Skip to main content
Privacy Tools

Privacy Tools That Actually Stop Phishing, Not Just Annoy You

Most 'privacy tools' are snake oil. I rank what actually works: password managers, phishing-resistant MFA, and breach checkers—and why SMS 2FA is a last resort.

Here's a number that should make you sit up: Microsoft says it blocks more than 300 million fraudulent sign-in attempts to its cloud services every single day (Microsoft Security Blog). That's 300 million times someone tried to break into an account—many of them using passwords stolen from breaches. Yet most people think a 'privacy tool' is a VPN or a private browser. Wrong. The real privacy tools are the ones that stop your credentials from being usable in the first place. I'm going to bust some myths and give you my straight-shooting take on what to actually use.

Is a password manager really worth it, or can I just remember my passwords?

Stop. You are not the exception. Password reuse is the fuel for credential-stuffing attacks, where attackers try previously breached passwords against corporate accounts (Microsoft Security Blog). A password manager generates and stores unique, random passwords for every account—that's the single best move you can make for your own privacy (CISA Secure Our World). The NCSC even says writing a password down is acceptable if kept somewhere safe, but a password manager is better (NCSC Three Random Words). I use one, and I'm not a tech wizard. It takes ten minutes to set up and saves you from the nightmare of one breach cascading into your bank account.

But aren't long passphrases like 'correct horse battery staple' enough?

They're better than 'Password123', but they're not enough. The NCSC recommends three random words, like 'applenemobiro'—that's a good start (NCSC Three Random Words). NIST, the federal guideline, says passwords used as the only factor should be at least 15 characters (NIST SP 800-63B). But here's the kicker: even a great password doesn't help if it's been leaked in a breach. That's why you need to check Have I Been Pwned—a free service that tells you if your email has appeared in a known breach (Have I Been Pwned About). If it has, rotate that password immediately. And don't fall for the myth that you need to change passwords every 90 days—NIST actually advises against forced periodic changes (NIST SP 800-63B). So, yes, use a passphrase, but pair it with a breach check.

If I have two-factor authentication, am I safe?

Not necessarily. This is the biggest misconception I see. SMS codes can be intercepted via SIM swapping—a social engineering attack where attackers convince your carrier to transfer your number to their SIM (CISA Implementing Phishing-Resistant MFA). Push notifications? Attackers can spam you with 'push bombing' until you accidentally approve. CISA lists four ways traditional MFA is bypassed: phishing, push bombing, SS7 protocol vulnerabilities, and SIM swapping (CISA Implementing Phishing-Resistant MFA). So, yes, MFA is a huge step up—Microsoft says it blocks over 99.9% of account compromise attacks (Microsoft Security Blog)—but not all MFA is equal.

What's the gold standard for MFA, then?

Phishing-resistant MFA. That means hardware security keys (FIDO2) or passkeys. CISA ranks these as the gold standard because they resist phishing, push bombing, SS7, and SIM swap (CISA Implementing Phishing-Resistant MFA). If you can't use a key, at least use an authenticator app with number matching, and treat SMS as a last resort (CISA Implementing Phishing-Resistant MFA). I know, I know—you don't want to carry a key fob. But you already carry a phone. Set up passkeys on your phone for your email and bank. It's not that hard, and it's worth it.

Are those 'privacy browsers' and VPNs worth it?

They have their place, but they won't stop you from getting phished. A VPN encrypts your traffic, but if you willingly type your password into a fake login page, the VPN does nothing. The FBI's IC3 received 193,407 phishing complaints in 2024—that's the most-reported crime category (FBI IC3 2024 Internet Crime Report). And Verizon found that 68% of data breaches involve a human element, like someone falling for phishing (Verizon 2024 DBIR). So the most important 'privacy tool' is your own skepticism. Hover over links, check sender addresses, and don't act on urgent threats (CISA Secure Our World).

Bottom line

The best privacy tool is a password manager plus phishing-resistant MFA on your email and bank accounts, and a quick check of Have I Been Pwned for any old accounts. Stop chasing shiny VPNs and start with the boring stuff that actually works.

Sources

  • CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
  • NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
  • Have I Been Pwned - https://haveibeenpwned.com/About
  • FBI IC3 2024 Report - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf

Share this article:

Comments (0)

No comments yet. Be the first to comment!