Don't Get Hacked: A Simple Guide to Keeping Your Accounts and Your Data Safe
Your online accounts are like the door to your room — and your study progress, your messages, and your private details all live behind it. Here is how to keep that door locked, spot the people trying to trick their way in, and know what is rightfully yours.
Almost all real-world 'hacking' is just guessed passwords or people tricked into typing their password on a fake page — not genius break-ins. You can protect yourself with a few habits: use a long, unique password made of a few words, turn on two-step verification, never type your password into a page you reached from a message link, and don't share your account. Your data is yours, and you have the right to see, correct, and delete it.
You have probably heard a story like this. A friend's Facebook or WhatsApp suddenly starts sending strange messages asking everyone for money. Or someone clicks a link that says "your account is locked" and the next day they cannot log in at all. It feels random and frightening, like bad luck that lands on people for no reason.
It is not random. Almost every "hacking" you hear about in real life is not some genius breaking through a computer wall. It is much simpler: someone guessed an easy password, or someone got tricked into typing their password on a fake page. That is good news, because it means you can protect yourself with a few habits — no technical skill required.
This article walks you through those habits in plain language. Whether you log in to a school portal, a tuition class app, an email account, or a learning platform, the same ideas keep you safe.
First, understand what an "account" really is
An account is simply the platform's way of knowing that you are you. When you log in, you are proving your identity so the system shows your work, your marks, your messages — and not someone else's. The two pieces that usually prove this are your username (who you are) and your password (the secret only you should know).
Some platforms let you log in with just a username and a password. A username is not a secret — your classmates might know it, it might even be your index number or your name. That makes the password the only real lock on the door. So when a login is simpler, the password matters more, not less. The convenience of an easy login does not remove your responsibility to keep the secret part secret.
Think of it like your school bag. The bag itself is visible to everyone — that is your username. But what is inside, and the way you keep it closed, is up to you to guard. A weak password is like leaving the bag wide open on a bench at the bus stand.
Strong passwords, made simple
A strong password is one that a stranger cannot guess and a computer cannot quickly crack. The most common weak passwords in Sri Lanka are exactly the ones you would expect: your name, your birthday, "123456", "password", your phone number, or your favourite cricketer. If a classmate could guess it in three tries, it is not strong.
The easiest way to make a strong password that you can still remember is to use a short phrase — three or four random words joined together, perhaps with a number and a symbol. Something like "BlueKottuLamp7" is far stronger than "Nimal2008" and much easier to remember than a jumble of letters. Length beats cleverness: a longer password is harder to break than a short one full of strange symbols.
Two more rules carry most of the weight. First, do not use the same password everywhere — if one account leaks, all the others fall with it. Second, never write your real password where others can see it, like the back of your phone case or a note shared in a group chat.
- Aim for at least 12 characters — longer is stronger.
- Mix words, a number, and a symbol so it is not a single dictionary word.
- Never reuse your email password on any other site — your email is the master key.
- Avoid anything a classmate could guess: name, birthday, phone number, school.
- If a site offers an extra code by SMS or app (called two-step verification), turn it on.
Phishing: the fake message designed to fool you
Phishing (said "fishing") is when someone sends you a fake message — by email, SMS, or chat — pretending to be a service you trust, so that you hand over your password or click a harmful link. The name fits: they cast bait and hope you bite. The most common bait creates fear or urgency: "Your account has been locked," "Suspicious login detected," "Reset your password now or lose access," or "You have won a free data package — claim in 24 hours."
The trick works because it rushes you. When you are scared of losing your account or excited about a prize, you stop checking and start clicking. A real organisation will almost never threaten to delete your account in the next hour, and will never ask you to confirm your password by replying to a message.
Here is the key thing to understand: a fake "reset your password" page can look exactly like the real one. The logo, the colours, the wording — all copied. The difference is hidden in the address, the sender, and the request itself. So you must learn to check those, because your eyes alone will be fooled.
How to tell a fake from the real thing
You do not need special software to catch most phishing. You need to slow down for ten seconds and check three things before you tap or type anything. These small habits stop the large majority of attacks.
Checking the sender means looking at the actual email address, not just the display name. Anyone can set their name to "School Office" or "Idasara Support", but the address behind it gives them away — something like "support@idasara-secure-login.xyz" is not the same as a genuine address. On a phone, tap the sender's name to reveal the full address.
Hovering before tapping means checking where a link really goes before you open it. On a computer, rest your mouse pointer over the link and the true address appears at the bottom of the screen. On a phone, press and hold the link (do not tap) and a preview of the real address pops up. If the link claims to be your school portal but the address is some unfamiliar site, do not open it.
The golden rule that beats every fake page: never enter your password on a page you reached by clicking a link in a message. If you get an email saying your account needs attention, do not use its link. Close it, open your browser yourself, type the website address you already know, and log in there. If the warning was real, you will see it once you are safely logged in. If it was fake, you have lost nothing.
- Check the real sender address, not just the display name.
- Hover (computer) or press-and-hold (phone) to preview a link before opening it.
- Watch for urgency, threats, prizes, and spelling mistakes — classic phishing signs.
- Never type your password into a page opened from a message link.
- When in doubt, go to the website yourself by typing the address you know.
Why sharing your account quietly harms you
It feels harmless to share your login with a friend so they can "just check something", or to use a sibling's account because it was already open. On a learning platform, this does real damage — and not to the platform, to you.
