Protect your privacy online
Do these three things first ๐
Set up a password manager ๐
One vault, one master password, and a different password for every account.
Turn on two-factor authentication ๐ฒ
Start with your email. It is the master key to every other account you own.
Freeze your credit files ๐ง
Free by law, at all three bureaus. Blocks anyone from opening accounts in your name.
Privacy is a basic human right. The United States still has no comprehensive federal privacy law, and while roughly two dozen states have now passed their own, the protections vary by state. Which means most of the work of protecting your privacy online falls to you.
You will hear people say “but I have nothing to hide.” That misses the point. Protecting your privacy is not only about you. It is about the people in your contacts, your photos and your message history, whose information is exposed when yours is.
Here is what that looks like in practice. Someone reuses one password across their email, their social accounts and their bank. A shopping site they signed up for years ago gets breached. The password from that breach opens their email. From the email, an attacker resets everything else. Within a day the bank account is drained and everyone in their contacts is getting messages that look like they came from a friend.
So, to avoid this nightmare scenario, here is a list of things you can do to protect your privacy online.
1. Use a password manager
Using a password manager goes the longest way in protecting your privacy online. Every account needs its own password, and no human can remember eighty of them. A password manager solves that.
It generates a long random password for each account, stores them in an encrypted vault, and fills them in for you. Meanwhile, you need to only remember one master password.
1Password is the polished paid option. Bitwarden is free and open source and does the same job. If you use Apple devices, the built-in password manager already offers to generate and save passwords when you sign up for something new, and unlocks with Face ID or a fingerprint.
What if the password manager gets breached? It is a fair worry, and it has happened to at least one major provider. The answer is that your vault is encrypted with your master password, which the company does not have. A breach of their servers does not hand anyone your passwords, but it does mean you should change your master password and rotate the credentials for your most sensitive accounts. That is still a far better position than reusing one password everywhere.
Where to start: install one, then move your email, bank and primary social account into it first. Do the rest whenever you happen to log in somewhere.
2. Turn on two-factor authentication
Your password is a lock. Two-factor authentication adds a second check that a stolen password alone cannot pass.
There are a few kinds, and they are not equally good:
| Method | How it works | Verdict |
|---|---|---|
| Authenticator app | A code on your phone that changes every 30 seconds | Start here |
| Passkey | Replaces the password entirely, unlocked by your face or fingerprint | Take it when offered |
| Push notification | A prompt on your phone that you approve or deny | Good, low friction |
| Text message | A code by SMS, which can be intercepted through SIM swapping | Last resort |
Start with email, banking and work accounts. Your email is the master key to everything else, so if you do only one, do that one.
3. Freeze your credit files
Freezing your credit means no one can open a new account in your name, including you, until you unfreeze it. It is the most effective protection against identity theft, and it is free by law.
Do it at all three bureaus. Freezing one does nothing if a lender checks another:
โ ๏ธ Heads up
Credit bureaus sell a product called a credit lock that sounds identical to a freeze and costs money. You want the freeze. It is free by law. Decline the monitoring add-ons they offer during signup.
When you apply for a loan or a credit card, log in and lift the freeze temporarily, then let it reset. A freeze has no effect on your credit score or your existing accounts.
Worth doing as well: freeze your ChexSystems file, which banks use to approve new checking accounts. Start at IdentityTheft.gov.
4. Learn to spot phishing
Most accounts are not broken into. They are handed over. Phishing is how.
The tells are consistent:
- The sender address is close but wrong. Not the display name, which is trivial to fake. The actual address.
- There is a deadline. “Your account will be suspended today.” Urgency exists to stop you from checking.
- The link does not go where it says. Hover over it on desktop, or press and hold on mobile, and read the real destination.
- Something arrived that you did not expect. An invoice, a delivery notice, a password reset you did not request.
If you clicked but entered nothing: you are probably fine. Close the page and delete anything it downloaded without opening it.
If you entered your password: move quickly. Change that password, then change it anywhere else you used the same one. Turn on two-factor authentication for the account. Review recent activity for logins or changes you did not make. If financial details were involved, call your bank directly using the number on your card, not a number from the email.
๐ก Pro tip
Never act on a link in a message. Open the site yourself and log in the way you normally would. That one habit defeats almost every phishing attempt, no matter how convincing the email looks.
