Cheat sheets

Everyday checklists

Short step-by-step lists: work through the points and the risk drops noticeably.

Secure an account in 10 minutes

The minimum that stops most common takeovers.

  • Change your password to a long one (14+ characters) that is unique for every important site.
  • Keep passwords in a password manager — you only have to remember one master password.
  • Turn on two-factor authentication, preferably with an app or a key rather than SMS.
  • Check your email for breaches and change passwords wherever they were exposed.
  • Remove old devices and unfamiliar sign-ins in your account's security settings.
  • Give your main email its own password used nowhere else: every other reset goes through it.
  • Turn on alerts for sign-ins from a new device.
Generate a password

How to spot a phishing email

Five seconds of attention before you click a link.

  • Look at the sender's address, not the name: "Bank" can come from an address that has nothing to do with the bank.
  • Hover over a link and compare the real address with what the text says.
  • Be wary of urgency and threats: "your account will be blocked in an hour", "final warning".
  • Services don't ask you to reply with your password, SMS code or card details.
  • A generic "Dear customer" instead of your name and odd mistakes in the text are bad signs.
  • Don't open attachments ending in .exe, .scr, .zip, or Office files that say "enable macros".
  • If in doubt, go to the service's site yourself by typing the address, not through the link in the email.
  • Check a suspicious link first: in emails on our mailbox, each link has a "Check" button next to it.
Check a link

Before you publish a photo or document

A file says more about you than what's visible on screen.

  • Strip EXIF from photos: it can hold your home's GPS coordinates, your phone model and the exact time.
  • In Word and PDF documents, check the author, organization and edit history — remove those too.
  • In screenshots, hide addresses, numbers, names in lists, tabs and notifications.
  • Don't post photos of tickets, barcodes, card numbers or documents — codes can be read from a picture.
  • Remember that messengers and social networks often strip metadata themselves, but sending a photo as a file keeps it.
  • If you must send a file with personal data, share a link that stops working after a while.
Remove photo metadata

Signing up on a site you don't trust

How to get what you need without leaving extra behind.

  • Use a temporary email instead of your main one — then spam and the site's data leak won't reach you.
  • Create a separate password: its leak shouldn't open your other accounts.
  • Don't give a phone number or documents if the site works without them.
  • Pay with a virtual or single-use card with a limited balance.
  • If you sign up for a one-time code or file, don't use an address you'll need later — a temporary inbox disappears.
  • For anything important (bank, work, government services), don't use a temporary email: you'd lose account recovery.
Create a temporary email

What to do if your password leaked

The order of steps when a service reports a breach or you find your address in a database.

  • Immediately change your password on the site where the leak happened.
  • Change the same password everywhere you used it — start with email and banks.
  • Turn on two-factor authentication where you don't have it yet.
  • End active sessions on all devices in your account settings.
  • Review emails about password changes and suspicious sign-ins from the last few days.
  • Be more careful with emails and calls: after a breach, scammers know your name and email.
  • Stop using one password for different sites.
Check your email for breaches

How to share a password or secret safely

So a password doesn't stay in someone's chat history forever.

  • Don't send passwords as an ordinary message: it stays in history and backups for years.
  • Use a note that burns after reading and send only the link.
  • Send the link and the password through different channels: the link in one messenger, the code by phone.
  • Set a short lifetime for the note and delete it once the recipient has read it.
  • After handing over a temporary password, ask the recipient to change it right away.
Create a secret note