Cybersecurity

None of this is expert advice. It's what people worked out for themselves, usually the hard way — what actually helped, and what they'd tell someone standing where you are. Take what fits and leave the rest.

How this was put together

If you only read a few

  1. Use an authenticator app instead of SMS for two-factor authentication.

    SMS is vulnerable to SIM swapping, penetration, and loss of SIM cards; apps do not rely on cell signals.

    • Changing or upgrading devices can lead to being hard locked out of everything.

    7 people, independently

    • Recognize that SMS two-factor authentication is vulnerable to interception and SIM swapping attacks.1
  2. Generate distinct, random passwords for each account; avoid reusing them.

    Reusing credentials makes other sites only as secure as the weakest one; if a password is compromised on a weak site, all linked accounts are at risk. Two-factor authentication does not excuse poor password hygiene.

    3 people, independently

  3. Hang up on suspicious bank calls and call back using a verified number found on your card or official site.

    Fraudsters can keep a line open with dialing tones to trick people.

    one person who lived it

  4. Bookmark trusted websites and use those bookmarks to log in rather than searching for them each time.

    Searching for bank login pages increases the risk of encountering fake sites.

    one person who lived it

  5. Assign different months to birthdays on reward cards to receive coupons throughout the year.

    Some reward cards send free stuff coupons on your birthday.

    one person who lived it

  1. Be cautious with browser-integrated password managers if others have access to your computer account.

    Saved passwords may be accessible to anyone logged into your Windows account.

    • Chrome password manager saves passwords that anyone on your Windows account can access.

    one person who lived it

  2. Put a port lock on your mobile number to prevent unauthorized transfers.

    Scammers may try to convince providers to port your number to another provider.

    one person who lived it

  3. Manually type website addresses into your browser instead of clicking login links in emails to avoid spoofed sites.

    Emails may direct you to fake websites designed to steal login information.

    one person who lived it

  4. Close the window immediately and navigate to the website by typing the URL directly into the address bar.

    Phishing sites may prompt repeated password entries to trick you.

    one person who lived it

9 more on this
  1. Go through your password manager and third-party links to delete services you do not use.

    This is critical because unused logins can be a vulnerability.

    one person who lived it

  2. When receiving urgent security emails that cause confusion or panic, pause to judge if you are being manipulated before acting.

    Scammers often use confusion and panic to throw victims off base.

    one person who lived it

  3. Focus on securing passwords for high-value accounts such as email, banking, social media, government services, and credit cards.

    Thieves can use these accounts to cause significant life disruption.

    one person who lived it

  4. Read the full URL before entering sensitive details to verify it matches the expected domain structure.

    Some domains look similar but are not legitimate, such as a secure subdomain versus a fake main domain.

    one person who lived it

  5. Avoid clicking links from URL shorteners.

    They hide the final destination.

    one person who lived it

  6. Never share your one-time password with anyone, including banks, family, or support staff.

    one person who lived it

  7. Share master password vault access with a trusted partner for emergency recovery.

    It allows retrieval of key passwords in emergencies, such as losing access to devices.

    one person who lived it

  8. Avoid using email addresses associated with sensitive personal documents for general web logins.

    Such emails may contain personal information, such as PDFs with social security numbers.

    one person who lived it

  9. Report internal emails containing shortened URLs as potential phishing.

    This raises awareness and pressures senders to stop using them.

    one person who lived it

Close