Devices
Installing a game safely on desktop, mobile or tablet
Most trouble that arrives with a game client arrives because the client came from somewhere other than the vendor. The rules for avoiding that are short and they differ by platform, so this page sets them out one platform at a time, then covers what a legitimate installer does, what it asks for, and how to remove it cleanly.
The one rule, and why it holds
Install from the vendor's own site or an official app store, and from nowhere else. Every other rule on this page is a consequence of that one.
It holds because of who is accountable. A store listing has a publisher identity attached to it, a review process behind it, and a removal mechanism when something is found to be wrong. A vendor's own download page is signed, versioned and supported. A third-party mirror, a file-sharing link or a download button inside a video description has none of those properties, and the file it serves can be replaced at any time without the page changing at all.
Search results deserve the same scrutiny as links in messages. Paid placements and imitative site names both appear above genuine results from time to time. Typing the vendor's address, or using a bookmark saved when you were not in a hurry, removes that entire category of problem.
Official sources, platform by platform
- Windows
- The publisher's own site or the Microsoft Store, or an established game distribution platform where the publisher lists the title officially. Expect a signed installer: Windows will name the publisher in the security prompt. An unnamed or unknown publisher is a reason to stop and check where the file came from.
- macOS
- The App Store or the publisher's own site. Expect a signed and notarised application; macOS will say clearly when a download has not been checked, and that message is worth reading rather than clicking past.
- Linux
- The publisher's own packages, a distribution repository, or an official Flatpak or Snap listing where one exists. Where a community-maintained package is the only option, prefer the distribution's own repository over a script copied from a forum, and read any script before running it.
- Android
- Google Play or another store the publisher names on its own site. Installing an APK obtained from a general file site removes the store's review and update path, and is how a large share of Android malware arrives. If a game is not on the store for your device, that is information, not an obstacle to route around.
- iPhone and iPad
- The App Store. Any page asking you to install a configuration profile or an enterprise certificate to play a game is asking for something no ordinary game requires.
- Browser-based play
- Some games run in the browser with no installation at all. The address bar is then the whole of the security question: the vendor's domain, spelled correctly, over HTTPS.
What a legitimate installer does
A game client is a large application and it legitimately does several things that look intrusive if you have not seen them before. Knowing the ordinary behaviour makes the unusual behaviour visible.
- Downloads a lot of data after installation. The installer is often a small launcher that fetches the game itself, which is why the download size on the page and the space used on disk differ so widely.
- Asks for a firewall exception. Online games need network access. Granting it for private networks is normal; granting it for public networks is a choice you can decline.
- Installs a launcher that starts with the system. Common, and worth turning off if you would rather start the game yourself. It is usually a setting inside the launcher.
- Includes anti-cheat software. Some competitive titles install components with deep system access. Whether that trade is acceptable is a personal decision, but it should be a decision, taken knowingly.
- Creates a separate account or profile. Ordinary; the game account is not the same thing as the device account.
Behaviour that is not ordinary
- An installer that asks you to switch off your security software before continuing.
- A request to install a browser extension, a toolbar or a “download manager” alongside the game.
- A prompt for payment details inside an installer rather than in the game or the store.
- A file whose name and size do not match what the publisher's page describes.
- An installer arriving in an archive with a password supplied in a comment or a message, which exists to defeat scanning.
Permissions worth questioning
Mobile games request permissions at first launch, and the useful question for each one is whether the game has a feature that plainly needs it.
| Permission | Plausible use | Reasonable response |
|---|---|---|
| Notifications | Event reminders, friend requests, energy timers. | Decline or allow; it changes nothing about play. Often the most intrusive setting in practice. |
| Photos or media | Setting a profile picture, saving screenshots. | Grant only when you use the feature, and prefer limited access where offered. |
| Microphone | Voice chat. | Decline unless voice chat is being used deliberately, particularly on a child's device. |
| Contacts | Finding friends who play. | Decline. It shares other people's information, not only your own. |
| Precise location | Rare outside location-based games. | Decline unless the game is explicitly built on location. |
| Accessibility services | Almost never legitimate for a game. | Decline. This permission grants very broad control of the device. |
Permissions can be reviewed and withdrawn later in the device settings, and a game that stops working when an unrelated permission is withdrawn has told you something useful about itself.
Modified clients, cheats and helper tools
Three categories get grouped together and deserve separating. Cosmetic add-ons that a publisher officially supports are generally fine and are distributed through the publisher. Unofficial modifications of a game client are a breach of most terms of service and risk the account. Tools promising currency, unlocked content or automated play are, in the overwhelming majority of cases, either a credential-harvesting mechanism or malware, and they are installed by the user voluntarily with the user's own permissions.
The Australian Cyber Security Centre publishes general guidance on software from untrusted sources, and the advice reduces to something short: if the value proposition of a download is that it defeats the rules of a service, its actual business model is not the one advertised.
Data, storage and the household connection
Online games download a full client and then patch it regularly, sometimes weekly. Two practical consequences for an Australian household are worth planning for. On a metered or mobile connection, the first install and subsequent patches can consume a substantial share of an allowance, so scheduling the initial download on a fixed connection is worth the wait. And on a shared connection, a large patch downloading in the background affects everyone else on it, which is a household negotiation rather than a technical fault.
On storage, install sizes grow over the life of a live game. A device close to full will behave badly long before the game stops working, and the symptoms — failed patches, corrupted downloads, long load times — are easy to mistake for a problem with the game itself.
Removing a game properly
- Cancel any subscription first, inside the store or the vendor's account page. Removing an application does not stop a recurring charge.
- Uninstall through the platform's own mechanism rather than by deleting a folder, so launchers, services and firewall rules are removed with it.
- Check for a separate launcher left behind, and remove it too if no other game uses it.
- Review the account itself. Removing the client leaves the account in place; deleting the account is a separate request to the vendor, covered on our page about signing up and closing accounts.
- Withdraw permissions on mobile, since they persist until the application is gone and occasionally afterwards in the settings list.