Synthworks OnlineComparison library

Reference

Security terms, defined

The vocabulary used across this library, with the reason each term matters when comparing products. Terms that are routinely used to imply more than they mean are marked where that happens.

How to use this page

Marketing in this category borrows technical vocabulary and stretches it. "Military-grade encryption" describes a cipher available to anybody at no cost. "Real-time protection" describes something quite different on iOS than on Windows. Definitions are the cheapest defence against that, and each entry below says both what the term means and what it is commonly used to imply.

The entries are grouped by where they belong: detection, network, credentials, and the things that go wrong. Cross-references point to the pages where each concept is applied.

Detection and malicious software

Malware
The umbrella term for software written to act against the interests of the device's owner — ransomware, spyware, banking trojans, adware and the rest. "Virus" is a specific and now fairly rare subtype that became the everyday word for the whole category.
Signature
A fingerprint of a file already identified as malicious. Signature matching is fast and precise, and by definition it only recognises what has already been catalogued. This is why update frequency matters to a scanner.
Heuristic analysis
Detection based on characteristics and behaviour rather than an exact match — a program that encrypts many files quickly, for instance. Catches things no signature covers; produces more false alarms in exchange.
Zero-day
A vulnerability being exploited before a fix exists. The term describes the timing of the patch, not the severity of the flaw. It is often deployed in advertising to suggest a product defends against the unknown in general, which no product can promise.
False positive
A legitimate file flagged as malicious. The reason detection rates alone are a poor measure: a scanner that flags everything detects everything.
Real-time protection
Continuous checking as files are opened or applications installed, rather than only during a scheduled scan. What it can examine depends entirely on the operating system's permissions — see the platform comparison.
Quarantine
Isolating a suspect file rather than deleting it, so that a false positive can be reversed. A product that deletes without quarantining removes your ability to recover from its own mistake.
Ransomware
Malware that encrypts files and demands payment for the key. A tested backup is the only measure that reliably restores the files, which is why backup sits ahead of detection in most public guidance, including the material published by the Australian Cyber Security Centre.
Potentially unwanted program
Software that is not malicious but is unwelcome — bundled toolbars, aggressive cleanup utilities, adware. Products differ in whether they flag these at all.

Networks and VPNs

VPN
A virtual private network: an encrypted tunnel between your device and a server run by the provider, from which your traffic continues to its destination. It changes who can see your traffic on the local network and what address sites see. It is not anonymity, and it is not malware protection.
Kill switch
A setting that blocks traffic entirely if the VPN tunnel drops, preventing a silent fallback to the unprotected connection. Without it, a dropped tunnel is invisible and the protection simply stops.
DNS leak
Name lookups travelling outside the tunnel even though other traffic is inside it, which reveals the sites being visited to whoever handles those lookups. Products that route DNS through the tunnel avoid it.
No-logs policy
A provider's claim not to retain records of what passes through its servers. It is a policy statement, verifiable only through independent audit or legal process. Treat the claim as a claim, not as a technical property.
Public Wi-Fi risk
The scenario VPNs are most often sold on. It has narrowed considerably now that the great majority of web traffic is encrypted in transit by default, though a VPN still hides which sites you are reaching from the local network.
AES-256
A widely used encryption standard, available to anyone and used in ordinary web traffic. "Bank-grade" and "military-grade" are marketing terms for it, not a distinguishing product feature.

Accounts and credentials

Multi-factor authentication
Requiring a second element beyond the password — an app code, a hardware key, or a message. The single highest-value free measure available on most accounts. An authenticator app or hardware key resists interception better than an SMS code.
Credential stuffing
Automated attempts to sign in to many services using username and password pairs from an unrelated breach. It works only where passwords are reused, which is what a password manager fixes.
Password manager
Software that generates and stores a distinct password per site behind one master credential. Browsers and both major mobile platforms include one at no cost; paid ones compete on portability and additional features rather than on whether they work.
Passkey
A sign-in method that replaces the password with a key pair held by your device and unlocked by its own screen lock or biometric. Nothing reusable is transmitted, which removes both reuse and interception as attack routes.
Breach monitoring
A service that watches breach data for identifiers you nominate and notifies you when one appears. It notifies; it cannot withdraw the data or act on your behalf. See what each type of protection does.

How things go wrong

Phishing
A message impersonating a trusted organisation to obtain credentials or payment. Still the most common route to a consumer account compromise, and the reason link filtering earns its place in a bundle.
Smishing and vishing
Phishing carried out by text message and by voice call respectively. Vishing frequently includes a request to install remote-access software, which is the point at which a call becomes a compromise.
Social engineering
Manipulating a person rather than defeating a system. It is the reason the pattern-spotting habits on the reporting page matter more than any product setting.
Scareware
A page or program that fabricates an alarm — a fake scan, a fake infection warning, a fake system dialog — in order to sell something or to obtain remote access. No web page can inspect your device, so any page claiming to have found something on it is fabricating the finding.
Configuration profile
On iOS, a settings package that can change device behaviour. Legitimate for workplace and school devices; a route for abuse when installed from a web page under some pretext. Worth checking in Settings if one is present that you did not expect.
Sideloading
Installing an application from outside an official store. Possible on Android, and the origin of most Android compromises, typically after a link in a message rather than a deliberate decision.
Notifiable data breach
In Australia, a breach that an organisation covered by the Privacy Act 1988 must report to affected individuals and to the Office of the Australian Information Commissioner where serious harm is likely.

Terms this site does not use

Some vocabulary is avoided here because it cannot be supported. "Complete protection", "total security", "100% detection", "undetectable" and "fully anonymous" all describe outcomes that no product delivers and that no publisher can verify. Where a vendor uses such a phrase, this library reports it as the vendor's wording rather than adopting it, for the reasons set out in how comparisons here are built.