Frozen snapshot of 9 October 2026 · upstream commit bb25081
A login form with a username field and a masked password field.
Photo: Username and password 20170626.jpg by Santeri Viinamäki, CC BY-SA 4.0, via Wikimedia Commons. Cropped and colour-muted for display.
Section 14·10 items·9 October 2026

Account and Information Security

two-factor authentication, passwords, SIM cards, losing your phone, fraudulent bank card charges, logged-in devices, app permissions, facial recognition, the rights to access and delete, AI relay sites of unknown origin. Outcome type: money/personal information.

A 5B 1C 4
Money 7Personal freedom 3

Outcome type: money and personal information. When someone else gets into your account, the first thing you lose is money. They will also use your account to scam the people in your contacts. In effect, your identity has been taken too.

Sources are reproduced exactly as they appear in the Chinese original, including Chinese titles of laws and quoted statutory text. Original Chinese text of this section at upstream commit bb25081, on GitHub.

Items in this section (10)
  1. AItem 1Turn on two-step verification for your email, payment and social media accounts, preferring phone pop-up confirmation, with SMS codes only as the second choice
  2. CItem 2Give your email its own password, not reused on any website
  3. CItem 3Set a screen-lock passcode on your phone and a PIN on your SIM card
  4. CItem 4If you lose your phone, do this in order: report the SIM card lost, lock the phone remotely, change passwords, report to the police, freeze bank cards
  5. AItem 5If your card is used fraudulently, report it lost and freeze it first, then report to the police, then demand compensation from the bank: proving “you made the charge yourself” is the bank's job
  6. CItem 6Check your accounts' logged-in devices and authorized apps every so often, and clear out the ones you don't use
  7. AItem 7Don't tap “Agree to all” just to use an app: for information that isn't necessary, refusing consent can't be grounds for denying you the service
  8. AItem 8You have the right to view, copy, correct and delete your own personal information, and you can sue if refused
  9. AItem 9You don't have to agree to face scanning: if there is another way, they can't make face scanning your only option, and if you don't consent they must give you an alternative
  10. BItem 10Don't hand your code, keys and private data to “AI relay stations” of unknown origin, especially when you let AI execute commands automatically
Section 14, Item 1·Outcome  Money

Turn on two-step verification for your email, payment and social media accounts, preferring phone pop-up confirmation, with SMS codes only as the second choice

Value for cost Very high
In plain terms

Two-step verification means that when you log in, besides the password, there is one more check that it's really you. With the method where a pop-up appears on your phone and you tap to confirm, more than nine in ten phishing account thefts were blocked. The old method of answering questions like “Where did you last log in?” or “What's your backup email?” blocked only about one in ten phishing account thefts.

Cost
Free. Set it up once per account; it takes two or three minutes. No money Done in passing No willpower Benefit size large
Benefit
Google tallied 350,000 real attempts to steal accounts (also called account hijacking). One kind of check relies on a device, such as a pop-up on your phone asking you to tap to confirm, or plugging in a security key. This kind blocked “over 94% of phishing-originated hijacking attempts and 100% of automated hijacking attempts.” Phishing means tricking you into entering your password on a fake website; automated means machines trying leaked passwords in bulk. The other kind relies on answering questions, such as asking where you last logged in or what your backup email is. This kind “blocked as little as 10% of phishing hijacks and 73% of automated hijacks”
Evidence grade
A
Notes
The same study also found that these checks sometimes lock out the real owner. Of genuine users, 52% failed to get in on the first try, though in the end 97% did get in. Turn this on for your email first, because most other accounts can recover their passwords through email. Use verification codes only yourself; for what you take on by reading out a code or scanning your face for someone else, see Section 8, Item 45 (reading out verification codes)
Sources
Doerfler P, Thomas K, Marincenko M, et al. (2019). Evaluating Login Challenges as a Defense Against Account Takeover. The World Wide Web Conference (WWW '19). https://doi.org/10.1145/3308558.3313481
Section 14, Item 2·Outcome  Money

Give your email its own password, not reused on any website

Value for cost High
In plain terms

Passwords stolen from other websites get used to log straight into your email. Once someone is into your email, every account whose password can be recovered through that email is lost along with it. So your email password should be its own, used nowhere else.

