Sources

Facts marked with a source link refer to this register. Each entry says which claim the source supports and when it was checked.

How sources are chosen

Authorities first: Kyberturvallisuuskeskus (the National Cyber Security Centre), Kilpailu- ja kuluttajavirasto (the Finnish Competition and Consumer Authority, KKV), and Poliisi (the police). After that the legislation itself, peer-reviewed research, independent test laboratories and established journalism.

Manufacturer documentation is used only to describe how a device works, which settings it has and how it handles data. Marketing copy is not used to judge a product's security.

If a claim can only be found in a news story about a study, we read the study. If we cannot get hold of it, the claim is weakened or removed.

The read date on each entry shows when it was checked. Changing information is checked again when official guidance, legislation or product behaviour changes.

Android contacts access

  • S-ANDROID-CONTACTS

    The Android 17 contact picker can share only the people and fields selected by the user without granting an app access to the whole address book.

    The picker is available on Android 17, or API level 37. The app has to use the picker before the user can share only the contacts needed through it.

    Android Developers, Googlehttps://developer.android.com/about/versions/17/features/contact-pickerRead on

Android device certification

  • S-GOOGLE-PLAY-CERTIFICATION

    A Play Protect certified Android device has passed compatibility testing. An uncertified device may not receive system or app updates.

    Price does not determine certification. You can check the status in Google Play under Settings > About > Play Protect certification.

    Google Play Helphttps://support.google.com/googleplay/answer/7165974?hl=enRead on

Android malware protection

  • S-GOOGLE-PLAY-PROTECT

    Google Play Protect checks Android apps during installation and scans the device regularly. It can warn about, disable or remove a harmful app.

    Play Protect is enabled by default. It also checks apps installed outside Google Play and can warn about harmful web addresses.

    Google Play Helphttps://support.google.com/googleplay/answer/2812853?hl=enRead on

Android private MAC address

Android updates

  • S-ANDROID-UPDATES

    Android version, Android security update and Google Play system update appear as separate items in the phone settings.

    Availability and schedules depend on the device, manufacturer and mobile operator. A phone system update does not reveal the update status of a separate smart device.

    Android Help, Googlehttps://support.google.com/android/answer/7680439?hl=enRead on

Antivirus

  • S-DEFENDER

    Microsoft Defender, which comes with Windows, scored full marks for protection in an independent test laboratory's June 2026 round. Thirteen products received the same score in total.

    June 2026 round, Windows 11. Microsoft Defender Antivirus 4.18 scored 6/6 for protection, 5.5/6 for performance and 6/6 for usability.

    The round tested 16 products. Thirteen of them scored 6/6 for protection. The test round changes every few months, so check the source for the latest result.

    AV-TEST Institutehttps://www.av-test.org/en/antivirus/home-windows/Read on

App permissions

  • S-ANDROID-LOCAL-NETWORK

    Android 17 blocks local-network traffic by default for apps updated to target Android 17. An app needs local-network permission or a system device picker.

    The restriction applies to apps targeting Android 17, or SDK 37, and later. For now, an app targeting an older version receives local-network access with its internet permission.

    Local-network access belongs to the Nearby devices permission group. Internet access can work while local discovery and control fail.

    Android Developershttps://developer.android.com/privacy-and-security/local-network-permissionRead on

  • S-ANDROID-WIFI

    On Android 13 or later, an app that manages Wi-Fi connections may ask for Nearby devices access. The request also depends on the app's target version and the Wi-Fi operation it uses.

    An app running on Android 13 or later requests NEARBY_WIFI_DEVICES when it targets Android 13 or later and uses certain Wi-Fi operations. The permission is shown to the user as part of the Nearby devices group.

    An older app can still ask for location. Some Wi-Fi APIs, including network scanning, can require precise location even on a new Android version.

    Android Developershttps://developer.android.com/develop/connectivity/wifi/wifi-permissionsRead on

  • S-APPLE-APP-PERMISSIONS

    On iPhone, Local Network, Bluetooth, location and contacts are separate permissions. They can be reviewed and changed in the privacy settings.

    Settings > Privacy & Security shows which apps have requested each kind of access. Access can be granted or removed later.

    Apple Supporthttps://support.apple.com/en-us/102515Read on

  • S-APPLE-LOCAL-NETWORK

    Since iOS 14, an app must ask for permission before it discovers devices on the local network. You can review and change that access in the iPhone's privacy settings.

    Local-network access can be changed under Settings > Privacy & Security > Local Network. Denying it does not stop the app’s ordinary internet access.

    Apple Supporthttps://support.apple.com/en-us/102229Read on

Apple private Wi-Fi address

  • S-APPLE-PRIVATE-WIFI

    An Apple device uses a private address on Wi-Fi networks to reduce tracking. Apple recommends leaving it enabled on networks that support it.

    On current systems, the address can be fixed or rotating depending on the network security. A router may report the device as new when it first joins using a private address.

