🔐 Protect Your Online Accounts

A simple guide to modern security methods for your important accounts

⚠️ Warning!

Recently, a huge leak of 16 billion credentials was reported. If you use the same password for multiple accounts, you're in danger! Hackers will try to reuse your login/password across all resources like social networks, banks, messengers, and even corporate accounts.

Security levels of your accounts:

Critically dangerous: Only login and password required for access
Dangerous: 2FA via SMS - the most vulnerable two-factor authentication method
Better: OTP codes in apps (Google Authenticator) - but still vulnerable to phishing
Best protection: Passkeys - protect against phishing and man-in-the-middle attacks

Choose a service to configure protection

Google
Microsoft
Apple
Meta/Facebook
WhatsApp
Telegram
X (Twitter)
LinkedIn
GitHub
Amazon
AWS
PayPal
Binance
Dropbox
Banking

Protecting Your Google Account

1

Set up multiple Passkeys

Passkeys provide maximum protection against phishing and cyber attacks. Create multiple keys for browsers, devices, and password managers as backups.
Set up Passkeys
2

Enable Advanced Protection Program

This program provides an additional layer of security for high-risk accounts (journalists, activists, business leaders). Warning: may limit non-standard email applications.
Enable Protection
3

Change your password if it's weak

Use a strong unique password or passphrase. Never use the same password for multiple services.
Change Password

Protecting Your Microsoft Account

1

Set up multiple Passkeys

Microsoft actively supports the Passkeys standard for maximum protection against phishing. Add keys for different devices.
Set up Passkeys
2

Enable 2FA or passwordless authentication

Two-factor authentication adds an additional layer of protection. Passwordless authentication via Passkeys is even more secure.
Set up 2FA

Protecting Your Apple ID

1

Add physical security keys

Apple currently only supports physical security keys (e.g., YubiKey). This provides the highest level of protection against remote attacks.
Learn More
2

Add trusted devices

Multiple trusted devices will ensure access to your account even if you lose your main device. Make sure all devices are physically secure.
Manage Devices

Protecting Your Meta/Facebook Account

1

Enable two-factor authentication

2FA protects your account even if your password is compromised. Use an authenticator app instead of SMS for better security.
Set up 2FA
2

Set up Passkeys

Facebook recently announced full Passkey support on mobile devices. This is the most modern and secure way to protect against phishing.
Create Passkey

Protecting WhatsApp

1

Create a Passkey

WhatsApp supports only one Passkey, so make sure the device with the key is reliably protected and cannot be lost.
Path: Settings → Account → Passkeys → Create passkey → Continue
2

Alternative: Two-step verification

If you can't use Passkey, be sure to enable two-step verification with a 6-digit PIN code.
Path: Settings → Account → Two-step verification

Protecting Telegram

1

Enable two-step verification

Unfortunately, Telegram doesn't support Passkeys yet. Two-step verification is the only available additional layer of protection.
Path: Settings → Privacy and Security → Two-Step Verification
Detailed Instructions
2

Check active sessions

Regularly check the list of active sessions and terminate suspicious connections.
Path: Settings → Privacy and Security → Active Sessions

Protecting Your X (Twitter) Account

1

Create a Passkey

X supports modern Passkeys for maximum protection against phishing attacks and account hijacking.
Create Passkey
2

Choose security key as 2FA method

Physical security keys provide better protection than SMS or authenticator apps.
Set up 2FA

Protecting Your LinkedIn Account

1

Create a Passkey

LinkedIn supports Passkeys to protect your professional account from phishing and unauthorized access.
Create Passkey
2

Enable two-factor authentication

For additional protection, set up 2FA via authenticator app.
Set up 2FA

Protecting Your GitHub Account

1

Enable 2FA with security keys

GitHub requires 2FA for all users. Use hardware security keys or passkeys for the strongest protection of your code repositories.
Set up 2FA
2

Use SSH keys for Git operations

SSH keys provide secure authentication for Git operations without exposing passwords. Generate unique keys for each device.
Set up SSH Keys
3

