I would also add another tip: create a separate email to use for financial accounts. Don't use this email for anything else.
Can you elaborate on why.
(Shops are regularly hacked with leak of email addresses and possibly compromising passwords.)
21–30 of 70 posts
I would also add another tip: create a separate email to use for financial accounts. Don't use this email for anything else.
Can you elaborate on why.
(Shops are regularly hacked with leak of email addresses and possibly compromising passwords.)
I am not 100% sold on one particular password manager. Any hints/suggestions?
I am not 100% sold on one particular password manager. Any hints/suggestions?
I am not 100% sold on one particular password manager. Any hints/suggestions?
Personally I like keepass. I don't love it, and it's UI could definitely use some work, but it suites my needs fairly well.
If you're being specifically targeted by a sufficiently capable adversary, this is, at best, a speed bump. Categorize your levels of paranoia appropriately.
If you do all these things, your resistance to even NSA-level incriminating evidence goes WAY down, and your vulnerability to local LEO and hackers goes to near-zero.
This is, at best, a brick wall, through which an adversary would have to bulldoze.
Isn't 2FA considered dangerous now? We've seen how susceptible it can be to social engineering. On a related note, I noticed that my Windows Phone displays text message notifications even when it's locked... So adding a PIN doesn't prevent an attacker from doing 2FA if they have access to my phone.
SMS 2FA isn't safe at least, and even NIST is deprecating it. The rest depends on dumb implementations, like Paypal allowing 2FA bypass with a change of the login link, or Google allowing 2FA bypass of all of its other methods by forcing you to use a phone number as "backup", which is to 2FA what secret questions were to passwords (their Achilles's heel).
However a secret question like "who did you have a crush on back in 5th grade" is limited to maybe 10 people the world who know and I'm comfortable with that (of course this changes with the over-publicising of our lives on social media).
But I'm digressing and agree TOTOP 2FA is great for the masses. Just be sure to have the backup codes stored in a safe space.
1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc.
2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconceptions. You don't even have control of your entire life, let alone ability to secure it. Most the data on you is owned by others and not even available to you to secure. The world is not private or secure. Everyone needs to know and think about this when they are tweeting, sexting, talking shit about future president and then being surprised when SS comes to investigate.
3) idea that security is either on/off, a binary, that you can be secure or not. Is False and leads to extremely poor security choices, over/under securing. Nothing is secure. There is not such thing as SECURE. Things lie on a gradient of security from easy to break to impractically difficult. Things on the impractical to break technically end are still broken due to social engineering, externalities (power consumption of cpu), poor practices surrounding item, etc. Security is making the effort required to get an item greater than the value of getting the item.
I am not 100% sold on one particular password manager. Any hints/suggestions?
The article is very slightly more nuanced but the conceptss the title purports is DANGEROUSLY INCOMPETENT for any security expert / discussion / context. 1) idea that security is something you check off and be done with is dangerously wrong. Security must be continuous, must be updated, reviewed, etc. 2) idea that you can "encrypt" [secure] your entire life is ludacris and leads to many dangerous security misconcepti…
I'm sure you means ludicrous and not https://en.wikipedia.org/wiki/Ludacris