Modern learning tools personalise what they show you. They track which lessons you have done, which questions you got wrong, and which topics you are weak in, so they can recommend exactly the practice you need next. This only works if the account reflects one real person. If your friend logs in and answers a few questions as you, the system now thinks you understand things you do not — and stops giving you the practice you actually need. Your progress data becomes a mix of two people, and the help you receive becomes wrong.
There is also a plain safety reason. The more people who know your password, the more places it can leak, and the less you can trust that your account is truly yours. Sharing a password is like giving out a copy of your house key and hoping everyone who has it is careful. Keep one account for one person. If a family member needs access to a platform, they should have their own account.
Your data and your rights
When you use any platform, it stores information about you. It is worth knowing what, so you are never in the dark. This usually includes the details you gave when signing up (name, contact, perhaps your school or grade), and the activity you generate while using it (lessons opened, answers given, progress and marks, times you logged in). A learning platform keeps your study record so it can help you improve.
This data is yours in a meaningful sense, and good platforms respect that. You generally have the right to see what they hold about you, to correct anything that is wrong, and to ask for your account and data to be deleted if you choose to leave. A trustworthy service explains this in a privacy policy and gives you a way to manage your own information rather than hiding it.
Because this record is valuable to you, protect it the same way you protect a password. Do not hand your data away by typing it into random forms, quizzes, or "check if your name won" pages that ask for personal details. Share personal information only with services you chose and trust, and only as much as they genuinely need.
Key facts
- Almost every real-world 'hacking' is not a technical break-in — it is a guessed password or someone tricked into typing their password on a fake page.
- A strong password should be at least 12 characters; length beats complexity, so a phrase of three or four random words like 'BlueKottuLamp7' is stronger and easier to remember than a short jumble of symbols.
- Never reuse your email password on any other site — your email is the master key that can reset all your other accounts.
- Phishing messages create fear or urgency ('your account is locked', 'you won a free data package') to rush you into clicking; a real organisation will never ask you to confirm your password by replying to a message.
- The golden rule against phishing: never type your password into a page you reached by clicking a link in a message — close it, open your browser, and type the website address you already know.
- Sharing your learning-platform login corrupts your progress data — if someone answers questions as you, the system thinks you understand topics you do not and stops giving the practice you actually need.
- Platforms store both the details you gave at sign-up and the activity you generate; your data is yours and you generally have the right to see it, correct it, and ask for it to be deleted.
Key takeaways
- Most "hacking" is just guessed passwords and trick messages — both are easy to defend against.
- Use a long password made of a few words, never reuse it, and never write it where others can see.
- Phishing uses fear and urgency; slow down and check the sender and the link before acting.
- Never type your password into a page you reached from a message link — open the site yourself.
- One account, one person: sharing a login corrupts your progress data and your privacy.
- Your data is yours — you have the right to see it, correct it, and delete it.
Try this now
Pick the one account that matters most to you — usually your email, because it can reset all your others. First, check its password: is it long, unique, and impossible for a classmate to guess? If not, change it now to a phrase of three or four words plus a number. Then look in the account's settings for "two-step verification" or "2-step login" and turn it on so a code is needed alongside your password. Finally, open any one email in your inbox and practise the safe habit: tap the sender's name to reveal the real address, and press-and-hold one link to preview where it really goes — without opening it. Five minutes, and your most important door is far better locked.
Frequently asked questions
How do most accounts actually get hacked?
Almost never by a genius breaking through a computer wall. Most accounts are taken over because someone guessed an easy password (like a name, birthday, or '123456'), or because the owner was tricked into typing their password on a fake page sent through a message. Both are easy to defend against with simple habits.
What makes a password strong but still easy to remember?
Use a phrase of three or four random words joined together, plus a number and a symbol — for example 'BlueKottuLamp7'. Aim for at least 12 characters. Length matters more than strange symbols, and never use the same password on more than one site.
How do I know if a message or link is phishing?
Slow down and check three things: the real sender address (not just the display name), where the link actually goes (press-and-hold on a phone, or hover on a computer to preview it), and whether the message is rushing you with fear or a prize. Watch for urgency, threats, and spelling mistakes — these are classic phishing signs.
What is the one rule that beats every fake login page?
Never enter your password on a page you reached by clicking a link in a message. If a message says your account needs attention, close it, open your browser yourself, type the website address you already know, and log in there. If the warning was real you will see it once you are safely logged in; if it was fake, you have lost nothing.
Why is it bad to share my account or password with a friend?
On a learning platform it harms you directly. The system tracks what you have learned and where you are weak to recommend the right practice. If a friend answers questions as you, the system thinks you understand things you do not and stops giving the help you need. Sharing a password also means it can leak from more places. One account, one person.
What data do platforms store about me, and what are my rights?
Platforms usually store the details you gave at sign-up (name, contact, school or grade) and the activity you generate (lessons opened, answers, progress, login times). This data is yours: you generally have the right to see what they hold, correct anything wrong, and ask for your account and data to be deleted. A trustworthy service explains this in a privacy policy.
These habits matter most on the platforms where your real progress lives. On Idasara, your account holds your study record — the topics you have mastered and the ones you are still working on — and that record is yours alone. Keeping it secure is not just about safety; it is what lets the platform understand you accurately and guide your learning honestly. So treat your Idasara login the way this article describes: keep the password to yourself, log in only through the site you know, and let your progress reflect the one person it is meant to — you. That is the quiet foundation everything else you learn here is built on.
Start free