- Calculate password entropy with H = L · log₂A and know the formula's limits
- Compare MFA methods and choose a phishing-resistant one
- Recognise social engineering scenarios and respond correctly
- Apply everyday hygiene rules for devices and backups
Elvin's social media account was taken over, even though his password was long and complex. The reason turned out to be simple: years ago he had used the same password on a gaming forum, the forum's database leaked, and bots tried the leaked email-and-password pairs on hundreds of sites. In this lesson we go deeper into passwords, multi-factor authentication and attacks that target human psychology.
Password strength in bits
The number of possible passwords is C = Aᴸ. Professionals express this huge number as entropy, in bits. Every extra bit doubles the attacker's work.
- Hentropy, in bits
- Lpassword length (number of characters)
- Aalphabet size: lowercase 26, uppercase 26, digits 10, symbols 33
import math
def pool_size(pw):
pool = 0
if any(c.islower() for c in pw): pool += 26
if any(c.isupper() for c in pw): pool += 26
if any(c.isdigit() for c in pw): pool += 10
if any(not c.isalnum() for c in pw): pool += 33
return pool
LEAKED = {'123456', 'qwerty', 'password', 'baku2024!', 'iloveyou'}
for pw in ['qwerty', 'Baku2024!', 'nar-velosiped-bulud-7', 'P@ssw0rd2026']:
bits = len(pw) * math.log2(pool_size(pw))
note = 'LEAKED - never use' if pw.lower() in LEAKED else ''
print(pw.ljust(22), f'{bits:5.1f} bits', note)▸ Expected output
qwerty 28.2 bits LEAKED - never use Baku2024! 59.1 bits LEAKED - never use nar-velosiped-bulud-7 128.3 bits P@ssw0rd2026 78.8 bits
P@ssw0rd2026, then type a passphrase of random words and compare the effective entropy.Nobody can remember dozens of unique passwords, which is why you need a password manager. It generates a random password for every site and keeps them all in a “vault” encrypted with one master password. A bonus: the manager autofills only on the correct domain and stays silent on a fake one — a hidden anti-phishing signal.
Multi-factor authentication
Multi-factor authentication (MFA) requires at least two proofs of different kinds: something you know (password, PIN), something you have (phone, security key) and something you are (fingerprint, face). Two passwords are not two factors — both are “something you know”. And MFA methods are not equally strong:
| Method | How it works | Weak spot |
|---|---|---|
| SMS code | the carrier sends a one-time code to your phone | SIM-swap fraud, phishing that asks for the code |
| Authenticator app (TOTP) | computes a code every 30 seconds from a shared secret and the clock | a phishing site can relay the code in real time |
| Push notification | an “Approve” button on your phone | “MFA fatigue”: a tired user approves by mistake |
| Passkey, FIDO2 security key | a private key on the device signs a challenge for one specific domain | simply does not work on a fake domain — phishing-resistant |
import hashlib, hmac, struct
def totp(secret, unix_time, step=30, digits=6):
counter = unix_time // step
digest = hmac.new(secret, struct.pack('>Q', counter), hashlib.sha1).digest()
offset = digest[-1] & 0x0F
number = int.from_bytes(digest[offset:offset + 4], 'big') & 0x7FFFFFFF
return str(number % 10 ** digits).zfill(digits)
secret = b'12345678901234567890' # test secret from RFC 6238
for t in [59, 60, 89, 90]:
print('time', str(t).rjust(2), '-> code', totp(secret, t))▸ Expected output
time 59 -> code 287082 time 60 -> code 359152 time 89 -> code 359152 time 90 -> code 969429
The secret sits inside the QR code shown when you turn MFA on. That is why you must never show that QR code to anyone, and why you should store the backup recovery codes in your password manager.
Phishing and social engineering
Social engineering hacks people rather than technology. The attacker creates urgency, frightens, poses as a boss or a bank employee, and exploits curiosity or the wish to help. The channel varies: email (phishing), SMS (smishing), phone calls (vishing), QR codes, even a friend's hijacked account.
In each scenario, find the trick and the correct action.
1. SMS: “Your card is blocked. To restore it: bank-az-secure.info”.
2. Call: “This is the bank's security team. To cancel a suspicious transfer, read us the code from the SMS”.
3. Email to an accountant: the sender's name is the director's, but the address is unfamiliar: “Urgent! Pay the new supplier's account today, don't call, I'm in a meeting”.
4. A friend on a messenger: “Vote for me in a contest, send me the code you receive”.
Show solutionHide solution
2. A bank never asks for the SMS code — that code is what approves the transfer. Hang up and call the bank yourself.
3. CEO fraud (business email compromise): urgency + “don't call”. Verify the payment through a separate channel, using a number you already know.
4. Your friend's account has been hijacked; the “code” is the login code for your own account. Don't send it; warn your friend another way.
Device and privacy hygiene
- Turn on automatic updates: most patches close weaknesses that are already publicly known.
- A screen lock and disk encryption (BitLocker on Windows, FileVault on macOS) turn a stolen laptop into a useless piece of metal.
- Review app permissions: a flashlight app does not need your contacts or location.
- Breach-notification services (for example, Have I Been Pwned) show which leaks your email appeared in — change every password that shows up there.
- Share less on social media — birthday, school, home address: they feed reconnaissance and answer “security questions”.
A passphrase is made of words chosen at random from a 7,776-word list. Calculate the entropy for 3, 4, 5 and 6 words and print each on its own line as N words: X bits, with X rounded to one decimal place.
import math
WORDLIST = 7776
# for 3, 4, 5 and 6 words print: N words: X bits▸ Expected output
3 words: 38.8 bits 4 words: 51.7 bits 5 words: 64.6 bits 6 words: 77.5 bits
Key points
- Entropy H = L · log₂A is measured in bits, but it is valid only for random passwords.
- A unique password for every site: realistic only with a password manager.
- MFA needs factors of different kinds; passkeys are phishing-resistant, while SMS is the weakest option.
- Social engineering uses urgency, fear and authority; the answer is to pause and verify through a separate channel.
- Updates, disk encryption and 3-2-1 backups are the basic hygiene of any device.
Check yourself
10 questions. Every correct answer earns XP.