Social media allows us to instantly connect with friends, family, colleagues, brands, celebrities and more. Over 4.55 billion people now use social media worldwide. However, social media also comes with risks, especially around privacy and security.
As a cybersecurity expert with over a decade of experience in cloud data security, I‘ve seen how small mistakes on social media can lead to huge problems. In this post, I‘ll provide 7 practical tips to enhance your social media safety. I‘ll also highlight some of the most secure and private social media apps available in 2024.
Contents
7 Ways to Stay Safe on Social Media
Social media scams and hacking are on the rise. According to the FTC, social media scams have increased over 1,000% since 2017. Here are 7 ways you can protect your privacy and security when using social media:
1. Use Strong Passwords
Weak passwords are one of the easiest ways your social media accounts can get hacked. Cybercriminals use automated tools to guess weak passwords in minutes.
Here are some best practices I recommend to strengthen your social media passwords:
-
Use different passwords for each social media account. Password reuse is very dangerous – if one account is compromised, they have access to all your accounts.
-
Make passwords long, complex and unpredictable. I advise using at least 12 characters mixing upper and lower case letters, numbers and symbols. The longer the better.
-
Consider using a password manager like LastPass or 1Password to generate and store unique strong passwords. This prevents password fatigue or the need to write them down.
-
Enable two-factor authentication (2FA) which adds an extra layer of security to your logins. 2FA requires providing your password plus an additional verification like an SMS code or authentication app.
According to Microsoft, enabling 2FA stops 99.9% of account hacks even if your password is compromised.
Tips for Creating Stronger Passwords
When creating passwords, avoid obvious things like dictionary words, names, birthdays or phrases that could be easy for hackers to guess.
Some tips:
-
Use randomness – mix random words together along with numbers and symbols
-
Utilize password generators to quickly create unpredictable passwords
-
For hard to remember passwords, use memory techniques like creating an acronym
The key is avoiding predictable passwords that could be guessed while also keeping your passwords safely stored and organized.
2. Adjust Your Privacy Settings
I recommend reviewing the privacy settings on each of your social networks and adjusting them according to your comfort level. Settings to check include:
-
Who can see your posts and profile information like your bio, location, birthdate, phone number, email address, etc. Lock this down to the most private settings.
-
Who can lookup your profile or contact you using just your name, email or phone number. Disable this.
-
Options like allowing your posts and photos to be shared publicly or reshared by others. Turn these off.
-
Location tracking settings on your mobile device. Disable location services for your social apps.
-
Ad targeting preferences that profile you based on your usage. Opt out of ad targeting.
-
Face recognition settings that identify you in photos. This helps protect your privacy.
Adjust these privacy settings to be as restrictive as possible. According to a Pew Research study, 74% of social media users have actively taken steps to hide their profile or posts from specific people.
3. Be Wary of Links
Malicious links are commonly used in social media scams and hacking attempts. Some tips for identifying suspicious links:
-
Don‘t click links from strangers. Verify the source first before clicking.
-
Hover over any link to preview the actual URL before clicking. Watch for odd links or URL misspellings.
-
Use a URL scanner like VirusTotal to analyze any sketchy links before visiting them.
-
Enable link preview options in apps like Twitter to see what‘s actually behind a link.
-
Have an antivirus app installed to detect malware hidden in links. I recommend Webroot, Avast or Malwarebytes.
Also be cautious about entering your login credentials on websites. Double check that any login screen matches the official site and has valid HTTPS security certifications before entering your password.
Finally, look out for shortened links which hide the underlying URL. Expand them first using preview tools to view the destination.
4. Limit Personal Information
A key social media safety tip is being judicious about the personal information you share online. This data can be used against you in targeted social engineering attacks.
According to studies, the average social media user shares their full date of birth, phone number and even bank details which expose them to identity theft.
-
Avoid sharing your address, phone number or email openly online.
-
Never share your social security number, credit card information or financial account numbers publicly.
-
Be vague about birthdates, only sharing the month and date. No need to publicize your full year of birth.
-
Consider using a city or region instead of sharing your exact address.
-
Think twice before posting vacation plans publicly when away from home.
The more private you keep your personal information, the better. Always ask yourself – does this really need to be posted publicly?
5. Beware of Social Media Scams
Scams on social media are rampant and are designed to manipulate you into sharing personal information or financial details.
Here are some common social media scam tactics I see:
-
Fake notifications about your account being compromised, disabled or needing to be verified. The notification prompts you to click a link or provide your login credentials.
-
Posts pretending to be someone you know in distress and in need of money.
-
Investment opportunities or crypto giveaways that seem too good to be true.
-
Messages requesting donations to fake charities or causes, often using fake accounts that impersonate real people or organizations.
-
Posts promoting coupon codes, free gift cards or prizes when you fill out a survey that asks for financial information.
If something seems even slightly suspicious, use common sense precautions before acting. Verify using a known alternate method of communication first. And never share personal financial information through unsolicited social media messages.
6. Limit App Permissions
Here are some key tips related to social media app permissions:
-
When you install an app, it may request access to data like your profile, contacts, photos, location and more. Only allow what is absolutely necessary for that app‘s functionality.
-
Social media apps do not need permissions to access contacts, camera, microphone, location or other unnecessary data in most cases. Deny these.
-
Periodically review approved app permissions and remove access for any that seem excessive or unnecessary.
-
Be very selective about third-party apps that plug into networks like LinkedIn, Facebook or TikTok. Only install reputable apps from recognized developers. Look for a high number of users and positive reviews.
-
Revoke permissions and delete any unused apps that may still have access to your profile data.
