This article keeps its old title and its numbered shape. The original version was a list with almost no air. The advice was not wrong. It was too thin to use on a bad day.
We still will not invent settings labels. If your account page is missing a control, skip that item.
## 1. Give this account its own password
Reuse is the common failure. If the password also unlocks a shop or a forum, a leak over there becomes a login over here. Long and unique beats clever. A manager beats memory.
Change it if you know you reused it. Do that before you finish this page.
## 2. Treat the email account as the real key
Reset mail goes to the address you signed up with. Lock that mailbox down first: unique password, and a second factor at the email provider if you have one. An Oernoe password is weaker than it looks when the inbox is easy.
If you used a workplace email, plan for the day you lose it. Move recovery while you still have access.
## 3. Turn on a second factor only if it is actually there
Look in account settings. If you can add an authenticator, a key, or codes, do it the same afternoon. If you cannot, do not wait on a blog post that said “soon.” Your password is still the door.
When backup codes appear, store them off the same cloud account.
## 4. Nobody legitimate needs the password
Not support, not a friend helping you “check the account,” not a comment that says you won something. If you already typed it into a fake page, change it from a bookmark, then check the mailbox.
## 5. Read the hostname before you type
Official pages live on oernoe.com hosts. Search, account, and the www site are the ones you will use most. A message that wants you to “restore access” on a different domain is working you.
Type the address. Do not copy it from an email you did not expect.
The real sign-up page can use Google. Fake pages copy that button. Start from https://www.oernoe.com/login.
## 6. Look at activity when you have a way to look
If settings show recent logins or sessions, read them after you travel or after a scare. Sign out the strangers. If you have no session list, a password change is the blunt tool.
Times and cities are more useful than vibes. Write them down if you contact support.
## 7. Shared computers get a private window and a sign-out
Libraries, hotel business centers, and the laptop at a relative’s house should not keep your cookie. Private window, do the task, sign out, close the window. Do not save the password in that browser.
If you forgot, change the password from a machine you own.
## 8. Be dull about extensions and “helpers”
A browser add-on that wants to read every page can read this one too. Install software you can name. Remove the rest.
The same rule applies to people who want remote access to “fix” your account.
## 9. Update the boring software
Browser and operating system updates close holes that steal cookies. You do not need a speech about patches. Click the update, reboot if it asks, continue your day.
## 10. Write to support while the trail is fresh
If the account sent a reset you did not ask for, or files appeared, or you cannot get in after a reset, email support@oernoe.com. Say the username, the email, and the time. Do not send the password. Do not send a full dump of unrelated accounts.
If you are locked out because you lost the mailbox, say that clearly. Recovery will be slower. That is better than a support process that hands accounts to whoever writes first.
## Two extras the old list skipped
Public wifi is fine for reading. It is a poor place to change a password or open Health. Use a phone network if you are about to type credentials.
Optional paid features, if you ever buy them, will go through a payment page. Keep that receipt. A thief who adds a payment method is a different problem than a thief who only guesses a password.
## What this list is not
It is not a claim that the company can see every threat. It is not a substitute for the longer August 2026 security article if you want more narrative. It is ten things you can do without waiting for a product launch.
If you only do three: unique password, locked mailbox, no surprise links.
## If you only remember the shape
Password that lives nowhere else. Mailbox that is harder to steal than the Oernoe form. Settings checked when you travel. Links you typed. Sign-out on machines you do not own. Support mail that does not include the password.
The numbered list is for skimming. The sentences are for the day something feels off. Use either. Just do not keep the March-length version that ended mid-thought.
## A note the original buried
Staff will not ask you to install remote-control software. Staff will not ask you to move money to keep the account. Those messages are from other people. Delete them and, if you already clicked, change the password from a bookmark.
## Why this list still exists
The August safety article is the better long read. This slug already ranks in old links and in the journal index. Leaving it as a 200-word list would have been the thin page we are trying not to publish. So we kept the ten headings and wrote the parts a person needs when they are actually worried.
If the two pieces overlap, that is fine. The actions are the same actions. The wording here stays in list form so you can skim.
## How to use the list after a scare
Start at 5 and 6, not at 1. Hostname and sessions tell you whether someone else is already inside. Then change the password. Then lock the mailbox. Then write to support if the sessions looked wrong.
If nothing looks wrong and you are only nervous because of a news story, start at 1 and 2. Unique password, locked mailbox. Then stop. Anxiety is not a reason to delete the account.
## Phishing details people skip
The fake page will copy the logo and the four fields. The giveaway is the URL and the extra story: “unusual login from another country, click here.” Go to the bookmark instead. If there was a real unusual login, you can still change the password from the real host.
Attachments that claim to be an invoice for Oernoe are not how this company bills a free account. Optional paid features, if you choose them, will be something you started. An unsolicited PDF is not that.
## Public wifi, again, in one paragraph
Coffee-shop wifi can be enough to read Search. It is a bad place to approve a new Google sign-in or to open Health. Step outside onto cellular if you are about to type a password. That habit matters more than a speech about encryption.
## If you stop using the account
Sign out everywhere you can. Change the password. Remove payment methods if you ever added one. You can ask support about deletion if you want the account gone. We will not invent a delete-button name. If you see delete in settings, it will be obvious.
An abandoned account with a reused password is a gift to whoever buys old breach lists. Either use it or close it.
We still will not invent settings labels. If your account page is missing a control, skip that item.
