I change my mind


January 2026

Counter-Intuitive Tips

*sponsored by Yubico​


Uncommon Cybersecurity Advice

What if strong privacy and security is based more on how simple it is (and therefore how likely you are to keep using it) than how effective it might be? If you know somebody who finds cybersecurity a bit overwhelming, you'll want to share this with them:

​Don't use an Authenticator App (+ other uncommon tips)​

Go Deeper: Lately I've been spending a lot of time trying to figure out systems and tools that build security and privacy without too much extra inconvenience or burden on us as users. Here are two things you can do mentioned in this week's video:


Looking at a book called Logo Modernism

Freeze Credit

It's easy to set up and it's the most effective way to stop identity theft.

​Watch the Tutorial →​

A type specimen of Google Fonts

Verify Contacts

A unique way to verify that you're communicating with the right person.

​Apple Contact Verification →​


Are Authenticator Apps Bad?


Hi [CORRECTED_NAME GOES HERE], so I admit, there is an element of clickbait here. No, authenticator apps aren't bad and they're definitely a better way to secure your online accounts than with an SMS text code.

But I hate using authenticator apps.

Please tell me that I'm not the only one who has taken 20-30 seconds to pull out my phone, open the authenticator app, try to type out the 6-digit code but not finish before the timer resets and I have to backspace and try again.

Yea...that's annoying.

It's taken me a long time to fully understand this, but I'm realizing that security and privacy is hard enough to implement without making it harder on ourselves than it needs to be. What are ways in which we can make it so easy we barely think about it?

Here are some ideas I'm proposing:

  • Camera Permission: Instead of worrying about all the camera permissions on your devices...why not cover all the cameras on your phone, laptop & desktop as a first line of defense?
  • Scam Prevention: Instead of trying to train my mom and dad how to spot a scam email and keep them up-to-date on the latest AI impersonation threats, why not create a private verification phrase?
  • 2FA authenticator apps: Instead of pulling out an authenticator app on your phone, why not keep a 2FA security key plugged in to your computer and ready to tap?

These are just a few of the seven ideas I have to make security and privacy a no-brainer. Be sure to watch the whole video here (it's only 7 minutes long).


Better 2FA

I keep a YubiKey on my keychain and one plugged into my laptop computer (both secured with a PIN code). Securely logging into my accounts only takes 3 seconds and doesn't require me to think...I just tap. Get $5 off a YubiKey here:


This Week in Privacy News

​WhatsApp Introduces "High Security Mode"​

Similar to Apple's "Lockdown Mode", Meta's WhatsApp messaging service is offering users an advanced security mode, letting users opt into stronger protections against hackers in exchange for a more restrictive experience.

--> Reuters.com/business/media-telecom/whatsapp-unveils-high-security-mode-latest-tech-firm-offer-users-stronger-2026-01-27/

​Microsoft hands over encryption keys to FBI​

The tech giant Microsoft said it receives around 20 requests for BitLocker keys a year and will provide them to governments in response to valid court orders. But why, when companies like Apple and Meta set up their systems so such a privacy violation isn’t possible?

--> Forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/
​

​2025 was a record year for data breaches​

A new report by the Identity Theft Resource Center reported 3,322 data breaches last year, which is a record high and a sharp rise over previous years. It doesn't seem like this is slowing down for 2026 either.

--> IDTheftcenter.org/wp-content/uploads/2026/01/2025-ITRC-Annual-Data-Breach-Report.pdf


Your Thoughts?

Do you still use a separate authenticator app? I'm curious to hear if it's just to save some extra money or if you actually prefer that over alternatives like a 2FA key.

Have a great weekend!

✌️

Josh


3824 Cedar Springs Rd #801-8170, Dallas, TX 75219
​Unsubscribe Β· Preferences​

Upgrade your Online Privacy & Security

Join thousands of individuals and small businesses who understand the value of protecting their important accounts and online privacy. πŸ“· Popular YouTube host πŸ”‘ Simple security πŸ”’Privacy advocate βœ… Get the free "Security Priorities Checklist" here πŸ‘‡ πŸ‘‡

Read more from Upgrade your Online Privacy & Security
Stop using Signal?

April 2026 Secure Messaging *sponsored by DeleteMe "Signal Only" is Bad Advice The prevailing privacy wisdom says that you need to migrate ALL of your communication over to Signal, Threema or some other app. But what if this is bad advice? What if you adopted a strategy to blend in and use apps and/or devices as a way to compartmentalize your communication? Here's what I mean: SECURE Messaging isn't what you think Go Deeper: There are some people who say that Signal isn't secure anymore and...

Credit Card alternatives

March 2026 Secure Payments 3 Levels of Payment Security Have you ever considered how stupid it is that a "security code" is literally printed on the back of your physical credit card? It's no wonder there's so much financial fraud, which we pay for via credit card fees, by the way. There are better, more secure payment methods, but most people either don't know about them or think they're too complicated. Here's an easy breakdown: 3 Levels of Payment Security (credit card alternatives) Go...

Online trackers

February 2026 Stop Online Tracking 3-Layer Approach Anyone Can Use This week I'm sharing something by my friend Henry from Techlore who published a great video about online trackers and the three layers of protection you can use (from easiest to hardest): 3 Layers to Stop Online Tracking (Techlore) Go Deeper: As with anything having to do with your online presence, there are quite a few angles you can take to add greater protection. It could be your browser (like Brave) or even how you give...