Skip to main content

PrimerUpdated October 20264 min read

Staying Safe Online: Passwords, Sign-In, Phishing, and Updates

The everyday security habits that stop most attacks: strong unique passwords, multi-factor sign-in, spotting phishing, keeping devices updated, and sharing carefully. Written for students, families, and anyone starting out.

  • Cybersecurity
  • Beginner
  • Start Here
  • Digital Citizenship
  • Online Safety

Most successful attacks do not involve genius hackers. They involve a reused password, a convincing fake message, or a device that missed an update. That is encouraging, because it means a handful of habits stop most of the attacks people actually face.

This is the second step in our cybersecurity basics learning path. If you are new to the topic, start with What Is Cybersecurity? first.

Habit 1: one strong password per account

When a website is breached, attackers often get a list of email addresses and passwords. They then try those same pairs on hundreds of other sites, a technique called credential stuffing. If you reused the password, one breach becomes many.

So the most important rule is a different password for every account. Nobody can remember dozens of strong passwords, and nobody should try. Two practical approaches:

  • A password manager. An app that creates and remembers a long random password for each site, locked behind one strong master password. Most phones and browsers include one.
  • Passphrases. Several unrelated words strung together, such as four or five random words, are long, hard to guess, and easier to type than a jumble of symbols.

Length matters more than cleverness. Swapping letters for numbers ("p4ssw0rd") fools no one; attackers' tools try those substitutions automatically.

Habit 2: turn on multi-factor sign-in

Multi-factor authentication (MFA) means signing in with two kinds of proof: something you know (a password) plus something you have (your phone or a security key) or something you are (a fingerprint). A stolen password alone is then not enough.

Turn it on first for the accounts that unlock everything else: your email, because it can reset every other password, and any account tied to money. An authenticator app or a physical security key is stronger than a code sent by text message, but any second factor is far better than none.

One warning: if anyone asks you to read them a sign-in code, it is a scam. Real companies do not ask for those codes.

Habit 3: learn to spot phishing

Phishing is a message that pretends to come from someone you trust, to get you to click a link, open an attachment, enter a password, or send money. It arrives by email, text, social media, or phone call.

Warning signs:

  • Urgency or fear. "Your account will be closed in 24 hours." "Unusual activity detected."
  • A request for credentials, codes, or payment. Especially gift cards or wire transfers.
  • A sender or link that is almost right. A misspelled company name, or a link whose real address does not match the organization.
  • Something unexpected. A prize you did not enter, a delivery you did not order, an invoice from a company you do not use.

The safest response is to go around the message. Do not click the link. Open the app or type the website address yourself, or call the organization using a number you already know. If the message was real, the same information will be waiting there.

Habit 4: keep everything updated

Updates often fix vulnerabilities: weaknesses that attackers already know how to use. Once a fix is published, attackers study it and target everyone who has not installed it yet. Delaying updates leaves a known door open.

Turn on automatic updates for your phone, computer, browser, and apps. Replace devices that no longer receive security updates; an old router or phone that the manufacturer has stopped supporting will never be fixed.

Habit 5: share carefully

Information you post can be used to guess passwords, answer security questions, or make a phishing message more convincing. Before sharing, ask:

  • Does this reveal where I live, where I go to school, or when my home is empty?
  • Would I be comfortable with a stranger, an employer, or a college seeing this in five years?
  • Does this app really need my location, contacts, or microphone?

Review the privacy settings on your accounts and remove app permissions you do not use. Good digital citizenship also means protecting other people: ask before posting photos of friends, and never share someone else's private information.

If something goes wrong

Mistakes happen to careful people. If you clicked a bad link or think an account was taken over:

  1. Change the password for that account, and anywhere else you used it.
  2. Turn on MFA if it was not already on.
  3. Tell someone: a parent, teacher, your IT team, or the organization involved. Speed matters more than embarrassment.
  4. Watch for unusual activity in your email, bank, and social accounts.

Try it yourself

Do a 30-minute security checkup:

  1. Turn on MFA for your main email account.
  2. Find one account where you reused a password and change it.
  3. Check that automatic updates are on for your phone and browser.
  4. Review which apps have access to your location and remove one you do not need.

The next step in this path looks at the other side: how attackers find weaknesses in software itself.

Further reading

Rex Black Inc. · Since 1994 · Dallas, Texas

Keep reading

Related reading

Practices

Where this leads

Working on something like this?Talk to the people who wrote it.

Book a call