CBSE 2026 results are out, Mukul scored a perfect 100/100 in Computer ScienceSee all toppers →

KwickAcademy Computer Science · 7 min · free

Passwords, Privacy and Authentication

7 min4 KwickClipsFull text belowFree
Next lesson →Kajal Ma'am (MCA), teaching since 2004Remembered in this browser

Authentication proves you are you. A strong password is long and mixed, and two factor authentication adds a second kind of proof. Length beats clever tricks, because brute force tries millions of guesses per second.

Follows the syllabus of: CBSE Class 9 Computer Applications (165), CBSE Class 10 Computer Applications (165), ISC Class 11 Computer Science (868), GSEB Std 12 Computer Studies

On screen in this lesson

Authentication and privacy

Authentication: proving you are really you
A login with a password is authentication
Privacy: controlling who sees your information

Weak and strong passwords

PasswordStrength
password123Very weak
Riya2009Weak
Tr0p!cal#Mango7Strong
blue-kite-rice-lampStrong

What makes a password strong

Long: at least 12 characters
Mix of A-Z, a-z, 0-9 and symbols
No name, birthday or phone number
No common words or patterns like 1234
A different password for every account

Why length beats tricks

Programs try millions of guesses per second
Trying every combination is brute force
Each extra character multiplies the choices
Long passphrases resist guessing best

Password managers

An app that stores passwords in an encrypted vault
You remember only one master password
Creates strong random passwords
Fills them in only on the correct website

Password manager: pros and cons

ProsCons
Unique passwordsForgotten master
No reuseOne key to all
Spots fake sitesNeeds 2FA too

Quick answers

Why is a long passphrase strong?

Each extra character multiplies the number of guesses needed.

Is an SMS code or an authenticator app safer?

An authenticator app.

KwickClips from this lesson

Short clips, one idea each. Good for revision the night before.

The full lesson, in text

Hello students, welcome to Kwickprep. Is your password your name followed by one two three? A computer can guess that in less than a second. Today we will learn what makes a strong password and how password managers work. We will also learn two factor authentication and privacy settings.

First, two key words. Authentication means proving that you really are who you say you are. When you log in with a password, the website authenticates you. Privacy means controlling who can see your personal information. Passwords protect your accounts, and privacy settings protect your information.

Look at these passwords. Password one two three is one of the most common passwords in the world, so it is guessed first. Riya two zero zero nine uses a name and a birth year, which friends can easily guess. The third mixes capital letters, small letters, numbers and symbols. The fourth is a passphrase, four random words joined together, which is long and easy to remember.

So what makes a password strong? Length matters most, so use at least twelve characters. Mix capital letters, small letters, numbers and symbols. Do not use personal details such as your name, birthday or phone number. Do not use common words or patterns like one two three four. And use a different password for every account.

Why is length so powerful? Attackers use programs that try millions of guesses every second. This is called a brute force attack. Every extra character multiplies the number of possible passwords. A short password with symbols can still fall quickly. A long passphrase takes far longer to guess.

But how do you remember a different password for every account? You use a password manager. A password manager is an app that stores all your passwords in an encrypted vault, which means a locked and scrambled store. You remember only one strong master password. It can create strong random passwords for you. It also fills them in automatically, and only on the correct website.

Like every tool, a password manager has pros and cons. On the plus side, every account gets a unique strong password. It also helps against fake websites, because it will not fill a password on a look alike address. On the minus side, if you forget your master password, you may lose access to everything. And the master password itself must be very strong, with two factor authentication switched on.

Now, two factor authentication. There are three kinds of proof, called factors. Something you know, such as a password or pin. Something you have, such as your phone that receives an O T P. Something you are, such as your fingerprint or face. Two factor authentication means using two different kinds of proof together.

Here is how a login with two factor authentication works. First, you enter your username and password. The website checks, is the password wrong? If yes, access is denied. If not, it sends a one time password to your phone, or asks for an authenticator app code. It then checks the code. If the code matches, you are logged in.

Why is two factor authentication so useful? Even if a hacker steals your password, they still need your phone. Payment apps already use this idea, your phone plus your payment pin. Authenticator apps are safer than S M S codes, because S M S can be redirected by fraud. And never share the code with anyone who calls you.

Now, privacy settings on apps. When an app asks for permission, ask yourself, does it really need this? A torch app does not need your contacts or location. Set location to only while using the app, not always. Check your phone's settings every few months and remove permissions you do not need. Delete apps you no longer use.

Social media apps have their own privacy settings. Make your account private, so only approved followers see your posts. Control who can message you, tag you or find you by phone number. Hide your email, phone number and birthday from your profile. Turn off location on posts. And check which other apps are connected to your account.

Some exams ask you to describe a login check as an algorithm. Here is a simple version in pseudocode. The user inputs a password and then the code sent to the phone. The word and means both checks must be true. If the password matches the stored one and the code matches the sent one, it outputs Access granted. Otherwise it outputs Access denied.

Pause and predict. Which login is more secure? A password alone can be stolen by a fake website. A password with an S M S code is safer. A password with an authenticator app is safer still. A long passphrase with a security key is the strongest here, because a security key is a small device that fake websites cannot fool.

Let us revise what we learned today. A strong password is long, mixed and has no personal details. A password manager stores unique passwords behind one master password. Two factor authentication combines two kinds of proof, such as a password and a phone. Give apps only the permissions they need. And keep your social media accounts private.

Courses that teach this

CourseUnit
CBSE Class 9 Computer Applications (165)Cyber-safety
CBSE Class 10 Computer Applications (165)HTML
ISC Class 11 Computer Science (868)Social Context of Computing
GSEB Std 12 Computer StudiesWeb Page Creation with KompoZer
Edexcel GCSE GCSE Computer Science (1CP2)Topic 4: Networks

Voice-over in this lesson is AI-generated. The script is written and checked by Kajal Ma'am. Boards can revise a syllabus mid-year, so confirm anything you plan around against the official board circular. Keep your passwords, OTPs and ID numbers to yourself — we never ask for them. To reach Kajal Ma'am, use the WhatsApp button; sharing your number there is how we call you back.

Free to watch, no sign-up. Live classes with Kajal Ma'am are the paid course; these lessons stay free either way.

Want a plan that actually fits your board dates?

Ask Kajal Ma'am directly, 20+ years teaching computer science. Free demo class first, no payment.

Talk to Kajal Ma'am on WhatsApp

Or see the Class 12 Computer Science course →

Studying outside India?

We coach CBSE, IGCSE & international students across the globe, one-to-one, in your local time zone.

Visit International →