English how-to · updated 2026

Passwords and online safety

A security search parents and students make after every breach headline. This page has 50 important questions and answers. Original explainer for daily search — not a government login or live tracker.

A strong password is long and unique — a passphrase beats “Summer2026!”. Use a password manager so you are not recycling the same string on email, banking, and games. Turn on two-factor authentication (2FA).

Nobody from your bank DMs you for the SMS code. Phishing links copy real logos. If a prize wants your password, it is not a prize.

50 important questions. Quick 10 is a random set; Full set plays every question.

50 questions and answers

Original explainers for English readers — not copied match reports or official papers. Tap a question to see the answer.

1. A good password is

Answer: long, unique, and not reused

Managers generate and store them.

2. 2FA means

Answer: a second check (app, key, or code) after the password

Authenticator apps beat SMS when you can use them.

3. A phishing email tries to

Answer: trick you into giving a password or clicking a fake site

Check the real domain, not the logo.

4. If a site is breached, you should

Answer: change that password and any reuse of it

Have I Been Pwned-style checks exist.

5. Public Wi-Fi is riskier for

Answer: logging into email and banking without a VPN/care

Use the phone network for money if unsure.

6. A password manager is

Answer: an encrypted vault for unique passwords

Protect it with a long master passphrase.

7. Never share

Answer: one-time codes or your 2FA prompts

Scammers sit on the phone and ask you to read the SMS.

8. HTTPS in the padlock means

Answer: the link to that site is encrypted — not that the site is honest

Still check you are on the real bank domain.

9. Length in a passphrase usually beats

Answer: a short mix of symbols you will reuse

Four rare words can be stronger than P@ss1.

10. A unique password per important site stops

Answer: one breach opening your email and bank together

Reuse is the silent failure.

11. Store recovery codes for 2FA

Answer: offline or in the manager, not in the same inbox only

Lose the phone, keep the account.

12. A SIM-swap attack tries to

Answer: steal your number so SMS codes arrive to the thief

App or hardware 2FA resists this better than SMS.

13. Shoulder surfing is

Answer: watching you type a PIN or password in public

Cup the screen on trains.

14. Software updates matter because

Answer: they close holes attackers already know

Turn on auto-update when you can.

15. A hardware security key is

Answer: a physical second factor that phishing sites cannot easily fake

It is among the strongest 2FA options.

16. Security questions such as first pet are weak if

Answer: the answer is on social media

Better: a random string, not a real fact.

17. On a public library PC, avoid

Answer: staying logged into email or banking

Log out and clear if you must use it.

18. Unknown USB sticks can

Answer: carry malware; do not plug them into your only PC

Hand them to IT if at work.

19. Oversharing your holiday dates and home address

Answer: helps thieves plan

Post photos after you are home.

20. A fake app-store listing can

Answer: steal the password you type into it

Install banks from the real store page you typed.

21. QR-code phishing sends you to

Answer: a lookalike site that harvests logins

Read the URL after the scan.

22. A password manager master phrase should be

Answer: long and not reused anywhere else

If that vault opens, everything opens.

23. Autofill on a weird lookalike domain can

Answer: dump a password into a fake form

Check the host name first.

24. Children accounts still need

Answer: unique passwords and privacy settings, not the family dog name

School portals get phished too.

25. A lock screen on a phone stops

Answer: a snatched device opening mail at once

Use a long passcode, not 0000.

26. Bank staff will not ask you to

Answer: read a one-time SMS code to them on a surprise call

Hang up and call the number on the card.

27. HTTPS on a phishing clone means

Answer: the fake site can still have a padlock

The padlock is not a badge of virtue.

28. After a breach email that looks official, first

Answer: go to the real site by typing the address, not the link

Then change that password.

29. SMS 2FA is better than nothing but weaker than

Answer: an authenticator app or a security key

Prefer app-based codes when the site offers them.

30. Writing passwords on paper can be OK if

Answer: the paper is stored privately, not on the monitor

A manager is still easier at scale.

31. A VPN on cafe Wi-Fi helps

Answer: stop casual snooping of your traffic; it does not make a fake site real

Still check domains.

32. Social engineering is

Answer: tricking a human instead of breaking encryption

Help-desk scams are this.

33. Password hints that say daughter + year

Answer: are easy for anyone who knows you

Skip hints or make them nonsense.

34. Browser saved passwords need

Answer: a device login that is not blank

Share the laptop, share the vault.

35. Firmware and router default logins should be

Answer: changed from admin/admin

Neighbour attacks start there.

36. A breach of a site you used once still means

Answer: change that password and any reuse of it

Old forums still leak.

37. Two-factor prompt fatigue (many unexpected pushes) can be

Answer: an attacker trying to make you tap Yes

Deny and change the password on a safe device.

38. Incognito mode does not

Answer: hide you from the website or your ISP

It is not invisibility.

39. A strong unique email password matters most because

Answer: reset links for other sites land there

Protect the mailbox first.

40. Public charging cables or kiosks can

Answer: carry juice-jacking risk; use your own brick

A power bank you own is safer.

41. Work documents on a personal free app can

Answer: break company policy and leak data

Use the tools IT named.

42. A password of four digits for a long-life email is

Answer: far too small a space to guess

PINs are for short local locks, not mail.

43. If a prize wants your password to claim it

Answer: it is not a prize

No legitimate lottery needs your bank login.

44. Turning on login alerts (new device mail) helps you

Answer: spot a takeover early

Act the same day you see a city you were not in.

45. Sharing a Netflix-style password is a milder risk than sharing

Answer: the email that resets your bank

Still against many terms, and reuse spreads.

46. A child using a parent email as the recovery address means

Answer: the parent mailbox is now a master key

Protect that parent mailbox.

47. Downloading cracks or free office keys is

Answer: a common malware path

Pay or use real free software.

48. A lookalike domain (rn instead of m) is

Answer: a classic phishing trick

Read slowly before you type a password.

49. Backups matter in safety because

Answer: ransomware and lockouts happen

An offline copy survives a hijacked cloud.

50. The safest habit is

Answer: unique long secrets plus 2FA plus a sceptical click finger

No single tip replaces the set.

Read next