A
Turn on two-step verification for your email, payment and social media accounts, preferring phone pop-up confirmation, with SMS codes only as the second choice
Value for cost Very high
In plain termsTwo-step verification means that when you log in, besides the password, there is one more check that it's really you. With the method where a pop-up appears on your phone and you tap to confirm, more than nine in ten phishing account thefts were blocked. The old method of answering questions like “Where did you last log in?” or “What's your backup email?” blocked only about one in ten phishing account thefts.
- Cost
- Free. Set it up once per account; it takes two or three minutes.
No money
Done in passing
No willpower
Benefit size large
- Benefit
- Google tallied 350,000 real attempts to steal accounts (also called account hijacking). One kind of check relies on a device, such as a pop-up on your phone asking you to tap to confirm, or plugging in a security key. This kind blocked “over 94% of phishing-originated hijacking attempts and 100% of automated hijacking attempts.” Phishing means tricking you into entering your password on a fake website; automated means machines trying leaked passwords in bulk. The other kind relies on answering questions, such as asking where you last logged in or what your backup email is. This kind “blocked as little as 10% of phishing hijacks and 73% of automated hijacks”
- Evidence grade
- A
- Notes
- The same study also found that these checks sometimes lock out the real owner. Of genuine users, 52% failed to get in on the first try, though in the end 97% did get in. Turn this on for your email first, because most other accounts can recover their passwords through email. Use verification codes only yourself; for what you take on by reading out a code or scanning your face for someone else, see Section 8, Item 45 (reading out verification codes)
- Sources
- Doerfler P, Thomas K, Marincenko M, et al. (2019). Evaluating Login Challenges as a Defense Against Account Takeover. The World Wide Web Conference (WWW '19). https://doi.org/10.1145/3308558.3313481
C
Give your email its own password, not reused on any website
Value for cost High
In plain termsPasswords stolen from other websites get used to log straight into your email. Once someone is into your email, every account whose password can be recovered through that email is lost along with it. So your email password should be its own, used nowhere else.
- Cost
- Free. Keep it in a password manager and you don't have to remember it yourself. The hard part is breaking the old habit of using one password everywhere.
No money
Done in passing
Some willpower
Benefit size large
- Benefit
- Trying account names and passwords leaked elsewhere, one by one, to log in is called credential stuffing; it is the least-effort way to attack, and your email will be tried this way too. Once someone is into your email, every account that uses it for password recovery is lost along with it. The advice of the US Cybersecurity and Infrastructure Security Agency is: use a different strong password for each account, at least 16 characters long, and keep them in a password manager
- Evidence grade
- C
- Notes
- If you can't remember them, use the password manager built into your browser. It remembers each website's password for you, which is far better than using the same password everywhere. Don't store passwords in WeChat Favorites or in a notes app
C
Set a screen-lock passcode on your phone and a PIN on your SIM card
Value for cost Very high
In plain termsThe SIM card is the small card inside your phone; SMS verification codes are received through it. If your phone is lost, whoever finds it will pull this card out, put it in another phone to receive your verification codes, and then reset your accounts one by one. Set a PIN on the card, and when the card is moved to another phone, this code has to be entered first as soon as the phone is turned on; that route is cut off.
- Cost
- Free. Set the screen-lock passcode and the PIN once each, and you're done.
No money
Done in passing
No willpower
Benefit size large
- Benefit
- After your phone is lost, the quickest route for whoever finds it is to put the SIM card into another phone and receive your SMS verification codes. With the codes, they can reset your accounts one by one. If the SIM card has a PIN, then in another phone the password has to be entered first at power-on, and the finder can't use it to receive verification codes
- Evidence grade
- C
- Notes
- Set the PIN under the “SIM card lock” option in your phone's settings. The factory default code is usually 1234 or 0000. Enter it wrong three times in a row, and you'll need the PUK code from your carrier to unlock it. So once it's set, first write this code down on paper
- Sources
- 作者经验,无直接文献
C
If you lose your phone, do this in order: report the SIM card lost, lock the phone remotely, change passwords, report to the police, freeze bank cards
Value for cost Very high
In plain termsOrder matters more than speed. Step one, report the SIM card lost, and the lifeline of verification codes is cut. Next, lock the phone remotely, then use a computer to change your email and payment passwords, then report to the police and get a receipt, and finally freeze your bank cards depending on the situation. If you don't have your phone with you, you can also borrow someone else's phone and call your carrier's customer service to report the SIM lost.
- Cost
- Free. The whole routine takes ten-odd minutes.
