How to Stay Safe Online in the United States

How to Stay Safe Online in the United States

Checked September 25, 2026. This is practical setup help, not legal advice. If a menu on your phone does not match a step below, the agency or manufacturer page wins.

Staying safer online in the United States is mostly a short list of habits, not a new gadget. Use a unique password, turn on two-factor sign-in, install updates, and lock the home Wi-Fi. Those steps protect a parent, a grandparent, and a child better than a long list of threats.

This guide is for households, not for a company security team. It sticks to advice from the Federal Trade Commission, the Cybersecurity and Infrastructure Security Agency (CISA), and IdentityTheft.gov. It does not rank browsers, sell a VPN, or treat a bill in Congress as a law.

Do these six things first

  • Turn on automatic updates for the phone, computer, browser, and apps.
  • Give email, banking, and social accounts a unique password of at least 16 characters, stored in a password manager.
  • Turn on two-factor sign-in. Prefer an authenticator app or a security key when the account offers one.
  • Set the home router to WPA3 Personal, or WPA2 Personal if WPA3 is not there. Change both the Wi-Fi password and the router admin password.
  • On social accounts, hide the phone number, email, and full birth date from the public profile.
  • If a company says your information was in a breach, start at IdentityTheft.gov/databreach. Do not pay a stranger who calls about it.

What this means for you

You do not control every company that already has your name. You do control the accounts they can walk into, the network in the house, and how much a stranger can see on a public profile. Do the six steps above before you worry about ad tracking. Tracking is real. A reused email password is the problem that empties an account this week.

Protect the accounts that matter

Start with email, then the bank, then any account that can reset the others. If someone gets the email password, they can reset almost everything else.

Passwords

CISA says a strong password is long, random, and unique: at least 16 characters, not a birthday or a pet’s name, and different for every account. A passphrase of unrelated words works. “Horse Purple Hat Run Bay” is the kind of example CISA gives. A line from a song does not.

The FTC, on its consumer page, says to aim for at least 15 characters if you make the password yourself, and to avoid common phrases. The two agencies are close. Follow the longer number. Use a password manager, or the password generator built into the phone or browser, so you do not have to remember each one. The password for the manager itself has to be strong. Write that one down and keep it somewhere that is not a note on the unlocked phone.

Two-factor sign-in

Two-factor sign-in means the site asks for a second proof after the password. A stolen password is not enough. The FTC says the most common second step is a code by text or email. It also says an authenticator app or a security key is more secure, and to choose one of those when you have the option.

Text codes are still worth turning on if they are the only choice. Do not read a code to someone who called you. Hang up. Contact the company with a number or website you look up yourself. The FTC’s rule for unexpected messages is the same idea: do not use the link they sent. Go to the company on your own.

Security questions

The FTC says to skip questions a stranger can guess or look up, such as a first car, a ZIP code, a birthplace, or a mother’s maiden name. If the site forces one of those questions, answer with a random phrase you store in the password manager, not the true fact.

Update the devices, then the router

The FTC says criminals look for weak points before a company can patch them. Turn on automatic updates for the security software, browser, operating system, and phone apps. An adult child can turn those on during a visit. That is a better gift than a new app.

The router is the front door for the phones, the laptop, and the smart TV. The FTC’s home Wi-Fi guide says to set encryption to WPA3 Personal, or WPA2 Personal if that is the best the router offers. WPA and WEP are outdated. If those are the only choices, update the router software. If WPA2 or WPA3 still do not appear, the FTC says to consider a new router.

Change two passwords, not one. The Wi-Fi password is what devices use to join. The admin password is what opens the router settings. If someone gets the admin password, they can undo the rest. Do not use your name, address, or the router brand in either password. Turn off remote management, Wi-Fi Protected Setup (WPS), and Universal Plug and Play (UPnP) if you see them. The FTC says those features are convenient and can make the network less secure.

A guest network, with its own name and password, is the right place for visitors and for devices you do not fully trust. Register the router with the manufacturer, or ask the internet provider, so it actually receives updates. The exact clicks depend on the brand. Use the manufacturer’s instructions rather than a screenshot from an undated post.

What companies can see, and what you can turn down

Sites and apps remember logins, measure which pages you open, and use that to show ads. That is ordinary. It is not the same as someone reading your mail. You can still shrink it.

  • When a site asks you to “accept all” cookies, look for a reject or settings link. You do not have to take every optional cookie to read the page.
  • On the phone, review location, camera, microphone, and contacts for apps you rarely use. Turn off the ones that are not needed for the app to work.
  • In a Google, Apple, or store account, open the privacy or ad settings and turn off personalization you do not want. The menu names move. Use the company’s own help page if the label changed.
  • A padlock or “https” means the connection is encrypted. The FTC has warned that scammers also encrypt fake sites. The lock does not prove the site is the real bank. Type the address yourself, or use a bookmark.

