
Most account breaches don’t come from some elite hacker, but from weak passwords, the same one reused everywhere, or being tricked into typing it into a fake page. The good news is that just two habits are enough to protect you against most of the risk.
Two-factor authentication (2FA)
2FA means that on top of your password, you need a second factor – usually a code from an app like Google Authenticator. Even if a bad actor knows your password, they still can’t get in without this code. Turn on 2FA for your main email first, because email is the key to recovering every other account.
Where possible, favor a code-generating app over text messages, since SMS can be hijacked through SIM-swapping tricks.
Password managers
Nobody can remember fifty different strong passwords – so people reuse one password for everything, and that is the fatal weak point. A password manager creates and stores long, random, unique passwords for each site on your behalf. You only have to remember one master password.
Getting started today isn’t hard: install a reputable manager, change your email and banking passwords first, then gradually update the rest each time you log in. A few minutes spent now can save you a whole week of cleanup later.