12 steps you can take right now to be safer online

There's a fundamental question you can ask of both the internet and real life: "How do I enjoy my time here without taking unnecessary risks?" In grass-touching meatspace, you can cut out processed foods, carry pepper spray and avoid skydiving without a partner.

But the best methods for staying safe online aren't as intuitive. The internet is a massive town square where people are constantly bellowing deeply personal facts about themselves. It's no surprise that it's become a breeding ground for scams, theft and other criminal activity.

Given the breadth of dangers, it may feel easier to throw up your hands and say that whatever happens will happen. I'm here to tell you, though, that cybersecurity doesn't have to be complex, difficult or time-consuming. You don't need to be a hacker to foil a hacker — you only have to take advantage of simple tips and free apps designed to make you safer online. Whether you commit to all 12 detailed here or only focus on one, you'll be much more secure for it.

One of the most important things you can do to ensure your digital security is to install all software updates as soon as they become available on your devices. When you see the notification, don't wait — train yourself to download the update immediately.

Not all software updates are about security, but the ones that are form your best line of defense against technical hacks. When developers discover a flaw that can be exploited, they ship an update to fix it. By the time the flaw gets patched, chances are very high that hackers also know about it, so any time lost means you could be the next to get exploited.

As you go down this list, you'll learn that cybersecurity threats are less technical than you think. To counter the ones that are, however, there's nothing more important you can do than install security updates.

Weak, easily guessed passwords are one of the most frequent causes of data breaches and malware attacks. If a password is one of the ten or so most common, an attacker may be able to guess it with no other information. If it's connected to you — your birthday, say, or mother's maiden name — it may be guessable from information anyone can look up online.

Even if your password is a random string of characters, it might still be guessable if it's too short. Hackers can use programs to guess all possible combinations and try each one on a target account. The longer a password is, the more exponentially difficult it is to guess.

Close up on screen of website sign in button
SEAN GLADWELL via Getty Images

That means you need passwords that are both long and meaningless to you. You might rightly complain that these are bastards to remember, but you're in luck: password managers can do that for you. A password manager app or browser extension can create passwords when you need them, store them securely and fill them in automatically. All you have to remember is the one master password that unlocks all the others.

Even the strongest password might get revealed through no fault of your own, like if it's stored without encryption and leaked in a data breach. That's why it helps to have two-factor authentication (2FA), also known as multi-factor authentication (MFA), as a second secure layer on every account.

You probably already know 2FA as the irritating extra step that makes you go get your phone — but that's not the only way to do it. Many apps, including Google and Apple, now let you log in through passkeys. These not only don't require you to enter a code or password, but use asymmetric encryption, sharing credentials between your device and the service that runs the passkeys. It's a lot quicker for you, and leaves nothing to steal.

Ransomware and its cousins are a growth industry within the cybercrime economy. These attacks corrupt your files or lock you out of them until you pay a fee to get them back. The easiest way to foil a ransomware attack, or to clear any other kind of malware off a device, is to restore the entire system from the most recent backup.

To make sure you actually have a backup, experts recommend the 3-2-1 rule: three different backups, on two different types of storage, with at least one physically distant from the main system. For example, you could have one backup on another device in your house, one in the cloud and one on a portable hard drive. Automatic backup services can save disk images for you at set intervals so you don't have to remember to do it yourself.

Despite all the technobabble flying around the cybersecurity world, a great many scams and hacks are accomplished through methods a 19th-century con artist would recognize. Scammers pose as experts or authority figures to gain your trust, and use frightening language to bypass your critical thinking. Ticking clocks, emotional manipulation and fake identities are all in the toolbox.

Bank fraud through phone messages.Businessman holding phone with scam message on digital screen. Fake text SMS scam.Scammers online.Cyber scam
Alex Cristi via Getty Images

Take phishing, in which hackers trick you into giving up your information willingly. A typical phishing email might pose as a bank, credit bureau or other authoritative service. In red letters, it may demand your bank password or social security number to immediately fix an irregularity with your account. Other common approaches include warning you about speeding tickets you never incurred or sending receipts for subscriptions you never bought.

Social engineering attacks are constantly evolving, but they often fall back on the same strategies. The best way to foil them is to take a deep breath every time you receive a frightening email or text message, then research it in detail: look up the email address, check the visual design to make sure the sender is who they claim to be, and ask yourself if there's any way the message could be true. I highly recommend working through this phishing quiz — it's tough, but fair, and extremely educational.

This is a companion to the previous tip. Social engineering scams don't always try to get you to give up information yourself. They also get you to click on links that put secret malware on your device — like keyloggers that watch you type your passwords or ransomware programs that corrupt your files.

If you're ever not sure about an email attachment or a link you're being asked to click, copy the link (without opening it) and paste it into a URL checker like this one from NordVPN. These free tools can tell you if a link is associated with any known malware domains.

URL checker
Sam Chapman for Engadget

You can also mouse over any link, then look at the bottom-left of your browser to see what URL it will take you to. If an email is from your bank, any links within it should go to your bank's website. If it's going anywhere else, especially to an unidentifiable string of characters, be suspicious.

A related tip is to never copy and paste something into your URL bar if you aren't absolutely sure of what it will do. Social engineering doesn't always get you to click the link — sometimes attackers leave it un-hyperlinked so mousing over it doesn't reveal anything. This also goes for the command modules on desktop and laptop computers. In a recent documented attack, hackers convinced AI chatbots to suggest a command that gave them root access to the victim's device. Never copy-paste anything into the command window without verifying it first, especially if an AI told you to do it.