No money
Done in passing
No willpower
Benefit size large
- Benefit
- Order matters more than speed. Step one: report the SIM card lost, and others can no longer receive your verification codes. Step two: lock the phone remotely, and wipe its contents. Step three: change your email and payment passwords from a computer. Step four: report to the police and get a receipt. Finally, freeze your bank cards as needed. The US Federal Communications Commission's advice is the same: even if you think the phone is merely lost, lock it remotely. If it was stolen, report it to the police right away, giving the model and the IMEI number (the phone's identity number), and tell your carrier right away
- Evidence grade
- C
- Notes
- Write down the customer service numbers of the three carriers in advance: China Mobile 10086, China Unicom 10010, China Telecom 10000. Also note which city your own phone number was registered in; customer service will ask. You can just as well call customer service from someone else's phone to report the SIM lost
A
If your card is used fraudulently, report it lost and freeze it first, then report to the police, then demand compensation from the bank: proving “you made the charge yourself” is the bank's job
Value for cost High
In plain termsIf your card is used fraudulently, you don't have to prove “I didn't make this charge.” It's the other way around: the bank has to produce evidence that you yourself made the charge, and if it can't, it has to compensate you. The condition is that you report the card lost and freeze it as soon as you find out. If you put off reporting it, the additional losses after that are yours to bear.
- Cost
- Free. As soon as you notice anything wrong on the card, report it lost or freeze it at once. Keep the police report records, the loss-report records and the transaction notices the bank sent you. If the card is still on you, make a small balance inquiry, deposit or withdrawal nearby, leaving a record that proves the real card was in your hands when it happened. The hard part is holding back from arguing with customer service first; report the card lost first.
No money
Done in passing
Some willpower
Benefit size large
- Benefit
- The Supreme People's Court's provisions split up “who has to produce the evidence.” If you claim this was counterfeit-card fraud or online fraud, you have to produce evidence first. Counterfeit-card fraud means someone made a copy of your card and used it. All of these can serve as proof: legal documents that have already taken effect, where the real card was at the time of the transaction, and where the transaction took place. Also account transaction details, transaction notices, police report records, loss-report records and so on. Conversely, if the card-issuing bank or a non-bank payment institution (third-party payment) says the charge was made by the cardholder personally, or with the cardholder's authorization, it is they who must produce the evidence. If, after you notify the bank, the bank fails to verify in time, or fails to provide and preserve the transaction slips and surveillance footage in time, and the evidence can no longer be obtained as a result, the bank bears the consequences of the missing evidence. Once this is established: a debit card (savings card) holder can require the issuing bank to pay them the principal and interest of the deposits that were fraudulently taken, and to compensate for losses. A credit card holder can require the return of the overdraft principal and interest and the penalty charges that were deducted, and compensation for losses; if the bank in turn demands that you repay this overdraft, the court will not support it. You can also require the issuing bank to promptly cancel the corresponding negative credit records (nationwide, in force from May 25, 2021)
- Evidence grade
- A
- Notes
- There are two situations in which you bear responsibility yourself. One: you didn't keep your bank card, password, verification codes and the like safe, and you were at fault (the original wording is “at fault for failing to fulfill the duty of proper safekeeping” (未尽妥善保管义务具有过错)); you bear responsibility in proportion to your fault. So don't tell anyone your password, and don't forward verification codes to anyone (see Item 1: for two-step verification, prefer phone pop-up confirmation). Two: you didn't report the loss in time and let the losses keep growing; the extra part you bear yourself. So the first step is always to report the card lost and freeze it; don't call customer service to argue first. The same rules also apply to third-party payment institutions. If its promotional materials say “compensation first” (先行赔付), and the promise is specific and clear, you can require it to compensate you first accordingly. If you were tricked into transferring the money out yourself, a different procedure applies; see Section 8, Item 2 (if you find you've been scammed, call 110 (police) or 96110 at once and ask for a payment stop).
C
Check your accounts' logged-in devices and authorized apps every so often, and clear out the ones you don't use
Value for cost Standard
In plain terms“Logged-in devices” means the phones and computers that can still use your account right now. People who steal accounts often lie low for a while before making a move. If a device you don't recognize shows up in the list, or software you stopped using long ago is still connected to your account, log out of all sessions as soon as you see it, then change your password.
- Cost
- Free. A few minutes each time. The hard part is that no one reminds you; you have to remember to check yourself.
