The goal is not for a child to memorize security vocabulary; it is for them to know what to do when creating an account or seeing an unexpected login prompt.
01
Protect the account, not just the phone
A screen lock protects a device in someone’s hand, while account security protects messages, photos, purchases, and identity if a password is guessed or reused. Explain that a password belongs only in the real app or site and that a code sent by text or an authenticator should never be handed to someone who asks for it.
02
Set up three habits together
Use unique passwords stored in a reputable password manager where appropriate, turn on multifactor authentication, and keep recovery information with the parent or caregiver who will actually help. Passkeys can reduce password reuse when a service supports them, but the child still needs to recognize a fake sign-in page.
- ✓Unique Do not reuse the same password across games, school, and messaging.
- ✓Second step Use MFA or a passkey and never share one-time codes.
- ✓Recovery Know which trusted adult and verified route will help regain access.
03
Keep the conversation open
Create one account together and narrate the decisions. Then ask the child to teach the process back to you. The explanation does not need to be technical; it should show that they know when to slow down.
What would make a login screen or code request feel suspicious?
04
Where the phone setup helps—and stops
ChildPhone can limit which apps are available and help keep the device updated, but it does not replace account security. A permitted app can still contain a stolen account, a reused password, or a convincing phishing prompt.
Sources and further reading
Primary guidance and platform documentation reviewed for this article.