    Apple Supporthttps://support.apple.com/en-us/102509Read on

CE marking and conformity assessment

  • S-EU-CE

    CE marking is the manufacturer's declaration that a product meets the applicable EU requirements. It belongs only on product groups for which EU rules require it.

    The manufacturer is responsible for the conformity assessment, technical file, EU declaration of conformity and affixing the marking. Some product groups require a notified body to take part.

    Not every product needs CE marking, and it must not be affixed outside product groups covered by the relevant EU rules. The marking is not an approval issued to the product by the EU or an authority.

    European Commissionhttps://single-market-economy.ec.europa.eu/single-market/goods/ce-marking_enRead on

Consumer protection and phone sales

  • S-KKV-NEUVONTA

    Kuluttajaneuvonta (Consumer Advisory Services) gives information and guidance on consumer law and in disputes. The service works by telephone and through a web form.

    The service is meant for an individual consumer’s own situation. The authority itself supervises companies at a general level and does not settle individual disputes.

    Kilpailu- ja kuluttajavirasto (KKV)https://www.kkv.fi/kuluttaja-asiat/kuluttajaneuvonta/Read on

  • S-KKV-NEUVONTA-KIELET

    Kuluttajaneuvonta gives guidance in Finnish and Swedish. Anyone who wants to be advised in another language arranges an interpreter themselves and at their own expense. The advice number answers in Finnish.

    Read on the authority’s own English-language page, which states the service languages outright: “Consumer advice gives guidance in Finnish and Swedish. Therefore persons wishing to consult an advisor in some other language must get an interpreter at their own expense.” The same page marks the number 09 5110 1200 “(only in Finnish)”.

    The language of the service affects whether the phone or the online form is a suitable way to use it.

    Kilpailu- ja kuluttajavirasto (KKV)https://www.kkv.fi/en/consumer-advice/Read on

  • S-KKV-VAHVISTUS

    A contract made in a phone sale does not bind the consumer unless they accept the offer the seller sends afterwards in writing or in another durable form. In force since 1 January 2023.

    The provision is Chapter 6, Section 12 a of the kuluttajansuojalaki (the Consumer Protection Act), added by Act 693/2022 of 8 July 2022 and in force from 1 January 2023. Kilpailu- ja kuluttajavirasto’s wording: after the call, the company must deliver the offer it made to the consumer in writing or in another durable form. If the consumer does not accept the offer, the contract is not binding, and the seller may not demand payment, the return of goods or their storage.

    There are two exceptions, and they sit in different sections. The communications-service exception is separate from cases where the consumer began the contact.

    The communications service exception is in Chapter 6, Section 4, on the application of the provisions to certain services: where the contract concerns communications services as defined in the Act on Electronic Communications Services, Section 12 a does not apply. In practice that means phone and internet subscriptions.

    The other exception is inside Section 12 a itself: the rule does not cover a situation where the consumer contacted the trader, or where the trader called at the consumer’s express request.

    Both sections read in the consolidated text on Finlex on 6 August 2026.

    Kilpailu- ja kuluttajavirasto (KKV)https://www.kkv.fi/kuluttaja-asiat/puhelin-ja-kotimyynti/puhelinmyynti/Read on

  • S-KSL-PERUUTUS

    Most things sold by phone carry a 14-day right of withdrawal. For goods the period starts on receipt, for services when the contract is made.

    You can withdraw using the company’s form, by email, on the company’s website, or by including a note with the goods you return. You do not have to give a reason.

    The consumer must be able to show that notice was given. A written notice is therefore the easiest to prove in practice, even though the law does not require email or a form in particular.

    Return costs fall to the consumer unless the company has undertaken to pay them. If the company did not mention the costs in advance, the consumer does not pay them.

    Examples include an opened sealed recording or hygiene product, made-to-order goods and goods that spoil quickly. Services and digital content have further exclusions. The handbook’s short list is not exhaustive, so an individual case must be checked against KKV’s current list.

    Kilpailu- ja kuluttajavirasto (KKV)https://www.kkv.fi/kuluttaja-asiat/puhelin-ja-kotimyynti/peruuttaminen-ja-palauttaminen-puhelinmyynnissa/Read on

Device interfaces and local updates

  • S-NIST-IOT-INTERFACES

    A network is not a device's only interface. NIST distinguishes network and local interfaces such as Bluetooth, USB ports and memory cards. Updates can also be delivered locally.

    The NIST IR 8259A baseline treats network and local device interfaces separately. Local interfaces include USB ports and memory-card slots, while a network interface may use Bluetooth.

    A software update can be delivered remotely over a network or locally on removable media. A device that does not connect to the internet is therefore not automatically outside every security question.

    National Institute of Standards and Technologyhttps://csrc.nist.gov/pubs/ir/8259/a/finalRead on

Device security regulation

  • S-EU-CRA

    The EU Cyber Resilience Act obliges a manufacturer to state the support period at the point of sale. Most obligations start on 11 December 2027 and the reporting duties on 11 September 2026.

