Glossary

27 terms, defined in plain language. Search filters the list as you type.

Authenticator app
An app that generates time-based codes for signing in. Cannot be intercepted like SMS, but can still be phished.
Backup
A copy of your data that the problem cannot reach. A permanently connected drive is a second copy, not a backup.Backups that actually save you
Breach
An incident where a service's data is taken. Whether your password is exposed depends on how it was stored and how guessable it was.Free vs paid security software: an honest comparison
Chargeback
The process for reversing a card payment. It is why card payments carry more protection than bank transfers.
Cookie
A small file a site stores in your browser. Necessary for staying signed in; also used for tracking across sites.
Encryption at rest
Storage that is encrypted when the device is off, so removing the drive does not reveal the contents.
Extension
An add-on that can read and change the pages you visit. A privileged position worth auditing occasionally.A 20-minute security check-up
Factory reset
Returning a device to its original state. On encrypted phones this is genuinely sufficient before selling.
Firmware
Software built into a device such as a router. It receives security updates and is commonly neglected.
Guest network
A separate Wi-Fi network for visitors and untrusted devices, isolated from your own machines.
Multi-factor authentication
Requiring more than a password to sign in. The single most effective change most people can make.
Passkey
A credential bound to a site's real domain, so it cannot be used on a phishing page. The category that resists phishing by design.
Password manager
An application that stores and fills unique passwords. Its extension also refuses to fill on the wrong domain.Setting up a password manager properly
Patch Tuesday
The regular monthly release of security updates by some vendors. A useful prompt to check that updates are applying.
Phishing
Persuading you to hand over credentials or money by impersonating someone you trust.How to spot phishing
Port forwarding
A router rule that makes a service on your network reachable from the internet. Remove rules you no longer need.
Ransomware
Malware that encrypts your files and demands payment, usually after copying the data first.Ransomware: how it works, and what to do
Recovery code
A one-time code for regaining access when your usual second factor is unavailable. As sensitive as the account itself.Setting up a password manager properly
Scareware
A page or program claiming your device is infected in order to sell you something or have you install malware.
SIM swap
Moving a phone number to an attacker's SIM, which redirects SMS codes. The main weakness of SMS-based authentication.
SSD
Solid-state storage. Faster than a mechanical drive, and erased by discarding the encryption key rather than by overwriting.
Two-factor fatigue
Repeated approval prompts until someone taps accept. Countered by implementations that require matching a number on screen.
Update
A vendor fix, frequently for a security flaw. Applying updates promptly removes an entire category of attack.Securing your home router
VPN
An encrypted tunnel to a provider's server. Hides browsing from the local network; does not stop malware.Free vs paid security software: an honest comparison
Wear levelling
How SSDs spread writes across the drive. The reason overwriting an SSD is not a reliable way to erase it.
WPA3
The current Wi-Fi encryption standard. Use it where supported, WPA2 otherwise, and never WEP.
3-2-1 rule
Three copies of your data, on two kinds of storage, with one kept off-site or offline.