Plain-language definitions of the terms you’ll meet across our guides.
- Phishing, a message (email, text, DM) that impersonates a trusted brand to trick you into handing over passwords, codes, or money.
- Smishing, phishing by SMS text message.
- Two-factor authentication (2FA), a second step at login (a code or a tap) so a stolen password alone can’t get someone in. Also called multi-factor authentication (MFA).
- Passphrase, a password made of several random words (e.g.
river-lamp-tuesday-garden). Longer and easier to remember than a short “complex” password. - Password manager, an app that generates and stores a unique strong password for every account, behind one master password.
- Data breach, when a company’s stored data (emails, passwords, card numbers) is exposed or stolen.
- Credential stuffing, attackers taking passwords leaked in one breach and trying them on other sites, which works whenever you’ve reused a password.
- Malware, malicious software (viruses, spyware, trojans) designed to harm or spy on your device.
- Ransomware, malware that locks your files and demands payment to unlock them.
- HTTPS, the encrypted version of a web connection (the padlock). It protects data in transit, but doesn’t prove the site is honest.
- Typosquatting, registering lookalike domains (
paypa1.com) to catch people who mistype or don’t check the address. - Social engineering, manipulating people (urgency, authority, fear) rather than hacking software. Most scams rely on it.
- VPN, a service that encrypts your internet traffic and hides your browsing from the network you’re on.
- Browser security extension, an add-on that checks links against a database of known-bad sites and warns you before a page loads.
- Zero-day, a software flaw that’s being exploited before the maker has a fix.
- End-to-end encryption, only the sender and recipient can read the content; not even the service in between.
Want the practical version?
Every term above shows up in a real how-to. Start with our guides.