    Regulation (EU) 2024/2847 entered into force on 10 December 2024. Under Article 71, most obligations apply from 11 December 2027 and the Article 14 reporting duties from 11 September 2026. The chapter on conformity assessment bodies applied from 11 June 2026.

    The manufacturer must determine a support period for the product. Once the main obligations apply, the end date of that period must be stated clearly at the point of sale.

    An actively exploited vulnerability requires an early warning within 24 hours and a fuller notification within 72 hours of the manufacturer becoming aware. The final report is due no later than 14 days after a corrective or mitigating measure becomes available.

    A severe security incident has the same first two deadlines. Its final report is due within one month of the 72-hour notification.

    Article 14(8) requires the manufacturer to inform impacted users and, where appropriate, all users. Article 69(3) extends the Article 14 duties to every in-scope product placed on the market before 11 December 2027.

    Notifications are submitted through ENISA’s Single Reporting Platform. The coordinating CSIRT is generally determined by the manufacturer’s main establishment in the EU.

    The Commission’s plain-language summary explains the timetable. The Commission’s reporting page and ENISA’s platform guidance describe the reporting process.

    Delegated Regulation (EU) 2026/339 repeals the earlier Radio Equipment Directive cybersecurity rule on the same date, 11 December 2027.

    Official Journal of the European Unionhttps://eur-lex.europa.eu/eli/reg/2024/2847/oj/engRead on

  • S-EU-RED

    EU security requirements cover radio equipment in scope when it is placed on the EU market from 1 August 2025. The rule changes to the Cyber Resilience Act framework on 11 December 2027.

    Delegated Regulation (EU) 2022/30 brings points d, e and f of Article 3(3) of the Radio Equipment Directive into use for different categories. These include internet-connected equipment, childcare equipment, toys, wearables and equipment capable of transferring money.

    The date concerns when a device is placed on the EU market, not every device already in use. Delegated Regulation (EU) 2026/339 repeals this rule on 11 December 2027. The transition covers equipment placed on the market from 1 August 2025 through 10 December 2027.

    EUR-Lex, European Commissionhttps://eur-lex.europa.eu/eli/reg_del/2022/30/2023-10-27/engRead on

  • S-TRAFICOM-MERKKI

    Traficom has stopped granting new Tietoturvamerkki (Finnish Cybersecurity Label) certificates. The reason given is the EU security requirements that came into force for internet-connected devices on 1 August 2025.

    The announcement was published on 21 October 2024. Labels already granted stayed valid for a transition period and are not renewed.

    Looking for the Tietoturvamerkki on the box is therefore no longer current buying advice.

    Traficomhttps://www.traficom.fi/fi/uutiset/liikenne-ja-viestintavirasto-traficom-lopettaa-uusien-tietoturvamerkkien-myontamisenRead on

Gift-card scams

  • S-FTC-LAHJAKORTIT

    A contact that requires you to buy a gift card and give away its code as payment is a scam. If you already gave away the code, contact the card issuer immediately and ask for your money back.

    A scammer tells the target which gift card to buy and asks for the card number and PIN. Those codes give the scammer access to the value on the card even when the buyer still holds the card itself.

    The FTC advises contacting the company that issued the card immediately, reporting the scam and asking for the money back. Keep the card and receipt for the report.

    Federal Trade Commissionhttps://consumer.ftc.gov/articles/avoiding-and-reporting-gift-card-scamsRead on

Guest Wi-Fi design

  • S-OPENWRT-GUEST

    Guest Wi-Fi can use its own network interface, address range and firewall zone. The firewall can allow internet access from that network while blocking access to the main local network.

    The OpenWrt guide creates a separate network interface, IP address range, address-assignment service and firewall zone for guest Wi-Fi. Its firewall permits traffic from the guest network to the internet, but not to the main local network.

    The guide treats client isolation as a separate setting. It stops wireless clients on the guest network communicating directly with one another, but it is not the firewall boundary between the guest and home networks.

    OpenWrthttps://openwrt.org/docs/guide-user/network/wifi/guestwifi/guest-wlanRead on

Guest-network isolation setting

  • S-NETGEAR-GUEST

    Access from a guest network to the local network can be a separate setting. The guest-network name alone therefore does not prove that guests or smart devices are isolated from other devices in the home.

    The manufacturer’s instructions include a separate option that can allow guest-network devices to see one another and access the local network. With the option cleared, guests can reach the internet but not computers or other devices on the main network.

    The instructions apply to a named product family. The site uses them only as evidence that you must verify isolation in your own router’s settings rather than infer it from the network name.

    NETGEAR Supporthttps://kb.netgear.com/31579/How-do-I-set-up-a-guest-network-on-my-Orbi-WiFi-SystemRead on

Home devices in a residential proxy network

  • S-TRAFICOM-IPIDEA

    The Finnish National Cyber Security Centre observed traffic connected to the IPIDEA residential proxy network in Finland and described how apps and Android streaming devices can enrol a home device in the network.

