How to help someone remotely without asking for their password

A guide for whoever ends up being the computer person: what never to ask for, what a healthy remote session looks like, and what to explain beforehand.

Sooner or later you become the computer person in the family or at work. And almost every time, the conversation starts the same way: "something is not working, can you have a look?"

That moment matters more than it seems, because the habits you set now teach the other person what normal looks like — and what they learn from you is what they will apply with the next person who calls.

The rule: never ask for the password.

You do not need it. If someone is sitting at the computer and can press a button, they can give you access without telling you any password at all.

Asking does three things, all of them bad. It teaches the person that handing over a password to someone "helping" is normal — which is precisely the scenario phone scammers rely on. It moves responsibility for anything that happens to that account onto you. And with a colleague, it may breach company policy outright.

If a password genuinely turns out to be needed during the session, they type it, not you. And if that happens often, it is a sign they need a password manager — not that you need their password.

What a healthy session looks like

Tell them beforehand what you are going to do. One sentence: "I will see your screen and move the mouse for a few minutes." Without it, the first cursor movement they did not make is alarming.

They approve the connection. The best protection is not a password, it is a person pressing Accept at a moment they were expecting to. If the session became possible through a code they read out to you over the phone, better still: that code is good for the moment, not forever.

They can see what you are doing, the whole time. Their screen stays on. Help that happens behind a blank screen is not help.

Tell them when you are done, and end the session yourself. Do not leave it open "just in case".

What to explain, once

Two minutes well spent, because it protects them next time — when the caller is someone else:

  • Nobody from the bank, the internet provider or "from Microsoft" calls out of the blue to ask for access to a computer. Real companies do not start that conversation.
  • Access is only given to someone they called, on a number they already knew.
  • If the caller is rushing or frightening them, that is the signal to stop, not to comply. Urgency is a scammer's main tool.
  • The password goes to nobody. Including you.

That last point is the one that counts most, and it is far more convincing if you have never asked for it yourself.

If you do this professionally

If this is work, those same principles turn into baseline requirements for whatever tool you pick:

  • Explicit consent on every connection, rather than a fixed password that travels by email and stays valid indefinitely.
  • Revocable access: if one of your devices is lost, or someone leaves the team, their access has to stop from one place.
  • Traffic encrypted between the two computers, not merely "encrypted as far as the server".
  • A record of sessions — who connected, when, for how long. Not to watch anyone, but so you can answer the question if it is ever asked.

Worth saying the other way round too: if your tool relies on one shared password handed to every client, you have built precisely the thing you warn them about.

The special case: nobody is there

Sometimes there genuinely is no one to press Accept — it is your own server, or your computer at home. Then consent moves earlier in time: you give it once, deliberately, authorising that specific device.

The difference from a password is that the authorisation is tied to the device rather than to a secret someone else could learn, and that you can withdraw it remotely at any point. Where several people share the same machines, who is allowed to start a connection becomes as important a question as what they connect with.

In short

Do not ask for the password, say what you are doing, let them approve it, close the session when you are done. Four simple habits — and the only ones that stop your help from quietly training someone to say yes the next time a caller is not helping at all.