The Everyday Safety Signals I Used to Trust Without Question
The Everyday Safety Signals I Used to Trust Without Question
For a long time I navigated the internet using a handful of quick mental shortcuts, a padlock icon here, a familiar name there, a password-protected wifi network somewhere else, and I treated each one as proof that I was safe. None of them are actually proof of anything on their own, and realising that changed how I approach basically every online decision I make now. These aren't the dramatic, obviously-dodgy scenarios everyone already knows to avoid, they're the small everyday signals that feel reassuring but don't actually hold up once you look at what they're really telling you.
The Padlock Icon Isn't the Safety Check I Thought It Was
I used to treat the little padlock next to a web address as a shorthand for "this site is safe," and for years that felt like a perfectly reasonable rule of thumb. What that padlock actually confirms is that the connection between my browser and the site is encrypted, nothing more. It says nothing about whether the site itself is genuine, well-intentioned, or run by someone trying to steal my card details. Scam sites can get that same padlock just as easily as a legitimate bank can, setting up encryption is a basic, cheap step that any site owner can take regardless of what they're actually doing with the page. Now I treat the padlock as the bare minimum I'd expect from any site, not as a signal of trustworthiness, and I look at the actual web address and the site's behaviour instead.
Why "Deleted" Rarely Means Actually Gone
I used to assume that once I deleted a message, a photo, or a post, it had genuinely disappeared, and I made decisions based on that assumption more than I'd like to admit. In reality, deleting something from your own view usually just removes it from your own view. Messages can already be screenshotted or forwarded before you delete them, cloud backups can retain a copy you never see, and platforms often keep data in some form for far longer than the delete button implies. I've stopped thinking of "delete" as an undo button and started thinking of it as closer to "hide," which changes what I'm willing to send or post in the first place. If something isn't fine existing somewhere I can't control, I don't send it, because the delete option was never the safety net I assumed it was.
A Message From Someone I Know Isn't Automatically Safe
This is the one that genuinely unsettled me the first time it clicked, because it undermines a signal I'd trusted my entire life without thinking about it. A message from a contact whose name and photo I recognise feels inherently safe, it's someone I already know, so my guard naturally drops. But an account being compromised doesn't change how it displays to everyone else, it still shows the right name, the right photo, sometimes even the right writing style if the attacker has seen enough of that person's messages. A link or urgent request from a genuine contact's compromised account looks identical to a message from that person, right up until you act on it. I've written separately about the verification habits I actually rely on whenever I suspect something might be an AI-assisted scam, which covers exactly this kind of situation, where the sender looks completely legitimate but the request itself is the actual red flag.
A Password on the Wifi Doesn't Mean the Connection Is Private
I spent a long time assuming that if a wifi network asked for a password, that password was doing something meaningful to protect my data once I was connected. A password-protected network keeps random strangers off that specific network, but it doesn't necessarily encrypt what I'm doing once I'm on it, and it says nothing at all about who else set up that network or what they can see from their end. Plenty of cafes and hotels hand the same password to every single customer, which makes it barely different from having no password at all in terms of actual privacy between users on that network. Since realising this, I run a VPN automatically any time I connect to a network I don't control, NordVPN encrypts my traffic regardless of what the network itself is or isn't doing, which means the password on the wifi stops being something I have to trust at all.

The "Nothing to Hide" Mindset That Quietly Backfires
I used to brush off a lot of privacy advice with the thought that I don't really have anything worth hiding, so it didn't feel like it applied to me. The problem with that mindset is that it's not really about hiding anything, it's about what someone else can do with information about you once they have it, regardless of how boring or embarrassing you think that information is. Your daily routine, who you bank with, where your kids go to school, none of that is secret exactly, but all of it is useful to someone trying to impersonate you, target you, or build a convincing scam around details that feel too mundane to protect. I stopped asking myself whether I had anything to hide and started asking what someone could actually do with a given piece of information if they had it, which turned out to be a far more useful question.
Every one of these assumptions felt completely reasonable at the time, which is exactly why they're worth naming individually rather than lumping under one vague idea of "being careful online." A padlock that only proves encryption, a delete button that only hides rather than erases, a familiar name that can belong to a compromised account, a wifi password that protects the network rather than the connection, and a nothing-to-hide mindset that misses the actual point of privacy. None of these require any technical skill to understand once you see past the shortcut, just a willingness to ask what a signal is actually telling you rather than what it feels like it's telling you. I've covered some of the more commonly known assumptions separately if you want the wider list alongside these, and if something ever looks off and you want to report it, Action Fraud is the right place to flag a scam message or site in the UK. My free Safety Toolkit covers the practical steps I'd recommend for putting all of this into practice.