    The Finnish-language notice was published on 18 March 2026. IPIDEA observations began increasing in Finland on 18 February 2026, and the Centre was receiving nearly 900 observations a day when the notice was published.

    The notice says enrolment code may be present in an app, a game or an Android streaming device. Its advice includes keeping Google Play Protect enabled, avoiding untrusted free VPN services and keeping devices updated.

    The observation rate describes the situation in March 2026. It is neither a count of infected devices nor a current measurement.

    Traficom, National Cyber Security Centre Finlandhttps://kyberturvallisuuskeskus.fi/fi/uutiset/ipidea-kotilaitteita-hyodyntava-valityspalveluverkkoRead on

Home network

  • S-GOOGLE-DOUBLE-NAT

    Two routers in sequence create double NAT, which can complicate communication between devices, online gaming and port forwarding.

    The guidance describes double NAT between two private router networks. Different address ranges and firewalls can prevent devices from finding or using one another.

    It specifically lists online gaming, port forwarding and UPnP as possible trouble spots. In bridge mode, the second device no longer forms a separate routed network.

    Google Nest Helphttps://support.google.com/googlehome/answer/6277579?hl=en-IERead on

  • S-NETGEAR-ROUTER-MODE

    In router mode, NAT blocks direct access to private addresses behind the router.

    The manufacturer’s guidance distinguishes router mode from access-point mode. Router mode enables NAT automatically and blocks direct access to private addresses behind the device.

    The guidance covers router mode and NAT behaviour. It does not assess whether the product is secure or suitable.

    NETGEAR Supporthttps://kb.netgear.com/000058849/What-do-I-need-to-know-about-using-my-NETGEAR-WAC510-access-point-in-router-modeRead on

Home network and router security

  • S-TRAFICOM-REITITIN

    The router is the home network's main barrier against the public internet. Turning off remote management, changing the default password, keeping updates current, WPA2 or WPA3 encryption and a separate guest network are the most important security measures on a home router.

    On remote management, the guidance is blunt: it calls remote management the single largest risk to the device’s security. The setting may be labelled remote access, remote management or remote admin.

    On cabling: the flat’s incoming internet cable must not be connected to a LAN port on the router, because that bypasses the router’s protections. The same applies to a building’s shared broadband.

    Encryption doubles as a lifespan gauge: with neither WPA3 nor WPA2 available, the guidance says the router is reaching the end of its usable life. The source is available in Finnish and was updated on 14 April 2026.

    Traficomhttps://www.traficom.fi/fi/arjen-tietoturva/kotiverkon-ja-reitittimen-tietoturvaRead on

Home networks and smart devices

  • S-ACSC-IOT

    Smart devices should be placed on a separate guest network. Client isolation can also stop devices on that network communicating with each other when they do not need to.

    The guidance recommends an additional network for smart devices, which a router may call a guest network. If the devices do not need to communicate with each other, it also recommends enabling client isolation.

    The same page advises changing universal default passwords, enabling automatic updates and checking what data a device collects and how long it will be supported before buying it.

    Australian Cyber Security Centrehttps://www.cyber.gov.au/protect-yourself/securing-your-devices/how-secure-your-devices/internet-things-devicesRead on

HTTPS and browser connection information

  • S-CHROME-HTTPS

    HTTPS encrypts the connection between a browser and a website. Chrome shows the connection status to the left of the address and warns when a connection is not private.

    HTTPS makes it harder for anyone between the browser and the website to read or change the connection’s contents. It does not prove that the website itself is trustworthy. The guidance advises checking the site name even when the connection is secure and not entering sensitive information on a page that triggers a browser warning.

    Chrome does not always use a padlock icon. Connection details are available from the security status icon to the left of the address.

    Google Chrome Helphttps://support.google.com/chrome/answer/95617?hl=enRead on

Identity theft

  • S-LUOTTOKIELTO

    A voluntary credit ban can be entered free of charge in the Positive Credit Register. You can consent to the register passing the information to Suomen Asiakastieto and Dun & Bradstreet.

    The ban is entered free of charge in the Positive Credit Register’s online service. You can also consent to the register passing the information to Suomen Asiakastieto Oy and Dun & Bradstreet Finland Oy.

    A credit ban does not stop you from taking out a loan yourself. It makes getting credit difficult for somebody trying to use your details.

    Positive Credit Register, Finnish Tax Administrationhttps://www.vero.fi/positiivinenluottotietorekisteri/yksityishenkiloille/vapaaehtoinen-luottokielto/Read on

iPhone app sandboxing

  • S-APPLE-APP-SANDBOX

    Third-party iPhone apps run in a sandbox. An app cannot modify other apps or the operating system, and access outside its own information goes through services provided by the system.

    App isolation also limits a third-party security app. It cannot scan other apps and the whole system in the same way as Windows antivirus.

    Apple Platform Securityhttps://support.apple.com/en-gb/guide/security/sec15bfe098e/webRead on

iPhone app security

  • S-APPLE-IOS-APP-SECURITY

    iOS verifies an app's source and code signature before allowing the app to run.

