MARJ
SIGN IN
VIL1checked 2d ago

Security Basics: Password Manager, 2FA, and the Anatomy of Phishing

A secured account set: a password manager in use, 2FA on your key accounts, and passkeys where offered

⚠️ Version note: exact menu paths for enabling 2FA and passkeys change per service and update often. This lesson names what to look for. Last checked: 24 July 2026.

You will get breached. The question is what it costs you.

Not "might". Will. Somewhere, a service you use will get hacked and your password will end up in a database that gets traded and dumped online. This has almost certainly already happened to you — the average person's details are in several known breaches.

Here's the thing that determines whether that's a catastrophe or a shrug: do you reuse passwords?

Because a breach doesn't just expose one account. Attackers take the email-and-password pairs from one leaked site and try them, automatically, on hundreds of others — banks, email, social media. If your password for the breached forum is the same as your email password, one leak from a site you forgot about hands them your entire life. This is called credential stuffing, and it's the single most common way ordinary people get seriously hacked.

The whole of practical security for a normal person comes down to breaking that chain. Three moves do almost all of the work, and none of them require you to be technical. This lesson is those three.

What you'll have at the end

  • A password manager holding unique passwords for every account
  • 2FA on the accounts that matter most
  • Passkeys turned on where offered — the thing replacing passwords
  • The ability to spot a phishing attempt in the two seconds you have

Step 01

The one idea: never reuse a password (5 min)

The core of everything: every account gets a different password. One breach then exposes exactly one account, and the damage stops there.

This is impossible to do in your head — nobody can remember 80 unique strong passwords — which is exactly why people reuse. The answer isn't a better memory. It's to stop using your memory for this at all and hand the job to software built for it.

Why not "clever" passwords? Summer2024! and P@ssw0rd feel secure and aren't — attackers' tools know every substitution and every season. And a "strong" password reused everywhere is still one breach away from useless. Uniqueness matters more than cleverness. A long, random, different password per site beats a fiendishly clever one you reuse.

✅ Check: you can state why reusing even a very strong password is the core risk.


Step 02

Install a password manager (15 min) — the keystone

A password manager generates a unique random password for every site, stores them encrypted, and fills them in for you. You remember one strong password (the "master password"); it remembers the rest.

  1. Pick one. Reputable options include Bitwarden (free, open-source), 1Password, or the manager built into your browser/phone (Apple Passwords, Google Password Manager). Any real one beats none.
  2. Install the app and the browser extension.
  3. Create your master password. This is the one you must never forget and never reuse. Make it a passphrase — four or five random words, like correct-harbour-violin-echo — which is both easier to remember and harder to crack than X7$k!. Length beats symbols.
  4. Turn on the manager's own 2FA (step 4). It holds everything; protect it most.

Then, over time:

  • Let it generate a new random password every time you sign up for something.
  • When you log into an old account, let it replace the reused password with a generated one.
  • Use its security check feature — it scans your saved logins for reused and breached passwords and gives you a to-do list. Start with your email and bank.

Your email is the master key to your whole life — every "reset password" link goes there. Secure it first, with a unique password and 2FA. If someone owns your email, they own everything it can reset.

✅ Check: a password manager is installed, your master password is a passphrase you haven't reused, and at least your email and one other important account now have unique generated passwords.

If it moved: look for a "password health", "security dashboard", or "watchtower" feature — every good manager has one under a slightly different name.


Step 03

Understand what makes a password strong (4 min)

Quickly, because the manager handles it — but the intuition is useful.

  • Length beats complexity. A long passphrase of random words is stronger and more memorable than a short mess of symbols. Attackers guess by the trillion per second; each extra word multiplies the work enormously.
  • Random beats meaningful. Anything derived from you — birthday, pet, name, favourite team — is guessable and often findable on your social media.
  • Reuse ruins everything. The strongest password in the world, used on two sites, is only as safe as the weaker of those two sites.

You won't apply these by hand for most accounts (the manager does), but they explain your one memorised password: the master.

✅ Check: your master password is long and made of random words, not short and meaningful.


Step 04

Turn on 2FA (15 min)

Two-factor authentication means logging in needs two things: something you know (password) plus something you have (your phone). Now a stolen password alone is useless — the attacker also needs your physical device.

The methods, worst to best:

MethodSecurityNotes
SMS codeWeakest 2FA — but far better than noneVulnerable to "SIM swap" attacks; fine for low-value accounts
Authenticator appStrongGenerates a rotating 6-digit code (Google Authenticator, Authy, or your password manager). No signal needed
Hardware key / passkeyStrongestA physical key or device biometric — phishing-resistant

Turn it on for the accounts that would hurt most first, in this order: email, banking/money, password manager, then main social accounts. You don't need it on everything; you need it on the accounts whose loss would be a disaster.

Where to find it: usually Settings → Security → Two-factor / 2-step verification.

Save your backup codes. When you enable 2FA, the service gives you one-time recovery codes for if you lose your phone. Save them in your password manager (not a screenshot in your camera roll). People lock themselves out permanently by skipping this.

✅ Check: 2FA is on for your email and at least one financial account, and your backup codes are saved somewhere safe.


Step 05

Passkeys: the thing replacing passwords (8 min)

Newer and worth adopting: a passkey replaces the password entirely. Instead of a secret you type, your device proves it's you (with Face ID, fingerprint, or a PIN) using cryptography that never sends a reusable secret anywhere.