5. Switch your browser and search engine
Chrome and Edge are built by advertising and data companies. Their default behavior reflects that. Firefox blocks cross-site tracking out of the box. Brave blocks trackers and ads by default. Tor Browser routes your traffic through multiple relays to hide your IP address, at a noticeable cost to speed.
Search engines are the same story. Google, Bing and Yahoo log your searches and build a profile from them. The alternatives:
- DuckDuckGo does not tie searches to a profile.
- Brave Search runs on its own index rather than reselling someone else’s.
- Startpage returns Google results without passing along who asked.
This is the easiest change on the list. It takes about ninety seconds and you will barely notice the difference.
6. Block third-party cookies
Third-party cookies are set by companies other than the site you are visiting, and they follow you between sites to build a profile of where you go and what you look at.
If you have been waiting for browsers to fix this for you, stop waiting. Google spent six years promising to remove third-party cookies from Chrome, reversed that decision in April 2025, and in October 2025 announced it was retiring most of the Privacy Sandbox technologies built to replace them. Third-party cookies remain on by default in Chrome with no removal date.
Safari, Firefox and Brave block them already. So:
- On Chrome, go to Settings, then Privacy and security, and block third-party cookies manually.
- On any browser, install uBlock Origin, which blocks trackers rather than just cookies.
- Cookie consent banners help at the margins. Click “reject all” when it is offered. Do not rely on it.
7. Audit your browser extensions
Extensions can read what you do in your browser. Many ask for exactly that permission during install, and people grant it without reading.
There is a second problem. The specific combination of extensions you have installed can be detectable, and an unusual combination makes your browser easier to fingerprint and follow across sites. Not every extension is detectable and the risk is often overstated, but the general principle holds: fewer is better.
Open your extensions list. Remove anything you have not deliberately used in the last month. Extensions also change hands, and a useful tool bought by a new owner can quietly turn into a data collector.
8. Rethink your email provider
There is a persistent claim that Google reads your Gmail to target ads at you. That has not been true since 2017, when Google announced it would stop scanning consumer Gmail content for ad personalization. Ads in Gmail are now based on your broader Google account activity rather than the text of your messages.
The accurate concern is different, and it has not gone away. Gmail is still processed automatically: for spam and malware filtering, for features like package tracking and calendar suggestions, and now for AI features. Your mail is not private from the company that stores it. It is simply not being mined for ad keywords specifically.
Whether that bothers you is a judgment call. If it does, Proton Mail offers end-to-end encryption and does not scan message contents.
Switching without losing anything:
- Create the new account.
- Change your email address on the accounts that matter most first: bank, utilities, government, primary social.
- Leave the old inbox running and forwarding for six months. As things arrive, update them one at a time.
- Let the junk stay behind at the old address.
Email aliasing services are also worth knowing about. They give you a disposable address for each site you sign up for, so a breach at one company cannot be linked to your real address or to your other accounts.
9. Use an encrypted messaging app
Most messaging apps now encrypt message contents. That is the easy half of the problem.
The harder half is metadata: who you talk to, when, how often, and for how long. Content is the letter. Metadata is the envelope, and the envelope reveals more than people expect. WhatsApp encrypts your messages, and its parent company still collects the metadata around them.
Signal is the exception. By its own account, the only data it holds is the phone number you registered with, the date you registered, and the date you last used the service. That is it.
If who you talk to is as sensitive as what you say, use Signal.
10. Put your smart home devices on their own network
Cameras, doorbells, thermostats, speakers, TVs. They sit on your network permanently, they are rarely updated, and each one is a way in. A compromised smart bulb is not interesting by itself. A compromised smart bulb on the same network as your work laptop is.
The fix is to separate them. Put smart home devices on a guest network so they cannot see the rest of your devices.
If you use a Race Wi-Fi router, this is a few taps in the Race CommandIQ app. Open My Network, tap the plus sign, and select Add Network. Choose Guest, name it, set a password, and turn on device isolation so the devices on it cannot reach each other or anything on your main network. You can also set a start and end time, which is useful for actual guests rather than devices.
While you are in the app, check that ProtectIQ is on. Go to My Network, then the Services tab, then ProtectIQ. It scans traffic at the router, blocks known malicious sites and intrusion attempts, and notifies you after the fact. Blocking happens automatically, so there is nothing to respond to. It is available to every subscriber using a Race Wi-Fi router.
Two habits worth building alongside it: change the default password on every device that has one, and turn off features you do not use. A camera’s remote access is an entry point if you never open the app anyway.
