The viral security tier lists get the basics backwards

The security tier lists going round social media rank Telegram above WhatsApp, ClamAV above Bitdefender and a jailbroken model as high safety. We rebuilt all eight rankings against the evidence, kept the logos, and showed our criterion for every tier.

Share
The viral security tier lists get the basics backwards

A set of security tier lists is doing enormous numbers on social media right now. Nine dark graphics, one per category: operating systems, antivirus, AI assistants, browsers, phones, cloud drives, messaging, email and residential proxies. Clean layouts, recognisable logos, confident verdicts. They present themselves as authoritative.

They are also wrong in ways that leave the people who trust them believing they are safer than they are. Not wrong at the margins, where reasonable people disagree about Brave versus Firefox. Wrong about what encryption is on by default, what independent testing actually measures, and in one case what the word safety means.

Start with the packaging, because the packaging is doing the persuading. All nine graphics rank with red at the top as exceptional, working down to blue for bad. The industry has spent decades on the opposite convention: red is the warning colour. Put red at the top of a list of products you like and nearly everyone skimming at speed absorbs the opposite of what you meant. Our versions below keep the convention. Green is the strongest position, red means avoid.

More fundamentally, none of the lists states its criterion. Ranked by what? Privacy, security, capability and price are four different questions, and each can return a completely different order. So for each category below we say what we measured, then show our ranking. We kept the logos and added the evidence.

Most of what follows is a privacy ranking. Two lists, phones and desktop operating systems, rank security instead, and each says so and carries its privacy note beside it rather than pretending the two questions are the same.

Messaging

The viral list puts SimpleX, Session and Briar in its top tier, ranks Signal a tier below them, and places Telegram above WhatsApp. On the criterion that matters most, default end-to-end encryption for everyone you talk to, that ordering is backwards. Telegram cloud chats are not end-to-end encrypted by default. Secret Chats are opt-in, cover one to one conversations only, and there is no end-to-end option for groups at all. WhatsApp has run the Signal protocol by default since 2016; the honest objection is metadata, not encryption. Session is an innovative design that dropped the Signal protocol, and with it forward secrecy, which is a strange property to celebrate in a privacy ranking. Signal remains the correct default for almost everyone, with the phone number requirement noted.

Zero Day Wire tier list ranking messaging apps by default encryption. Signal leads and SMS sits at the bottom.

Antivirus

The viral list rates ClamAV and Sophos exceptional, Microsoft Defender a middling good, and TotalAV bad. Independent test data says otherwise. In the AV-Comparatives March 2026 Malware Protection Test, Bitdefender posted the highest online protection rate at 99.97 per cent, and Defender scored ADVANCED+ in Real-World Protection with a perfect 18 of 18 in AV-TEST. ClamAV is an open-source engine built for mail gateways and file servers. It is useful there, it is not an endpoint protection product, and it does not appear in consumer comparative testing at all. Rating it above Bitdefender is not a bold opinion, it is a category error that downgrades anyone who acts on it.

Our list does put one thing above Bitdefender, and it is the one entry no lab can measure: you. Between the leading engines the detection gap is now a fraction of a per cent, while the gap between careful and careless use is the whole game. The operator decides what gets installed, what gets clicked and whether patches land, and is also the only scanner that inspects everything and uploads nothing to any vendor or government. That last clause is the privacy question the product pages never answer. An antivirus engine is the most privileged software on your machine: it sees every file you touch and ships telemetry and samples to a vendor cloud in some jurisdiction. Kaspersky's US prohibition and Avast's browsing data resale history are both versions of the same question, and it is a privacy question, not a detection one. Pick the jurisdiction you can live with.

Endpoint protection tier list topped by the user. Lab-tested engines follow, with cautions on who each scanner reports to.

Browsers

The viral browsers list contains two search engines, a metasearch engine and an operating system. Qwant and Mojeek are search engines. SearXNG is self-hosted metasearch. Tails is an amnesic operating system that happens to ship a browser. None of them has a place in a browser ranking, and including them tells you how much care went into the rest. On the actual question, tracking and fingerprinting resistance out of the box, Tor Browser is the strongest thing that exists, Mullvad Browser applies the same fingerprinting work paired with a VPN, and the avoid tier for Chrome and Edge is directionally right for the wrong stated reasons. The material change is Manifest V3 cutting what content blockers can do.

Browser privacy tier list ranked on tracking resistance. Tor Browser leads while Chrome and Edge sit bottom.

Email

The viral list is closest to defensible here, which makes the misses more interesting. Tuta and Proton belong near the top. But iCloud Mail sits in the bad tier alongside Gmail and Hotmail, and that placement misunderstands it: Apple does not scan content for advertising, though Mail is excluded from Advanced Data Protection, so it is a conditional rather than an avoid. The bigger point the list never makes is that email is not a confidential medium and never was. SMTP metadata is visible regardless of provider. For anything genuinely sensitive, the move is to Signal, with email used only to arrange it.

