Life lessons

A Phone Is Not a Safe

Digital culture sells the feeling of a secret space: a hidden folder, a disappearing message, a protected chat. But a secret section inside a phone is still part of the phone, and a sent message is part of somebody else’s device.

Current NIST guidance on digital identity looks noticeably different from the old schoolroom ritual of “eight characters, a capital letter, a digit and a mandatory change every three months”. The current edition emphasises length, blocking known compromised passwords, dropping pointless composition rules, and changing a password on signs of compromise rather than by the calendar.

This is a good example of mature security: a requirement is judged not by how strict it looks but by whether it reduces real risk. A long unique phrase plus an extra factor is usually more useful than a password someone changes on schedule from Winter25! to Spring26!.

A device can be lost, unlocked, infected with malware, seized, or forced to sync data to the cloud. The person you are talking to can take a screenshot, forward a message, or save it before it disappears.

AI services have added a risk of their own. A long contract, a medical document or a work archive is easy to upload into a system simply because reading it is inconvenient. But convenience is not permission to hand over data.

Before uploading, work out whether your contract or your organisation’s policy allows it, where the data will be stored, who will get access, and whether the service may be used for third-party information. Medical data, unpublished material, contracts, personal details and trade secrets deserve particular care.

So the first question of digital security is:

Does this need to be on the device at all?

Disappearing messages shorten how long some participants keep them, but they do not guarantee that the information disappears. A deleted file should not be treated as reliably destroyed either.

It is more sensible to work from a simple model:

Anything sent once may become available to a third person.

This does not mean writing every message as a statement for a court. Close communication is impossible without some trust. But particularly sensitive information is better:

  • not created unless necessary;
  • not forwarded into a group chat;
  • kept in a protected place;
  • restricted in access;
  • removed from backups, if that is genuinely required;
  • considered in terms of the consequences of disclosure.

The “hidden volume” technique creates an extra secret and an extra risk. Under coercion it can make the situation worse, if the hidden section is found.

Digital security should reduce your dependence on deception, not build a more elaborate deception.

If someone demands to see your messages, the problem may not be technical. It may be about control, abuse, or the absence of a safe personal space. What you need then is not a second messenger but a person or a service able to help you defend your boundaries.

Once you have decided what is actually worth keeping, the duller and more reliable part of protection begins: unique passwords, separate access factors and tested backups.

If one site loses its data, the same password should not open your email, your bank and your medical records.

Passwords are best generated and stored in a good manager. The master password should be long, memorable and used nowhere else.

Hiding it inside a long list of similar-looking strings is a bad idea. Such a system depends on remembering exactly where the deliberate error is, and creates a real chance that the owner will lock himself out.

Recovery codes can be kept separately:

  • in a protected physical record;
  • in a safe;
  • in encrypted storage;
  • with a trusted person, if that is justified.

Important accounts should have two-factor authentication: besides the password, one more confirmation is required. Where more robust methods are available — a hardware key or a passkey — they are usually preferable to an ordinary code sent by message.

There is no need to complicate a PIN with a theatrical dance of extra keypresses. Better to cover the keypad with your hand and not enter the code where you are being watched.

If you had to give a password to someone else, change it after they have used it. In a properly built system, though, each user gets their own access. A shared password makes it impossible to tell who did what.

Backups must exist independently of the original. A copy on the same drive protects against accidental deletion less well than it seems, and hardly protects at all against failure, theft or fire.

A digital document is not eternal. Formats become obsolete, drives fail, accounts get blocked. Reliability comes not from being digital but from copying regularly and testing restores from time to time.

The most common home safe is the chat you keep with yourself. That is where the passport photo goes before a trip, along with a picture of a bank card, the wi-fi password at the summer house, a scan of a contract, the door code at your parents’ place and a note from the clinic. The convenience lies precisely in the fact that no decision is made: the file is not chosen for storage, it is set aside for a minute. As a result the most sensitive archive a person owns is assembled without a single deliberate act and synced to every device they have ever logged into, including the work laptop and an old tablet at their parents’ house.

It is more useful to treat a phone as a shop window rather than a safe: anything that lands there may one day be seen by someone else. Auditing your saved messages takes a quarter of an hour and usually ends with the unpleasant discovery of what is in there.