    The verification chain aims to confirm that the app comes from a known source, its code has not been modified and it is allowed to run on that device.

    Apple Platform Securityhttps://support.apple.com/en-euro/guide/security/secf49cad4db/webRead on

iPhone app updates

  • S-APPLE-APP-UPDATES

    App Store apps update automatically by default. Automatic updates can be checked in iPhone settings, and an individual app can be updated from the App Store.

    An app update is separate from an iPhone system update. Neither one reveals the software update status of a separate smart device.

    Apple Supporthttps://support.apple.com/en-us/102629Read on

iPhone contacts access

  • S-APPLE-CONTACTS

    On iPhone, an app can receive limited contacts access so that it sees only the people selected by the user.

    Access can be changed under Settings > Privacy & Security > Contacts. Limited Access lets the user select individual people instead of sharing the whole contacts list.

    Apple Supporthttps://support.apple.com/en-qa/guide/iphone/iph9536aa9a5/iosRead on

iPhone system updates

  • S-APPLE-UPDATES

    An iPhone system update is checked under Settings > General > Software Update.

    This update applies to the iPhone operating system. It does not reveal the update status of a phone app or the software on a separate smart device.

    Apple Supporthttps://support.apple.com/en-us/118575Read on

Method of withdrawal notice

  • S-EU-WITHDRAWAL-NOTICE

    A consumer may withdraw in their own words when the statement is unambiguous. A telephone call can be valid, but the consumer must be able to prove the notice.

    Recital 44 names a telephone call as a possible way to withdraw. The statement must be unambiguous, and the consumer bears the burden of proving that notice was given in time.

    A written message is therefore good practical advice, but it is not a condition for validity.

    European Union Consumer Rights Directivehttps://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32011L0083Read on

Paid extra cover and warranties

Passkeys and phishing resistance

  • S-NIST-PASSKEYS

    A properly implemented WebAuthn passkey is bound to the service's domain. A false site therefore cannot capture and reuse its output in the same way as a manually entered code.

    NIST does not consider manually entered one-time codes phishing-resistant. WebAuthn can provide phishing resistance by binding the authentication key to the correct domain.

    A synced passkey can use one or more factors. It should not always be called a second step after a password because it may replace the password entirely.

    National Institute of Standards and Technologyhttps://pages.nist.gov/800-63-4/sp800-63b.html#phishresRead on

Passkeys, FIDO2 and WebAuthn

  • S-FIDO-PASSKEYS

    A passkey is a FIDO credential built on FIDO2 standards. WebAuthn is the browser API, not another name for a passkey.

    The FIDO Alliance defines a passkey as a FIDO credential. Passkeys use the FIDO2 standards, which include WebAuthn and CTAP.

    WebAuthn is the browser API through which a website uses a passkey. FIDO2 and WebAuthn describe the technology; they are not synonyms for a passkey.

    FIDO Alliancehttps://fidoalliance.org/passkeys/Read on

Passwords and authentication

  • S-TRAFICOM-SALASANAT

    A long, unique password is better than a short one, and different services must have different passwords. A good password does not need changing at regular intervals.

    On length, the guidance says a long and unique password is better than a short one because it is hard to guess, and that 15 characters is already enough for many services.

    On reuse: use a different password in different services, so that a password leaked from one service cannot be used to log in to the others.

    The guidance also recommends a password management app and multi-factor authentication. The page was updated on 8 April 2026.

    Traficomhttps://traficom.fi/fi/ohjeet-ja-oppaat/ohjeet-ja-oppaat-yksityishenkiloille/salasanat-haltuun-kuka-kayttaa-tiliasiRead on

Phishing for bank credentials and confirmation codes

  • S-POLIISI-TUNNUSKOODIT

    Banks and public authorities do not ask for bank credentials or confirmation codes by email, text message or telephone. Approve only a transaction you started yourself.

    The police advise opening the bank through an address you type yourself or its official app. If credentials have already been given out, contact the bank immediately and file a criminal report.

    Poliisi (the police)https://poliisi.fi/-/pankkitunnuksia-kalastellaan-kehittyneella-menetelmallaRead on

Preventing identity theft

  • S-SUOMIFI-KIELLOT

    After personal data has leaked, you can restrict the release of contact details, block address notifications at both DVV and Posti, and limit changes to the tax-refund account number to MyTax.

    Suomi.fi advises considering these restrictions particularly when a Finnish personal identity code has reached an unauthorised person. Contact-disclosure restrictions limit access through address and contact-information services.

    Address notifications are blocked separately at Digi- ja vaestotietovirasto, the Digital and Population Data Services Agency, and Posti. In MyTax, the tax-refund account number can be limited to changes made after strong authentication, so a paper notification is not enough.

    Suomi.fihttps://www.suomi.fi/oppaat/tietovuoto/vaiheet/kiellotRead on

Privacy of DNS queries

  • S-DNS-PRIVACY

    A DNS query can reveal the requested domain and its source to the resolver. Encrypted DNS protects the query in transit, but the selected resolver still processes it.

