No jargon

What does that mean?

The most common concepts in short form. Each explanation leads to a specific next step.

2FA

Login requiring two different types of confirmation, e.g. password and hardware key. Two passwords do not form two different components.

Enable second component →Link to the concept

MFA

Authentication with at least two types of ingredients: something you know, have or are. 2FA is one of its variants.

Compare login methods →Link to the concept

TOTP

A one-time code calculated on the basis of a common secret and time, usually by the 2FA application. The code can be extorted; prescribe it only when logging in, which started itself.

Move application 2FA →Link to the concept

Passkey

The cryptographic certificate assigned to the service. Its use is approved on the device, e.g. PIN or biometry. The method of synchronization and recovery depends on the supplier.

Meet passkey login →Link to the concept

Hardware key

Physical device used to confirm login. FIDO keys can store passkeys or act as a second component; the possibilities depend on the device and service.

Prepare the hardware key →Link to the concept

Password manager

A tool to generate and store unique passwords. Secure its access, take care of recovery and watch out for unsecured exports.

Start using the password manager →Link to the concept

Password expression

A password composed of a few words. Words drawn independently of the corresponding list have different predictability than a well-known quote or sentence chosen by man.

Check how the password manager is protected →Link to the concept

Hash and control sum

The result of the shortcut function for specified data. Compliance with the sum from a trusted source helps to verify the integrity of the file; it does not in itself confirm its security.

Compare the sum of the file →Link to the concept

Salt

Random value added when password hashing, so that the same passwords have different entries. It does not have to be secret and does not replace the costly password storage function.

Understand storing passwords →Link to the concept

Phishing

An attempt to get your data, money or access by impersonating a trusted person or service. It can be reached by email, SMS, conversation or chat.

Check suspicious message →Link to the concept

Host

The server name or IP address in the URL. In https://konto.example.test/Login host is account.example.test, and /login is path. The host name itself does not confirm the site's reputation.

Read address items →Link to the concept

Punycode

The writing used to replace parts of international domain names into ASCII. Often starts with xn--. Such writing is not in itself proof of deception.

Read the full URL →Link to the concept

HTTPS

The HTTP connection protected by TLS. It helps secure the data on the way to the indicated site; the lock does not confirm the integrity of its owner.

Meet the limitations of HTTPS →Link to the concept

Origin

For the typical HTTPS address: protocol, host and port that the browser treats as a single origin. Two subdomains have different origami and separate localStorage.

Check local data processing →Link to the concept

Backup codes

Codes issued by the service to log in or retrieve access when the basic method does not work. Treat them as secrets; the usage and cancellation rules define the service.

Prepare emergency access →Link to the concept

Backup

An additional copy of the data from which it can be played after loss or damage. Check restoration before failure; synchronization itself can also move file deletion.

Prepare the plan and try to recreate →Link to the concept

Sources and further reading

The definitions are simplified for use in Security Lab. For details, see the guidebook and source documentation.

Update: .