Over the last two decades, lots of us have gotten into the habit of dumping all sorts of personal information on social media. This trend has supercharged the scam economy. It may seem harmless to broadcast the names of your kids or the dates you'll be on vacation, but every piece of data you put into the world makes it easier for a stranger to get hooks into you.

For example, "grandparent scams" are on the rise right now. Grifters contact a target, usually a senior, pretending to be their grandchild. They'll claim to be in a crisis and need money fast. The more information they have on their target, the more convincing their tale of woe will be. Social media is a prime place to study a potential victim.

Oversharing can also be a compounding problem. If you use weak passwords, your public information can be used to guess your credentials or answer your security questions. So, if you don't have a password manager yet, think twice before you engage with that quiz post on Facebook that asks for the name of your childhood pet.

I'm a big booster of virtual private networks (VPNs), but it's important to be realistic about what they can and can't do. Even the best VPNs aren't total cybersecurity solutions — you can't just set one and assume you're safe forever. A VPN can't protect you if you use easily guessed passwords, for example, or click on a malware link. It's about hiding your identity, not making you invulnerable.

So what can a VPN do? In short, it replaces your IP address (a fingerprint that identifies you online) with another IP address, belonging to a server owned by the VPN. The VPN server does business with the internet on your behalf, while its conversations with your device are encrypted so it can't be traced back to you.

Proton VPN's app for Windows.
Sam Chapman for Engadget

This means no third party can connect your online actions with your real-world identity. Nobody will be harvesting data on the websites you visit to sell to advertisers, nor building a file on you that an unscrupulous government might misuse. VPNs also protect you from fake public Wi-Fi networks set up by cybercriminals — even if a hacker tricks you with a man-in-the-middle attack, they can't do much without your real IP address.

Many top VPNs, including my top pick Proton VPN, include ad blockers that can also keep cookies and tracking pixels from latching onto you. So, even if a VPN can't do everything, you'll be far safer and more private with one than without one. If you don’t want to pay for a new subscription right now, I've also compiled a list of the best free VPNs that are actually safe to use.

The most important time to look for malware is when you're downloading a file from the internet. Not only can unwanted apps hitch rides on seemingly safe files, but links can start downloads in secret, even if you don't think they're meant to be downloading anything. A solid antivirus program can catch malware as it arrives on your system, and if it's uncertain, can lock suspicious files in quarantine until it knows whether they're safe or not.

Dedicated antivirus apps are sometimes even capable of catching malware that hasn't been seen or used yet. AV software uses machine learning to identify the common patterns of malware, filtering out new viruses that behave like old ones.

But what about malware that's already gotten through the perimeter? An antivirus app can also check your computer at set intervals in search of unwanted apps, including those that might be masquerading as system files. Windows computers now come pre-installed with Windows Defender, which is enough to handle most of these tasks, but I recommend at least one anti-malware program on any device.

If you're concerned about your information being misused or mishandled, remember that the less you put out into the world, the less danger you're in. Keeping your private data off social media is one important step, but there are other ways your data gets disseminated — and other options for responding.

For example, you often need an email address to sign up for an online account. If you use your real email, your contact information is now floating around online, increasing the chance of someone using it to scam you (or at least adding you to mailing lists you never signed up for). To stay safe, use an email masker. These services give you a fake email address you can use to create accounts, which automatically forwards messages to your real address.

DuckDuckGo
Sam Chapman for Engadget

Search engines, especially Google, are also notorious for building profiles on users by watching the terms they search for. You can dodge that by switching to a private search engine like DuckDuckGo, which doesn't track anything you do — it's funded by non-targeted ad sales on its search results pages, not by selling your data to brokers.

Speaking of data brokers: unfortunately, if you've been on the internet at any point in the last 10 years without taking intense precautions, your data is probably in the hands of at least one business that makes money by hoarding and selling it. These data brokers range from public-facing, people-search sites to private backend dealers.

Data brokers are poorly regulated and lax about safety. The longer one has your personal information, the more likely it is to leak. The good news is that most brokers (though not all of them) are legally required to delete your data if you ask them to.

However, there are a lot of data brokers out there, and they really want to keep your data. Each one makes opting out harder than uninstalling a Norton product — and hundreds of them may have files on you. To make the process easier, you can use a data removal service like DeleteMe or Surfshark VPN's partner service Incogni.

Let's close out the list by getting a little old school. I've already discussed how many online scams depend on classic con artistry to work. By the same token, physical infiltration and smash-and-grab tactics still pose a threat to cybersecurity.

It doesn't take too much imagination to see how this could work. If you leave your laptop or phone unattended in public, for example, someone might insert a flash drive that loads malware onto the system. In one illustrative case, a thief in the Minneapolis area would loiter in bars, watch people unlock their phones, then steal those phones and unlock them himself.

I'm not saying you need to be paranoid every second you're in public. Just use the same level of caution you'd use to protect your car. Lock your phone with a biometric key so only you can open it, and make sure not to leave any device lying around if it can access your online accounts. And at work, be careful not to let anyone into a secure area if they don't have the proper credentials.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/12-steps-you-can-take-right-now-to-be-safer-online-130008335.html?src=rss

Lego Black Friday deals are still live: Up to 50 percent off on Star Wars, Disney, Harry Potter and more toy sets for the biggest holiday sale

Were you a Lego set kid or a giant-bucket-of-Legos kid? I was a sets kid all the way — I loved, and still love, the zen feeling of building something incredible a little bit at a time. Also, every time I tried to build something from the giant bucket, it fell apart immediately, but let's not dwell on that. For this year's Black Friday and Cyber Monday, we're trawling the net for the best deals on Lego sets, from family-friendly tie-ins to architectural behemoths. If you've had your eye on a set but demurred due to the price, this list is for you.

