Skip to content
Educora
Beginner18 min2 / 12

Personal security: passwords, MFA and phishing

Measure password strength in bits, understand how password managers and multi-factor authentication work, recognise social engineering in realistic examples and keep your devices in good shape.

Check yourself
In this lesson you will learn
  • Calculate password entropy with H = L · log₂A and know the formula's limits
  • Compare MFA methods and choose a phishing-resistant one
  • Recognise social engineering scenarios and respond correctly
  • Apply everyday hygiene rules for devices and backups

Elvin's social media account was taken over, even though his password was long and complex. The reason turned out to be simple: years ago he had used the same password on a gaming forum, the forum's database leaked, and bots tried the leaked email-and-password pairs on hundreds of sites. In this lesson we go deeper into passwords, multi-factor authentication and attacks that target human psychology.

Password strength in bits

The number of possible passwords is C = Aᴸ. Professionals express this huge number as entropy, in bits. Every extra bit doubles the attacker's work.

H = L · log₂A
where:
  • Hentropy, in bits
  • Lpassword length (number of characters)
  • Aalphabet size: lowercase 26, uppercase 26, digits 10, symbols 33
Python
import math

def pool_size(pw):
    pool = 0
    if any(c.islower() for c in pw): pool += 26
    if any(c.isupper() for c in pw): pool += 26
    if any(c.isdigit() for c in pw): pool += 10
    if any(not c.isalnum() for c in pw): pool += 33
    return pool

LEAKED = {'123456', 'qwerty', 'password', 'baku2024!', 'iloveyou'}

for pw in ['qwerty', 'Baku2024!', 'nar-velosiped-bulud-7', 'P@ssw0rd2026']:
    bits = len(pw) * math.log2(pool_size(pw))
    note = 'LEAKED - never use' if pw.lower() in LEAKED else ''
    print(pw.ljust(22), f'{bits:5.1f} bits', note)
▸ Expected output
qwerty                  28.2 bits LEAKED - never use
Baku2024!               59.1 bits LEAKED - never use
nar-velosiped-bulud-7  128.3 bits
P@ssw0rd2026            78.8 bits
Real sites combine this calculation with a list of leaked passwords: a password on the list is rejected, however many bits it “shows”.
Interactive
Loading simulation…
The password is never sent or stored. Start with P@ssw0rd2026, then type a passphrase of random words and compare the effective entropy.

Nobody can remember dozens of unique passwords, which is why you need a password manager. It generates a random password for every site and keeps them all in a “vault” encrypted with one master password. A bonus: the manager autofills only on the correct domain and stays silent on a fake one — a hidden anti-phishing signal.

Multi-factor authentication

Multi-factor authentication (MFA) requires at least two proofs of different kinds: something you know (password, PIN), something you have (phone, security key) and something you are (fingerprint, face). Two passwords are not two factors — both are “something you know”. And MFA methods are not equally strong:

MethodHow it worksWeak spot
SMS codethe carrier sends a one-time code to your phoneSIM-swap fraud, phishing that asks for the code
Authenticator app (TOTP)computes a code every 30 seconds from a shared secret and the clocka phishing site can relay the code in real time
Push notificationan “Approve” button on your phone“MFA fatigue”: a tired user approves by mistake
Passkey, FIDO2 security keya private key on the device signs a challenge for one specific domainsimply does not work on a fake domain — phishing-resistant
Python
import hashlib, hmac, struct

def totp(secret, unix_time, step=30, digits=6):
    counter = unix_time // step
    digest = hmac.new(secret, struct.pack('>Q', counter), hashlib.sha1).digest()
    offset = digest[-1] & 0x0F
    number = int.from_bytes(digest[offset:offset + 4], 'big') & 0x7FFFFFFF
    return str(number % 10 ** digits).zfill(digits)

secret = b'12345678901234567890'   # test secret from RFC 6238
for t in [59, 60, 89, 90]:
    print('time', str(t).rjust(2), '-> code', totp(secret, t))
▸ Expected output
time 59 -> code 287082
time 60 -> code 359152
time 89 -> code 359152
time 90 -> code 969429
This is exactly how an authenticator app works: the code is computed from the secret and the number of the current 30-second window. Seconds 60 and 89 are in the same window, so the code is the same.

The secret sits inside the QR code shown when you turn MFA on. That is why you must never show that QR code to anyone, and why you should store the backup recovery codes in your password manager.

Phishing and social engineering

Social engineering hacks people rather than technology. The attacker creates urgency, frightens, poses as a boss or a bank employee, and exploits curiosity or the wish to help. The channel varies: email (phishing), SMS (smishing), phone calls (vishing), QR codes, even a friend's hijacked account.

Four realistic scenarios

In each scenario, find the trick and the correct action.
1. SMS: “Your card is blocked. To restore it: bank-az-secure.info”.
2. Call: “This is the bank's security team. To cancel a suspicious transfer, read us the code from the SMS”.
3. Email to an accountant: the sender's name is the director's, but the address is unfamiliar: “Urgent! Pay the new supplier's account today, don't call, I'm in a meeting”.
4. A friend on a messenger: “Vote for me in a contest, send me the code you receive”.

Show solution
1. Fear + a fake domain (not the bank's own). Don't click; call the number on the back of your card yourself.
2. A bank never asks for the SMS code — that code is what approves the transfer. Hang up and call the bank yourself.
3. CEO fraud (business email compromise): urgency + “don't call”. Verify the payment through a separate channel, using a number you already know.
4. Your friend's account has been hijacked; the “code” is the login code for your own account. Don't send it; warn your friend another way.

Device and privacy hygiene

  • Turn on automatic updates: most patches close weaknesses that are already publicly known.
  • A screen lock and disk encryption (BitLocker on Windows, FileVault on macOS) turn a stolen laptop into a useless piece of metal.
  • Review app permissions: a flashlight app does not need your contacts or location.
  • Breach-notification services (for example, Have I Been Pwned) show which leaks your email appeared in — change every password that shows up there.
  • Share less on social media — birthday, school, home address: they feed reconnaissance and answer “security questions”.
Exercise

A passphrase is made of words chosen at random from a 7,776-word list. Calculate the entropy for 3, 4, 5 and 6 words and print each on its own line as N words: X bits, with X rounded to one decimal place.

Exercise · Python
import math

WORDLIST = 7776
# for 3, 4, 5 and 6 words print: N words: X bits
▸ Expected output
3 words: 38.8 bits
4 words: 51.7 bits
5 words: 64.6 bits
6 words: 77.5 bits

Key points

  • Entropy H = L · log₂A is measured in bits, but it is valid only for random passwords.
  • A unique password for every site: realistic only with a password manager.
  • MFA needs factors of different kinds; passkeys are phishing-resistant, while SMS is the weakest option.
  • Social engineering uses urgency, fear and authority; the answer is to pause and verify through a separate channel.
  • Updates, disk encryption and 3-2-1 backups are the basic hygiene of any device.

Check yourself

10 questions. Every correct answer earns XP.

1 / 10
A password has 10 random characters from a 64-character alphabet. What is its entropy?