● Plain-language internet safety

Online safety, investigated for the rest of us.

No jargon, no scare tactics — just the handful of habits that keep most people safe online, written for anyone who's never been asked to care about this before.

Purrfectly Protected mascot
Start here

Four things that matter more than everything else combined

If you only do four things after reading this page, make it these. They block the overwhelming majority of real-world attacks.

01

Use a password manager

One strong master password. Everything else gets generated and remembered for you.

02

Turn on two-step verification

A second lock on your most important accounts — email, banking, social media.

03

Let updates install

Those "update available" notices are mostly security fixes. Don't put them off.

04

Pause before you click

Urgency and pressure are the two biggest tells that something's a scam.

The case files

Go deeper on the things that matter

Each guide is short on purpose. Skim it once, then come back when it's actually relevant.

Passwords & passkeys

Most break-ins happen because a password was reused somewhere else that got leaked.

  • Use a password manager (built into your phone or browser is fine) so every account gets its own long, random password.
  • Never reuse a password across sites — one leak shouldn't unlock everything.
  • Where offered, switch to a "passkey" — it replaces the password with your fingerprint or face, and can't be phished.

Spotting phishing

Phishing is a fake message pretending to be your bank, a delivery company, or even a friend.

  • Anything urgent, alarming, or "act now" is the biggest tell — real organizations rarely rush you.
  • Check the sender's actual email address, not just the display name.
  • Never click a link in an unexpected message — open the app or website yourself instead.

Wi-Fi & your devices

Your home router and your phone are the front door to everything else.

  • Change your router's default admin password — it often ships with one anyone can look up.
  • Keep your phone, computer, and apps updated; updates quietly patch security holes.
  • On public Wi-Fi (cafés, airports), avoid logging into banking or sensitive accounts.

Social media & privacy

Oversharing gives scammers exactly what they need to sound convincing.

  • Set profiles to friends-only, and think twice before accepting strangers' friend requests.
  • Avoid posting real-time location, travel dates, or details that answer security questions (pet names, schools).
  • Be skeptical of anyone you've only met online who asks for money or gifts, however genuine it feels.

Phone & tech-support scams

A caller claiming to be from "tech support," the bank, or a government agency is one of the oldest tricks — still effective.

  • No legitimate company or agency will ask you to pay with gift cards, wire transfers, or cryptocurrency.
  • Real tech support will never call you first out of the blue about a "virus" on your computer.
  • If in doubt, hang up and call the organization back using the number on their official website.

Updates & backups

The single most effective, least exciting thing you can do for your security.

  • Turn on automatic updates for your phone, computer, and apps wherever possible.
  • Keep a backup of anything irreplaceable — photos, documents — somewhere separate from your main device.
  • Restart devices occasionally; some updates only finish installing after a restart.
Trust your instincts

Six red flags that show up in almost every scam

You don't need to memorize every scam — just learn to notice these patterns.

Urgency

"Act in the next hour or your account is closed."

Unusual payment

Requests for gift cards, wire transfers, or crypto.

Too good to be true

Prizes, refunds, or deals you never applied for.

Mismatched details

The sender's email or link doesn't match the real company.

Secrecy

"Don't tell anyone" or "keep this confidential."

Unexpected contact

You didn't request the call, text, or message.

In plain English

A short glossary

The handful of terms you'll actually run into, translated.

Phishing
A fake message designed to trick you into giving up a password, payment, or personal info.
Two-factor / two-step
A second proof of identity beyond your password — usually a code sent to your phone.
Malware
Software designed to harm your device or steal your data, often installed without your knowledge.
VPN
A tool that reroutes and encrypts your internet connection — mainly useful for privacy on public Wi-Fi.
Passkey
A newer sign-in method using your device's fingerprint or face instead of a typed password.
Update / patch
A software fix — often for a security problem — released after a product has shipped.
On the case

From the blog

A weekly look at a real breach or scam, and what it actually means for you.

Case File #001 · July 25, 2026

The RockYou Breach: Why a 2009 Hack Still Matters Today

32 million passwords leaked in plain text. Sixteen years later, it's still one of the most-used tools in a hacker's kit — here's why, and what it means for your passwords right now.

Read the case file →
View all posts