It's a good idea to use a price tracker to see if you're getting the best Lego Black Friday deals. You'll find Lego bargains this holiday season at retailers like Amazon and Walmart, but don't overlook Lego's own site. If you join the free Lego Insiders program, you'll get special discounts and exclusive member gifts with each purchase, plus points you can redeem for your next set or bucket.

You can now officially backorder the hottest Lego gift of the season, the Star Trek USS Enterprise set, which was just announced. With a titanic 3,600 pieces and mini-figures of the whole Next Generation crew, it's a must-have for any Star Trek fans. The set is available for $400 starting today.

LEGO Ideas The Insect Collection 21342 for $40 (50 percent off)

LEGO Architecture New York City Model Kit 21028 for $34 (44 percent off)

LEGO Harry Potter Mandrake Figure & Pot Plant Toy 76433 for $41 (41 percent off)

LEGO Disney Frozen Advent Calendar 2025 43273 for $24 (47 percent off)

LEGO Dreamzzz Izzie's Dream Animals Toys 71481 for $24 (40 percent off)

LEGO Icons Blacktron Renegade 10355 for $54 (46 percent off)

LEGO Friends Space Research Rover 42602 for $33 (34 percent off)

LEGO City Yellow Mobile Construction Crane Building Toy 60409 for $77 (30 percent off)

LEGO NINJAGO Dragon Stone Shrine 71819 for $79 (34 percent off)

LEGO Santa's Sleigh 40499 for $25 (37 percent off)

LEGO Disney and Pixar Wall-E and EVE Building Set for Adults for $56 (20 percent off)

LEGO Classic Large Creative Brick Box 10698 for $39 (34 percent off)

LEGO Architecture Statue of Liberty 21042 for $81 (33 percent off)

LEGO Creator 3 in 1 Magical Unicorn Toy 31140 for $7 (32 percent off)

LEGO Botanicals Mini Bonsai Trees Building Set 10373 for $45 (31 percent off)

LEGO Technic & Speed Champions McLaren Racing Pack for $54 (30 percent off)

LEGO Speed Champions Mercedes-AMG G 63 and Mercedes-AMG SL 63 for $25 (44 percent off)

LEGO Harry Potter Thestral Family Building Toy 76458 for $49 (30 percent off)

LEGO Technic NASA Apollo Lunar Roving Vehicle LRV Building Set 42182 for $154 (30 percent off)

LEGO Technic NASA Mars Rover Perseverance Building Toys 42158 for $70 (30 percent off)

LEGO Icons Dried Flower Centerpiece 10314 for $35 (30 percent off)

LEGO Christmas Table Decoration 40743 for $25 (37 percent off)

LEGO Santa's Delivery Truck Building Toy for Kids 40746 for $14 (30 percent off)

LEGO City Fire Rescue Plane Toy 60413 for $38 (31 percent off)

LEGO Creator 3 in 1 Wild Animals: Majestic Rhino with Birds 31171 for $42 (30 percent off)

LEGO Star Wars: A New Hope Boarding the Tantive IV Fantasy Toy 75387 for $38 (30 percent off)

LEGO City Yellow Delivery Truck Toy 60440 for $70 (30 percent off)

LEGO Speed Champions 2 Fast 2 Furious Nissan Skyline GT-R (R34) Race Car 76917 for $17 (30 percent off)

LEGO Star Wars Millenium Falcon A New Hope 25th Anniversary Collectible Model for $68 (20 percent off)

LEGO Star Wars Brick-Built Star Wars Logo 75407 for $48 (20 percent off)

LEGO Star Wars R2-D2 Building Toy Set 75379 for $80 (20 percent off)

LEGO City Donut Truck Toy 60452 for $16 (20 percent off)

LEGO Botanicals Happy Plants Building Toys 10349 for $18 (20 percent off)

LEGO Botanicals Mini Orchid Building Set 10343 for $24 (20 percent off)

LEGO Ideas Tuxedo Cat 21349 for $80 (20 percent off)

LEGO Creator 3 in 1 Retro Camera Toy 31147 for $16 (20 percent off)

LEGO DC Batman Mech Armor Super Hero Toy 76270 for $12 (20 percent off)

LEGO Friends Autumn's Room Building Toy 42646 for $17 (15 percent off)

LEGO NINJAGO Arin's Ninja Off-Road Buggy Car Toy for $40 (20 percent off)

LEGO Super Mario Captain Toad's Camp Building Toy 72040 for $12 (20 percent off)

LEGO Technic Aston Martin Valkyrie Toy Car 42208 for $53 (19 percent off)

LEGO Harry Potter Hogwarts Castle and Grounds 76419 for $140 (18 percent off)

LEGO Art Hokusai The Great Wave Framed Japanese Wall Art Building Set 31208 for $85 (15 percent off)

LEGO Animal Crossing Kapp'n's Island Boat Tour 77048 for $20 (32 percent off)

LEGO Animal Crossing Stargazing with Celeste 77053 for $6 (36 percent off)

LEGO NINJAGO Cole's Elemental Earth Mech Mini Ninja Toy 71806 for $17 (15 percent off)

LEGO Friends Cotton Candy Stand and Scooter 42643 for $8 (15 percent off)

This article originally appeared on Engadget at https://www.engadget.com/deals/lego-black-friday-deals-are-still-live-up-to-50-percent-off-on-star-wars-disney-harry-potter-and-more-toy-sets-for-the-biggest-holiday-sale-155007472.html?src=rss

How to cancel Private Internet Access and get a refund

Private Internet Access (PIA) comes with some of the best pricing of any VPN, and often doesn't feel like a budget service. I say "often" because, sadly, it does sometimes feel like you get what you pay for with PIA. While I'm working on seeing what settings iron out the kinks, the fact is that PIA doesn't always leave you with the internet speeds you need for everyday use.