Email providers ranked by who can read content. Self-hosted OpenPGP and Proton Mail top the list.

Phones

Pixels running GrapheneOS at the top is a placement we share. The rest of the viral list ranks brands. The specification that actually predicts your exposure is the guaranteed security update window and how fast patches actually arrive, and no manufacturer advertises it. An iPhone with Lockdown Mode enabled is a strong defence against exactly the zero-click exploit class mercenary spyware uses, which is why it sits high in ours. And the real bottom tier is not a brand at all. It is any phone past its update date, where known exploited vulnerabilities stay open permanently.

The privacy note, since the update window is a security measure: a stock Pixel reports to Google and an iPhone to Apple. GrapheneOS tops this list precisely because it removes that reporting relationship without giving up the hardware security underneath.

Phone security ranked on update guarantees. GrapheneOS on Pixel leads and out-of-support phones sit bottom.

Cloud storage

The viral list rates Mega high, pCloud good and iCloud bad. The dividing line that matters is simpler: can the provider decrypt your files. Mega is end-to-end by design, but the 2022 ETH Zurich analysis of its key handling is required reading before relying on it. pCloud sells encryption as a paid add-on covering one folder, and standard storage is not zero-knowledge. iCloud with Advanced Data Protection enabled is adequate for most categories. And the cheapest large improvement available to anyone is Cryptomator on top of whichever mainstream provider you already pay for, which turns their storage into ciphertext without a migration.

Cloud storage ranked by who holds the keys. Client-side encryption leads and mainstream drives sit bottom.

Desktop operating systems

Windows in the bad tier and a hand-coded operating system in the high tier is not a serious evaluation, it is an aesthetic. A patched Windows 11 with Defender, BitLocker and virtualisation-based security enabled is a serious stack, and it clearly outperforms the neglected Linux install the list implicitly recommends. Qubes OS earns the top slot on isolation by compartmentalisation. The genuine avoid tier is unsupported software of any flavour: Windows 10 security updates ended in October 2025, and the same logic applies to end-of-life macOS and Linux releases. Writing your own operating system is a hobby, not a hardening strategy.

The privacy note here is the honest version of the viral list's instinct. Windows and macOS ship telemetry by default and most Linux distributions ship none, which is a real difference, but it is a privacy difference, not a security one. Blurring the two is how a patched Windows 11 ends up rated Bad underneath a hand-coded hobby system. Run Linux for the privacy win if it suits you, and whatever you run, run it patched.

Desktop operating systems ranked on isolation and attack surface. Qubes OS leads and unsupported systems sit bottom.

AI assistants

This is the list that inverts the meaning of a word. It ranks by safety, then places a jailbroken model in its high tier. Removing a model's safety constraints does not improve your privacy by any mechanism. The prompts still travel to the same servers under the same retention terms; all you have removed is the refusal behaviour. The privacy ranking that survives contact with the terms of service is boring: local models are the strongest position because nothing leaves the machine, contractual zero-retention on business and API tiers comes next, and the real avoid is putting regulated or client data into any assistant without a signed processing agreement.

AI assistants ranked on prompt data handling. Local models lead and jailbroken models sit at avoid.

The list we are not correcting

The ninth graphic ranks residential proxy providers. We are not publishing a counterpart, because the consumer residential proxy market has a consent problem: exit addresses are typically sourced from ordinary people's devices through bundled SDKs, and the person whose connection is being borrowed rarely knows it is happening. Ranking vendors inside that market implies the category is fine and only the brand choice matters. It is not a call we are willing to make.

The caveat with a purchase order

Every ranking in this piece carries the same assumption: the device itself is trustworthy. That caveat is not hypothetical, and as of June it has a paper trail. ICE paid $2 million for Graphite, Paragon's spyware that remotely compromises a phone and lifts messages out of Signal, WhatsApp and Facebook Messenger, and the agency's justification to lawmakers pointed at the "exploitation of encrypted communication platforms". 404 Media sued for the contract records and the first release arrived heavily redacted, down to the release notes describing what the software can actually do, though the surviving overview describes an operational security team that helps customers minimise the risk of exposure and attribution. Read that against the messaging ranking above. The strongest tier means nothing on a compromised device, and the tooling that compromises devices is bought with purchase orders. The defences with evidence behind them are unglamorous: patch on the day, reboot daily, Lockdown Mode on iOS, Advanced Protection on Android.

The Bigger Picture

These lists spread because they are legible. Tiers, logos, a confident verdict, no homework. The corrective is not a better-designed graphic, it is a stated criterion. Ranked on what, measured by whom, and what would change the answer. Every ranking above states one, and each carries the same caution the viral lists omit: it assumes a trustworthy device, patched and current, because against a zero-click exploit chain every app on every list performs identically.

Distrust any tier list that cannot finish the sentence "ranked by".