## 1. Give this account its own password
Reuse is the common failure. If the password also unlocks a shop or a forum, a leak over there becomes a login over here. Long and unique beats clever. A manager beats memory.
Change it if you know you reused it. Do that before you finish this page.
## 2. Treat the email account as the real key
Reset mail goes to the address you signed up with. Lock that mailbox down first: unique password, and a second factor at the email provider if you have one. An Oernoe password is weaker than it looks when the inbox is easy.
If you used a workplace email, plan for the day you lose it. Move recovery while you still have access.
## 3. Turn on a second factor only if it is actually there
Look in account settings. If you can add an authenticator, a key, or codes, do it the same afternoon. If you cannot, do not wait on a blog post that said “soon.” Your password is still the door.
When backup codes appear, store them off the same cloud account.
## 4. Nobody legitimate needs the password
Not support, not a friend helping you “check the account,” not a comment that says you won something. If you already typed it into a fake page, change it from a bookmark, then check the mailbox.
## 5. Read the hostname before you type
Official pages live on oernoe.com hosts. Search, account, and the www site are the ones you will use most. A message that wants you to “restore access” on a different domain is working you.
Type the address. Do not copy it from an email you did not expect.
The real sign-up page can use Google. Fake pages copy that button. Start from https://www.oernoe.com/login.
## 6. Look at activity when you have a way to look
If settings show recent logins or sessions, read them after you travel or after a scare. Sign out the strangers. If you have no session list, a password change is the blunt tool.
Times and cities are more useful than vibes. Write them down if you contact support.
## 7. Shared computers get a private window and a sign-out
Libraries, hotel business centers, and the laptop at a relative’s house should not keep your cookie. Private window, do the task, sign out, close the window. Do not save the password in that browser.
If you forgot, change the password from a machine you own.
## 8. Be dull about extensions and “helpers”
A browser add-on that wants to read every page can read this one too. Install software you can name. Remove the rest.
The same rule applies to people who want remote access to “fix” your account.
## 9. Update the boring software
Browser and operating system updates close holes that steal cookies. You do not need a speech about patches. Click the update, reboot if it asks, continue your day.
## 10. Write to support while the trail is fresh
If the account sent a reset you did not ask for, or files appeared, or you cannot get in after a reset, email support@oernoe.com. Say the username, the email, and the time. Do not send the password. Do not send a full dump of unrelated accounts.
If you are locked out because you lost the mailbox, say that clearly. Recovery will be slower. That is better than a support process that hands accounts to whoever writes first.
## Two extras the old list skipped
Public wifi is fine for reading. It is a poor place to change a password or open Health. Use a phone network if you are about to type credentials.
Optional paid features, if you ever buy them, will go through a payment page. Keep that receipt. A thief who adds a payment method is a different problem than a thief who only guesses a password.
## What this list is not
It is not a claim that the company can see every threat. It is not a substitute for the longer August 2026 security article if you want more narrative. It is ten things you can do without waiting for a product launch.
If you only do three: unique password, locked mailbox, no surprise links.
## If you only remember the shape
Password that lives nowhere else. Mailbox that is harder to steal than the Oernoe form. Settings checked when you travel. Links you typed. Sign-out on machines you do not own. Support mail that does not include the password.
The numbered list is for skimming. The sentences are for the day something feels off. Use either. Just do not keep the March-length version that ended mid-thought.
## A note the original buried
Staff will not ask you to install remote-control software. Staff will not ask you to move money to keep the account. Those messages are from other people. Delete them and, if you already clicked, change the password from a bookmark.
## Why this list still exists
The August safety article is the better long read. This slug already ranks in old links and in the journal index. Leaving it as a 200-word list would have been the thin page we are trying not to publish. So we kept the ten headings and wrote the parts a person needs when they are actually worried.
If the two pieces overlap, that is fine. The actions are the same actions. The wording here stays in list form so you can skim.
## How to use the list after a scare
Start at 5 and 6, not at 1. Hostname and sessions tell you whether someone else is already inside. Then change the password. Then lock the mailbox. Then write to support if the sessions looked wrong.
If nothing looks wrong and you are only nervous because of a news story, start at 1 and 2. Unique password, locked mailbox. Then stop. Anxiety is not a reason to delete the account.
## Phishing details people skip
The fake page will copy the logo and the four fields. The giveaway is the URL and the extra story: “unusual login from another country, click here.” Go to the bookmark instead. If there was a real unusual login, you can still change the password from the real host.
Attachments that claim to be an invoice for Oernoe are not how this company bills a free account. Optional paid features, if you choose them, will be something you started. An unsolicited PDF is not that.
## Public wifi, again, in one paragraph
Coffee-shop wifi can be enough to read Search. It is a bad place to approve a new Google sign-in or to open Health. Step outside onto cellular if you are about to type a password. That habit matters more than a speech about encryption.
## If you stop using the account
Sign out everywhere you can. Change the password. Remove payment methods if you ever added one. You can ask support about deletion if you want the account gone. We will not invent a delete-button name. If you see delete in settings, it will be obvious.
An abandoned account with a reused password is a gift to whoever buys old breach lists. Either use it or close it.
O
Oernoe Editorial Team
Technology experts committed to building privacy-first solutions and helping users understand how digital services work. Passionate about creating transparent, ethical platforms.
Get in touchRelated Articles
Want to Learn More?
Explore our complete guides and knowledge base for more insights on privacy, technology, and best practices.
Browse Our Guides