Skip to content
VaultPass

Guide · Fundamentals

Everything that matters, in order of how much it matters

You do not need to understand cryptography to be reasonably protected. You need four decisions made well, and this guide puts them in order of impact.

Security Guide

Understand how cybercriminals think and act, explained for humans.

Why should I censor my texts before using AI (ChatGPT)?

Artificial intelligences are not private. What you type (customer emails, contracts, company code) travels to their servers and, depending on your plan, may be used to train future models. On top of that, staff at those companies can review conversations to "improve the system".

The real danger: If you paste a customer's card number or ID so the AI can help you draft an email, that confidential data ends up recorded outside your control. Our tool replaces it with tags like [CARD HIDDEN] before it leaves your computer.

What is a "Dictionary Attack"?

Attackers know that people are predictable. Instead of testing random letter combinations, they use massive lists of real words (dictionaries) and combine them with typical dates or numbers.

Example: If your name is "Alex" and you were born in "1993", you might use Alex.1993. Mathematically it looks long, but an automated program tries that exact combination in milliseconds, because the word "Alex" and the number "1993" are in its human-pattern database.

What is "Brute Force"?

It is the most basic method, but lethal if your password is short: a computer literally tries every possible combination, from a to zzzzzzzz, at inhuman speeds.

The numbers: A modern high-end graphics card can test tens of billions of passwords per second against fast hashes. If your password only has lowercase letters and is 8 characters long, it falls immediately.

What is "Entropy"?

Entropy is the mathematical way to measure the "level of chaos" of a password, expressed in bits. Every extra bit doubles the attacker's work: 40 bits is weak, 80 bits is a fortress.

When the auditor says "longer than the age of the universe", it means the number of combinations is so brutal that, even with every computer on the planet working together, the sun would burn out before brute force guessed the key.

What if my password leaks anyway?

It happens all the time: breaches occur on the company side, not yours. That is why two habits matter: never reuse the same password (so the damage stays in one account) and enable two-step verification, ideally with an authenticator app or a hardware key instead of SMS.

Rule of thumb: Memorise one very long password (the one for your password manager) and let the manager invent and remember the rest.

The order matters more than the list

Almost every security guide is a long list of tips, all presented as equally urgent. The result is that people start with the easiest one, get bored and never reach the one that actually mattered.

This is the order by real impact:

  1. A unique password on your email and two-factor authentication there. Do only this and you have done half the work.
  2. A password manager, so you can stop reusing keys without memorising anything.
  3. Two-factor on banking and anything holding money.
  4. Recovery codes saved on paper, away from your phone.
  5. System and browser kept updated, which is dull and closes most technical holes.

What comes after that — VPNs, paid antivirus, specialised browsers — is perfectly respectable and has far less impact. If you have not done the five points above, starting there is optimising the wrong part.

What you are actually defending against

The mental image of someone deciding to attack you personally is almost always wrong, and it leads people to misjudge their own risk. What really happens is this:

  • Automated attacks using leaked lists. A program tries millions of email-and-password pairs across dozens of services. By far the most common.
  • Mass phishing. Emails and texts sent to millions of addresses hoping a small percentage bite.
  • Phone fraud using real data from breaches to sound credible.

All three are indiscriminate. That is why "I am nobody important" protects you from nothing: you do not have to be interesting to be on a list.

The four decisions, with the reasoning

1. A different password on every site

This is what turns someone else's breach into a local problem instead of a cascade. It does not require memory: it requires a manager.

2. Two-factor authentication

It turns a stolen password into a minor problem. The method matters — an authenticator app resists better than SMS, and a physical key better than both — butany method turned on beats none by a wide margin.

3. Knowing how to recognise a scam

No technical measure protects you if you are the one handing over the password. Check the real domain, the real destination of the link, and whether the message is rushing you. Perfect spelling and the browser padlock prove nothing.

4. Having a plan for when something goes wrong

Recovery codes saved, a second device registered, and knowing what to do the day a breach notice arrives.

What you can stop doing

  • Changing passwords every three months. Discouraged since 2017 by the very bodies that popularised it.
  • Swapping letters for numbers. Attack dictionaries do that automatically.
  • Avoiding public Wi-Fi for fear of traffic being read. HTTPS already encrypts it; the real risk is a fake network.
  • Trusting the browser padlock as proof a site is legitimate. It only says the connection is encrypted.

Frequently asked

Common questions

If I can only do one thing, what should it be?

Put a unique, long password on your email and turn on two-factor authentication there. Email is where everything else is recovered from, so protecting it protects the rest by extension.

Is a paid antivirus worth it?

For an up-to-date Windows machine in ordinary home use, the protection built into the system is enough. The money goes much further on a password manager or a pair of security keys.

I am nobody important. Am I really going to be attacked?

Nobody picks you. The attacks that affect ordinary people are automated and work through lists of millions of leaked credentials. You do not have to be interesting to be on a list.

Where to go next