Welcome to Section 2
Introduction to Online Risks
Section 2: Introduction to Online Risks
Passwords & 2FA Made Simple
● Why passwords are like the “first lock on your door.”
● Good passwords: examples and how to create and store them.
○ Password Example: hgCyN0$AQHb*
○ Password Criteria: 10-16 length, random, use as many characters as
allowed
● Password managers: what they are & recommendation.
● What 2FA is and why it’s important.
● Exercise: Turn on 2FA for your email or another account
Passwords & 2FA Made Simple (continued..)
● 2FA is 2 factor authentication, when enabled sign ins require two forms of
verification
● Adds another layer of security - this is both good and bad
Passwords & 2FA Exercise
● Password Exercise: check up on at least a couple of your passwords
● 2FA Exercise: enable 2FA on at least one account
Check if Your Data Has Been Leaked
● What a data breach/leak is: data from a company being inappropriately leaked
● Why it matters: hackers have your info
● How to check if you’re exposed: HaveIBeenPwned & others
● What to do if you are
● Exercise: Check if you have any accounts that have been leaked and check 2-3x a year
Check if Your Data Has Been Leaked
● What a data breach/leak is (when companies get hacked and leak your info).
● Why it matters (hackers can reuse your email/pw combos → identity theft, account
takeover).
● How to check if you’re exposed (tools like Have I Been Pwned).
● What to do if you are (change pw, enable 2FA, monitor accounts, maybe freeze credit).
● Action: Check if you have any accounts that have been leaked and check 3-4x a year
Phishing, Smishing & Scam Awareness
● Defining Phishing, Smishing, Social Engineering Common scam signs
● Real examples of phishing emails, smishing texts, and social engineering
● Avoid these attacks: stop, analyze, verify, decide
● Exercise: Review your personal email inbox, social media, or texts → identify 2 suspicious
messages
Phishing, Smishing & Scam Awareness
● Common scam signs (urgent tone, bad grammar, suspicious links)
● Show real examples of phishing emails/texts and how you would dissect them (or talk
about how we’ll talk about them in section 3)
● Avoid phishing and social engineering by either going directly to the website of the
supposed sender or calling the supposed sender back
● Exercise: Review inbox → identify 2 suspicious emails
●
Unsafe Browsing and Downloading Files
● Spotting fake websites, padlock/checking HTTPS
● Use some form of adblocker, browser safety feature, and anti malware
● As much as you can AVOID downloading files of any sort (google drive
workaround)
●
● Exercise: Use an adblocker, install an anti-malware, be aware next
time you’re browsing
Social Media Privacy & Oversharing
● Why oversharing on social media is very risky.
● Adjusting privacy settings on Facebook/IG/LinkedIn.
● Metadata in pictures and other things.
● Exercise: Update at least one privacy setting on one of your platform and
check your other social media even if out of date.
Public Wi-Fi & Device Safety
● Risks of coffee shop Wi-Fi.
● Quick tips: VPNs, tethering from phone, no sensitive logins on public Wi-Fi.
● Keep devices updated
●
●
●
●
●
●