Privacy / Checklist
Online Safety Advice That Holds
Much of the standard advice is obsolete. What is left is short, unglamorous, and covers the large majority of realistic risk.
Security advice accumulates and rarely gets pruned. A lot of what circulates addresses threats that no longer dominate, while the things that actually protect people are dull and get less attention.
The list that matters, in order of effect
One: unique passwords, in a manager. Converts a breach anywhere into a local problem instead of a cascade. This is the single highest-value action available and it addresses the most common way people are actually compromised.
Two: a phishing-resistant second factor on your email. A passkey or hardware key. Email resets everything else, which makes it the account that matters most, and passkeys are the only method that defeats a convincing fake login page.
Three: never authenticate from a link in a message. Go to the service the way you normally do. One habit, defeats nearly all credential phishing.
Four: automatic updates everywhere. Phone, computer, browser, router. Most compromise of ordinary people uses known flaws with available patches.
Five: verify money requests through a channel you chose. Hang up and call back. Defeats every impersonation, including cloned voices and video, because the attacker does not control the channel you initiate.
Six: backups that are not permanently connected. The only real defence against ransomware, and against the more common problem of a failed drive.
Seven: review app and extension permissions occasionally. Twenty minutes twice a year.
That is the whole list. Everything else is refinement.
Advice that has aged badly
"Change your passwords every 90 days." Withdrawn by the standards bodies that recommended it. Forced rotation produces predictable variations and weaker passwords. Change a password when there is a reason.
"Never use public wifi." Written when most traffic was unencrypted. Nearly everything is encrypted now, and the residual risks are metadata and hostile captive portals rather than someone reading your email.
"Look for the padlock." It means encrypted, not legitimate. Nearly every phishing site has one.
"Spot the bad grammar." Fraudulent messages are now fluent.
"Install antivirus." Built-in protection on current systems is adequate for most people, and the dominant threats are not addressed by scanning files.
"Cover your webcam." Not harmful, and not where the risk is.
"Use complex passwords with symbols." Length beats complexity, and the symbol requirements produce memorable-to-nobody passwords that get written down.
What actually compromises ordinary people
Reused passwords exposed in a breach elsewhere. The most common cause by a wide margin.
Phishing, increasingly well made.
Account recovery attacks, where an attacker uses a dead recovery email or a recycled phone number.
Social engineering by phone, including the support call and the family emergency.
Malicious browser extensions.
Unpatched software, especially the browser.
Notice that four of six are account problems rather than device problems. Security effort aimed at the device rather than the accounts is aimed at the wrong place.
The account hygiene that matters
Check your recovery options. A recovery email you no longer control or a phone number that has been reassigned defeats every other protection. This is the most neglected item on any list and it takes ten minutes.
Keep recovery codes somewhere physical.
Register a second factor on more than one device, so losing a phone is inconvenient rather than terminal.
Review devices signed into your accounts and remove what you do not recognise.
For people helping family members
Teach one rule rather than many: if someone contacts you about money or an account, contact them back on a number you looked up yourself.
Set up a password manager for them and put their accounts in it.
Set up a family verification word for emergency calls.
Enable automatic updates and leave them alone.
Do not teach threat detection. The production quality of modern fraud has passed the point where perception is a reliable defence, and teaching people to look for tells gives false confidence.
Doing the whole list in an evening
The seven items above are usually treated as a project and abandoned. Done in order, they take about two hours.
Install a password manager, twenty minutes. Import from the browser, set a strong unique passphrase, add a second factor to the manager itself.
Secure the email account, twenty minutes. Unique password, register a passkey or hardware key, generate recovery codes and print them, check the recovery email and phone are current, sign out of unknown sessions.
Do the same for the five accounts that matter most, forty minutes. Bank, primary shopping, phone carrier, work, cloud storage.
Turn on automatic updates everywhere, ten minutes.
Review browser extensions, ten minutes. Remove what you do not use.
Set up one backup, twenty minutes. External drive, built-in tool, let it run.
Agree the family verification word, five minutes.
Two hours, once. It addresses more realistic risk than any product, and the recovery-options check alone prevents the most common permanent account loss.