Cost
Free. Keep it in a password manager and you don't have to remember it yourself. The hard part is breaking the old habit of using one password everywhere. No money Done in passing Some willpower Benefit size large
Benefit
Trying account names and passwords leaked elsewhere, one by one, to log in is called credential stuffing; it is the least-effort way to attack, and your email will be tried this way too. Once someone is into your email, every account that uses it for password recovery is lost along with it. The advice of the US Cybersecurity and Infrastructure Security Agency is: use a different strong password for each account, at least 16 characters long, and keep them in a password manager
Evidence grade
C
Notes
If you can't remember them, use the password manager built into your browser. It remembers each website's password for you, which is far better than using the same password everywhere. Don't store passwords in WeChat Favorites or in a notes app
Section 14, Item 3·Outcome  Money

Set a screen-lock passcode on your phone and a PIN on your SIM card

Value for cost Very high
In plain terms

The SIM card is the small card inside your phone; SMS verification codes are received through it. If your phone is lost, whoever finds it will pull this card out, put it in another phone to receive your verification codes, and then reset your accounts one by one. Set a PIN on the card, and when the card is moved to another phone, this code has to be entered first as soon as the phone is turned on; that route is cut off.

Cost
Free. Set the screen-lock passcode and the PIN once each, and you're done. No money Done in passing No willpower Benefit size large
Benefit
After your phone is lost, the quickest route for whoever finds it is to put the SIM card into another phone and receive your SMS verification codes. With the codes, they can reset your accounts one by one. If the SIM card has a PIN, then in another phone the password has to be entered first at power-on, and the finder can't use it to receive verification codes
Evidence grade
C
Notes
Set the PIN under the “SIM card lock” option in your phone's settings. The factory default code is usually 1234 or 0000. Enter it wrong three times in a row, and you'll need the PUK code from your carrier to unlock it. So once it's set, first write this code down on paper
Sources
作者经验,无直接文献
Section 14, Item 4·Outcome  Money

If you lose your phone, do this in order: report the SIM card lost, lock the phone remotely, change passwords, report to the police, freeze bank cards

Value for cost Very high
In plain terms

Order matters more than speed. Step one, report the SIM card lost, and the lifeline of verification codes is cut. Next, lock the phone remotely, then use a computer to change your email and payment passwords, then report to the police and get a receipt, and finally freeze your bank cards depending on the situation. If you don't have your phone with you, you can also borrow someone else's phone and call your carrier's customer service to report the SIM lost.

Cost
Free. The whole routine takes ten-odd minutes. No money Done in passing No willpower Benefit size large
Benefit
Order matters more than speed. Step one: report the SIM card lost, and others can no longer receive your verification codes. Step two: lock the phone remotely, and wipe its contents. Step three: change your email and payment passwords from a computer. Step four: report to the police and get a receipt. Finally, freeze your bank cards as needed. The US Federal Communications Commission's advice is the same: even if you think the phone is merely lost, lock it remotely. If it was stolen, report it to the police right away, giving the model and the IMEI number (the phone's identity number), and tell your carrier right away
Evidence grade
C
Notes
Write down the customer service numbers of the three carriers in advance: China Mobile 10086, China Unicom 10010, China Telecom 10000. Also note which city your own phone number was registered in; customer service will ask. You can just as well call customer service from someone else's phone to report the SIM lost
Sources
US FCC. Protect Your Smart Device. https://www.fcc.gov/consumers/guides/protect-your-mobile-device;步骤顺序是作者经验;补办身份证见第 7 节,冒名贷款见第 8 节关于征信的一条
Section 14, Item 5·Outcome  Money

If your card is used fraudulently, report it lost and freeze it first, then report to the police, then demand compensation from the bank: proving “you made the charge yourself” is the bank's job

Value for cost High
In plain terms

If your card is used fraudulently, you don't have to prove “I didn't make this charge.” It's the other way around: the bank has to produce evidence that you yourself made the charge, and if it can't, it has to compensate you. The condition is that you report the card lost and freeze it as soon as you find out. If you put off reporting it, the additional losses after that are yours to bear.

