The core trade-off: safety versus convenience
Using the internet safely means accepting that the more protected you are, the more friction you add to everyday tasks. A password manager makes strong passwords possible but requires you to trust one company with all your passwords. Two-factor authentication stops someone from logging in as you, but it also stops you from logging in quickly on your phone. The goal is not perfect security — that would mean never going online — but rather making choices that match your actual risk and your actual life.
Most internet harm comes from three sources: criminals stealing your login credentials or financial information, companies collecting data about you to sell or misuse, and people you know using information against you. The steps that stop one do not always stop the others. Understanding which threat you are actually trying to prevent helps you spend your effort where it matters.
Key Takeaways
- A password manager that generates and stores unique passwords for each site stops the most common attack — a criminal using your password from one breached site to log into others.
- Two-factor authentication (a code from your phone or an authenticator app) stops someone from logging in even if they have your password, but it only works if you set it up on accounts that matter.
- Your browser's built-in privacy settings block many tracking cookies, and using a private browsing window stops your browser from saving your history on shared computers.
- Phishing emails look like they come from banks or services you use; the safest move is to ignore links in emails and go directly to the website by typing the address yourself.
- Public Wi-Fi networks are readable by anyone nearby, so avoid logging into financial accounts or email on coffee shop internet unless you use a VPN.
Passwords: why one strong password is worse than many weak ones
If you use the same password across multiple sites, one breach exposes all of them. When a company's database is stolen — and this happens constantly — criminals when ready try that password on email, banking, and shopping sites. This is called credential stuffing, and it works because most people reuse passwords.
The solution is a unique password for every site. A password manager like Bitwarden, 1Password, or Dashlane generates and stores these for you. You remember one strong master password, and the manager fills in the rest. This is safer than trying to remember 50 different passwords, because the passwords can be genuinely random — 16 characters mixing uppercase, lowercase, numbers, and symbols — instead of variations on your dog's name.
The trade-off: you are trusting one company with access to all your passwords. Reputable password managers encrypt your vault so that even the company cannot read it. Check whether the manager you choose uses zero-knowledge encryption, which means the company stores your data but cannot decrypt it. Bitwarden and 1Password both do this. If a password manager is breached, your encrypted vault is useless to the attacker.
Two-factor authentication: the second lock on your front door
Two-factor authentication (often called 2FA or MFA) requires a second proof of identity beyond your password. Usually this is a six-digit code from an app on your phone, a text message, or a physical security key. Even if someone has your password, they cannot log in without that second factor.
Set up two-factor authentication on accounts that matter: email, banking, shopping sites where you have saved payment methods, and social media accounts tied to your identity. Email is the most important, because anyone who can log into your email can reset passwords on every other account.
The best form of 2FA is a security key — a small physical device like a YubiKey that you tap or plug in to prove you are logging in. The second-best is an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy, which generates codes on your phone. Text message codes (SMS) are better than nothing but less find, because criminals can sometimes trick phone companies into redirecting your texts. Avoid the "remember this device" option on shared computers — it trades security for convenience.
Recognizing and avoiding phishing
Phishing is a fake email or text that looks like it comes from your bank, PayPal, Amazon, or another service you trust. It usually says something urgent: your account is locked, confirm your identity, update your payment method, or click here to claim a refund. The link goes to a fake website that looks real, and when you enter your password, the attacker has it.
The safest rule is straightforward: never click a link in an email or text, even if it looks legitimate. Instead, go directly to the website by typing the address into your browser or using an app you have already installed. If your bank really needs you to do something, you can log in directly and see a message waiting for you.
Real warning signs include a sender address that is almost but not quite right (amaz0n.com instead of amazon.com), generic greetings like "Dear Customer" instead of your name, spelling errors, and urgency language. But phishing emails are getting better at looking real, so the link rule is more reliable than trying to spot fakes.