7. Monitor Your Online Reputation
I recommend occasionally Googling yourself to check your overall social media footprint across platforms. Look for:
-
Any accounts opened in your name that you did not create. Social media makes it easy for someone to impersonate you.
-
Suspicious posts or messages that you did not write. A sign your account may be compromised.
-
Other signs of potential identity theft – new addresses, jobs or names associated with your details.
-
Images of yourself posted publicly without your knowledge or consent.
This allows you to catch any suspicious activity and address it quickly by reporting the account or content and deleting it.
According to studies, over 80% of people have no idea how easy it is to find their personal information online. So being proactive protects your online reputation.
Safest Social Media Apps and Platforms
Now let‘s review some of the most secure, private and reputable social media apps available based on their privacy protections and security features.
Signal – Most Secure Messaging App
Signal is widely considered the most secure messaging app thanks to its use of end-to-end encryption. With end-to-end encryption, messages can only be read by the sender and recipient. Not even Signal itself can access the decrypted message contents.
Some other advantages of Signal include:
-
Disappearing messages: Set a timer for messages to be automatically deleted from a recipient‘s device after a period of time. Reduces evidence and improves privacy.
-
Sealed Sender for anonymous messaging: Messages are anonymized so the recipient does not see your name or number. Ideal for whistleblowers.
-
Minimal metadata collection: Signal does not store user contacts, social graphs, movements, relationships or chat timestamps.
-
Open source software: Signal‘s code is open source meaning it can be inspected and audited by independent experts.
Signal received top marks in a privacy evaluation by the Electronic Frontier Foundation. And it‘s trusted by security experts including Edward Snowden. For the highest levels of privacy, Signal is unmatched as a secure communication platform.
How Does Signal‘s Encryption Work?
Signal uses an advanced end-to-end encryption protocol called Signal Protocol to secure all messages. Here are some of the key features:
-
Each message is encrypted with a one-time key so no two messages use the same key.
-
The encryption keys are generated on and never leave your device. Keys are exchanged securely between devices.
-
By default, messages are stored minimally and encrypted on your device. Signal cannot decrypt them.
-
Voice and video calls are also fully end-to-end encrypted for privacy.
Signal‘s encryption implementation is open source and regularly audited for safety, unlike closed competitors like WhatsApp.
Wickr Me – Ephemeral Messaging
Wickr Me is another favorite messaging app among security researchers, experts and journalists. Like Signal, it uses end-to-end encryption to secure your messages and calls.
Some key advantages of Wickr Me:
-
All messages are encrypted with advanced cryptographic protocols according to the company. Voice, video and file sharing is encrypted.
-
Ephemeral messaging causes all messages to be automatically deleted from devices after a preset timeframe. This leaves no forensic evidence.
-
No personal information required. You can sign up with just a username. No phone number needed.
-
Wickr generates revenue through enterprise services and claims it has zero interest in collecting, selling or monetizing user data.
For privacy advocates who want ephemeral messaging between trusted contacts, Wickr Me is a top choice.
Mastodon – Open Decentralized Network
Mastodon has been gaining momentum as an open, decentralized and privacy-focused alternative to Twitter. It is a non-profit federated social network built on open source software.
Some of the key privacy advantages of Mastodon include:
-
Decentralized network: Rather than one platform like Twitter, Mastodon is built on independent community-run servers joined together in a federated network. This means no central authority owns your data.
-
Granular privacy settings: You have more control over who can interact with or view your content compared to Twitter. Post privacy is configurable.
-
No ads: Mastodon is ad-free, so your data is not sold to or analyzed by advertisers.
-
No algorithm manipulation: Mastodon shows posts in chronological order without algorithms controlling reach or recommendations.
While smaller than mainstream networks, Mastodon offers a promising and ethically designed alternative social network.
Mastodon User Growth
Since its creation in 2016, Mastodon has experienced steady growth as users look for less commercialized social media options:
-
By 2017, Mastodon had gained over 1 million users.
-
By 2021, active monthly users exceeded 2.2 million people with 6 million posts per month.
-
In April 2022, Mastodon saw a viral spike from Twitter users and gained nearly 1 million users in that month alone bringing the total to over 3.1 million monthly active users.
While a fraction of Twitter‘s user base, Mastodon shows that decentralized social networks are gaining interest from privacy proponents.
DuckDuckGo – Mobile Privacy Protection
While DuckDuckGo is best known for private web search, their mobile apps provide all-in-one privacy protection for phones and tablets.
For example, DuckDuckGo‘s apps can:
-
Block hidden third-party trackers that follow you around the internet from collecting your data. This prevents targeted surveillance advertising.
-
Provide "app tracking protection" across your device to block shady SDKs and analytics gathering within apps.
-
Offer private messaging with end-to-end encryption to contacts.
-
Generate virtual email addresses to protect your personal inbox from spam.
-
Encrypt internet traffic when possible via HTTPS using a secure VPN connection.
According to researchers, the average mobile device contains over a dozen third-party trackers collecting user data. DuckDuckGo can stop them for enhanced mobile privacy.
Putting Social Media Privacy Tips into Practice
The internet and social media provide great ways to stay connected and express ourselves. However we must balance the benefits with the need for privacy, security and responsible usage.
Putting even some of these social media safety tips into practice can make a big difference. As social media usage continues to grow worldwide, it‘s more important than ever to be proactive about protecting your personal data and online presence.
I hope these detailed security recommendations provide a helpful starting point to manage your privacy on social platforms. Please reach out if you need any assistance further locking down your social media presence and accounts.
Stay safe online!