Cost
Free. As soon as you notice anything wrong on the card, report it lost or freeze it at once. Keep the police report records, the loss-report records and the transaction notices the bank sent you. If the card is still on you, make a small balance inquiry, deposit or withdrawal nearby, leaving a record that proves the real card was in your hands when it happened. The hard part is holding back from arguing with customer service first; report the card lost first. No money Done in passing Some willpower Benefit size large
Benefit
The Supreme People's Court's provisions split up “who has to produce the evidence.” If you claim this was counterfeit-card fraud or online fraud, you have to produce evidence first. Counterfeit-card fraud means someone made a copy of your card and used it. All of these can serve as proof: legal documents that have already taken effect, where the real card was at the time of the transaction, and where the transaction took place. Also account transaction details, transaction notices, police report records, loss-report records and so on. Conversely, if the card-issuing bank or a non-bank payment institution (third-party payment) says the charge was made by the cardholder personally, or with the cardholder's authorization, it is they who must produce the evidence. If, after you notify the bank, the bank fails to verify in time, or fails to provide and preserve the transaction slips and surveillance footage in time, and the evidence can no longer be obtained as a result, the bank bears the consequences of the missing evidence. Once this is established: a debit card (savings card) holder can require the issuing bank to pay them the principal and interest of the deposits that were fraudulently taken, and to compensate for losses. A credit card holder can require the return of the overdraft principal and interest and the penalty charges that were deducted, and compensation for losses; if the bank in turn demands that you repay this overdraft, the court will not support it. You can also require the issuing bank to promptly cancel the corresponding negative credit records (nationwide, in force from May 25, 2021)
Evidence grade
A
Notes
There are two situations in which you bear responsibility yourself. One: you didn't keep your bank card, password, verification codes and the like safe, and you were at fault (the original wording is “at fault for failing to fulfill the duty of proper safekeeping” (未尽妥善保管义务具有过错)); you bear responsibility in proportion to your fault. So don't tell anyone your password, and don't forward verification codes to anyone (see Item 1: for two-step verification, prefer phone pop-up confirmation). Two: you didn't report the loss in time and let the losses keep growing; the extra part you bear yourself. So the first step is always to report the card lost and freeze it; don't call customer service to argue first. The same rules also apply to third-party payment institutions. If its promotional materials say “compensation first” (先行赔付), and the promise is specific and clear, you can require it to compensate you first accordingly. If you were tricked into transferring the money out yourself, a different procedure applies; see Section 8, Item 2 (if you find you've been scammed, call 110 (police) or 96110 at once and ask for a payment stop).
Sources
最高人民法院 (2021). 关于审理银行卡民事纠纷案件若干问题的规定(第四、五、七、十四、十五条). https://www.court.gov.cn/fabu/xiangqing/304771.html
Section 14, Item 6·Outcome  Money

Check your accounts' logged-in devices and authorized apps every so often, and clear out the ones you don't use

Value for cost Standard
In plain terms

“Logged-in devices” means the phones and computers that can still use your account right now. People who steal accounts often lie low for a while before making a move. If a device you don't recognize shows up in the list, or software you stopped using long ago is still connected to your account, log out of all sessions as soon as you see it, then change your password.

Cost
Free. A few minutes each time. The hard part is that no one reminds you; you have to remember to check yourself. No money Done in passing Some willpower Benefit size medium
Benefit
When an account is stolen, the thief often doesn't act right away; they lie low for a while first. The logged-in devices list in your account records the phones and computers that can still use this account right now. The authorized apps list records the other companies' software you have allowed to log in with this account. Unfamiliar devices in the list, and third-party software you stopped using long ago, are the easiest traces to spot
Evidence grade
C
Notes
WeChat, Alipay, email, Apple accounts and Android accounts all have this option. If you find a device you don't recognize, tap to log out of all sessions, then change your password
Sources
作者经验,无直接文献
Section 14, Item 7·Outcome  Personal freedom

Don't tap “Agree to all” just to use an app: for information that isn't necessary, refusing consent can't be grounds for denying you the service

Value for cost Standard
In plain terms

When an app asks for your information, if it isn't required to provide that service, the app can't stop you from using it because you refuse. What it may collect is also limited to what it actually needs. A map app needing your location is necessary; a flashlight app asking for your contacts is not.

Cost
Free. The hard part is holding back from tapping “Agree to all.” No money Done in passing Some willpower Benefit size medium
Benefit
The law spells out two rules. First, a product or service may not be refused on the grounds that the individual does not consent or withdraws consent, except where processing this information is necessary to provide the service. Second, collection shall be limited to the minimum scope needed to achieve the purpose of processing; only what is actually needed may be collected
Evidence grade
A
Notes
The test is whether this information is necessary to provide this service. A map app needing your location is necessary; a flashlight app needing your contacts is not. After installing an app, first go to the app permissions page in your phone's settings and turn off the permissions that aren't necessary. When you actually need one, choose to allow it only this time.
Sources
全国人大常委会 (2021). 个人信息保护法. 中国人大网. http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html:第六条「收集个人信息,应当限于实现处理目的的最小范围,不得过度收集个人信息」;第十六条「个人信息处理者不得以个人不同意处理其个人信息或者撤回同意为由,拒绝提供产品或者服务;处理个人信息属于提供产品或者服务所必需的除外」;第十五条「基于个人同意处理个人信息的,个人有权撤回其同意。个人信息处理者应当提供便捷的撤回同意的方式」
Section 14, Item 8·Outcome  Personal freedom