If you've found PIA unreliable, you may want to know how to end your subscription, get a refund and trade up to a more stable VPN service. Here, I'll explain how to stop your subscription from renewing, get your money back and delete your account (if you want to go that far).

Like with most VPNs, the standard way to cancel PIA is to stop your subscription from renewing at the end of the current payment period. Whether you've signed up for one month, one year or three years, you'll get to keep using the VPN until that time expires. Here's the process to follow.

  1. In a desktop or mobile web browser, go to privateinternetaccess.com. Click Login at the top of the screen.

  2. Enter your account username and password. You'll be taken to your client control panel. It should automatically load on the Subscription Overview tab, but check the left-hand column to make sure.

  3. Under the username for the subscription you want to cancel, find the "next billing" heading, then click the Turn off auto-renewal link.

  4. You'll get a message trying to convince you not to cancel. Click Turn off auto-renewal again, this time at the bottom-left of the window.

  5. Give a cancellation reason. Feel free to click "I have another reason," then enter one letter and click Continue with cancellation.

  6. Finally, the site will offer to connect you with tech support instead of cancelling. Hold the line and click Turn off auto-renewal once more.

PIA subscription overview
Sam Chapman for Engadget

After fighting through all that, you should get confirmation that your account won't renew when the billing period expires. You've now got the rest of the term to look for a new VPN.

Note that if you first download PIA from the Google Play Store or Apple App Store, you may have purchased your subscription directly through the app. In this case, your subscription will be managed by the app store you bought it through, and you'll need to go there to cancel. Just open your profile, tab the subscriptions heading and scroll down to find PIA.

If you're certain that you're done with PIA, you may want to go the extra mile and delete your account altogether. You can do this by submitting a support ticket. Go to helpdesk.privateinternetaccess.com, scroll down to the bottom of the page and click on Contact Us under the Resources heading (near the middle of the page).

PIA support ticket
Sam Chapman for Engadget

Write a clear, direct message. Feel free to use the above screenshot as an example. To get help faster, you can also use live chat — just go to the main PIA website, then click the button at the bottom-right that reads Need Help? Chat with us! This will get attention on your case right away, but you'll have to defeat an AI assistant first.

PIA only gives refunds within the first 30 days after purchase. If you're within that window and want your money back, start by cancelling auto-renewal, then send a support ticket or contact live chat as described in the previous section. Say you are requesting a full refund under the money-back guarantee. Stick to your guns, as they'll probably try to convince you not to go.

If you still need a VPN after cancelling PIA — and you almost certainly do if you ever go online — Engadget has a list of the best VPNs to help you with comparison shopping. As a quick summary, Proton VPN is the all-around best service. ExpressVPN is pricey, but gives you great speeds and excellent app design. If you need consistently fast speeds every time, go with Surfshark.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/how-to-cancel-private-internet-access-and-get-a-refund-030034510.html?src=rss

The best free VPNs in 2025

A good VPN is worth paying for. Almost every service I'll recommend as one of the best VPNs is either subscription-only or supported by paid plans. Free VPNs do have their place, though, as not everybody can afford yet another subscription in the software-as-a-service hellscape we live in. Since everyone deserves privacy and flexibility online, I wanted to put together a definitive list of the best free VPNs.

Now, some will say that free VPNs are, by definition, security risks that are to be avoided by default. That reputation exists because free VPNs often really are a risk. As proliferating age verification laws have created a need for VPNs, some free services have stepped up to answer the call, while others have taken advantage of it to spread malware. Free VPNs are easy for scammers to set up and hard for app stores to catch. I never recommend using one without doing thorough research.

To that end, the three providers on this list are exceptions to the risk of free VPNs. While they all have tradeoffs, they're also upfront about what they do and don't do. Each one comes with reliable security, a clean record of handling user data and apps that never force you to upgrade just so they'll work properly. They aren't the only good free VPNs, but they're the top three by far.

Editor's note: This list represents our ranking as of October 2025. We intend to revisit the list every three months at a minimum, at which time our picks may be adjusted based on changes in features, testing results and other factors.

The first three no-cost VPNs mentioned here are worthy of recommendation in their own ways, but didn't quite make the cut for our top picks. I've left notes on them here in case one of them turns out to be perfect for you, and because they're on my list for induction into the free VPN pantheon if they improve.

None of the above applies to Hotspot Shield, which you should not use. It's on here as a warning. You can find more details in that section below.

PrivadoVPN is a strong enough contender that I seriously considered adding it to the list as my fourth official recommendation. It's technically unlimited, though once you use 10GB of data, it sharply handicaps your speed for the rest of the month. Free users can choose between 13 server locations on four continents. It even performs well on worldwide latency tests, though download speeds swing pretty heavily.

That uncertain speed stat kept Privado out of the winner's circle, as did one other concern: although it has a clear and extensive privacy policy, it's never gone through a third-party audit. Additionally, it's a newer service, having only launched in 2019 — so it's harder to make claims about its business practices.

Finally, while hide.me, Windscribe and Proton VPN all retain their excellence on the paid plan, PrivadoVPN isn't as worth paying for. Outside the free plan, it's a decent VPN with no reason to pick it over Proton or ExpressVPN. That said, if it passes an audit — or faces a real-world test of its no-logs policy, like a server seizure — look for Privado to join the big leagues soon.

TunnelBear does free VPN service well — it just doesn't do enough. Trust me, I don’t take pleasure in criticizing its adorable, hole-digging bear mascot, which goes a long way toward making the app welcoming to beginners. I like that its free plan offers access to the entire server network, the only VPN that does so.

But the hard fact is that 2GB of data per month is not enough to do much of anything. With such a low data limit, TunnelBear's free plan is an enticement to upgrade to its paid service, not a viable VPN solution in its own right. That really is a good bear, though.

EventVPN, developed by the ExpressVPN team, was launched a month ago and could one day become an outstanding free VPN. However, given its bizarre decision to run ads in the app, I can't endorse it right now.

Were EventVPN not associated with ExpressVPN or Kape Technologies, I might defend its decision to show ads by pointing out that all ad tracking data is anonymized — there isn't even a backend in which to store it. That might be a decent way to fund a full-featured free VPN. But EventVPN is openly part of a lucrative VPN portfolio, and has its own paid tier, so there's no excuse for the 30-second video ads.

Hotspot Shield was once the poster child for free VPNs; today, it's become one of the clearest illustrations of why they're dangerous. You get 500MB of browsing data per day, which is reasonable, on par with Windscribe's best offer. However, not only does the free version cap speeds at 2 Mbps, but it also restricts you to one location, the United States.

Worse, it shows you ads. Unlike EventVPN, which at least limits itself to ads from a single service, Hotspot Shield lists no fewer than eight ad coordinators in its privacy policy. One of them is Meta, which you should never, ever trust with any sensitive data. I can't name a better textbook example of "if the product is free, you're the product."

Selecting a VPN is hard enough with all the competition out there, but with a free VPN, the stakes are even higher. Free VPNs are all over the place, and app stores don't vet them effectively. You're left on your own to determine whether a free VPN is mediocre, exploitative or even a straight-up malware vector.

My top three recommendations — hide.me, Windscribe and Proton VPN — are clean. If you choose to use another one, here are the red flags to consider.

Security: First, make absolutely certain the free VPN isn't a threat to your security. Research it to see if any experts have warned against it, and check to make sure it uses known and approved encryption protocols (OpenVPN, WireGuard, IKEv2 or an equivalent). If you have an antivirus program, download the VPN in sandbox mode so you can scan it while it's quarantined.

Privacy: Read the free VPN's privacy policy in detail to see if it claims any liberties with your personal data. As a rule, never use an "ad-supported" free VPN, since almost all ad services track users for targeted campaigns. Other free services, like Hola VPN, make money by selling user IP addresses as residential proxies. Be alert for any indication that the VPN will profit off your personal data.

Usage requirements: If you've determined a free VPN is safe and secure, your next step is to make sure you'll be able to use it for the tasks you have in mind. Most reputable free VPNs are limited in some way. Match the restrictions to what you need; for example, if you want a free VPN for streaming, pick one without data caps that lets you choose your own server location.

Speed: Even if it meets the minimum requirements of safety and privacy, a free VPN still needs to meet the same criteria as any paid service. Mainly, it's got to be fast. With the free VPN active, run speed tests using Ookla in several locations. On average, it shouldn't reduce your unprotected download speed by more than 25 percent.

Customer service: Some otherwise full-featured free VPNs skimp on customer service, restricting live help to paid users. Even Proton VPN is guilty of this. If you're a beginner or think you're going to need extra help, make sure to pick a free VPN with a well-written knowledgebase and available tech support.

Let's finish up with some of the free VPN questions we get most often. Leave a comment if you'd like me to answer one I haven't gotten to yet.

A free VPN is a virtual private network that's available to individual users at no cost. They generally take the form of desktop and mobile apps downloaded through websites or app stores. You can use them to filter your internet connection through another server, changing your virtual location and hiding what you do online.

Most people use free VPNs to make it appear that they're getting online from somewhere else. This gets around restrictions on internet usage in certain jurisdictions, like China's "Great Firewall" or the UK's age verification laws. It can also be used to stream TV shows and events that aren't available in the user's home region.

While free VPNs aren't inherently dangerous, the use case and underlying business model makes them an easy vector for unscrupulous companies to take advantage of vulnerable users. It's easy for a malicious actor to set one up quickly and get it hosted on an app store. Likewise, the people who download free VPNs tend to need them urgently and may not look too closely at what they're putting on their phones or computers.

As a rule of thumb, you should approach a free VPN with extreme caution. If it's not on our recommended list above, we'd suggest avoiding it. In general, it's almost always safer to seek out VPNs that support their free versions with paid subscriptions, since they don't need to make money under the table. But any VPN – or other digital service – that's put forward as totally free puts us in mind of the old adage about gambling: If you can't spot the sucker at the table, it's probably you.

I've rated hide.me as the best free VPN. Its free service gives you a lot to work with — seven free locations and a data cap that doesn't really apply in practice. It's also just as secure and trustworthy as its paid version, without skimping on anything important.

Yes — in fact, there are more free VPNs on mobile app stores than almost anywhere else. All three of my top picks (hide.me, Windscribe and Proton VPN) have apps for both iOS and Android, and nearly every other free VPN works on at least one mobile platform.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/best-free-vpn-120032818.html?src=rss

How to cancel Norton VPN, uninstall it and get your money back

Norton Security has some reliable products, but its VPN isn't one of them. In my Norton VPN review, I argued that it's only really worthwhile if you can get a discount on it as part of a Norton 360 package — and even in that case, you should only use it for non-sensitive activities due to some holes in Norton's comprehensive privacy policy.

That's a lot of conditions, so I'd understand if you're here because you've decided Norton VPN isn't for you. Read on to learn your options for cancelling this VPN, getting a refund and replacing it with a better provider.

The simplest way to cancel Norton VPN is to stop your subscription from automatically renewing. That way, you'll have until your plan expires to look for a new VPN. Note that the steps below are the same no matter how you got Norton VPN, whether on its own or as part of Norton 360 — though they only apply if you subscribed through the Norton website, not an app store.

  1. Sign into your account at my.norton.com. You'll be taken to your account dashboard with your subscriptions tab visible. If it's not, click on My Subscriptions.

  2. On your subscriptions hub, find the plan you get Norton VPN through. Click the words Manage Renewal or Cancel Subscription Renewal.

  3. In the window that appears, click Unsubscribe. Select a reason for cancellation (no need to be truthful) and click Next.

  4. At this point, you'll have to wade through several pleas for you to stay. Stand firm and keep clicking through until you can click No thanks, cancel my subscription.

  5. Continue clicking Next until you see a confirmation that auto-renewal has been turned off. Wait 24 hours for the change to take effect.

Norton subscription panel
Sam Chapman for Engadget

If you change your mind after turning auto-renewal off, you can turn it back on again anytime before the subscription expires. For those who bought through an app store, there's no way to turn off auto-renewal; you can only cancel the subscription altogether. See the end of the next section to learn how to do that.

You can request a refund on any annual subscription for 60 days after paying. Monthly subscriptions can only be refunded once, within 14 days of paying — if you renew a monthly plan then decide to cancel, you're out of luck.

The only way to get a refund is to contact Norton directly. If you're ready to go cold turkey, follow these steps.

  1. In a browser, open support.norton.com.

  2. Scroll down until you see nine buttons arranged in a 3x3 grid. Find the second button down in the left-hand column, Contact us, and click on it.

  3. Enter the email address for your Norton account. Check that inbox for a verification code, then enter it in the next box and click Verify.

  4. When the live chat asks you what you need help with, select Purchase & Billing, then Request refund. Give a reason in the dropdown menu.

  5. As usual, be persistent until you get a message in writing that your refund will be processed. Wait at least three days for the money to appear.

Contact Norton
Sam Chapman for Engadget

If you subscribed through the Apple App Store or Google Play Store, you'll have to cancel through the same platform where you started. Just go into the subscriptions page of the store's mobile app, find your Norton VPN subscription and click the Cancel button beside it. After that, just follow the prompts, then request a refund using the steps above.

To get your money back from Norton, you can't just shut off auto-renewal. You'll have to cancel your plan immediately and delete all Norton apps from your devices. I recommend following these steps even if you aren't eligible for a refund, since Norton software is notoriously hard to uninstall and will crop back up if you don't completely root it out.

On Android and iOS, uninstalling Norton VPN is relatively easy — after cancelling your subscription, delete it like you would any other app. Things are a bit trickier on the desktop OSes. On Windows, hold the Windows key and press R to make a black box appear. Type appwiz.cpl and hit Enter. A list of programs should appear; click on Norton VPN, then click Uninstall/Change and follow the instructions.

On a Mac, open your Applications folder and find Norton VPN. Click the app icon and drag it to the trash. This should start a separate program called Norton Uninstaller. Click OK, enter your password if asked, then click Uninstall. Finally, you'll need to restart your computer to finish uninstalling.

Once you've dispensed with Norton VPN, you can get started with a provider that fits your needs better. Proton VPN, my current top pick in our guide to the best VPNs, takes privacy more seriously than Norton and has superior app design and speeds. Surfshark is the fastest VPN, NordVPN has the best features and ExpressVPN is the friendliest for beginners.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/how-to-cancel-norton-vpn-uninstall-it-and-get-your-money-back-150000872.html?src=rss

Proton launches ‘Data Breach Observatory’ to track personal info leaks

Proton, the company behind Proton VPN and other encrypted apps like Proton Mail and Proton Drive, just launched a new web page called the Data Breach Observatory that aims to make accurate cybercrime data more widely accessible. The Observatory is intended to be a continually updated report that records any data leak detected on the dark web, with information sourced from the underground data marketplaces themselves.

The reason for the Observatory, according to Proton, is that too many studies of cyberattacks depend on organizations reporting when they've been hacked. A company might not make a data breach public for fear of backlash from customers, regulators or stockholders. Although it's impossible to tell how many breaches aren't reported, Proton believes it's a significant portion.

Compounding the transparency problem, most stolen data is advertised and traded on dark web markets that are hard to trace without specialized knowledge, like how diamond thieves don't tend to fence their loot at above-board jewelry stores. In other words, while most people know that personal information is frequently stolen and leaked, it's very difficult to know how much data is getting stolen, how often breaches occur and who's buying and selling the goods.

Proton's solution is to monitor the dark web itself, watching locations where data thieves go to advertise stolen information. By keeping an eye on these exchanges, Proton believes the Data Breach Observatory will be able to warn victims as early as possible, including before the targets themselves are aware of the leak. Making breach reports available in one place is also meant to educate the public about the actual size and scope of cybercrime, while making it harder for companies to keep quiet about getting hacked.

Proton plans to update the Observatory in "near real time," working with a risk detection firm called Constella Intelligence. It remains to be seen whether they'll be able to keep up the workload — according to Proton's own research, around 1,571 data breaches have occurred in 2025 so far, compromising well over 100 billion records. A clearing house for reporting on all of those definitely sounds valuable, but at around five breaches a day, it'll be a busy page.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/proton-launches-data-breach-observatory-to-track-personal-info-leaks-110047833.html?src=rss

The best VPN deals: Up to 88 percent off ProtonVPN, Surfshark, ExpressVPN, NordVPN and more

With a good virtual private network (VPN), you can stream TV shows and events from all over the world, protect your information from hackers and thwart those online trackers that watch you sleep and show you weird personalized ads. Although we strongly recommend using a VPN, you shouldn't jump on just any deal — a bit of comparison shopping goes a long way in this market. The pricing you see on VPN websites is often not an accurate portrayal of what you'll actually pay.

Even so, there are some great bargains on the table. Black Friday and Cyber Monday may be over, but lots of the best VPNs — including our top pick, Proton VPN — have end-of-year deals live that can save you anywhere from 67 to 88 percent on annual subscriptions. Most of these discounts only apply if you sign up for a year or more, but as long as you're sure you like the service, committing actually makes sense. You pay more at the start, but if you divide the cost by the months of service, it's significantly cheaper over time.

Most of the deals below follow that pattern, so make sure you're comfortable with a service before you take the plunge. Read on for the best VPN deals live this week.

ExpressVPN Basic — $97.72 for a two-year subscription with four months free (73 percent off): This is one of the best VPNs, especially for new users, who will find its apps and website headache-free on all platforms. In tests for my ExpressVPN review, it dropped my download speeds by less than 7 percent and successfully changed my virtual location 14 out of 15 times. In short, it's an all-around excellent service that only suffers from being a little overpriced — which is why I'm so excited whenever I find it offering a decent deal. This discount, which gets you 28 months of ExpressVPN service, represents a 73 percent savings. Be aware, though, that it'll renew at the $99.95 per year price.

ExpressVPN Advanced — $125.72 for a two-year subscription with four months free (67 percent off): ExpressVPN recently split its pricing into multiple tiers, but they all still come with similar discounts for going long. In addition to top-tier VPN service, advanced users get two additional simultaneous connections (for a total of 12), the ExpressVPN Keys password manager, advanced ad and tracker blocking, ID protection features and a 50 percent discount on an AirCove router. As above, note that it renews at $119.95 annually.

NordVPN Basic — $80.73 for a two-year subscription with three months free (74 percent off): NordVPN gets the most important parts of a VPN right. It's fast, it doesn't leak any of your data and it's great at changing your virtual location. I noted in my NordVPN review that it always connects quickly and includes a support page that makes it easy to get live help. NordVPN includes a lot of cool features, like servers that instantly connect you to Tor. This holiday deal gives you 74 percent off the two-year plan, which also comes with three extra months.

NordVPN Plus — $105.03 for a two-year subscription with three months free (74 percent off): In another holiday discount, NordVPN has also taken 74 percent off its Plus subscription. For only a little more, you get a powerful ad and tracker blocker that can also catch malware downloads, plus access to the NordPass password manager. A Plus plan also adds a data breach scanner that checks the dark web for your sensitive information.

Surfshark Starter — $53.73 for a two-year subscription with three months free (87 percent off): This is the "basic" level of Surfshark, but it includes the entire VPN; everything on Surfshark One is an extra perk. With this subscription, you'll get some of the most envelope-pushing features in the VPN world right now. Surfshark can rotate your IP constantly to help you evade detection — it even lets you choose your own entry and exit nodes for a double-hop connection. That all comes with a near-invisible impact on download speeds. With this year-round deal, you can save 87 percent on 27 months of Surfshark.

Surfshark One — $61.83 for a two-year subscription with three months free (88 percent off): A VPN is great, but it's not enough to protect your data all on its own. Surfshark One adds several apps that boost your security beyond just VPN service, including Surfshark Antivirus (scans devices and downloads for malware) and Surfshark Alert (alerts you whenever your sensitive information shows up in a data breach), plus Surfshark Search and Alternative ID from the tier below. This extra-low deal gives you 88 percent off all those features. If you bump up to Surfshark One+, you'll also get data removal through Incogni, but the price jumps enough that it's not quite worthwhile in my eyes.

CyberGhost — $56.94 for a two-year subscription with two months free (83 percent off): CyberGhost has some of the best automation you'll see on any VPN. With its Smart Rules system, you can determine how its apps respond to different types of Wi-Fi networks, with exceptions for specific networks you know by name. Typically, you can set it to auto-connect, disconnect or send you a message asking what to do. CyberGhost's other best feature is its streaming servers — I've found both better video quality and more consistent unblocking when I use them on streaming sites. Currently, you can get 26 months of CyberGhost for 83 percent off the usual price.

hide.me — $69.95 for a two-year subscription with four months free (75 percent off): Hide.me is an excellent free VPN — in fact, it's my favorite on the market, even with EventVPN and the free version of Proton VPN as competition. If you do want to upgrade to its paid plan, though, the two-year subscription offers great savings. Hide.me works well as a no-frills beginner VPN, with apps and a server network it should frankly be charging more for.

Private Internet Access — $79 for a three-year subscription with four months free (83 percent off): With this deal, you can get 40 months of Private Internet Access (PIA) for a little bit under $2 per month — an 83 percent discount on its monthly price. Despite being so cheap, PIA has plenty of features, coming with its own DNS servers, a built-in ad blocker and automation powers to rival CyberGhost. However, internet speeds can fluctuate while you're connected.

Practically every VPN heavily discounts its long-term subscriptions year-round, with even sharper discounts around occasions like the holidays. The only noteworthy exception is Mullvad, the Costco hot dog of VPNs (that's a compliment, to be clear). When there's constantly a huge discount going on, it can be hard to tell when you're actually getting a good deal. The best way to squeeze out more savings is to look for seasonal deals, student discounts or exclusive sales like Proton VPN's coupon for Engadget readers.

One trick VPNs often use is to add extra months onto an introductory deal, pushing the average monthly price even lower. When it comes time to renew, you usually can't get these extra months again. You often can't even renew for the same basic period of time — for example, you may only be able to renew a two-year subscription for one year. If you're planning to hold onto a VPN indefinitely, check the fine print to see how much it will cost per month after the first renewal, and ensure that fits into your budget.

Follow @EngadgetDeals on X for the latest tech deals and buying advice.

