CHECKING ACCOUNTS, DEVICES, PASSWORDS, BACKUPS...
STATUS: BASIC DEFENSE MODE
DIGITAL HYGIENE :: BASIC ONLINE SECURITY
> It is not about paranoia. It is about making common attacks harder.
WHY DIGITAL HYGIENE MATTERS
Most real-world security problems do not start with elite hacking. They start with reused passwords, fake login pages, old software, malicious attachments, weak recovery options, or accounts with no second factor.
Good digital hygiene reduces the damage when something goes wrong. It also makes your privacy tools more useful, because a VPN, Tor, or encrypted email cannot protect an account that uses a leaked password.
Use unique passwords, strong recovery settings, and two-factor authentication for important services.
Keep systems updated, encrypt storage, lock screens, and avoid installing random software.
Back up important files, clean metadata before sharing, and avoid storing sensitive data everywhere.
PASSWORDS
A good password strategy is simple: one unique password per account. Do not reuse passwords. If one service leaks, reused passwords let attackers try the same login elsewhere.
Use a password manager.
Use a unique password for every account.
Use long passphrases when you must remember one.
Never store passwords in plain text notes.
Never reuse your email password anywhere else.
TWO-FACTOR AUTHENTICATION
Two-factor authentication adds a second step after the password. It can stop many account takeovers, especially when a password is leaked or phished.
Authenticator apps, hardware security keys, passkeys, recovery codes stored offline.
SMS codes are better than nothing, but they are more exposed to SIM swap, interception, and phone-number attacks.
UPDATES
Updates are boring, but important. They fix bugs and security vulnerabilities in operating systems, browsers, phones, apps, routers, NAS devices, and plugins.
Update priority:
1. Browser
2. Operating system
3. Password manager
4. Mail client
5. Phone apps
6. Router / firewall / NAS
7. Exposed servers and web apps
PHISHING
Phishing tries to make you act quickly: click a link, open an attachment, enter credentials, approve a login, pay an invoice, or share a code. The attack often uses pressure, urgency, fear, or curiosity.
Look for fake spellings, extra words, strange TLDs, or shortened links.
Urgent password reset, payment request, MFA code request, or attachment from nowhere? Slow down.
For sensitive requests, confirm through a known phone number, internal chat, or trusted contact path.
BROWSER HYGIENE
Your browser is one of the most exposed applications you use. Keep it updated, reduce extensions, block trackers, and separate sensitive sessions from casual browsing.
Recommended habits:
- Use uBlock Origin or a trusted content blocker.
- Remove extensions you do not really need.
- Do not install random coupon, PDF, or video downloader extensions.
- Use separate browser profiles for work, banking, and casual browsing.
- Clear site permissions you no longer need.
- Prefer HTTPS-only mode when available.
APP PERMISSIONS
Apps often ask for more access than they need. Review permissions regularly, especially camera, microphone, location, contacts, files, Bluetooth, and notification access.
Disable location for apps that do not need it. Use “while using the app” instead of permanent location access.
Be careful with apps that require admin rights, browser extensions, screen recording, accessibility access, or full disk access.
BACKUPS
Backups protect against ransomware, disk failure, accidental deletion, stolen devices, and bad updates. A backup that was never tested is only a hope.
Simple backup rule:
3 copies of important data
2 different types of storage
1 copy offline or off-site
DEVICE BASICS
- Use a screen lock on phones, laptops, and tablets.
- Enable full-disk encryption when possible.
- Do not share admin accounts for daily work.
- Remove old devices from your account security pages.
- Review active sessions in email, cloud, and password manager accounts.
- Disable Bluetooth, file sharing, or remote access when not needed.
PRIVACY HABITS
Security and privacy overlap, but they are not the same. Security protects access. Privacy limits unnecessary exposure. Both matter.
Do not post documents, badges, tickets, addresses, screenshots, or photos without checking hidden data.
Use different emails or aliases for work, personal accounts, newsletters, and risky signups.
Block third-party trackers, avoid unnecessary apps, and prefer services with clearer privacy practices.
QUICK CHECKLIST
[ ] Password manager installed
[ ] Unique password for email
[ ] 2FA enabled on email
[ ] 2FA enabled on password manager
[ ] Recovery codes saved offline
[ ] Browser updated
[ ] Phone and computer updated
[ ] Unused extensions removed
[ ] Important files backed up
[ ] Backup restore tested
[ ] App permissions reviewed
[ ] Old sessions disconnected
COMMON MISTAKES
- Thinking private browsing hides you from every tracker.
- Using a VPN while staying logged into every personal account.
- Keeping the same password for email, cloud, and shopping accounts.
- Ignoring recovery email and phone number security.
- Trusting every browser extension.
- Sharing screenshots that reveal tabs, usernames, internal URLs, or notifications.