Account Security
Your email, Instagram, and bank account are only as safe as your password. Here's how to make them much harder to break into.
How to create a strong password +
A strong password is your first line of defence. Most accounts are broken into because the password was easy to guess.
Passwords to avoid (very easy to guess):
- Your name, husband's name, children's names, or pet's name
- Your birthday, anniversary, or phone number
- Simple words:
password,123456,india - The same password you use on another site
What makes a password strong?
- At least 12 characters long
- A mix of UPPERCASE letters, lowercase letters, numbers, and symbols (!@#)
- Something random that has no connection to your life
What is Two-Factor Authentication (2FA)? How to turn it on. +
Two-Factor Authentication (2FA) is like having a second lock on your door. Even if someone knows your password, they still can't get in without a second code that only you receive.
When 2FA is on, every time you log in, you'll get a one-time code sent to your phone (by SMS or an app). You enter that code along with your password.
How to turn on 2FA for common apps:
- Google / Gmail: myaccount.google.com โ Security โ 2-Step Verification โ Turn On
- Instagram: Profile โ Menu (โฐ) โ Settings โ Security โ Two-Factor Authentication โ Turn On
- WhatsApp: Settings โ Account โ Two-step verification โ Enable
- Facebook: Settings โ Security and Login โ Two-Factor Authentication โ Edit
Recognising a phishing message or fake link +
Phishing is when someone sends you a fake message pretending to be a real company (your bank, Instagram, the government) to trick you into giving your password or OTP.
Signs that a message is fake:
- It creates sudden urgency โ "Your account will be deleted in 24 hours!"
- It asks you to click a link and log in immediately
- The link looks almost right but is slightly wrong โ e.g.,
instagram-support.cominstead ofinstagram.com - It asks for your OTP, password, or bank PIN โ no legitimate company ever does this
- It comes from a random mobile number or a Gmail address pretending to be official
Securing your recovery email and phone number +
Your recovery email and recovery phone number are how you get back into your account if you forget your password. If someone else controls these, they can lock you out of everything.
What to check right now:
- Open your Google Account โ myaccount.google.com โ Security โ Ways we can verify it's you. Make sure the recovery phone and email belong to you โ not to an ex-partner or family member who controls your phone.
- Check your Instagram and Facebook recovery email and phone under Settings โ Personal Information.
- Make sure your recovery email account itself has a strong password and 2FA turned on โ otherwise it becomes the weakest link.
- If you share a phone number or email with a family member, create your own private email (e.g., a new Gmail) that only you control.
Passphrases โ stronger and easier than passwords +
A passphrase is a password made of multiple random words strung together. It's longer than a typical password, but much easier to remember โ and much harder to crack.
Why passphrases are better:
- A 4-word passphrase like "mango train purple river" is stronger than a complicated 8-character password like
P@ssw0rd! - They're easier to type on a phone keyboard
- They're easier to remember without writing down
- Computer programs that guess passwords find long, word-based phrases very hard to crack
How to create a strong passphrase:
- Choose 4 random, unrelated words โ "monsoon elephant laptop jasmine" works well. Don't use quotes, song lyrics, or anything personally meaningful.
- Optionally add a number and symbol between words: "monsoon7elephant!laptop"
- Use a unique passphrase for each important account
5-minute security upgrade โ the essentials right now +
If you only have 5 minutes, do these four things. They make the biggest difference.
- Enable 2FA on your Gmail โ Go to myaccount.google.com/security โ 2-Step Verification โ Turn On. This protects your email, which is the key to everything else.
- Enable 2FA on Instagram โ Profile โ โฐ โ Settings โ Security โ Two-Factor Authentication โ Turn On.
- Enable WhatsApp two-step verification โ Settings โ Account โ Two-step verification โ Enable โ set a 6-digit PIN.
- Check your Google recovery info โ myaccount.google.com โ Security โ "Ways we can verify it's you" โ make sure the recovery phone and email are ones only you control.