As of today, practice-makes-safe.org is open to the public, with its German version at übung-macht-sicher.de. This time it's about neither consulting nor a hobby, but about something that affects almost everyone: emails, text messages and warning pop-ups that look deceptively genuine and have just one aim — to get hold of money or login details. There are plenty of warnings about them. What was missing was a place to practise: calmly, without risk and without being embarrassed.
The site is a non-profit offering: no account, no advertising, no tracking, nothing to buy. It is meant for everyone who doesn't work with IT for a living — explicitly including older people, families and courses in which the topic is practised together.
Six stations, one course
You practise on simulated screens where nothing can actually happen. The course starts with what frightens people most: a warning pop-up that claims the computer has been locked and offers a phone number. Next come a simulated phone with texts and messenger messages (from the supposed parcel to “Hi Mum, new number”), the address duel over the bank's real address, and an inbox with ten emails — some genuine, some traps.
Every decision is explained straight away: how to recognise the trap, which trick lies behind it and what to do instead. Two stations do without a trap. “I clicked — what now?” is an emergency plan for the moment afterwards, without any finger-wagging. And “Asking AI for advice — with care” shows how to have an AI assess a suspicious message without trusting it blindly.
On top of that comes everything meant to turn an exercise into a habit: refreshers after a day, a week and a month, a practice record to print (explicitly not an exam and not a certificate), a class mode with a large display (it saves nothing) and a glossary that explains terms from “passkey” to “scareware” in everyday language.
Why practise — and why practice alone isn't enough
The idea rests on research that you can look up on the site, with sources. Doing beats reading: in a well-known study, people recognised fake websites better after 15 minutes with an anti-phishing game than after a tutorial. A large study with more than 19,500 employees, on the other hand, found that the usual training achieves little overall; those who had completed an interactive exercise later clicked on a phishing email about 19% less often — a relative effect that is small in absolute terms. And the effect fades over time, which is why refreshing helps.
That's why the exercises are short, every decision is explained straight away and the site says clearly what practice can't do: it makes nobody invulnerable. Where they are offered, passkeys help — on a fake site they simply don't work — and where they aren't, two-step verification does. Add to that a password manager, updates and the golden rule of calling back on a number you already know.
House rules: invented companies, reserved addresses
A practice site against fraud must not harm anyone itself. That's why all the companies in the exercises are invented — ParcelGull, Kestrelmoor Bank, CraneBasket — and were checked against trademark registers and a web search before publication. Every address ends in .example or .test, endings that are reserved for examples and can't belong to anyone. There are no real logos, no imitations of real companies' websites and no copied scam messages. Every number and every factual claim has a source and a date.
One rule mattered to me in particular while building it: the interface must not give the answer away. Fakes carry the same ending as their original, genuine and fake senders exist on both endings, and not every text message with a link is a trap. Anyone who passes a station should really be able to do it — not have guessed a pattern in the site.
And one more: what you practise is looking, not tapping. Where a link leads is shown by hovering over it with the mouse or by the “Show link target” button. Anyone who clicks anyway lands nowhere but gets a friendly note: in a real message, the page would now be open.
The thing about the ü
One detail shows how close the technology and the subject are. Unlike practice-makes-safe.org, the German address begins with an ü, a u with two dots (an umlaut). Web addresses may contain letters like this, but technically they are translated into a substitute spelling: übung-macht-sicher.de becomes xn--bung-macht-sicher-12b.de. Some programs display exactly this form — and then a genuine address suddenly looks foreign. Scammers use the same technique to disguise addresses with similar-looking letters. That's why the site writes its German address with “ue”, the usual way of spelling ü without the dots: anyone who types übung-macht-sicher.de ends up at uebung-macht-sicher.de.
Behind the scenes, the ü has a second story. Azure doesn't issue any of its otherwise free certificates for umlaut addresses — it only provides for letters, digits, hyphens and dots. So the certificate for the umlaut addresses comes from Let's Encrypt, issued on a dedicated server that stores it in an Azure Key Vault. From there, the App Service fetches every new version by itself, and a small watchdog checks every day what is actually being served.
Under the bonnet: deliberately simple
Technically, the site stands on the same foundation as the others in the family — Blazor on .NET 10 — and at present uses the simplest part of it: every page is fully rendered on the server, and the exercises run as lean JavaScript in the browser, building on the content the server delivers. Anyone who has switched JavaScript off gets a notice instead of a broken page.
A strict Content Security Policy — the rule that tells the browser which scripts it may run — allows only scripts from the site's own server, plus exactly one small inline script with a fixed checksum. The site's core rule exists twice: an address is read from the right, and what matters is the word directly before the ending. It is written once in C# for the texts from the server and once in JavaScript for the highlighting in the browser. More than 200 tests keep the two in step and at the same time watch over the house rules — for example, that every practice address sits on a reserved ending and that the numbers in the texts match the exercises.
Please pass it on
The site does the most good where nobody would go looking for it. Send it to your parents, grandparents or neighbours and play through a station together. Courses, schools, seniors' meetings and libraries may use and show the exercises free of charge in non-commercial educational settings, as long as the source is named — the details are on the page “In class and with family”. Found a mistake or have an idea for an exercise? Write to info@carecom.de.
And if you'd like to know how something like this could be built for your own project — lean, without tracking and with checked content: that's exactly what CARECOM Consulting is for.
Finally, something to pass on: a German-language A4 sheet introduces übung-macht-sicher.de together with its two pro bono sisters — its-all-right.org as a quiet place in the noise of the world, and lostcontext.ai for AI without hype and without panic. Three websites that sell nothing: download the flyer as a PDF (A4, 0.8 MB) — to print, pin up or send on.