Sources
Facts marked with a source link refer to this register. Each entry says which claim the source supports and when it was checked.
How sources are chosen
Authorities first: Kyberturvallisuuskeskus (the National Cyber Security Centre), Kilpailu- ja kuluttajavirasto (the Finnish Competition and Consumer Authority, KKV), and Poliisi (the police). After that the legislation itself, peer-reviewed research, independent test laboratories and established journalism.
Manufacturer documentation is used only to describe how a device works, which settings it has and how it handles data. Marketing copy is not used to judge a product's security.
If a claim can only be found in a news story about a study, we read the study. If we cannot get hold of it, the claim is weakened or removed.
The read date on each entry shows when it was checked. Changing information is checked again when official guidance, legislation or product behaviour changes.
Antivirus
S-DEFENDERMicrosoft Defender, which comes with Windows, scored full marks for protection in an independent test laboratory's June 2026 round, as did ten other products, most of them paid.
June 2026 round, Windows 11. Microsoft Defender Antivirus 4.18 scored 6/6 for protection, 5.5/6 for performance and 6/6 for usability.
Ten other products scored full marks for protection in the same round, and most of them are paid. That is the substance of the claim: Defender is in the same leading group, not above it.
The test round changes every few months. This line is checked again before publication.
App permissions
S-ANDROID-WIFIFrom Android 13 onwards, an app that manages Wi-Fi connections usually asks for nearby Wi-Fi devices permission. On older Android versions, the equivalent function required location access.
On Android 13 and later,
NEARBY_WIFI_DEVICESreplacedACCESS_FINE_LOCATIONfor many Wi-Fi operations. Some Wi-Fi APIs, including network scanning, can still require precise location.The permission shown during device setup therefore depends on the Android version and what the app does.
Consumer protection and phone sales
S-KKV-NEUVONTAKuluttajaneuvonta (Consumer Advisory Services) gives information and guidance on consumer law and in disputes. The service works by telephone and through a web form.
The service is meant for an individual consumer’s own situation. The authority itself supervises companies at a general level and does not settle individual disputes.
S-KKV-NEUVONTA-KIELETKuluttajaneuvonta gives guidance in Finnish and Swedish. Anyone who wants to be advised in another language arranges an interpreter themselves and at their own expense. The advice number answers in Finnish.
Read on the authority’s own English-language page, which states the service languages outright: “Consumer advice gives guidance in Finnish and Swedish. Therefore persons wishing to consult an advisor in some other language must get an interpreter at their own expense.” The same page marks the number 09 5110 1200 “(only in Finnish)”.
This entry exists for the English edition. For its reader the language of a service is not a detail; it is the fact that decides which channel they use.
S-KKV-VAHVISTUSA contract made in a phone sale does not bind the consumer unless they accept the offer the seller sends afterwards in writing or in another durable form. In force since 1 January 2023.
The provision is Chapter 6, Section 12 a of the kuluttajansuojalaki (the Consumer Protection Act), added by Act 693/2022 of 8 July 2022 and in force from 1 January 2023. Kilpailu- ja kuluttajavirasto’s wording: after the call, the company must deliver the offer it made to the consumer in writing or in another durable form. If the consumer does not accept the offer, the contract is not binding, and the seller may not demand payment, the return of goods or their storage.
There are two exceptions and they sit in different places in the law. Anyone looking for both of them in Section 12 a finds only the second.
The communications service exception is in Chapter 6, Section 4, on the application of the provisions to certain services: where the contract concerns communications services as defined in the Act on Electronic Communications Services, Section 12 a does not apply. In practice that means phone and internet subscriptions.
The other exception is inside Section 12 a itself: the rule does not cover a situation where the consumer contacted the trader, or where the trader called at the consumer’s express request.
Both sections read in the consolidated text on Finlex on 6 August 2026.
S-KSL-PERUUTUSMost things sold by phone carry a 14-day right of withdrawal. For goods the period starts on receipt, for services when the contract is made.
You can withdraw using the company’s form, by email, on the company’s website, or by including a note with the goods you return. You do not have to give a reason.
Return costs fall to the consumer unless the company has undertaken to pay them. If the company did not mention the costs in advance, the consumer does not pay them.
The right does not cover an opened sealed audio or video recording, goods made or altered to the consumer’s own specification, or goods that spoil quickly.
Device security regulation
S-EU-CRAThe EU Cyber Resilience Act obliges a manufacturer to state the support period at the point of sale. Most obligations start on 11 December 2027 and the reporting duties on 11 September 2026.
Regulation (EU) 2024/2847 entered into force on 10 December 2024. The Commission’s summary reads: “Its main provisions will start applying from 11 December 2027.”
The reporting duties start earlier: “reporting obligations set out in Article 14 apply from 11 September 2026.” The chapter on conformity assessment bodies starts on 11 June 2026.
For a buyer the point that matters most is the support period. The manufacturer has to determine it and state clearly, at the point of sale, when it ends.