A VPN can hide your address from the cafe network. It does not stop a site you are logged into from knowing who you are, and it does not make a fake login page safe. Passwords, updates, and two-factor sign-in come first. This site does not recommend a VPN brand.

Kids and older adults

For a child under 13, the Children’s Online Privacy Protection Act gives a parent a say before a covered site or app collects personal information. The FTC says that information includes a name, address, phone, email, location, photos, video, audio, and identifiers that can track a child across sites. You can review what was collected, take consent back, and ask for deletion. Report a site that ignores those rules at ReportFraud.ftc.gov.

COPPA is not a teen privacy law, and it is not a substitute for the phone setup. A child needs their own account, not a parent’s login. App stores should ask a parent before a new download. Those switches live in Apple’s Family Sharing and Screen Time, or in Google’s Family Link on Android. Family Link does not supervise an iPhone.

For an older adult, the useful help is in person. Turn on updates and two-factor sign-in together. Put the password manager on their phone. Agree that no caller, including someone who sounds like the bank or a grandchild in trouble, gets a code or a gift-card payment. The FTC says scammers pretend to be a company or the government. Hang up and call back on a number you find yourself.

What U.S. law does, and does not, do for you

There is no single federal page that lists the same privacy buttons for every adult in every state. The FTC enforces rules against unfair or deceptive practices, and it enforces the children’s privacy rule. Some states add rights to see, delete, or opt out of the sale or sharing of personal information. Those rights depend on where you live and on whether the company is covered. A privacy bill in Congress, including one introduced in April 2026, is not a right you can use until it becomes law.

If a site has a “Your Privacy Choices” link, that is the place to start. If the link is missing and you live in a state with a privacy law, your state attorney general’s site is the next stop. Do not pay a service that promises to “delete you from the internet.” Some data brokers have opt-out forms. A paid scan is not the same as a legal right.

If your information was in a breach

IdentityTheft.gov is the federal recovery site. If you do not know whether someone has already used the information, it still tells you to check, freeze, and watch your credit.

  1. Get your free credit reports at AnnualCreditReport.com. You can check them online every week for free. If you see an account you do not recognize, contact that company, then report it at IdentityTheft.gov.
  2. Place a credit freeze. It is free. While it is on, a new credit account should not be opened. You can lift it when you apply for credit yourself.
  3. If you do not want a freeze, you can place a free one-year fraud alert by contacting one of the three credit bureaus. A business then has to verify your identity before it opens an account.
  4. Take free credit monitoring if the company that lost the data offers it.
  5. If a password was exposed, change it, and change any other account that used the same password. Turn on two-factor sign-in.
  6. If a bank or card number was exposed, contact the bank. Ask them to close the card and send a new one. Check for charges you do not recognize.

Ignore a text or call that says you must pay to “clear” the breach. Go to IdentityTheft.gov, or to the company’s site by typing the address, not by tapping the message.

What to skip

  • Do not buy a tool because an ad said you were being watched. Updates, unique passwords, and two-factor sign-in do more.
  • Do not reuse one password across email, the bank, and social accounts.
  • Do not post a full birth date, phone number, or home address on a public profile. Those answers unlock other accounts.
  • Do not follow a router or browser guide that cannot name the official page it came from. Menus move.
  • Do not treat this page as legal advice, or a privacy bill as a law.

Questions people ask

Is there one U.S. law that covers all of my online privacy?

No single federal consumer page covers every adult in every state. The FTC handles deceptive practices and children’s privacy under 13. State rights to access, delete, or opt out vary. Check the company’s privacy choices link, then your state attorney general if you need the local rule.

Is a text-message code good enough?

It is better than a password alone. The FTC says an authenticator app or a security key is more secure when the account offers one. Never read a code to a caller.

Should I get a VPN?

Not as the first step. A VPN can hide your address on a public network. It does not replace a unique password, two-factor sign-in, or updates, and it does not make a fake website safe.

How often should I check my credit after a breach?

IdentityTheft.gov says you can check your reports online every week for free at AnnualCreditReport.com. A freeze is free and stops new credit accounts while it is on.

What should I set up for a child or a parent?

For a child, use their own account and the phone maker’s parent tools, and read the FTC’s children’s privacy page before you approve an app that asks for personal information. For a parent, turn on updates and two-factor sign-in with them, and agree that no caller gets a code.

Sources

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *