Module 2: Protect Accounts and Devices

Updates, Apps, and Permissions

Learn what installing software really grants and how to choose safer sources and permissions.

In this lesson, you will learn to:

  • Use trustworthy update and installation routes.
  • Evaluate whether requested permissions match an app's purpose.

Updates, Apps, and Permissions

Explains security updates, publisher identity, app stores, installers, browser extensions, mobile permissions, and least privilege.

Updates repair known weaknesses

Software contains mistakes. Some allow an attacker or malicious website to run code, read information, or bypass a protection. Once a fix is available, delaying the update leaves the known weakness open. Turn on automatic updates for the operating system, browser, phone, security software, router, and frequently used applications where practical.

Use built-in updaters, managed software centers, official app stores, or an independently reached publisher site. An urgent message claiming to provide a patch may itself be the attack. Check that the device is still supported; a device that no longer receives security fixes may need replacement or a safer limited role. Restart when required, because some protections do not become active until the update completes.

Installing means granting capability

An application or browser extension may read files, view every webpage, access the microphone, track location, modify downloads, or act through your account. The question is not only whether the software is popular. Ask who publishes it, why you need it, when it was last maintained, whether the requested access matches its purpose, and whether a less powerful option exists.

Review permissions after installation because updates and changed habits can make old access unnecessary. Remove extensions and apps you no longer use. On mobile devices, “allow once” or “only while using” often provides enough capability. Administrator access should be exceptional. A calculator does not need contacts; a wallpaper extension does not need to read every webpage. Mismatched permissions are a reason to stop.

Pirated and fake software changes the trust equation

Cracked software, unofficial mobile packages, cheat tools, fake browser updates, and sponsored search results can carry stealers, remote-access tools, or unwanted programs. A professional page and an HTTPS connection only show that the connection is encrypted; they do not prove the operator is honest. Navigate from the software project’s known homepage or repository, then verify the publisher and expected file.

If a website says that proving you are human requires opening the Run dialog, Terminal, or PowerShell and pasting a command, stop. That interaction gives the page a route to execute instructions outside the browser. Close the page and, if you followed the instructions, disconnect as appropriate, seek help, scan the device, and protect accounts from a different trusted device.

Resources