S-EU-REDEU security requirements for internet-connected radio equipment have applied since 1 August 2025. The requirements fall under the CE marking.
Delegated Regulation (EU) 2022/30 brings into use points d, e and f of Article 3(3) of the Radio Equipment Directive. They cover internet-connected equipment, childcare equipment, toys, wearables and equipment capable of making payments.
The date of application moved by a year. Delegated Regulation (EU) 2023/2444 changed it to “It shall apply from 1 August 2025”, so that the harmonised standards had time to be finished.
S-TRAFICOM-MERKKITraficom has stopped granting new Tietoturvamerkki (Finnish Cybersecurity Label) certificates. The reason given is the EU security requirements that came into force for internet-connected devices on 1 August 2025.
The announcement was published on 21 October 2024. Labels already granted stayed valid for a transition period and are not renewed.
Looking for the Tietoturvamerkki on the box is therefore no longer current buying advice.
Home network
S-GOOGLE-DOUBLE-NATTwo routers in sequence create double NAT, which can complicate communication between devices, online gaming and port forwarding.
The guidance describes double NAT between two private router networks. Different address ranges and firewalls can prevent devices from finding or using one another.
It specifically lists online gaming, port forwarding and UPnP as possible trouble spots. Bridge mode disables NAT and routing, so it does not provide the isolation described by this site.
S-NETGEAR-ROUTER-MODEIn router mode, NAT blocks direct access to private addresses behind the router.
The manufacturer’s guidance distinguishes router mode from access-point mode. Router mode enables NAT automatically and blocks direct access to private addresses behind the device.
The source is used only to describe router mode and NAT behaviour, not to assess or recommend the specific product.
Home networks and smart devices
S-ACSC-IOTSmart devices should be placed on a separate guest network. Client isolation can also stop devices on that network communicating with each other when they do not need to.
The guidance recommends an additional network for smart devices, which a router may call a guest network. If the devices do not need to communicate with each other, it also recommends enabling client isolation.
The same page advises changing universal default passwords, enabling automatic updates and checking what data a device collects and how long it will be supported before buying it.
HTTPS and browser connection information
S-CHROME-HTTPSHTTPS encrypts the connection between a browser and a website. Chrome shows the connection status to the left of the address and warns when a connection is not private.
HTTPS makes it harder for anyone between the browser and the website to read or change the connection’s contents. It does not prove that the website itself is trustworthy. The guidance advises checking the site name even when the connection is secure and not entering sensitive information on a page that triggers a browser warning.
Chrome does not always use a padlock icon. Connection details are available from the security status icon to the left of the address.
Identity theft
S-LUOTTOKIELTOA voluntary credit ban can be entered free of charge in the Tax Administration's positive credit register. Credit reference companies sell the same service for a fee.
The guidance says that you can enter a voluntary credit ban in the Tax Administration’s positive credit register, and that the Tax Administration’s service is free of charge.
A credit ban does not stop you from taking out a loan yourself. It makes getting credit difficult for somebody trying to use your details.
After a data breach the same guidance also recommends a ban on changes of address, a ban on changes of account number, and a ban on the release of contact details.
Passwords and authentication
S-TRAFICOM-SALASANATA long, unique password is better than a short one, and different services must have different passwords. A good password does not need changing at regular intervals.
On length, the guidance says a long and unique password is better than a short one because it is hard to guess, and that 15 characters is already enough for many services.
On reuse: use a different password in different services, so that a password leaked from one service cannot be used to log in to the others.
The guidance also recommends a password management app and multi-factor authentication. The page was updated on 8 April 2026.
Robot-vacuum maps
S-IROBOT-MAPSiRobot Smart Maps are stored in the cloud. Disabling mapping stops spatial data being sent but also disables features that depend on the map.
iRobot says Smart Maps are stored in the cloud rather than in the app. Sending map data can be disabled in the app’s privacy settings.
Disabling mapping also removes room cleaning, keep-out zones, schedules and other features that use the map. The source covers iRobot products; other manufacturers may work differently.
Routers and update support
S-FBI-EOLCriminals use routers the manufacturer no longer updates to hide their crimes. Remote management being switched on was one common factor.
The announcement is dated 7 May 2025, reference I-050725-PSA. According to it, routers made in 2010 or earlier are unlikely to receive updates any more. Malware installs a proxy on the router, and crimes are committed through it in another person’s name.
The recommended actions: replace a router that has fallen out of support, install the updates that are available, switch remote management off, and restart the device.
The end of update support is a valid reason to replace a router, although the device’s age alone is not.
Scams and phishing
S-KYBER-HUIJAUSBanks and authorities never ask for personal details or bank credentials by text message or email. The aim of a scam is to create urgency and fear.
Kyberturvallisuuskeskus (the National Cyber Security Centre) advises that if the credentials have already been given, the bank should be contacted at once and a report made to the police. Its news material is a living source, so it is linked to as current material and no fixed figures are quoted from it.
