Glossary

Digital Security Glossary

Plain-language definitions of common account, authentication, threat, recovery and security terms.

Authenticator

A password, passkey, security key, one-time code or other mechanism used to prove control of an account.

Backup code

A single-use recovery code provided when MFA is configured.

Credential stuffing

Automated attempts to use leaked username-and-password pairs on other services.

Encryption

A process that transforms readable data into protected form using a key.

Hashing

A one-way transformation used for tasks such as password verification and integrity checking.

MFA

Multi-factor authentication: sign-in using more than one factor or a multi-factor authenticator.

Passkey

A public-key credential used to sign in without sending a reusable password to the service.

Phishing

A deceptive attempt to make someone reveal information or approve an action through an impostor message or site.

Ransomware

Malware that disrupts access to data or systems and demands payment or another action.

Recovery method

A phone number, email, trusted device, backup code or process used to regain account access.

SIM swap

A takeover of a phone number by moving it to another SIM or eSIM.

Security key

A physical cryptographic authenticator, often using FIDO/WebAuthn standards.

Session

A period during which an account remains signed in after authentication.

Spoofing

Falsifying an identity signal such as a sender address, caller ID or website appearance.

Vulnerability

A weakness that could be exploited to affect confidentiality, integrity or availability.

Zero trust

A security approach that avoids assuming trust solely because a user or device is inside a network.