups, wipe the device and restore from one made before the infection.
- If you don't have backups, this is exactly why it's worth setting them up now, before you need them.
Stalkerware and Phone Monitoring
Stalkerware is monitoring software installed on your phone, often by a partner, ex, or family member, that can read your messages, track your location, and see your photos without your knowledge. It's a documented tool used against LGBTQ+ people, sometimes by someone you live with or are close to.
If you think this applies to you, read this before you do anything else. Deleting a monitoring app the moment you find it can alert the person watching that they've been discovered, which can make your situation more dangerous, not less. If you're not sure it's safe to act right away, talk to a domestic violence hotline or a tech safety organization first, they can help you plan next steps safely. The Safety Net Project is a good place to start.
Signs worth knowing
- Your battery drains unusually fast, or the phone feels warm when you're not using it.
- Someone seems to know details about your messages, location, or calls that they shouldn't.
- Unfamiliar apps, or apps disguised with generic names or icons.
- Your phone's data usage is higher than expected.
None of these confirm stalkerware on their own, but they're worth paying attention to together.
Strong Passwords and Password Managers
Use a password manager
The single best thing you can do for your passwords is stop remembering them yourself. We recommend Bitwarden, it's free, open source, and well regarded by security researchers. 1Password is a solid paid alternative.
We used to recommend LastPass here. We don't anymore. LastPass had a serious data breach that exposed customer vaults, so we've moved that recommendation to Bitwarden.
If you don't use a password manager
Use a long passphrase instead of a single transformed word, four or five random words strung together is both harder to crack and easier to remember than something like P@ssw0rd1.
Sign up for Mozilla Monitor to get notified if a password on a site you use turns up in a breach.
Here's what NOT to do
- Don't reuse passwords across sites.
- Don't use anything guessable, your name, birthdate, hometown.
- Never share your password with anyone else.
- If you must write passwords down, keep them somewhere encrypted, not a plain document on your desktop.
- Be cautious with biometrics (fingerprint, face) on devices or services from companies you don't know or trust.
Two-Factor Authentication
What is Two-Factor Authentication (2FA)?
2FA means logging in takes more than just your password, you also need to prove it's you a second way.
The most common method sends a code by text message. It's better than nothing, but SMS 2FA has a real weakness: SIM swapping. Someone can trick or bribe your phone carrier into moving your number to their SIM card, and then they receive your codes without ever touching your phone.
Where you can, use an authenticator app instead, it generates codes on your device and doesn't depend on your phone number at all. Options include Google Authenticator, Authy, or Aegis (open source, Android).
Save your backup codes
When you set up 2FA on any account, it gives you a set of one-time backup codes. Save them somewhere safe, a password manager works well, not a screenshot on your camera roll. If you ever lose your phone, these are the only way back into your account without going through a slow account recovery process.
What services offer this?
Most major platforms do. Worth prioritizing:
- Email: Gmail, Outlook, Yahoo
- Social media: Instagram, Facebook, X (formerly
Privacy Overview
Quick Exit
Press the ESC button twice times to quickly leave our site. or click the top right button that says EXIT