You have the right to view, copy, correct and delete your own personal information, and you can sue if refused

Value for cost Standard
In plain terms

You have the right to require a company to let you view, copy, correct and delete your own information. When the service has stopped, the retention period has expired or you have withdrawn consent, the company should delete it on its own anyway. If it refuses you, it must give its reasons; if it doesn't act, you can go straight to court and sue it. Closing an account and deleting your information are two different things; after closing the account you still have to request deletion separately.

Cost
Free. Only if the other side stalls do you need to file a complaint or sue. An actual lawsuit takes months at a minimum, and you pay your own lawyer's fees, so complaining first is the better deal. The hard part is that when they stall, you have to chase them again and again. No money Done in passing Some willpower Benefit size medium
Benefit
In several situations a company should delete your information on its own initiative: the service has stopped, the agreed retention period has expired, you have withdrawn consent, the purpose for which it was originally collected has been achieved, and so on. If it hasn't deleted it, you can require it to. If it refuses your exercise of these rights, it must give its reasons. You can sue it directly in court
Evidence grade
A
Notes
Closing an account and deleting your personal information are two different things; after closing it you still have to make a separate request for deletion. Before switching phones or selling your old one, first log out of and unlink all accounts on the old phone, then restore it to factory settings. What the law gives you is a right to deletion after the fact; it can't get back for you what has already leaked out.
Sources
全国人大常委会 (2021). 个人信息保护法. 中国人大网. http://www.npc.gov.cn/npc/c2/c30834/202108/t20210820_313088.html:第四十五条「个人有权向个人信息处理者查阅、复制其个人信息……个人请求查阅、复制其个人信息的,个人信息处理者应当及时提供」;第四十六条更正、补充权;第四十七条列了五种应当主动删除的情形,含「(一)处理目的已实现、无法实现或者为实现处理目的不再必要」「(二)个人信息处理者停止提供产品或者服务,或者保存期限已届满」「(三)个人撤回同意」,「个人信息处理者未删除的,个人有权请求删除」;第五十条「个人信息处理者应当建立便捷的个人行使权利的申请受理和处理机制。拒绝个人行使权利的请求的,应当说明理由」「个人可以依法向人民法院提起诉讼」
Section 14, Item 9·Outcome  Money

You don't have to agree to face scanning: if there is another way, they can't make face scanning your only option, and if you don't consent they must give you an alternative

Value for cost Standard
In plain terms

As long as there is another way to get the same thing done, they can't make face scanning your only option. If you don't consent to face scanning, they have to give you another method, such as a card, a password or your ID card, and they may not pressure you with “then we can't process your business.” In hotel rooms, public bathhouses, changing rooms and toilets, no one may install facial recognition equipment.

Cost
Free. When asked to scan your face, ask: “Is there another way to verify?” If they say no, require them to provide one. The hard part is speaking up in person. No money Done in passing Some willpower Benefit size medium
Benefit
The Measures for the Security Management of the Application of Facial Recognition Technology (人脸识别技术应用安全管理办法) state: “Where other non-facial-recognition technical means exist to achieve the same purpose or meet equivalent business requirements, facial recognition technology shall not be used as the sole means of verification. Where an individual does not consent to identity verification through facial information, other reasonable and convenient means shall be provided.” The Measures also state: “No organization or individual may, on the grounds of handling business, improving service quality or the like, mislead, defraud or coerce an individual into accepting identity verification by facial recognition technology.” If facial information is processed on the basis of your consent, “separate consent given voluntarily and explicitly on the premise of full knowledge” must be obtained: you are asked about this one matter on its own, and only your separate agreement counts. You have the right to withdraw consent, and the processor must provide a convenient way to withdraw it. Processing the facial information of minors under the age of fourteen requires the consent of their parents or other guardians. Installing facial recognition equipment in public places “shall be necessary for maintaining public security,” and conspicuous notice signs must be put up. Inside private spaces within public places, such as hotel rooms, public bathhouses, public changing rooms and public toilets, no organization or individual may install it. Facial information shall be stored within the facial recognition device and shall not be transmitted externally over the internet. There are two exceptions: where laws or administrative regulations provide otherwise, or where separate consent has been obtained (nationwide, in force from June 1, 2025)
Evidence grade
A
Notes
The most common cases are residential compound access gates, rental platforms, gyms and hotels asking you to register your face. When they say “the system only supports face scanning,” read them the original wording of the Measures. The original wording is: “Where other non-facial-recognition technical means exist to achieve the same purpose or meet equivalent business requirements, facial recognition technology shall not be used as the sole means of verification.” Then require them to provide another method, such as a card, a password or your ID card. If they still won't, report it to the local cyberspace administration authorities. Where the state has separate rules on verifying identity by face scanning, such as in some financial and government-service settings, those rules apply. The biggest difference between your face and a password is that a face can't be changed after it leaks, so it deserves more caution than a password. An organization that stores the facial information of 100,000 or more people must file with the cyberspace administration authorities at the provincial level or above within 30 working days; this is also one question to ask in judging whether they are legitimate. For the rights to view, correct and delete your own personal information, see Item 8. Someone borrowing your face to take out a loan of their own is a different matter; see Section 8, Item 45 (scanning your face as a favor).
Sources
国家互联网信息办公室、公安部 (2025). 人脸识别技术应用安全管理办法(第 19 号令,第十条、十二条、十三条,2025 年 6 月 1 日起施行). https://www.cac.gov.cn/2025-03/21/c_1744174262156096.htm
Section 14, Item 10·Outcome  Personal freedom

