Guides
Passwords, login and account recovery. Select the problem you want to solve.
Where to start? Choose a plan for your situation →
Do you know the concept? Open the safety dictionary →
Practice your reaction to suspicious message →
Passwords and password managers
First password manager: where to start
3 min readFirst move one account. See if you can save the password, use it and regain access to the safe. The rest can wait.
Why One Strong Password Is Not Enough
2 min readA long password can be hard to guess, and yet open several accounts at once. The problem starts when you use it again.
When to Change Password — And What To Do Beyond Change
2 min readLeak, false form and a foreign session require response. The month itself is not usually the reason for setting another variant of the same password.
Export password manager without revealing the safe
2 min readMoving passwords can create a file with secrets in an ordinary text. Check the format and location of the write before export.
Two-component authentication
How to enable 2FA and not lose access to your account
3 min readStart by mailing. Select the method, add it to your account and prepare a spare for the day your phone stops working.
New phone, same accounts: moving 2FA
3 min readThe installation of the authentication application itself does not play code. Move entries and check logins before you clear your previous phone.
Safety key: when to use it
2 min readA small USB or NFC device confirms the login to the right page. See how to add the key and prepare to lose it.
2FA backup codes: Prepare them before failure
2 min readThe backup code can replace the second component of the login. Save it so that losing your phone does not mean losing both methods.
2FA notification without your login
2 min readDo not approve a request that has not been started from your website. Check account activity by a known application or address.
Login using passkeys
Passkey: how to log in without a password
2 min readFingerprint or PIN unlocks the key saved on the device. We explain what gets the page and what happens after changing your phone.
Passkeys after losing your phone: how do you get access?
2 min readThe plan depends on where the key is stored. Check the supplier, the second device and the emergency method before they are needed.
Hashing in practice
How to check SHA-256 downloaded file
2 min readCompare the file with the sum published by the publisher. You need the right algorithm, the correct version of the file and the full result.
Why SHA-256 is not enough to store passwords
3 min readHash file and saving password on the server have different requirements. For passwords it also counts the cost of each attempt to guess.
Access to the account under control
How to prepare account recovery before failure
2 min readA good plan answers one question: how will you sign in when you don't have a phone? Prepare it for mail, password manager and device account.
Secure the mail through which you recover other accounts
2 min readPassword and 2FA are the beginning. Also check active sessions, messages and applications that can read mail.
Unknown login: how to regain account control
2 min readCheck whether the alert concerns your action. If not, secure login, end alien sessions and remove the remaining access routes.
Password in the leak: what to do one at a time
2 min readFirst confirm the information from the supplier and secure the account. Then take care of the places where the same password was used.
Lost phone: secure device and account
2 min readUse the official location service, take care of your phone number and check your account access. Do not quickly delete the methods needed to recover your device.
Updates without false messages
2 min readUpdate the system, browser and applications through their official mechanisms. The banner on a foreign site is not a service manual.
Backup: See if you can restore the data
2 min readSynchronization is not always a backup. Select data, second save place and a simple restoration test.
Recognition of fraud attempts
Suspect message: how to test it
3 min readNice graphics, correct Polish and a lock in your browser do not confirm the sender. Check the request regardless of the link you received.
A friend of mine is asking for a code or money.
2 min readThe real profile can be taken over. Confirm the unusual request by another way, especially when it concerns payment or code from SMS.
How to read URL before logging in
2 min readThe address is about a real host, not a logo or a familiar word. Learn to separate the host from the login data, path and parameters.
QR code: check the address before opening
2 min readThe QR code may hide the same suspicious link as the SMS. See the address preview and confirm what the operation relates to.
How to report phishing to CERT Poland
2 min readSend the suspect SMS to 8080, and report the page or message via official channel. The request does not replace account security.
No matching guides. Try a shorter password or select all topics.