    DNS queries also arise from embedded page content and browser prefetching. One query does not therefore prove that a person opened a particular page.

    A device often uses the resolver provided by its network. A browser, operating system or another application can choose a different resolver and an encrypted transport.

    Internet Engineering Task Forcehttps://www.rfc-editor.org/rfc/rfc9076.htmlRead on

Recovering a hacked or infected device

  • S-NCSC-DEVICE-RECOVERY

    If a harmful change cannot be removed with confidence, wiping the device and reinstalling the operating system provides a more reliable return to a clean state.

    The NCSC advises updating and scanning the device first. If the infection cannot be removed with confidence, wipe a computer and reinstall its operating system.

    UK National Cyber Security Centrehttps://www.ncsc.gov.uk/guidance/hacked-device-action-to-takeRead on

Recovering a Windows device after a remote-support scam

  • S-MICROSOFT-TECH-SCAM-RECOVERY

    After a remote-support scam, uninstall the requested apps, run a full security scan, install updates and change passwords. Resetting the device may need to be considered.

    Microsoft warns that a scammer with remote access may install malware or other unwanted programs. Removing only the visible remote-access app is therefore not a complete check.

    Microsoft Supporthttps://support.microsoft.com/en-us/office/protect-yourself-from-tech-support-scamsRead on

Residential IPv6 gateway filtering

  • S-IETF-IPV6-CPE

    A residential IPv6 router relies on stateful filtering, not address translation. New inbound connections should be blocked by default unless an internal device initiated the flow or an administrator created an explicit exception.

    RFC 6092 describes recommended security capabilities for residential and small-office IPv6 gateways. The operating principle is to allow return traffic for connections started inside and block other unsolicited traffic from outside.

    The document distinguishes this filtering from the NAT address translation commonly used with IPv4. A two-router boundary must therefore be checked for both IPv4 and IPv6 traffic.

    IETFhttps://www.rfc-editor.org/rfc/rfc6092.htmlRead on

Robot-vacuum maps

  • S-IROBOT-MAPS

    iRobot Smart Maps are stored in the cloud. Disabling mapping stops spatial data being sent but also disables features that depend on the map.

    iRobot says Smart Maps are stored in the cloud rather than in the app. Sending map data can be disabled in the app’s privacy settings.

    Disabling mapping also removes room cleaning, keep-out zones, schedules and other features that use the map. The source covers iRobot products; other manufacturers may work differently.

    iRobot Supporthttps://ondersteuning.irobot.nl/articles/en_US/Knowledge/17752Read on

Roles of the modem, fibre terminal and router

  • S-BBF-HOME-NETWORK

    The network termination in a home connection can be a fibre ONT or a DSL modem. The internet gateway, or router, connects the operator's access network to the home network. The functions can be provided by one device or several devices.

    The TR-488 home-network model separates the operator’s access network, network termination, internet gateway and devices in the home. The network termination is an ONT on fibre and a modem on DSL.

    The internet gateway sits between the access network and the home network. The model allows a single-box or multi-box design. TR-124 defines routing, firewall, WAN and LAN functions among the gateway requirements.

    Broadband Forumhttps://www.broadband-forum.org/pdfs/tr-488-1-0-0.pdfRead on

Routers and update support

  • S-FBI-EOL

    Criminals use routers the manufacturer no longer updates to hide their crimes. Remote management being switched on was one common factor.

    The announcement is dated 7 May 2025, reference I-050725-PSA. According to it, routers made in 2010 or earlier are unlikely to receive updates any more. Malware installs a proxy that relays other people’s traffic through the router.

    The recommended actions: replace a router that has fallen out of support, install the updates that are available, switch remote management off, and restart the device.

    The end of update support is a valid reason to replace a router, although the device’s age alone is not.

    FBI, Internet Crime Complaint Center (IC3)https://www.ic3.gov/PSA/2025/PSA250507Read on

Scams and phishing

  • S-KYBER-HUIJAUS

    A scam message or call can use urgency, fear and a credible-looking sender to make the recipient act before checking the request.

    Kyberturvallisuuskeskus (the National Cyber Security Centre) advises checking the apparent sender and the link address before acting. The source link carries the current advice.

    Traficom, Kyberturvallisuuskeskushttps://www.kyberturvallisuuskeskus.fi/fi/ajankohtaista/tietojenkalastelu-ja-huijausviestien-kanssa-tulee-olla-yha-tarkempiRead on

  • S-POLIISI-ILMOITUS

    A criminal report can be made in the police online service or at a police station. In non-urgent situations the police recommend the electronic report first. In urgent situations, call the emergency number 112.

    The English-language page explains how to file a report online or at a police station and says that 112 is for urgent situations.

    Poliisihttps://poliisi.fi/en/report-a-crimeRead on

Security-camera recording

  • S-NEST-CAMERA

    Local and cloud recording depend on the camera model and subscription. A recording already uploaded to the cloud remains available if the camera is stolen or damaged.

