Tech We Like All articles
Apps & Software

We Hired Ethical Hackers to Break Our Best Security Habits — Here's What Fell Apart Instantly

Tech We Like
We Hired Ethical Hackers to Break Our Best Security Habits — Here's What Fell Apart Instantly

There's a particular flavor of embarrassment that comes from watching a security professional crack something you genuinely believed was bulletproof. It happens fast. Faster than you'd expect. And it happened to us — repeatedly — over the course of a two-day testing session with a small team of ethical hackers we brought in to stress-test the security practices our readers swear by.

This wasn't a theoretical exercise. We collected the most popular password and authentication habits from our community, set up real accounts across real services, and let the pros go to work. No kid gloves. No warnings. Just realistic attack scenarios against the methods people actually rely on to protect their digital lives.

Some of the results were genuinely reassuring. A few were deeply uncomfortable. Here's everything we found.

How We Set This Up

We partnered with two certified ethical hackers — both with backgrounds in penetration testing for financial institutions — and gave them a list of ten security practices submitted by Tech We Like readers. For each method, we created fresh accounts on popular platforms (email, banking simulators, social media), implemented the practice exactly as the reader described it, and let the team attempt a realistic breach.

The attack methods they used weren't exotic. Credential stuffing, phishing simulations, SIM swapping attempts, brute force on offline hash files, and social engineering calls to mock customer support lines. The kind of stuff that's already happening to real people, right now, across the country.

The Practices That Basically Rolled Over

Complex passwords without a manager. A shocking number of people still manually construct passwords they think are clever — things like C0ff33!Mug#2024 — and reuse variations of them. Our hackers cracked this category fastest. Once they had a single leaked hash from a data breach database (which they pulled from publicly available breach dumps in about four minutes), pattern-matching tools identified the formula behind the password and generated likely variants for other accounts. If you're hand-crafting passwords with substitutions and think you're outsmarting anyone, you're not.

Security questions as a backup. We knew this one was shaky going in, but the speed was still jarring. "What's your mother's maiden name?" and "What city were you born in?" were answered correctly for our test accounts using a combination of LinkedIn, Facebook, and a single five-minute Google search. Security questions are essentially public information dressed up as secrets. Treat them like passwords — generate random nonsense answers and store them in your manager.

SMS-based two-factor authentication. This one stings because so many people feel safe with it. Our team demonstrated a SIM swap scenario — calling a carrier's support line pretending to be the account holder — and while they didn't complete an actual swap (that would be illegal even in testing), they got alarmingly far through the verification process with only publicly available personal details. SMS 2FA is meaningfully better than nothing, but it has a real ceiling.

The Practices That Actually Held Up

Passphrases — done right. There's a difference between a passphrase and a long password. A proper passphrase is four or more completely random, unrelated words: something like umbrella-fossil-carnival-dune. No substitutions, no predictable structure. Our hackers confirmed these are genuinely hard to crack at scale. The catch? Most people don't generate them randomly — they pick words that feel random but are actually thematically connected, which dramatically shrinks the search space. Use a passphrase generator, not your own brain.

Hardware security keys. This was the standout performer of the entire test. We used a FIDO2-compatible physical key on two accounts, and our hackers hit a wall every single time. Phishing pages can't capture the cryptographic handshake a hardware key performs. There's no SMS code to intercept, no backup email to compromise. The authentication is tied to the physical device and the specific domain it's registered to, so even a pixel-perfect phishing site gets nothing useful. Yes, you have to carry a small USB or NFC dongle. Yes, it's worth it — especially for your most critical accounts.

App-based authenticators with proper backup codes stored offline. Google Authenticator, Authy, and similar TOTP apps gave our team a meaningful fight. They're not unbreakable — a real-time phishing attack that captures the code the moment you enter it can still work — but they eliminated the SIM swap vulnerability entirely and significantly raised the cost of an attack. The key detail our hackers emphasized: your backup codes need to be stored somewhere genuinely offline. A printed sheet in a drawer beats a screenshot in your camera roll every single time.

Biometrics as a second factor (not a first). Fingerprint and face unlock got a mixed review. As a standalone login method, they're more vulnerable than people realize — not to spoofing necessarily, but to legal compulsion (you can be required to unlock a device with your face; you generally can't be forced to reveal a memorized password). But as the second factor in a layered setup, they're solid. The friction they add to account access without requiring you to type anything makes them genuinely useful in a multi-layer stack.

The One Practice Nobody Submitted That Our Hackers Kept Recommending

Passkeys. Almost no reader mentioned them, which tracks — they're still rolling out across platforms and the UX is inconsistent enough that most people haven't adopted them yet. But every single one of our ethical hackers brought them up unprompted. Passkeys are phishing-resistant by design, they don't require you to remember anything, and the big platforms — Apple, Google, Microsoft — are all pushing hard on adoption. If you haven't set up a passkey for your Google or Apple account yet, that's the single most impactful thing you can do this week.

The Bottom Line

Security isn't about finding one magic practice and calling it done. What our testing made obvious is that layering matters — a hardware key plus a password manager plus a passphrase-based master password is a genuinely different threat landscape than any one of those things alone.

The stuff that failed did so because it created an illusion of security without the substance. SMS codes feel like protection. Clever passwords feel unguessable. Security questions feel private. None of those feelings survive contact with someone who actually knows what they're doing.

The good news: the practices that worked aren't hard to implement. A $30 hardware key and ten minutes setting up an authenticator app will put you ahead of the vast majority of targets, which is ultimately how this math works. Attackers go for the easiest path. Make yourself the harder one.

All Articles

Related Articles

I Downloaded 9 AI Companion Apps So You Don't Have to Feel Weird About It Later

I Downloaded 9 AI Companion Apps So You Don't Have to Feel Weird About It Later

My Phone Was Winning. Here's the Weird Combo That Finally Flipped the Score.

My Phone Was Winning. Here's the Weird Combo That Finally Flipped the Score.

AI Video Generators Promised to Replace My Entire Production Team — Here's the Ugly Truth

AI Video Generators Promised to Replace My Entire Production Team — Here's the Ugly Truth