Don't hand your code, keys and private data to “AI relay stations” of unknown origin, especially when you let AI execute commands automatically

Value for cost Standard
In plain terms

A relay station sits between you and the model provider; it can see and alter everything you send out and every answer that comes back. A study tested over 400 relay stations: 9 slipped malicious code into responses, and 17 used the cloud service keys the researchers had deliberately planted. If you let AI execute commands automatically, a single altered command is enough for someone to take control of your computer.

Cost
Connecting directly to the official service is usually more expensive than a relay station, and topping up is less convenient too. The hard part is that relay stations are cheap, and one entry point can call models from several companies A little money Done in passing Some willpower Benefit size medium
Benefit
In June 2026 the Ministry of State Security issued a risk alert. Some relay stations keep the data users submit on their servers; some secretly intercept it and resell it to other large-model companies for training. Some hide backdoors, plant malicious code on users' devices, steal account keys and cloud credentials, and even install remote-control programs. The alert recommends using platforms with official direct connections and proper authorization, and not using platforms of unknown origin, without operating qualifications or without security safeguards. When using them, first redact personal private information and project materials, manage your keys carefully and rotate them regularly. If you run into abnormal charges, unexplained account bans or data anomalies, stop using the service at once, change your keys, scan for and remove viruses, and keep evidence. In 2026, researchers at the University of California, Santa Barbara and other institutions carried out a measurement study. They bought 28 paid relay stations from Taobao, Xianyu and overseas online shops, and collected 400 free relay stations from public communities. The result: 1 paid and 8 free stations injected malicious code into the tool calls they returned. A tool call is a command the AI has your computer execute, such as installing a software package. Another 2 picked their moment to strike; the paper's example is attacking only sessions that execute fully automatically. Also, 17 used the Amazon cloud service keys the researchers had deliberately planted. And 1 transferred money out of the researchers' Ethereum wallet; the wallet held only a little money, and the loss was under 50 US dollars. The modification the paper demonstrates is well hidden: replacing requests in an install command with the similarly spelled reqeusts, which you can't spot at a glance (nationwide)
Evidence grade
B
Notes
It is graded B because there is only one study, and it is a preprint, meaning a version made public before formal publication. Most of the relay stations tested were free; only 28 were paid, so it isn't possible to calculate “what share of relay stations have problems.” Some media reported that theft as 500,000 US dollars; the paper itself says under 50 dollars. The size of the benefit is set at medium based on the consequences: losses from stolen keys and code vary enormously, and the study has no amounts that can be applied. If you have already used a relay station of unknown origin, go to the model provider, revoke the keys you used and generate new ones, and replace your cloud service and code repository keys as well. When going through a relay station, don't let AI execute commands fully automatically; take a look at each command before letting it run. The side running a relay station faces criminal risk; see Section 11, Item 19 (AI relay stations). The beneficiary is you yourself.
Sources
国家安全部 (2026). 「AI中转站」,风险要防范. https://www.szzg.gov.cn/2026/xwzx/szkx/202606/t20260608_5331487.htm(数字中国建设峰会官网转载国家安全部微信公众号);Liu H, Shou C, Wen H, Chen Y, Fang RJ, Feng Y. (2026). Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain. arXiv:2604.08407. https://arxiv.org/abs/2604.08407