← All journal notes

06 / AI JOURNAL

Before you click: habits that make the internet safer

Check an unexpected message, protect your accounts, and approach unfamiliar AI tools with a little more care.

“Never click a link” is not a workable way to use the internet. A better habit is to pause when a message asks you to trust an unfamiliar page, share information, install something, or act urgently. These checks reduce risk without making ordinary browsing impossible.

Treat an unexpected request as something to verify

If a message says your account will close, a payment is overdue, or you must sign in immediately, avoid using its link to resolve the problem. Open the service through your usual app or a known address, then check there. Confirm unusual requests through a contact method you already trust.

A polished logo or convincing wording is not proof of identity. Phishing can arrive through email, texts, adverts, or calls and may try to obtain personal information or send you to a harmful website.

Sources & further readingNCSC: phishing scams

Make account protection part of the habit

Use passkeys where your service supports them. For accounts that still use passwords, use unique passwords and a password manager. Enable an additional sign-in factor where available, and keep account recovery options up to date.

Good account protection should support you even when a message is convincing. It should not depend entirely on spotting every scam.

Sources & further readingNCSC: passkeys NCSC: password managers and passkeys

Keep the things you browse with up to date

Enable automatic updates where possible for your operating system, browser, and document readers. Follow through when an update needs a restart, power, or more storage. These ordinary maintenance steps matter alongside careful clicking.

Sources & further readingNCSC: keeping devices and software up to date

My checklist for trying an unfamiliar AI tool

A repository link is a place to investigate a tool, not a guarantee that running it is safe. My starting checklist is:

  • Follow the project’s own documentation to identify the intended repository and installation source.
  • Read what access the tool wants. Start with sample files and the smallest permissions it needs.
  • Keep API keys, passwords, and confidential client material out of experiments and public issue reports.
  • Understand whether prompts or documents stay local or are sent to a hosted service.
  • For an agent that changes records or sends messages, keep a review step before actions with consequences.
Sources & further readingNCSC: what to do after phishing
07 / WHAT’S NEXT?

What could this make easier for you?

Bring the problem. We can work out which tools belong in the solution.

Discuss your idea ↗

Keep exploring

Open-source tools10 open-source building blocks for useful AIAI engineeringWhy a document assistant needs more than a chatbot
Chat on WhatsApp