Securing Your Student Accounts Without Becoming Paranoid

Student accounts are attractive targets: they hold coursework you cannot replace, they often come with free software licences, and university email addresses unlock discounts worth reselling. The good news is that four measures stop almost everything, and none of them requires becoming the kind of person who talks about threat models.

The four that matter

1. A password manager

Not because your passwords are weak, but because reuse is the actual attack. When a small site is breached, the attacker takes the email and password pairs and tries them everywhere. If your university login shares a password with a forum you joined in 2019, that is the whole attack.

A manager means every account has a different password and you do not have to remember any of them. This single change removes the most common way accounts are lost.

2. Two-factor authentication on the accounts that matter

Your email first, because email resets everything else. Then your university account, then anything with money attached.

An authenticator app is meaningfully better than SMS codes, because phone numbers can be transferred away from you. If SMS is the only option offered, it is still far better than nothing.

3. Back up your coursework in two places

Ransomware and a dead hard drive produce the same outcome, and both are more likely than being targeted by anyone sophisticated. Cloud sync plus an external drive covers it. Check once a term that the backup actually contains what you think it does โ€” untested backups fail at exactly the wrong moment.

4. Update things

Operating system, browser, phone. Most successful attacks use flaws that were patched months ago against people who postponed the restart. Turning on automatic updates is a one-time decision that closes most of the window.

Recognising the attacks you will actually see

Fake login pages. An email says your library access is expiring, the page looks correct, and the address is very slightly wrong. The defence is habit: never sign in from a link in an email. Open a new tab and type the address you already know.

Urgency. Almost every phishing message creates a deadline โ€” your account will be suspended, the scholarship closes today, the fee is overdue. Real institutions rarely give you four hours. Urgency should slow you down, not speed you up.

The helpful stranger. Someone offering to fix your laptop, share a paid account, or send you a file through an unusual channel. Free software from an unofficial source is the most common way students install something they did not intend to.

Advice that has aged badly

“Change your password every 90 days.” Forced rotation makes people pick weaker, predictable variations. Change a password when there is a reason to.

“Use special characters and numbers.” Length matters far more than character variety. A long passphrase beats a short cryptic string, and you can remember it.

“Never write passwords down.” Written on paper in a drawer at home is a perfectly reasonable backup for the handful you must know by heart. The realistic threat is remote, not someone searching your desk.

If something does go wrong

  1. Change the password on your email first, from a device you trust.
  2. Check the account’s recent activity and, critically, its forwarding rules and recovery addresses โ€” attackers add these so they keep access after you change the password.
  3. Change passwords on anything that shared the old one.
  4. Tell your university IT service. They deal with this constantly and can see things you cannot.

Step two is the one people skip, and it is the one that turns a solved problem into a recurring one.