The whole Security Lab
Find Next Step
Tools, instructions and simple explanations in one place. You can search without Polish characters.
Security Lab Content
- Tool
Password generator
For your password manager: generate random characters at your chosen length.
- Tool
Password analyzer
Check a sample password for predictable patterns.
- Tool
Passkey readiness
Check whether you are ready for passwordless sign-in.
- Tool
Compare sign-in methods
Compare 2FA, passkeys and hardware security keys, including their limitations.
- Tool
Phishing response plan
Plan your first steps after clicking a link, sharing data or opening a file.
- Tool
File checksums
Compute a file or text hash and compare it with the expected value.
- Tool
URL inspector
Read a link’s hostname and unusual elements without opening the website.
- Tool
Password resistance calculator
See how length and randomness affect the number of possible combinations.
- Tool
Account recovery plan
Prepare backup sign-in methods before losing your phone.
- Tool
Practice: suspicious messages
Practice checking links, requests for codes and unusual messages.
- Tool
Backup plan
Back up your files or phone and test restoring the data.
- Guide
First password manager: where to start
First move one account. See if you can save the password, use it and regain access to the safe. The rest can wait.
- Guide
How to enable 2FA and not lose access to your account
Start by mailing. Select the method, add it to your account and prepare a spare for the day your phone stops working.
- Guide
Passkey: how to log in without a password
Fingerprint or PIN unlocks the key saved on the device. We explain what gets the page and what happens after changing your phone.
- Guide
How to check SHA-256 downloaded file
Compare the file with the sum published by the publisher. You need the right algorithm, the correct version of the file and the full result.
- Guide
How to prepare account recovery before failure
A good plan answers one question: how will you sign in when you don't have a phone? Prepare it for mail, password manager and device account.
- Guide
Suspect message: how to test it
Nice graphics, correct Polish and a lock in your browser do not confirm the sender. Check the request regardless of the link you received.
- Guide
Why One Strong Password Is Not Enough
A long password can be hard to guess, and yet open several accounts at once. The problem starts when you use it again.
- Guide
When to Change Password — And What To Do Beyond Change
Leak, false form and a foreign session require response. The month itself is not usually the reason for setting another variant of the same password.
- Guide
New phone, same accounts: moving 2FA
The installation of the authentication application itself does not play code. Move entries and check logins before you clear your previous phone.
- Guide
Safety key: when to use it
A small USB or NFC device confirms the login to the right page. See how to add the key and prepare to lose it.
- Guide
Passkeys after losing your phone: how do you get access?
The plan depends on where the key is stored. Check the supplier, the second device and the emergency method before they are needed.
- Guide
Why SHA-256 is not enough to store passwords
Hash file and saving password on the server have different requirements. For passwords it also counts the cost of each attempt to guess.
- Guide
Secure the mail through which you recover other accounts
Password and 2FA are the beginning. Also check active sessions, messages and applications that can read mail.
- Guide
Unknown login: how to regain account control
Check whether the alert concerns your action. If not, secure login, end alien sessions and remove the remaining access routes.
- Guide
A friend of mine is asking for a code or money.
The real profile can be taken over. Confirm the unusual request by another way, especially when it concerns payment or code from SMS.
- Guide
2FA backup codes: Prepare them before failure
The backup code can replace the second component of the login. Save it so that losing your phone does not mean losing both methods.
- Guide
2FA notification without your login
Do not approve a request that has not been started from your website. Check account activity by a known application or address.
- Guide
Password in the leak: what to do one at a time
First confirm the information from the supplier and secure the account. Then take care of the places where the same password was used.
- Guide
Lost phone: secure device and account
Use the official location service, take care of your phone number and check your account access. Do not quickly delete the methods needed to recover your device.
- Guide
How to read URL before logging in
The address is about a real host, not a logo or a familiar word. Learn to separate the host from the login data, path and parameters.
- Guide
QR code: check the address before opening
The QR code may hide the same suspicious link as the SMS. See the address preview and confirm what the operation relates to.
- Guide
How to report phishing to CERT Poland
Send the suspect SMS to 8080, and report the page or message via official channel. The request does not replace account security.
- Guide
Updates without false messages
Update the system, browser and applications through their official mechanisms. The banner on a foreign site is not a service manual.
- Guide
Backup: See if you can restore the data
Synchronization is not always a backup. Select data, second save place and a simple restoration test.
- Guide
Export password manager without revealing the safe
Moving passwords can create a file with secrets in an ordinary text. Check the format and location of the write before export.
- Plan
Secure my accounts
Start with the post office, because it gives you access to other services.
- Plan
I received a suspicious message
Do not act under pressure. Check the case by a known application or independent contact.
- Plan
Change my phone
Keep access to the old device until new methods are tested.
- Plan
Check files
Combine the verification of the downloaded file with the updates and the working backup.
- Concept
2FA
Login requiring two different types of confirmation, e.g. password and hardware key. Two passwords do not form two different components.
- Concept
MFA
Authentication with at least two types of ingredients: something you know, have or are. 2FA is one of its variants.
- Concept
TOTP
A one-time code calculated on the basis of a common secret and time, usually by the 2FA application. The code can be extorted; prescribe it only when logging in, which started itself.
- Concept
Passkey
The cryptographic certificate assigned to the service. Its use is approved on the device, e.g. PIN or biometry. The method of synchronization and recovery depends on the supplier.
- Concept
Hardware key
Physical device used to confirm login. FIDO keys can store passkeys or act as a second component; the possibilities depend on the device and service.
- Concept
Password manager
A tool to generate and store unique passwords. Secure its access, take care of recovery and watch out for unsecured exports.
- Concept
Password expression
A password composed of a few words. Words drawn independently of the corresponding list have different predictability than a well-known quote or sentence chosen by man.
- Concept
Hash and control sum
The result of the shortcut function for specified data. Compliance with the sum from a trusted source helps to verify the integrity of the file; it does not in itself confirm its security.
- Concept
Salt
Random value added when password hashing, so that the same passwords have different entries. It does not have to be secret and does not replace the costly password storage function.
- Concept
Phishing
An attempt to get your data, money or access by impersonating a trusted person or service. It can be reached by email, SMS, conversation or chat.
- Concept
Host
The server name or IP address in the URL. In https://konto.example.test/Login host is account.example.test, and /login is path. The host name itself does not confirm the site's reputation.
- Concept
Punycode
The writing used to replace parts of international domain names into ASCII. Often starts with xn--. Such writing is not in itself proof of deception.
- Concept
HTTPS
The HTTP connection protected by TLS. It helps secure the data on the way to the indicated site; the lock does not confirm the integrity of its owner.
- Concept
Origin
For the typical HTTPS address: protocol, host and port that the browser treats as a single origin. Two subdomains have different origami and separate localStorage.
- Concept
Backup codes
Codes issued by the service to log in or retrieve access when the basic method does not work. Treat them as secrets; the usage and cancellation rules define the service.
- Concept
Backup
An additional copy of the data from which it can be played after loss or damage. Check restoration before failure; synchronization itself can also move file deletion.
No matching content found
Try a shorter password or other type of content. You can also choose a plan for your situation.