Why it's a genuine upgrade, not a gimmick:

  • Nothing to steal in a breach. There's no password stored on the server to leak.
  • Phishing-resistant by design. A passkey is tied to the real website's identity — it simply won't work on a fake lookalike site, which defeats the most common attack in step 6 automatically.
  • Nothing to remember or type.

When a service offers "sign in with a passkey" or "set up a passkey", take it — especially for Google, Apple, Microsoft, and major accounts. Your password manager or phone stores and syncs them. Passwords aren't gone yet, but this is clearly where things are heading.

✅ Check: you've created at least one passkey on a service that offers it.


Step 06

Spot phishing in two seconds (12 min)

All the above protects you from breaches. Phishing is the attack that skips them — it tricks you into handing over the keys directly, and no password manager saves you if you type your password into the attacker's site yourself.

A phishing message wants you to click a link and log in to a fake version of a real site, or to reveal a code. It works by manufacturing urgency (which is exactly the SO-14 tactic — slow down).

The tells, in rough order of reliability:

  1. Urgency + a link. "Your account will be closed in 24 hours — verify now." Real organisations rarely demand instant action through a link. Urgency is the phisher's core tool.
  2. The link doesn't go where it says. Hover over it (or long-press on mobile) and read the actual URL. paypa1.com, apple-support.net, secure-login-microsoft.xyz — the real domain is often a near-lookalike. The domain is the truth; the display text is a costume.
  3. They contacted you. You didn't initiate it, and now they need your details "to verify". Reverse it: never act on the message. Go to the site yourself, by typing the address you know or using your bookmark, and check if anything's actually wrong.
  4. Asking for a code, password, or "confirmation". No legitimate company will ever ask for your password or your 2FA code. Nobody real needs your 2FA code — a request for it is always an attack, usually someone trying to get into your account in real time while they have you on the phone.
  5. Slightly-off everything. Odd grammar, a generic "Dear Customer", a logo that's not quite right, a sender address that's a jumble. Individually weak signals; together, a pattern.

The one habit that defeats almost all of it: never log in by clicking a link in a message. If your bank "emails" you, don't click — open your banking app or type the address yourself. This single rule neutralises the overwhelming majority of phishing, because the fake link is the whole attack.

✅ Check: you can name the tells, and you've committed to the rule: navigate to sites yourself, never via a link in a message asking you to log in.


Six common mistakes

  1. Reusing passwords. The root cause of most real-world account takeovers.
  2. No 2FA on email. Your email resets everything else — it's the highest-value account you own.
  3. Clicking login links in messages. The entire phishing attack. Navigate yourself instead.
  4. Skipping backup codes, then getting locked out when you lose or wipe your phone.
  5. Giving out a 2FA code because someone "official" asked. Always an attack, no exceptions.
  6. Treating "strong but reused" as safe. Uniqueness matters more than complexity.

Exercise (50 min, verifiable output)

  1. Install a password manager. Create a passphrase master password.
  2. Run its security check. Note how many reused/breached passwords it finds.
  3. Replace the passwords on your three most important accounts (start with email) with generated ones.
  4. Turn on 2FA for your email and one financial account. Save the backup codes into the manager.
  5. Set up a passkey on one service that offers it.
  6. Check yourself on haveibeenpwned.com (safe, reputable) — see which breaches your email is already in. This is the motivation, made concrete.
  7. Find one real phishing-style email in your spam folder and identify three tells in it.

✅ Finish check: a password manager in use with unique passwords on your top accounts, 2FA on email

  • one financial account with codes saved, one passkey created, and three phishing tells identified in a real message.

Cheatsheet

THE CORE RULE
  every account gets a DIFFERENT password.
  one breach → one account, not all of them.

THE THREE MOVES
  1. password manager  → one master passphrase, it holds the rest
  2. 2FA               → email · money · the manager · socials
  3. passkeys          → turn on wherever offered (phishing-proof)

MASTER PASSWORD
  a passphrase: four random words. length beats symbols.
  never reused, never forgotten.

2FA, best to worst
  hardware key / passkey  >  authenticator app  >  SMS  >  nothing
  SAVE THE BACKUP CODES (in the manager, not your camera roll)

SECURE YOUR EMAIL FIRST — it resets everything else.

PHISHING — the tells
  urgency + a link · the link's real domain ≠ what it says
  they contacted you · asking for a code/password/"confirmation"
  NOBODY REAL NEEDS YOUR 2FA CODE — always an attack

THE ONE HABIT
  never log in via a link in a message.
  go to the site YOURSELF. defeats almost all phishing.

Sources

  1. NIST — Digital Identity Guidelines (SP 800-63B)
  2. US CISA — phishing, MFA and password manager guidance
  3. Troy Hunt — Have I Been Pwned; password reuse research
  4. FIDO Alliance — passkeys documentation

Next lesson: TC-12 — The Limits of AI-Written Code (L3) Related: TC-02 How the Internet Works · MN-10 The Anatomy of a Scam · SO-14 Pressure Tactics · AI-07 Hallucination Hunting Path: related — foundational for anyone with accounts online

Mark it when you've got the output in hand.

← All Technical Foundations lessons