Three phone settings sit at the center of the National Security Agency’s standing guidance on mobile devices: location services, Bluetooth, and Wi-Fi. The agency’s Mobile Device Best Practices document tells owners to switch off all three whenever a phone is not actively using them, not just while traveling or in public, treating each as an open door that stays open until someone closes it.
None of the three guidelines are new, but together they describe a phone that leaks information by default rather than by mistake. Location services report a device’s coordinates to apps and carriers, Bluetooth broadcasts a signal any nearby receiver can pick up, and Wi-Fi radios search for and sometimes auto-join networks without a prompt. The agency’s advice treats each radio the same way: leave it on and something nearby, eventually, will use it.
Location services and the sensitive places the NSA names directly
On location, the guidance is blunt. “Disable location services when not needed,” the NSA’s Mobile Device Best Practices document states, adding a second instruction that goes further than most consumer advice: the device should never be carried into sensitive locations at all. That second line treats the phone itself as a tracking device that keeps working even after its owner has stopped thinking about it, since a location history persists independent of whatever app most recently used the signal.
The practical effect is narrower than it sounds. Turning location services off does not stop cell towers from triangulating a device’s rough position, and it does not touch location tags a phone camera may add to photos taken with the setting on. It removes the constant, precise reporting that apps rely on for anything from maps to targeted advertising, which is the exposure the NSA’s guidance is aimed at closing.
Bluetooth stays active even after airplane mode is switched on
The Bluetooth instruction carries a warning most phone owners never see written down. “Disable Bluetooth,” the NSA document says, before adding a line that undercuts a common assumption: “Airplane mode does not always disable Bluetooth.” A radio that many people assume shuts off with a single toggle can keep broadcasting a device’s presence to anything scanning for it nearby.
That exposure is a design feature of Bluetooth, not a flaw introduced by any one phone. NIST’s guide to Bluetooth security states that devices “should be disabled on all Bluetooth devices, except when the user explicitly enables Bluetooth to establish a connection,” and that discoverability itself is the risk: a device broadcasting its name and presence becomes “a visible target” during the window before pairing completes. The Federal Communications Commission’s consumer guidance adds a specific version of the threat: an active Bluetooth connection can let an attacker see which devices a phone has paired with before, impersonate one of them, and gain access to the device as a result.
Wi-Fi radios that keep searching after the last network is forgotten
Wi-Fi gets the most detailed instruction of the three. “DO NOT connect to public Wi-Fi networks. Disable Wi-Fi when unneeded. Delete unused Wi-Fi networks,” the NSA document states, treating an idle Wi-Fi radio as riskier than a Bluetooth one because it actively searches for and can auto-join networks a phone has joined before. A separate 2021 NSA advisory on securing wireless devices in public settings put the baseline even more plainly: “At a minimum, NSA recommend disabling Wi-Fi, Bluetooth, and NFC when not in use.”
Deleting old networks closes a gap the disable toggle alone leaves open. A phone that remembers a coffee shop’s network from months earlier will broadcast a request for that network by name every time Wi-Fi is turned back on, handing anyone listening a list of places that device has been. Airports, hotel lobbies, and conference centers are the settings security researchers most often point to, since a phone hunting for a familiar network name gives an eavesdropper an easy way to impersonate that network and intercept whatever the device sends next.
A weekly reboot the agency admits has limits
Alongside the three radios, the NSA’s document adds a fourth habit: “Power the device off and on weekly.” The instruction sounds almost too simple to matter, and the agency does not oversell it. Reporting on the same guidance, Forbes noted the NSA’s own caveat that a reboot does nothing against the more advanced malware and spyware built to reload itself automatically once a device restarts, even as the agency maintains that “threats to mobile devices are more prevalent and increasing in scope and complexity.”
That combination — three settings to disable, one habit to repeat, and an explicit admission that none of it is a complete defense — is closer to what the guidance actually claims than a single fix. The NSA frames all four as reducing exposure, not eliminating it, which is why the document pairs them with dozens of other steps, from using only official app stores to avoiding public charging stations, rather than presenting any one toggle as sufficient on its own. Read together, the advice describes a phone that is safest when it is doing the least work in the background, not one that needs a single dramatic setting corrected.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A recalled pill hid a stimulant dose linked to heart attacks and death
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Doctors warn a silent liver disease now affects one in three American adults