English how-to · updated 2026
A security search parents and students make after every breach headline. This page has 50 important questions and answers. Original explainer for daily search — not a government login or live tracker.
A strong password is long and unique — a passphrase beats “Summer2026!”. Use a password manager so you are not recycling the same string on email, banking, and games. Turn on two-factor authentication (2FA).
Nobody from your bank DMs you for the SMS code. Phishing links copy real logos. If a prize wants your password, it is not a prize.
50 important questions. Quick 10 is a random set; Full set plays every question.
Original explainers for English readers — not copied match reports or official papers. Tap a question to see the answer.
Answer: long, unique, and not reused
Managers generate and store them.
Answer: a second check (app, key, or code) after the password
Authenticator apps beat SMS when you can use them.
Answer: trick you into giving a password or clicking a fake site
Check the real domain, not the logo.
Answer: change that password and any reuse of it
Have I Been Pwned-style checks exist.
Answer: logging into email and banking without a VPN/care
Use the phone network for money if unsure.
Answer: an encrypted vault for unique passwords
Protect it with a long master passphrase.
Answer: one-time codes or your 2FA prompts
Scammers sit on the phone and ask you to read the SMS.
Answer: the link to that site is encrypted — not that the site is honest
Still check you are on the real bank domain.
Answer: a short mix of symbols you will reuse
Four rare words can be stronger than P@ss1.
Answer: one breach opening your email and bank together
Reuse is the silent failure.
Answer: offline or in the manager, not in the same inbox only
Lose the phone, keep the account.
Answer: steal your number so SMS codes arrive to the thief
App or hardware 2FA resists this better than SMS.
Answer: watching you type a PIN or password in public
Cup the screen on trains.
Answer: they close holes attackers already know
Turn on auto-update when you can.
Answer: a physical second factor that phishing sites cannot easily fake
It is among the strongest 2FA options.
Answer: the answer is on social media
Better: a random string, not a real fact.
Answer: staying logged into email or banking
Log out and clear if you must use it.
Answer: carry malware; do not plug them into your only PC
Hand them to IT if at work.
Answer: helps thieves plan
Post photos after you are home.
Answer: steal the password you type into it
Install banks from the real store page you typed.
Answer: a lookalike site that harvests logins
Read the URL after the scan.
Answer: long and not reused anywhere else
If that vault opens, everything opens.
Answer: dump a password into a fake form
Check the host name first.
Answer: unique passwords and privacy settings, not the family dog name
School portals get phished too.
Answer: a snatched device opening mail at once
Use a long passcode, not 0000.
Answer: read a one-time SMS code to them on a surprise call
Hang up and call the number on the card.
Answer: the fake site can still have a padlock
The padlock is not a badge of virtue.
Answer: go to the real site by typing the address, not the link
Then change that password.
Answer: an authenticator app or a security key
Prefer app-based codes when the site offers them.
Answer: the paper is stored privately, not on the monitor
A manager is still easier at scale.
Answer: stop casual snooping of your traffic; it does not make a fake site real
Still check domains.
Answer: tricking a human instead of breaking encryption
Help-desk scams are this.
Answer: are easy for anyone who knows you
Skip hints or make them nonsense.
Answer: a device login that is not blank
Share the laptop, share the vault.
Answer: changed from admin/admin
Neighbour attacks start there.
Answer: change that password and any reuse of it
Old forums still leak.
Answer: an attacker trying to make you tap Yes
Deny and change the password on a safe device.
Answer: hide you from the website or your ISP
It is not invisibility.
Answer: reset links for other sites land there
Protect the mailbox first.
Answer: carry juice-jacking risk; use your own brick
A power bank you own is safer.
Answer: break company policy and leak data
Use the tools IT named.
Answer: far too small a space to guess
PINs are for short local locks, not mail.
Answer: it is not a prize
No legitimate lottery needs your bank login.
Answer: spot a takeover early
Act the same day you see a city you were not in.
Answer: the email that resets your bank
Still against many terms, and reuse spreads.
Answer: the parent mailbox is now a master key
Protect that parent mailbox.
Answer: a common malware path
Pay or use real free software.
Answer: a classic phishing trick
Read slowly before you type a password.
Answer: ransomware and lockouts happen
An offline copy survives a hijacked cloud.
Answer: unique long secrets plus 2FA plus a sceptical click finger
No single tip replaces the set.
Pick the next article in this topic — that is how a magazine issue is meant to be used.