Reading a web address like a pro
Nearly every online scam ends at a fake website. The address bar is your lie detector if you read it right:
- Find the real domain: it's the last two pieces before the first single "/". In portal.company.com/login, the domain is company.com. In company.com.secure-login.net, the domain is secure-login.net, a fake wearing a costume.
- Watch for lookalikes: rnicrosoft.com, paypa1.com, arnazon.com. Attackers register thousands of these.
- The padlock means private, not honest. HTTPS only means your connection is encrypted, and scam sites use it too. No padlock is a red flag; a padlock is not a green one.
- Type it yourself. For banking and other sensitive sites, use your own bookmark or type the address, never a link from an email or text.
Pop-ups, fake alerts, and scareware
"Your computer is infected! Call Microsoft now!" No. Real security warnings never include a phone number, never play alarm sounds, and never lock your screen from inside a browser tab. Close the tab (use Task Manager if needed) and never call the number. Tech-support scammers want remote access to your machine and your credit card.
- Real software updates come from the app itself or your OS settings, never from a web page.
- Download buttons on free-download sites are often ads. The real link is usually smaller and less flashy.
- Be stingy with browser extensions: they can read everything you see and type. Install few, from official stores, and prune them.
Public Wi-Fi, honestly
Coffee-shop Wi-Fi is safer than it was a decade ago; HTTPS now protects most traffic. But there are still real risks: fake hotspots with legitimate-sounding names ("Airport_Free_WiFi"), snoopy networks, and login portals harvesting details.
- Best option: skip public Wi-Fi and use your phone's hotspot for anything sensitive.
- Verify the network name with staff before connecting, because attackers set up evil twins.
- Use a reputable VPN on networks you don't control, especially for work.
- Tell your device to "forget" public networks afterward, so it doesn't silently auto-reconnect to any network with the same name later.
- Save the sensitive stuff like banking, tax filings, and work admin for networks you trust.
Do this today
- Bookmark your bank and other critical sites; only ever log in from the bookmark.
- Review your browser extensions and remove anything you don't recognize or use.
- Turn off "auto-connect to open networks" on your phone and laptop.
- Turn on your browser's built-in protection (Enhanced Safe Browsing in Chrome or the equivalent).