No money
Done in passing
Some willpower
Benefit size medium
- Benefit
- When an account is stolen, the thief often doesn't act right away; they lie low for a while first. The logged-in devices list in your account records the phones and computers that can still use this account right now. The authorized apps list records the other companies' software you have allowed to log in with this account. Unfamiliar devices in the list, and third-party software you stopped using long ago, are the easiest traces to spot
- Evidence grade
- C
- Notes
- WeChat, Alipay, email, Apple accounts and Android accounts all have this option. If you find a device you don't recognize, tap to log out of all sessions, then change your password
- Sources
- 作者经验,无直接文献
A
Don't tap “Agree to all” just to use an app: for information that isn't necessary, refusing consent can't be grounds for denying you the service
Value for cost Standard
In plain termsWhen an app asks for your information, if it isn't required to provide that service, the app can't stop you from using it because you refuse. What it may collect is also limited to what it actually needs. A map app needing your location is necessary; a flashlight app asking for your contacts is not.
- Cost
- Free. The hard part is holding back from tapping “Agree to all.”
No money
Done in passing
Some willpower
Benefit size medium
- Benefit
- The law spells out two rules. First, a product or service may not be refused on the grounds that the individual does not consent or withdraws consent, except where processing this information is necessary to provide the service. Second, collection shall be limited to the minimum scope needed to achieve the purpose of processing; only what is actually needed may be collected
- Evidence grade
- A
- Notes
- The test is whether this information is necessary to provide this service. A map app needing your location is necessary; a flashlight app needing your contacts is not. After installing an app, first go to the app permissions page in your phone's settings and turn off the permissions that aren't necessary. When you actually need one, choose to allow it only this time.
A
You have the right to view, copy, correct and delete your own personal information, and you can sue if refused
Value for cost Standard
In plain termsYou have the right to require a company to let you view, copy, correct and delete your own information. When the service has stopped, the retention period has expired or you have withdrawn consent, the company should delete it on its own anyway. If it refuses you, it must give its reasons; if it doesn't act, you can go straight to court and sue it. Closing an account and deleting your information are two different things; after closing the account you still have to request deletion separately.
- Cost
- Free. Only if the other side stalls do you need to file a complaint or sue. An actual lawsuit takes months at a minimum, and you pay your own lawyer's fees, so complaining first is the better deal. The hard part is that when they stall, you have to chase them again and again.
No money
Done in passing
Some willpower
Benefit size medium
- Benefit
- In several situations a company should delete your information on its own initiative: the service has stopped, the agreed retention period has expired, you have withdrawn consent, the purpose for which it was originally collected has been achieved, and so on. If it hasn't deleted it, you can require it to. If it refuses your exercise of these rights, it must give its reasons. You can sue it directly in court
- Evidence grade
- A
- Notes
- Closing an account and deleting your personal information are two different things; after closing it you still have to make a separate request for deletion. Before switching phones or selling your old one, first log out of and unlink all accounts on the old phone, then restore it to factory settings. What the law gives you is a right to deletion after the fact; it can't get back for you what has already leaked out.
- Sources
- 全国人大常委会 (2021). 个人信息保护法. 中国人大网. http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html:第四十五条「个人有权向个人信息处理者查阅、复制其个人信息……个人请求查阅、复制其个人信息的,个人信息处理者应当及时提供」;第四十六条更正、补充权;第四十七条列了五种应当主动删除的情形,含「(一)处理目的已实现、无法实现或者为实现处理目的不再必要」「(二)个人信息处理者停止提供产品或者服务,或者保存期限已届满」「(三)个人撤回同意」,「个人信息处理者未删除的,个人有权请求删除」;第五十条「个人信息处理者应当建立便捷的个人行使权利的申请受理和处理机制。拒绝个人行使权利的请求的,应当说明理由」「个人可以依法向人民法院提起诉讼」
A
You don't have to agree to face scanning: if there is another way, they can't make face scanning your only option, and if you don't consent they must give you an alternative
Value for cost Standard
In plain termsAs long as there is another way to get the same thing done, they can't make face scanning your only option. If you don't consent to face scanning, they have to give you another method, such as a card, a password or your ID card, and they may not pressure you with “then we can't process your business.” In hotel rooms, public bathhouses, changing rooms and toilets, no one may install facial recognition equipment.
- Cost
- Free. When asked to scan your face, ask: “Is there another way to verify?” If they say no, require them to provide one. The hard part is speaking up in person.