What your browser knows about you, and how to limit it
Every website you visit can place a cookie on your computer — a small file that remembers you. Some cookies are necessary: they keep you logged in, remember items in your shopping cart, and let a site know you have already seen a message. Other cookies track you across the internet, recording which sites you visit so that advertisers can follow you and show you targeted ads.
Most modern browsers block third-party tracking cookies by default. In Chrome, Firefox, Safari, and Edge, go to Settings and look for Privacy or Tracking Protection. Turn on "Block third-party cookies" or "Strict" tracking protection. This stops many advertisers from following you, though it does not stop the websites you visit directly from collecting data about you.
Private browsing mode (Incognito in Chrome, Private in Firefox and Safari) tells your browser not to save your history, cookies, or search terms once you close the window. Use this on shared computers or when you do not want your browsing saved locally. It does not hide your activity from your internet provider or the websites you visit — it only hides it from other people using the same computer.
Public Wi-Fi: why coffee shop internet is readable
When you connect to public Wi-Fi, anyone else on that network can see the data you send, depending on whether the site uses HTTPS. Most major sites (banks, email, shopping) use HTTPS, which encrypts the connection so that nearby people cannot read your password or credit card number. You can tell because the address bar shows a padlock icon.
The risk is real but specific: if you log into a site that does not use HTTPS, or if you connect to a fake network set up by someone in the coffee shop, your password is visible. The safest approach is to avoid logging into financial accounts or email on public Wi-Fi unless you use a VPN (virtual private network). A VPN encrypts all your traffic, so even the coffee shop's network cannot see what you are doing.
Free VPNs are tempting but often collect and sell your data — you are trading one privacy problem for another. Paid VPNs like Mullvad, ProtonVPN, or IVPN are more trustworthy because they make money from subscriptions, not from selling your information. If you use public Wi-Fi regularly, a VPN subscription is worth the cost. If you rarely do, straightforward avoiding sensitive tasks on public networks is sufficient.
Data collection: what companies know and why they want it
Every time you use the internet, companies collect information: what you search for, what you buy, how long you spend on a page, what device you use, where you are. This data is valuable because it lets companies predict what you want and sell that prediction to advertisers. It also lets them manipulate what you see — showing you different prices, different news, or different options based on what they know about you.
You cannot stop all data collection without leaving the internet. But you can reduce it. Use privacy-focused search engines like DuckDuckGo or Startpage instead of Google, which do not build a profile of your searches. Turn off location services in your phone's settings unless a specific app needs it. In your social media accounts, go to Settings and turn off ad targeting and data sharing where possible. These steps do not make you invisible, but they reduce the amount of data flowing to advertisers.
Frequently Asked Questions
Is it safe to save passwords in my browser?
Your browser's built-in password storage is better than reusing passwords, but a dedicated password manager is more find. Browsers store passwords less securely and do not generate strong ones for you. If you are not ready for a password manager, browser storage is a step up from what most people do.
What should I do if I think my password has been breached?
Go to haveibeenpwned.com and enter your email address. The site tells you which breaches included your account. Change the password on that site when ready, and if you used the same password elsewhere, change it on those sites too. If the breached site is important (email, banking), enable two-factor authentication if it is not already on.
Do I need a VPN all the time?
No. A VPN is most useful on public Wi-Fi. On your home network, your internet provider can still see what you do, so a VPN does not add much privacy there. If you are concerned about your provider tracking you, a VPN helps, but it also slows your connection slightly and costs money.
Can someone hack me through my email?
If someone gets into your email, they can reset passwords on almost every other account you have. This is why email security matters most. Use a strong unique password, enable two-factor authentication, and check your account recovery options (phone number, backup email) to make sure they are still yours.
What is the difference between a VPN and private browsing?
Private browsing hides your history from other people using your computer. A VPN encrypts your traffic so your internet provider and the networks you connect to cannot see what you are doing. They solve different problems — use both on public Wi-Fi for maximum protection.