    Depending on the model and subscription, a Nest camera can save events or continuous video to the cloud. Supported models can also hold events temporarily in local memory during a network outage.

    Google now calls the subscription Google Home Premium; its former name was Nest Aware. Recording methods vary by model and subscription. Other manufacturers may work differently.

    Google Home Helphttps://support.google.com/googlehome/answer/9242083?hl=enRead on

Site privacy and analytics

  • S-CLOUDFLARE-WEB-ANALYTICS

    Cloudflare Web Analytics counts visits and page views, measures loading performance, and shows the page path, referring hostname, country, and basic browser and device information.

    Cloudflare’s metrics include visits, page views and page load time. Its dimensions include the site hostname and path, referring hostname, country, device type, browser and operating system.

    Cloudflarehttps://developers.cloudflare.com/web-analytics/data-metrics/Read on

  • S-CLOUDFLARE-WEB-ANALYTICS-FAQ

    Cloudflare Web Analytics does not record the query string in a page URL.

    Cloudflare’s documentation says the service does not log the URL parts after the question mark. This excludes the search term from analytics even when the site’s local search appears in the URL query string.

    Cloudflarehttps://developers.cloudflare.com/web-analytics/faq/Read on

  • S-CLOUDFLARE-WEB-ANALYTICS-PRIVACY

    Cloudflare says its RUM measurement does not set or read cookies or browser storage. It receives the IP address but discards it at the nearest data centre without storing it.

    Cloudflare says the beacon does not use cookies, local storage, session storage or IndexedDB. The IP address arriving with the ordinary web request is discarded at the nearest Cloudflare data centre and is not stored in the core analytics database or logs.

    Cloudflarehttps://developers.cloudflare.com/speed/observatory/rum-beacon/Read on

Smart speakers and audio recordings

  • S-GOOGLE-ASSISTANT

    Google Assistant can save audio to an account when Voice and Audio Activity is enabled. Google also documents unintended activations and the option to delete recordings.

    Google says its Voice and Audio Activity setting saves Assistant audio recordings in the Google Account. Its stated purposes include improving voice recognition and reducing unintended activations. Assistant activity can be reviewed and deleted from the account.

    This source describes Google Assistant. Other manufacturers’ settings and storage behaviour must be checked in their own documentation.

    Google Assistant Helphttps://support.google.com/assistant/answer/7126196?hl=enRead on

Smart televisions

  • S-TV-ACR

    In a study of Samsung and LG smart televisions, content recognition covered pictures shown over HDMI too. Opting out stopped the measured recognition traffic.

    The study measured Samsung and LG models in the UK and US. It does not establish that every smart television model behaves in the same way.

    On the tested sets, recognition covered content arriving over HDMI too. The feature could be switched off, but doing so required several settings and menu levels.

    ACM Internet Measurement Conference 2024 (UC Davis, UCL, UC3M)https://discovery.ucl.ac.uk/id/eprint/10200730/Read on

Smart-device security

  • S-GOVUK-IOT

    Important requirements for consumer smart devices include unique passwords, a vulnerability reporting channel, update support, resilience to outages and deletion of personal data on resale.

    The consumer IoT guidance covers devices and their associated apps, cloud storage and other services. It calls for no universal default passwords, a public vulnerability reporting channel and a stated software support period.

    It also deals separately with continued operation during network and power outages and removing personal data when a device is sold or passed on.

    UK Department for Science, Innovation and Technologyhttps://www.gov.uk/government/publications/code-of-practice-for-consumer-iot-security/code-of-practice-for-consumer-iot-securityRead on

The IPIDEA residential proxy network

  • S-GOOGLE-IPIDEA

    Google found code that enrolled devices in the IPIDEA network inside applications and pre-installed on some uncertified Android devices, and used Play Protect to block known apps.

    Google published its investigation on 28 January 2026. Enrolment code could be embedded in an app that continued to perform its ordinary function. Google also found the code in software that promised to pay people for sharing their internet connection.

    Google protected certified Android devices by warning about known IPIDEA apps, removing them and blocking new installation attempts. The company estimated that its disruption reduced the pool of devices in the network by millions.

    The investigation does not give consumers a complete list of every affected app or device. Normal slowness or high data use therefore does not identify IPIDEA software on its own.

    Google Threat Intelligence Grouphttps://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-networkRead on

Using smart devices

  • S-NCSC-SMART

    A smart device's price does not determine its security. Current update support, a unique password, two-step verification and disabling unused remote access matter more.

    The guidance says that security does not require the latest or most expensive model. It recommends avoiding a device that is no longer supported or will fall out of support soon.

    NCSC also advises changing a universal default password, enabling two-step verification, disabling unused remote access, installing updates and factory-resetting a device before passing it on.

    UK National Cyber Security Centrehttps://www.ncsc.gov.uk/guidance/smart-devices-in-the-homeRead on

VLANs and firewall rules

  • S-OPNSENSE-VLAN

    A VLAN, or Virtual Local Area Network, divides the same physical network equipment into separate logical local networks. Traffic between them requires routing, and firewall rules decide which routed traffic is allowed.