No money
Done in passing
Some willpower
Benefit size medium
- Benefit
- The Measures for the Security Management of the Application of Facial Recognition Technology (人脸识别技术应用安全管理办法) state: “Where other non-facial-recognition technical means exist to achieve the same purpose or meet equivalent business requirements, facial recognition technology shall not be used as the sole means of verification. Where an individual does not consent to identity verification through facial information, other reasonable and convenient means shall be provided.” The Measures also state: “No organization or individual may, on the grounds of handling business, improving service quality or the like, mislead, defraud or coerce an individual into accepting identity verification by facial recognition technology.” If facial information is processed on the basis of your consent, “separate consent given voluntarily and explicitly on the premise of full knowledge” must be obtained: you are asked about this one matter on its own, and only your separate agreement counts. You have the right to withdraw consent, and the processor must provide a convenient way to withdraw it. Processing the facial information of minors under the age of fourteen requires the consent of their parents or other guardians. Installing facial recognition equipment in public places “shall be necessary for maintaining public security,” and conspicuous notice signs must be put up. Inside private spaces within public places, such as hotel rooms, public bathhouses, public changing rooms and public toilets, no organization or individual may install it. Facial information shall be stored within the facial recognition device and shall not be transmitted externally over the internet. There are two exceptions: where laws or administrative regulations provide otherwise, or where separate consent has been obtained (nationwide, in force from June 1, 2025)
- Evidence grade
- A
- Notes
- The most common cases are residential compound access gates, rental platforms, gyms and hotels asking you to register your face. When they say “the system only supports face scanning,” read them the original wording of the Measures. The original wording is: “Where other non-facial-recognition technical means exist to achieve the same purpose or meet equivalent business requirements, facial recognition technology shall not be used as the sole means of verification.” Then require them to provide another method, such as a card, a password or your ID card. If they still won't, report it to the local cyberspace administration authorities. Where the state has separate rules on verifying identity by face scanning, such as in some financial and government-service settings, those rules apply. The biggest difference between your face and a password is that a face can't be changed after it leaks, so it deserves more caution than a password. An organization that stores the facial information of 100,000 or more people must file with the cyberspace administration authorities at the provincial level or above within 30 working days; this is also one question to ask in judging whether they are legitimate. For the rights to view, correct and delete your own personal information, see Item 8. Someone borrowing your face to take out a loan of their own is a different matter; see Section 8, Item 45 (scanning your face as a favor).
B
Don't hand your code, keys and private data to “AI relay stations” of unknown origin, especially when you let AI execute commands automatically
Value for cost Standard
In plain termsA relay station sits between you and the model provider; it can see and alter everything you send out and every answer that comes back. A study tested over 400 relay stations: 9 slipped malicious code into responses, and 17 used the cloud service keys the researchers had deliberately planted. If you let AI execute commands automatically, a single altered command is enough for someone to take control of your computer.
- Cost
- Connecting directly to the official service is usually more expensive than a relay station, and topping up is less convenient too. The hard part is that relay stations are cheap, and one entry point can call models from several companies
A little money
Done in passing
Some willpower
Benefit size medium
- Benefit
- In June 2026 the Ministry of State Security issued a risk alert. Some relay stations keep the data users submit on their servers; some secretly intercept it and resell it to other large-model companies for training. Some hide backdoors, plant malicious code on users' devices, steal account keys and cloud credentials, and even install remote-control programs. The alert recommends using platforms with official direct connections and proper authorization, and not using platforms of unknown origin, without operating qualifications or without security safeguards. When using them, first redact personal private information and project materials, manage your keys carefully and rotate them regularly. If you run into abnormal charges, unexplained account bans or data anomalies, stop using the service at once, change your keys, scan for and remove viruses, and keep evidence. In 2026, researchers at the University of California, Santa Barbara and other institutions carried out a measurement study. They bought 28 paid relay stations from Taobao, Xianyu and overseas online shops, and collected 400 free relay stations from public communities. The result: 1 paid and 8 free stations injected malicious code into the tool calls they returned. A tool call is a command the AI has your computer execute, such as installing a software package. Another 2 picked their moment to strike; the paper's example is attacking only sessions that execute fully automatically. Also, 17 used the Amazon cloud service keys the researchers had deliberately planted. And 1 transferred money out of the researchers' Ethereum wallet; the wallet held only a little money, and the loss was under 50 US dollars. The modification the paper demonstrates is well hidden: replacing requests in an install command with the similarly spelled reqeusts, which you can't spot at a glance (nationwide)
- Evidence grade
- B
- Notes
- It is graded B because there is only one study, and it is a preprint, meaning a version made public before formal publication. Most of the relay stations tested were free; only 28 were paid, so it isn't possible to calculate “what share of relay stations have problems.” Some media reported that theft as 500,000 US dollars; the paper itself says under 50 dollars. The size of the benefit is set at medium based on the consequences: losses from stolen keys and code vary enormously, and the study has no amounts that can be applied. If you have already used a relay station of unknown origin, go to the model provider, revoke the keys you used and generate new ones, and replace your cloud service and code repository keys as well. When going through a relay station, don't let AI execute commands fully automatically; take a look at each command before letting it run. The side running a relay station faces criminal risk; see Section 11, Item 19 (AI relay stations). The beneficiary is you yourself.