If you're seeing this message, it means we're having trouble loading external resources on our website.

If you're behind a web filter, please make sure that the domains *.kastatic.org and *.kasandbox.org are unblocked.

Main content

How passwords and screenlocks help protect you

It's crucial to have unique passwords for each site to prevent security breaches. A password manager can help avoid reusing strong passwords. For device screen locks, simple pins or biometrics are generally enough, but be mindful of who has access to your devices to maintain safety.

To learn more about how you can keep yourself safe while on the Internet, visit: internet-safety.khanacademy.org.
Created by Sal Khan.

Want to join the conversation?

  • blobby green style avatar for user tristankim30
    I found this very helpful
    (5 votes)
    Default Khan Academy avatar avatar for user
  • winston default style avatar for user shyla
    Would my accounts be safer if I slightly changed each password on each different website? For example, if my password was- let's say "cool0874$." If I had that as my password on one page, would using something like "Cool0874$" or "cool0874%" still be safe on a different website? I mean, that way I'd be able to remember the base of the password, it's just that I'd have a bunch of different variations of it.
    (3 votes)
    Default Khan Academy avatar avatar for user
  • blobby green style avatar for user shakulranaut2000
    One problem which I think may arise is that if we use password manager, let's say Google password manager, and if unfortunately, my email account is hacked, then attackers will be able to access all the saved passwords for the websites which I use. How can we deal with it?
    (2 votes)
    Default Khan Academy avatar avatar for user
    • starky ultimate style avatar for user MagicalPotato
      Well.. that would happen if they were able to hack your email, but Google sends you an email whenever someone signs into your email on a new device and asks if it's you. And most of the time if it is a new device they are signing in on, it won't let them in until you let Google know it's alright. Also there is normally a setting called "two person authentication" which is where if someone is signing into your email, they will have to follow all the steps like "entering in the number from a text Google sends, meaning if they try to sign in they will also need your phone number to hack your email. I know that's a lot, but I do hope it helps!
      (2 votes)
  • winston default style avatar for user I need sleep
    What if your password manager gets hacked?
    (2 votes)
    Default Khan Academy avatar avatar for user
  • duskpin tree style avatar for user #1 Unicorn
    How do I see when the video was made?
    (1 vote)
    Default Khan Academy avatar avatar for user
  • leaf blue style avatar for user Yrmanager
    My name is Terrance Lawson and what is your name
    (0 votes)
    Default Khan Academy avatar avatar for user
  • hopper happy style avatar for user 😎SB😎
    why do i feel like there robots or just pre recorded?
    (0 votes)
    Default Khan Academy avatar avatar for user

Video transcript

- I could go on for hours about things to think about with passwords. Maybe the top two is that initially that a password needs to be unique on every different site. And the reason for that is that if you share a password, if you use the same, you know, your kid's middle name as the password on three different sites and any one of those gets broken into, now the attackers know your password to use elsewhere. And unfortunately for many of us, you know, there are these rules. You need to use capital letters and symbols and punctuation and numbers and it becomes impossible to remember, so what many people do is they come up with one strong password and then use it everywhere. And that's really a bad idea because again, you're vulnerable if it gets reused, if any of those sites gets compromised now it's out there in the open. So instead what we recommend is to use a password manager which is an app that remembers and then auto fills wherever you go. We have the Google password manager, it's built into Android, it's built into Chrome. But other OS makers, other, you know, vendors have their products. There's third party ones that are both free and paid. Again, you know, you might get what you pay for, so don't just take anything out there but if it's coming from Google, if it's coming from one of these big companies, that's much much better than memorizing and reusing that same password in multiple places. - And that makes a ton of sense. I mean, when we talk about the passwords for different websites, but what about, you know getting into your device or you know, your smartwatch or whatever, you know, and now you have other options, you can, there's biometrics, your thumbprint, or your face scan and all of that. Does it matter or is it, hey, this is pretty low risk that, you know, some spy from another country is going to get access to my phone so I should just, you know, it's just really to keep my kids out. - Yeah, so I mean, it depends. For most of us, what we're dealing with on device screen locks is that I left it in a taxi or a roommate or family member picked this up. And so then the threat model is pretty constrained. And it generally is okay to reuse, you know, to use a simple pin or a biometric. Now you do have to think about who else has access to it. In my own household, I have very smart kids, they watch Khan Academy videos, they've learned a lot. And so if I set the same thing for my watch, my wife's watch, my tablet, my phone, and they shoulder surf any of those, we have that same problem of you know, once it falls in one place it goes everywhere. For the most part though, I'm not that worried about that. - I have to say my oldest son, if there was like an Olympics for this, he would be a medalist. He can't help it. He knows he, but if someone, if you're in the room he somehow knows exactly what you typed in. So anyway, yes, beware. And I think he's a force for good, but there might be - - Yeah, I mean, foreign spies and 10 year old kids like there's a, you know, interesting Venn diagram there.