The Data You Hand Over

What is the safest data to have in a breach?

The idea

Every optional field, permission and connected app widens what is held about you and who holds it.

In the real world

Granting full contact access to an app that only needed a photo.

Going deeper

You cannot control how well a company protects data, and you can control how much of it they hold. Data never provided cannot be leaked, which is the only protection that does not depend on someone else's competence.

The practical surface is optional fields, app permissions and connected accounts. Each is granted once, in a moment where the goal is getting something working, and then persists indefinitely. Reviewing the permissions on one app usually finds several that are unrelated to what it does, and revoking them costs nothing.

Where it stops applying

Some data collection is genuinely necessary for a service to function, and minimalism can degrade the product. The target is the gap between what is needed and what is requested.

Why it matters

You cannot control how well a company protects data you chose not to give it.

Try this today

Review the permissions on one app and remove any it does not need to function.

Test yourself

A service is breached and one user is far less exposed than others with identical accounts. What did they most likely do differently?

Show the answer

Supplied less: skipped optional fields, declined unnecessary permissions, and did not link other accounts. Data never provided cannot leak, which is the only protection that does not depend on the company's security being good.

Learn this in the feed Answering from memory, then again days later, is what makes it stick.

More in Security, Privacy & Scams

Not All Second Factors Are Equal Verify Out of Band What Public Wi-Fi Can See People Are the Attack Surface Updates Close Known Doors Reuse Is the Real Risk

All Security, Privacy & Scams lessons