This article originally appeared on Engadget at https://www.engadget.com/deals/the-best-vpn-deals-up-to-88-percent-off-protonvpn-surfshark-expressvpn-nordvpn-and-more-120056445.html?src=rss

How to cancel your Surfshark subscription

I really like Surfshark VPN. Like I said in my full Surfshark review, it's the fastest VPN on the market, with download speeds that beat all the other best VPNs. It also gives you universal split tunneling, multi-hop with customizable endpoints and unlimited simultaneous connections.

Surfshark does have its flaws, though. The apps hang up on error messages a bit too often and features sometimes turn on when you don't need them. If anything about Surfshark is annoying you enough that you're ready to switch, here's how you can cancel your subscription, get a refund and (if you want) delete your account altogether.

To cancel Surfshark, all you need to do is stop your subscription from automatically renewing. After you cancel auto-renewal, you can keep using Surfshark for the rest of the period you paid for (unless you get the refund or delete your account entirely). Assuming you bought your subscription through the Surfshark website, follow these steps to cancel.

  1. Go to Surfshark.com. At the top-right of the screen, click My account.

  2. Enter your username and password, then log in. You'll be taken to your account dashboard at my.surfshark.com.

  3. At the top-right of the screen, click your account email address. Click on Subscription in the drop-down menu.

  4. Click the Payments tab under the words "Your subscription."

  5. Scroll down to the "Subscription details" section. Next to your Surfshark subscription, click on Cancel auto-renewal.

Cancel Surfshark auto-renew
Sam Chapman for Engadget

That's all there is to it. Remember that unless it's been 30 days or less since you subscribed, you won't be able to get a refund, and Surfshark doesn't offer prorating for unused time. Additionally, you can always cancel Surfshark by simply opening a live-chat window and asking the support team to do it for you — just be warned that you'll probably be asked to reconsider several times first.

If you subscribed through an app store, the cancellation process is different. You'll have to stop your auto-renewal through the platform where you first bought the subscription. In this section, I'll cover how to cancel through the desktop versions of each app store, since requests submitted there are more likely to work. Just note that you can do the same thing by going to the subscriptions section of your profile on the appropriate mobile app store.

If you bought Surfshark through the Google Play Store, open play.google.com on a desktop computer. Click the circle at the top-right that contains your account's first initial, then click Payments & subscriptions in the menu that appears. On the new page, click the Subscriptions tab, then scroll down until you find Surfshark. Click Manage, click Cancel Subscription and follow the instructions.

If you went through the Apple App store, a desktop computer is also the easiest way to cancel. Open the App Store in macOS, click Sign In at the bottom-left, then enter your email and Apple ID password. After signing in, check the bottom-left again and click your name, then click Account Settings at the top-right. Click Subscriptions, find Surfshark, then click Edit and Cancel Subscription.

You can buy Surfshark through Amazon, but if you do, you'll also have to cancel through Amazon. Go to Amazon and log in to your account. At the top-right, click Account & Lists, then Membership & Subscriptions. Scroll until you find Surfshark and click Cancel Subscription. After that, follow the onscreen prompts.

It's possible to delete your Surfshark account and immediately end your association with every Surfshark app, but there's no direct method — your only option is to start a live chat conversation. To do that, go to support.surfshark.com, scroll to the bottom and click Chat with us. In the conversation window, tell the bot you want to delete your Surfshark account. Be prepared to fend off several requests for you to reconsider.

Surfshark offers a full refund within 30 days of purchase. Live chat is the only way to request a refund. Go to support.surfshark.com and click Chat with us at the bottom of the page, then tell the live chat bot you want a full refund. It'll guide you from there.

Surfshark chat with us
Sam Chapman for Engadget

If you subscribed through Amazon or an app store, you'll need to request the refund through there instead. The typical refund policy for each platform applies, superseding Surfshark.

After you've cancelled Surfshark, I strongly recommend considering another VPN — it's not only a vital privacy precaution, but opens up worlds of streaming fun as well. My favorite for both price and performance is Proton VPN, but NordVPN is also a good choice, providing a similar experience to Surfshark but with apps that function a bit better. If you're prepared to pay a bit more for a service that works seamlessly, ExpressVPN may be for you.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/how-to-cancel-your-surfshark-subscription-110005758.html?src=rss

The 10 best gadgets for your pets

We're a pet-loving staff here at Engadget, with diverse distribution of cat people, dog people, other-small-fuzzy-creature people, bird feeder enjoyers and so on (at press time, I'm unsure if we have a rat person, but I'd be surprised if we didn't). And, of course, we love getting new gadgets of all sorts for our pets as much as for ourselves. This list, with gifts as low-tech as a blanket and as high-tech as the best $30 two-way camera you'll ever use, is for the pet lover in your life — whether that's you or another favorite human. Every entry comes waggingly approved by at least one fuzzy friend.

Check out the rest of our gift ideas here.

This article originally appeared on Engadget at https://www.engadget.com/home/smart-home/the-10-best-gadgets-for-your-pets-150714288.html?src=rss

The best board games to gift for the 2025 holiday season

It's become cliche to say that we live in a golden age of board games, but to paraphrase the great stoic philosopher Andy Bernard, it's great to know you're in the good old days before you've left them. Great titles are still coming out by the thousands every year, from crowd-pleasing party games to genre-bending, theme-heavy Euros. Whether the gamer in your life is looking for a mind-warping challenge, a fun evening with friends or something in-between, we've got new releases or old favorites they'll love.

Check out the rest of our gift ideas here.

This article originally appeared on Engadget at https://www.engadget.com/the-best-board-games-to-gift-for-the-2025-holiday-season-125529024.html?src=rss