    The guide expands the name Virtual Local Area Network and distinguishes tagged from untagged traffic. Tags let one link carry several VLANs between a router, managed switch and wireless access point.

    Each VLAN receives a separate IP network. Traffic crossing a VLAN boundary passes through a router, where firewall rules can control it. The guide uses guest Wi-Fi as one example of a wireless network attached to a VLAN.

    OPNsensehttps://docs.opnsense.org/manual/how-tos/vlan_and_lagg.htmlRead on

VPN connections

  • S-NCSC-VPN

    A VPN is an encrypted network connection that an organisation can use for remote access. Only traffic routed through it receives that protection, and a VPN is unnecessary when its benefits do not match a real need.

    The guidance covers organisational VPN deployments, not the choice of a consumer service. It supports work access as a genuine use case and limits protection to traffic routed through the VPN.

    NCSC says to determine the need first. If none of the benefits address that need, there is no need to use a VPN.

    National Cyber Security Centrehttps://www.ncsc.gov.uk/collection/device-security-guidance/infrastructure/virtual-private-networksRead on

VPN marketing

  • S-CR-VPN

    In a consumer organisation's test, 12 of 16 VPN services made inaccurate or exaggerated claims in their marketing.

    Published 7 December 2021, updated 30 September 2022. The test covered 16 services. The most common exaggerations concerned complete anonymity and protection from advertisers and authorities.

    The report also picks out the phrase “military-grade encryption”, for which there is no agreed definition at all.

    The result concerns VPN marketing in general. The study does not assess individual services.

    Consumer Reportshttps://www.consumerreports.org/vpn-services/vpn-testing-poor-privacy-security-hyperbolic-claims-a1103787639/Read on

  • S-VPN-ADS

    Studies of selected consumer VPN websites and influencer advertising found repeated exaggeration of what the product protects against.

    The CHI 2025 study went through 302 web pages from 78 providers in five countries. A separate IEEE S&P 2022 study looked at influencer marketing on YouTube and found systematic exaggeration of what the product protects.

    The same line of research found that even users who understand security overestimate how much protection they get, on the strength of the advertising.

    ACM CHI 2025; IEEE Symposium on Security and Privacy 2022https://dl.acm.org/doi/10.1145/3706598.3713980Read on

  • S-VPN-ASA

    The United Kingdom's advertising regulator found that a VPN advertisement caused unjustified fear and distress, and banned it from appearing again.

    The ruling is dated 20 April 2022. The ASA found the advertisement to be “excessively violent, threatening and distressing to the extent that it overshadowed any attempt at humour”, and told the advertiser to make sure its future advertisements do not cause fear or distress without justifiable reason.

    The ruling concerns how the advertisement was presented. It does not assess the technical protection of a VPN service.

    Advertising Standards Authority (ASA), United Kingdomhttps://www.asa.org.uk/rulings/surfshark-ltd-a22-1143696-surfshark-ltd.htmlRead on

VPN services

  • S-FTC-VPN

    A VPN app routes traffic through the provider's servers. It may encrypt the section between the device and the VPN server and change the apparent origin of traffic, but it does not make the user anonymous.

    A VPN routes traffic through servers controlled by its provider. An encrypted VPN connection limits what a local wifi network or internet provider can see about the contents of that traffic.

    The service does not make the user anonymous. Some trust shifts to the VPN provider, which may handle traffic and share information under its own terms.

    Federal Trade Commissionhttps://www.ftc.gov/business-guidance/blog/2018/02/market-vpn-appRead on

Warranty and liability for defects

  • S-KKV-TAKUU

    Giving a warranty is voluntary for the seller, and the statutory liability for defects continues after the warranty ends. A warranty has to give the buyer more than the law already gives.

    A warranty is voluntary, but it cannot restrict statutory liability for defects. The end of a warranty does not end liability for a defect in the item.

    The law does not tie the duration of the liability for defects to a number of years. It follows from how long a comparable item can reasonably be expected to last.

    Kilpailu- ja kuluttajavirasto (KKV)https://www.kkv.fi/kuluttaja-asiat/tietoa-ja-ohjeita-yrityksille/kuluttaja-asiamiehen-linjaukset/virhevastuu-ja-takuu-kulutustavaran-kaupassa/Read on

Wi-Fi settings

  • S-APPLE-WIFI

    Apple recommends WPA3 or WPA2/WPA3 transitional mode. Hiding a network name does not secure the network and can create privacy and compatibility problems.

    The guidance describes WPA3 Personal as the newest option, WPA2/WPA3 Transitional as the compatible choice for older devices, and WPA2 Personal (AES) as appropriate when newer modes cannot be used. WPA/WPA2 mixed mode, TKIP, WEP and open networks are listed as settings to avoid.

    An SSID is the visible network name. The guidance says to leave hiding disabled because it does not prevent detection or unauthorised access.

    Applehttps://support.apple.com/en-us/102766Read on