What is phishing?
Phishing tricks you into giving your credentials to an attacker, usually through a convincing copy of a login page reached from an email or message. It bypasses password strength entirely. A 32-character random password typed into a fake site is exposed as quickly as a weak one.
- Topic
- Attacks
- Reading time
- 1 min
- Reviewed
On this page
Why strong passwords do not help
Phishing does not guess your password; it asks you for it. This is why the security advice shifts here: check the domain before typing, use a password manager that refuses to autofill on the wrong domain, and prefer passkeys or hardware keys, which cryptographically verify the site's identity for you.
The autofill defence
A password manager's autofill is a quiet anti-phishing feature. It matches on the exact domain, so if it declines to fill a page that looks familiar, that hesitation is a signal worth trusting more than your own eyes.
Sources
These primary references support the terminology and current security guidance used in this definition.