S-POLIISI-ILMOITUSA criminal report can be made in the police online service or at a police station. In non-urgent situations the police recommend the electronic report first. In urgent situations, call the emergency number 112.
The electronic report requires identification, because the police have to be able to confirm who is making it. Printable forms are no longer distributed on the website.
Security-camera recording
S-NEST-CAMERALocal and cloud recording depend on the camera model and subscription. A recording already uploaded to the cloud remains available if the camera is stolen or damaged.
Google Nest’s documentation shows how much implementations vary. Depending on the model and subscription, a camera can save events or continuous video to the cloud. Supported models can also hold events temporarily in local memory during a network outage.
The source covers Nest cameras. It is used as an example of different recording models, not as a claim that all cameras work the same way.
Smart speakers and audio recordings
S-GOOGLE-ASSISTANTGoogle Assistant can save audio to an account when Voice and Audio Activity is enabled. Google also documents unintended activations and the option to delete recordings.
Google says its Voice and Audio Activity setting saves Assistant audio recordings in the Google Account. Its stated purposes include improving voice recognition and reducing unintended activations. Assistant activity can be reviewed and deleted from the account.
This source describes Google Assistant. Other manufacturers’ settings and storage behaviour must be checked in their own documentation.
Smart televisions
S-TV-ACRSmart televisions recognise what is on the screen and report it to the manufacturer. In the measurements, images were captured several times a minute.
The recognition also covers content arriving over the HDMI connection, that is, a picture watched from another device. The feature can be switched off, but the setting sits several menu levels down.
Smart-device security
S-GOVUK-IOTImportant requirements for consumer smart devices include unique passwords, a vulnerability reporting channel, update support, resilience to outages and deletion of personal data on resale.
The consumer IoT guidance covers devices and their associated apps, cloud storage and other services. It calls for no universal default passwords, a public vulnerability reporting channel and a stated software support period.
It also deals separately with continued operation during network and power outages and removing personal data when a device is sold or passed on.
Using smart devices
S-NCSC-SMARTA smart device's price does not determine its security. Current update support, a unique password, two-step verification and disabling unused remote access matter more.
The guidance says that security does not require the latest or most expensive model. It recommends avoiding a device that is no longer supported or will fall out of support soon.
NCSC also advises changing a universal default password, enabling two-step verification, disabling unused remote access, installing updates and factory-resetting a device before passing it on.
VPN marketing
S-CR-VPNIn a consumer organisation's test, 12 of 16 VPN services made inaccurate or exaggerated claims in their marketing.
Published 7 December 2021, updated 30 September 2022. The test covered 16 services. The most common exaggerations concerned complete anonymity and protection from advertisers and authorities.
The report also picks out the phrase “military-grade encryption”, for which there is no agreed definition at all.
This source supports only the general claim about exaggerated marketing. It is not used to assess individual VPN services.
S-VPN-ADSIn the marketing of VPN services sold to consumers, research finds that exaggeration is the rule rather than the exception.
The CHI 2025 study went through 302 web pages from 78 providers in five countries. A separate IEEE S&P 2022 study looked at influencer marketing on YouTube and found systematic exaggeration of what the product protects.
The same line of research found that even users who understand security overestimate how much protection they get, on the strength of the advertising.
S-VPN-ASAThe United Kingdom's advertising regulator found that a VPN advertisement caused unjustified fear and distress, and banned it from appearing again.
The ruling is dated 20 April 2022. The ASA found the advertisement to be “excessively violent, threatening and distressing to the extent that it overshadowed any attempt at humour”, and told the advertiser to make sure its future advertisements do not cause fear or distress without justifiable reason.
The ASA did not take a position on what a VPN protects. This source supports only the point that selling by fear has crossed a line in a regulator’s judgement.
Warranty and liability for defects
S-KKV-TAKUUGiving a warranty is voluntary for the seller, and the statutory liability for defects continues after the warranty ends. A warranty has to give the buyer more than the law already gives.
Kilpailu- ja kuluttajavirasto’s wording: “Issuing a warranty is voluntary” and “The end of the warranty period does not release the business from its liability for defects.”
On the warranty itself: “A warranty must be an additional benefit granted to the buyer, in other words it must provide the buyer with better rights than legal provisions.”
The law does not tie the duration of the liability for defects to a number of years. It follows from how long a comparable item can reasonably be expected to last.
Wi-Fi settings
S-APPLE-WIFIApple recommends WPA3 or WPA2/WPA3 transitional mode. Hiding a network name does not secure the network and can create privacy and compatibility problems.
The guidance describes WPA3 Personal as the newest option, WPA2/WPA3 Transitional as the compatible choice for older devices, and WPA2 Personal (AES) as appropriate when newer modes cannot be used. WEP and open networks are listed as settings to avoid.
An SSID is the visible network name. The guidance says to leave hiding disabled because it does not prevent detection or unauthorised access.
29 sources in total
Sources are checked again when official guidance, legislation or product behaviour changes.
Checked