Review authorized applications

Regularly audit third-party applications with access to your repositories. Revoke access for unused or suspicious apps.
Manage Applications

Protecting Your Amazon Account

1

Enable Two-Step Verification

Amazon calls 2FA "Two-Step Verification" and it adds an extra layer of security to your account. Choose between SMS or authenticator app - the app method is more secure.
Set up Two-Step Verification
2

Use an Authenticator App instead of SMS

If possible, use an authenticator app (Google Authenticator, Microsoft Authenticator, or AWS Virtual MFA) instead of SMS for better security. SMS can be intercepted or SIM cards can be cloned.
3

Review your payment methods and addresses

Regularly check your saved payment methods, shipping addresses, and recent orders for any unauthorized changes or purchases.
Manage Account Settings
4

Monitor account activity

Enable email notifications for purchases and account changes. Review your order history regularly to catch any unauthorized activity quickly.

Protecting Your AWS Account

1

Enable MFA for root account

The root account has full access to all AWS services. Use hardware security keys or virtual MFA devices to protect it. Never use the root account for daily operations.
Set up MFA
2

Use IAM users with least privilege

Create IAM users with minimal required permissions. Enable MFA for all IAM users with console access.
Manage IAM Users
3

Monitor account activity

Enable CloudTrail for audit logging and set up billing alerts to detect unauthorized usage.
Configure CloudTrail

Protecting Your PayPal Account

1

Set up Passkeys for secure login

PayPal now supports Passkeys, the most secure authentication method that protects against phishing attacks. This is the recommended option for maximum security.
Set up Passkeys
2

Alternative: Enable two-factor authentication

If you can't use Passkeys, enable 2FA as a backup. Use an authenticator app rather than SMS for better security.
Set up 2FA
3

Set up login notifications

Enable email and SMS notifications for all login attempts to quickly detect unauthorized access.
Configure Notifications
4

Review linked accounts regularly

Regularly check linked bank accounts, cards, and authorized merchants. Remove any you no longer use.
Manage Linked Accounts

Protecting Your Binance Account

1

Add multiple security keys

For cryptocurrency exchanges, it's critical to have multiple authentication methods. Add keys on different devices.
Set up Security Keys
2

Save recovery codes

Be sure to save backup recovery codes in a secure place. Losing access to a cryptocurrency account could mean losing all funds.
3

Configure additional security measures

Enable login notifications, IP address restrictions, and anti-phishing codes for maximum protection of your trading account.

Protecting Your Dropbox Account

1

Enable two-step verification

Protect your files and documents with 2FA. Use an authenticator app or security key for the strongest protection.
Set up 2FA
2

Review linked devices and apps

Regularly check which devices and third-party applications have access to your Dropbox account. Remove any unused or suspicious connections.
Manage Connected Apps

Protecting Your Banking Accounts

1

Enable multi-factor authentication

Most banks now support 2FA or MFA. Use authenticator apps instead of SMS when possible. Some banks also support hardware security keys.
2

Set up account alerts

Enable real-time notifications for all transactions, logins, and account changes via email and SMS to quickly detect fraudulent activity.
3

Use official banking apps only

Always download banking apps from official app stores and verify the publisher. Never use third-party apps for banking operations.
4

Monitor accounts regularly

Check your accounts frequently and review monthly statements carefully. Report any suspicious activity immediately to your bank.

🛡️ General Security Recommendations

Use a password manager: Create unique complex passwords for each service. Popular options: 1Password, Bitwarden, Dashlane.
Never use SMS for 2FA: SIM cards can be easily cloned or hijacked. Use authenticator apps or, even better, Passkeys. Learn more about authentication methods.
Create backups: Always have multiple ways to recover access - backup Passkeys, recovery codes, trusted devices.
Check active sessions: Regularly review the list of active connections in security settings and terminate suspicious sessions.
Keep software updated: Maintain browsers, operating systems, and applications up-to-date to protect against known vulnerabilities.
Be aware of phishing: Passkeys are the best protection against phishing attacks because they're tied to specific websites and can't be used on fake sites.