11. Treat public Wi-Fi as untrusted, not radioactive
Public Wi-Fi used to be genuinely dangerous, because a lot of web traffic moved in plain text and anyone on the network could read it. That is mostly no longer true. Nearly all sites now use HTTPS, which encrypts the connection between your browser and the site. Someone watching the coffee shop network sees that you connected to your bank. They do not see your password.
Modern browsers will tell you when a site is not encrypted. Chrome and Safari flag it as “Not Secure” in the address bar. Firefox shows a crossed-out padlock. If you see that warning, do not enter anything.
The risks that remain are real but different:
- A network that is not what it claims to be. It is trivial to name a hotspot something inviting and wait. Once you connect, whoever runs it controls your DNS and can redirect you to convincing fake login pages. Ask the venue for the actual network name.
- Apps, not browsers. Not every app enforces encryption as strictly as your browser does.
- The network operator sees where you go. Not the contents, but the destinations.
A VPN addresses that last category by encrypting everything and routing it through a server of your choosing. That is worth having if you work from cafes and airports regularly. Be aware that a VPN moves your trust rather than removing it: your provider now sees what the network used to. Pick one that has published an audited no-logs policy.
12. Encrypt what you put in cloud storage
Files in Google Drive and iCloud are encrypted in transit and at rest, but the provider holds the keys. That means they can access the contents, and they can be compelled to hand them over.
If that matters for a particular file, you have two options.
Use end-to-end encrypted storage, where files are encrypted on your device before they are uploaded and the provider cannot read them. Proton Drive and Filen both work this way. Nextcloud gives you the most control if you are comfortable hosting it yourself, which also means you own every security decision.
Or encrypt inside the storage you already use. Cryptomator creates an encrypted folder inside Dropbox or Drive, so you keep the service you like and the provider cannot read what is in that folder.
If you use iCloud, turn on Advanced Data Protection in your Apple account settings. It enables end-to-end encryption for most iCloud categories and it is off by default.
Where to actually start
You do not need to do all twelve. You need to do the first three, and then keep going when you have the energy.
Install a password manager and move your email into it. Turn on two-factor authentication for that account. Freeze your credit at all three bureaus.
Change your browser and search engine, block third-party cookies, and clear out extensions you no longer use. About an hour of work that removes a lot of routine tracking.
Work down the rest in whatever order fits your life. Every step here is permanent once it is done. None of them need doing twice.
Your internet provider should be on your side
Race is 100% fiber internet, built and supported in California. We do not sell customer information. Every Race Wi-Fi router includes the CommandIQ app, so you can see what is connected to your network and control it.
Check availability at your addressFrequently asked questions
What is the most important thing I can do to protect my privacy online?
Use a different password for every account, stored in a password manager, and turn on two-factor authentication for your email. Your email resets every other password you own, so it is the account worth protecting first. Password reuse is behind most account takeovers, and a password manager removes the need to remember anything.
Are password managers actually safe?
Yes, and safer than the alternative. Your vault is encrypted with a master password the company never receives, so a breach of their servers does not hand anyone your passwords. Breaches have happened, and the response is to change your master password and rotate your most sensitive logins. That is still a far better position than using one password everywhere.
Can my internet provider see what I do online?
Not the contents. Almost every site now uses HTTPS, which encrypts the connection between your browser and the site, so your provider cannot read the pages you load or what you type into them. It can see which sites you connect to, through DNS lookups and the addresses your traffic travels to. Race does not sell, share or distribute customer information, and you can read our privacy policy in full.
Does incognito mode protect my privacy?
Only from other people using your device. Incognito stops your browser from saving history, cookies and form entries locally. It does not hide your activity from the sites you visit, your employer, your school or your internet provider, and it does not stop you being tracked once you log in to an account.
Does a VPN make me anonymous?
No. A VPN encrypts your traffic and hides it from whoever runs the network you are on, which is genuinely useful on Wi-Fi you do not control. It moves your trust to the VPN company rather than removing the need to trust anyone. It also does nothing about cookies, browser fingerprinting, or anything you do while logged in to an account. Choose one with a published, independently audited no-logs policy.
Is public Wi-Fi still dangerous?
Less than it used to be. HTTPS is now close to universal, so someone watching the network sees which sites you connect to and not what you send them. The real risk is a network that is not what it claims to be, which can redirect you to convincing fake login pages. Ask the venue for the actual network name before you connect.
