Picture three bikes parked at dusk. Two use steel locks; one uses a chain. A thief with a cheap cutter can take the chained bike in about two minutes and vanish before anyone notices.
Bike thieves and online thieves share a habit: they hunt easy targets. University of Arizona MIS professor Hsinchun Chen puts it bluntly: “When it comes to online theft, the only reason you are safe is that other users are easier prey.”
Chen leads Hacker Web, a $5.4 million National Science Foundation project studying international hacking crews from places including Russia, China, and the United States. He also teaches in Arizona’s cybersecurity graduate program. After 27 years in the field, his metaphor is simple: cybersecurity is a chain, and you are only as strong as the weakest link. His six tips:
1. Use multi-factor authentication
MFA asks for two or more proofs so stolen passwords alone are not enough. ATMs have done this for years with a card plus a PIN. Online MFA is newer, but worth turning on everywhere it exists.
2. Prefer fingerprints over passwords when you can
Newer iPhones and many banking apps support it. “If you can use a fingerprint instead of a password, do it,” Chen says. Prints can be faked, but that is still harder than stealing a reused password.
3. Use many passwords and rotate them
If your password is still “password,” the outlook is bleak. Even people who mix cases and symbols often fail to rotate credentials. Change them every few months and never reuse the same one across accounts.
4. Keep antivirus software updated
New malware appears constantly. Stale antivirus becomes theater.

5. Use one trusted computer for banking and shopping
“Do not casually log in from every unknown machine,” Chen warns. Prefer one hardened PC, and be careful on phones, which can be easier to compromise.
6. Muddy the waters
Hide your trail where you can. Multiple email addresses, for example, make it harder for attackers to stitch your identity together.