كلمات المرور والمصادقة الثنائية | Passwords & Two-Factor Authentication
تعلّم ببساطة، خطوة بخطوة
Learn simply, step by step
معلومة واضحة، ثم خطوة جديدة.
Clear knowledge, one step at a time.
كلمات المرور والمصادقة الثنائية Passwords & Two-Factor Authentication
لماذا تعتبر كلمات المرور مهمة؟
تُعد كلمات المرور والمصادقة الثنائية من أهم وسائل حماية الحسابات على الإنترنت. كلمة المرور هي خط الدفاع الأول، وإذا كانت ضعيفة أو مستخدمة في أكثر من حساب، فقد يصبح الوصول إلى حساباتك أسهل عند تسريبها أو سرقتها.
لذلك لا يكفي اختيار كلمة مرور يصعب تخمينها فقط، بل يجب أيضًا تجنب استخدام نفس كلمة المرور في عدة خدمات.
كيف تنشئ كلمة مرور قوية؟
- استخدم كلمة مرور طويلة: الطول يساعد على جعل كلمة المرور أصعب في التخمين أو الكسر.
- اجعلها فريدة: استخدم كلمة مرور مختلفة لكل حساب مهم.
- تجنب المعلومات الشخصية: مثل اسمك أو تاريخ ميلادك أو رقم هاتفك.
- لا تستخدم كلمات سهلة: تجنب الأنماط الشائعة وكلمات المرور البسيطة.
لماذا لا تستخدم نفس كلمة المرور؟
إذا استخدمت نفس كلمة المرور في عدة مواقع وتم تسريب بيانات أحد هذه المواقع، فقد يحاول المهاجم استخدام كلمة المرور نفسها للدخول إلى حساباتك الأخرى.
ولهذا يمكن أن يساعد مدير كلمات المرور في إنشاء كلمات مرور طويلة وفريدة وحفظها، بدل محاولة تذكر كلمة مرور مختلفة لكل حساب.
ما هي المصادقة الثنائية 2FA؟
المصادقة الثنائية أو Two-Factor Authentication (2FA) تضيف خطوة تحقق ثانية بعد كلمة المرور. فإذا حصل شخص على كلمة مرورك، سيظل بحاجة إلى عامل التحقق الإضافي للوصول إلى الحساب.
يمكن أن تكون الخطوة الثانية رمزًا من تطبيق مصادقة، أو مفتاح أمان، أو رمزًا يُرسل عبر رسالة نصية، حسب الخيارات التي توفرها الخدمة.
تطبيق المصادقة أم SMS؟
الرسائل النصية أفضل من عدم استخدام المصادقة الثنائية عندما تكون هي الخيار المتاح، لكن تطبيقات المصادقة أو مفاتيح الأمان يمكن أن توفر حماية أقوى عندما تدعمها الخدمة.
ومن المهم أيضًا الاحتفاظ برموز الاسترداد التي تقدمها بعض الخدمات في مكان آمن، حتى تستطيع استعادة الوصول إلى حسابك إذا فقدت جهاز المصادقة.
لا تشارك رموز التحقق
قد يحاول المحتال إقناعك بإرسال رمز 2FA بحجة تأكيد هويتك أو حماية حسابك. لا تشارك كلمة المرور أو رمز التحقق مع أي شخص، وتأكد دائمًا أنك تسجل الدخول من الموقع أو التطبيق الرسمي.
ولمزيد من الإرشادات حول حماية الحسابات، يمكنك الاطلاع على
إرشادات CISA حول كلمات المرور القوية.
ولمزيد من الأدلة والأدوات التي تساعدك على حماية حساباتك وبياناتك، يمكنك زيارة
مركز الأمان في TheCrypTechAI.
الخلاصة
تساعد كلمات المرور والمصادقة الثنائية على إضافة أكثر من طبقة لحماية حساباتك. استخدم كلمة مرور طويلة وفريدة لكل حساب مهم، وفعّل 2FA عندما تكون متاحة، ولا تشارك كلمات المرور أو رموز التحقق مع الآخرين.
Why Are Passwords Important?
Passwords and Two-Factor Authentication are among the most important ways to protect your online accounts. A password is your first line of defense, and if it is weak or reused across multiple accounts, your accounts may become easier to access if that password is leaked or stolen.
That is why choosing a password that is difficult to guess is not enough. You should also avoid using the same password for multiple services.
How Do You Create a Strong Password?
- Use a long password: Length helps make a password more difficult to guess or crack.
- Make it unique: Use a different password for each important account.
- Avoid personal information: Do not use details such as your name, birthday, or phone number.
- Avoid simple passwords: Stay away from common words and predictable patterns.
Why Should You Avoid Reusing Passwords?
If you use the same password on several websites and one of those services suffers a data breach, an attacker may try that password on your other accounts.
A password manager can help you create and store long, unique passwords so you do not have to remember a different password for every account.
What Is Two-Factor Authentication (2FA)?
Two-Factor Authentication (2FA) adds another verification step after your password. Even if someone obtains your password, they may still need the additional authentication factor to access your account.
Depending on the service, the second factor might be a code from an authenticator app, a security key, or a code sent by text message.
Authenticator App or SMS?
SMS verification is better than having no two-factor authentication when it is the available option. However, authenticator apps or security keys can provide stronger protection when supported by the service.
You should also store any recovery codes provided by the service in a safe place. These codes can help you regain access if you lose your authentication device.
Never Share Verification Codes
A scammer may try to convince you to provide a 2FA code by claiming that it is needed to verify your identity or protect your account. Never share your password or verification codes with another person, and always make sure you are signing in through the official website or app.
For additional guidance on protecting accounts, you can read
CISA's guidance on strong passwords.
For more guides and tools that can help you protect your accounts and personal data, visit the
TheCrypTechAI Security Center.
Key Takeaway
Passwords and Two-Factor Authentication provide multiple layers of protection for your accounts. Use a long and unique password for every important account, enable 2FA when available, and never share your passwords or verification codes with others.
اختبر فهمك
Check Your Understanding
سؤالان سريعان لتثبيت أهم ما تعلمته.
Two quick questions to reinforce the key ideas.