Live data from Hacker News

Ask HN: Please critique my personal digital security strategy

news.ycombinator.com

1–10 of 23 posts

Ask HN: Please critique my personal digital security strategy

#1
Hi

After the latest events, I thought I'd share with HN what I do to protect myself from identity theft, and ask for suggestions. I'll try to be brief. The goal is to be in a sweet spot between convenience and security:

- Froze my credit on the 3 agencies

- My personal Google account is the central hub of my online identity: all accounts are hooked to my gmail, and I keep sensitive documents, including financial statements and contracts, on Google Drive. The Google password is complicated and as a MFA I have Google authenticator on my phone and printed backup codes. No recovery phone/email address set.

- I keep all my passwords in Lastpass. I really love the app and how well it works on mobile. As a MFA I have Google authenticator on my phone.

- My phone is secured with touch id and long pass code, and automatic data deletion after 10 failed attempts

- I use a lot of services, I just counted 430 online services. Each one ends up hooked to my gmail and a random password that I don't remember and store right away in Lastpass (including various bank accounts). Whenever available, I always enable the following MFA methods in order of preference:

* Google authenticator on my phone (e.g. Facebook)

* Email verification on my Google email (e.g. bank accounts)

* Text verification on my Google Voice number (e.g. bank accounts). I don't use my non-gv phone number because of how easy it is to trick call center operators into transferring the number away from a given SIM card. Seems very sad.

What do you think? It seems pretty secure to me. If I were to lose my phone, I'd recover Google via the backup codes, and all the other accounts via the google email.

Thanks!

Re: Ask HN: Please critique my personal digital security strategy

#5

And if (God forbid, because it could never happen) Google arbitrarily froze you out of your email account and you could not talk to a human at Google to remedy the situation . . . ?

Thanks for your reply.

That is a possibility, I might be naive but I consider it on the very unlikely side. What I would imagine in that case is that I would reset the important other accounts such as the bank ones by showing up in some physical office with my passport, or something similar, while waiting to solve the situation with Google.

What alternatives would you suggest? Spreading the accounts over different email addresses? Letting aside the privacy issue, to be honest I don't think there is another mail provider that I'd trust better than Google from a security point of view.

Re: Ask HN: Please critique my personal digital security strategy

#6
post #3

I've never used lastpass', but is there a way to backup your data? That seems like the biggest point of failure for me. I dislike purely hosted solutions for critical info because they become a bigger target as more people join.

Thanks for your reply.

Yes, with Lastpass you can export all your data to a csv that is generated at runtime using your master password. Although, to be honest, why would I need that? Assuming every important service in that list has some sort of MFA via Google authenticator/gmail/google voice number and a recovery option via the gmail address, what would a backup be useful for?

Essentially, the only passwords I really need to memorize in my head are the lastpass and google ones.

The biggest point of failure to me seems some bank account that I tried to recover in incognito mode which apparently just asks social security number plus some other idiotic information instead of relying on sending a recovery email. And there doesn't seem to be any way to change that, beside changing bank that is.

Re: Ask HN: Please critique my personal digital security strategy

#7
post #5

And if (God forbid, because it could never happen) Google arbitrarily froze you out of your email account and you could not talk to a human at Google to remedy the situation . . . ?

Thanks for your reply. That is a possibility, I might be naive but I consider it on the very unlikely side. What I would imagine in that case is that I would reset the important other accounts such as the bank ones by showing up in some physical office with my passport, or something similar, while waiting to solve the situation with Google. What alternatives would you suggest? Spreading the accounts over different em…

Yes I would hedge my bets.

I have seen businesses die because they only had one bank. You and I have both seen, from time to time, people complaining that something went wrong with a Google account with no apparent way to obtain recourse.

Always have a backup. And a contingency plan in case the backup plan fails.

I'm with you on LastPass. I am utterly reliant on it, and it bothers me greatly. I have hedged my bets a bit by backing things up with 1Password. But what a collosal pain in the ass that is. Friction leads to sloth, and sloth leads to system failure.

Re: Ask HN: Please critique my personal digital security strategy

#8
Just a word of caution on google Authenticator - the iOS version didn't seem to be maintained and it didn't have any sort of export or backup feature. I lost all my codes due to a factory reset of my phone. I've ever since (dec 2016) switched to using Authy for my codes.

Re: Ask HN: Please critique my personal digital security strategy

#10
post #8

Just a word of caution on google Authenticator - the iOS version didn't seem to be maintained and it didn't have any sort of export or backup feature. I lost all my codes due to a factory reset of my phone. I've ever since (dec 2016) switched to using Authy for my codes.

Oh wow that would be really bad (not catastrophic since again I could recover Google with backup codes and from there email recovery for the other accounts).

I heard good things about Authy but I've been a bit cautious to add yet another service (which sounds ironic considering the 430 accounts I originally mentioned) just for what it seems like a simple TOTP client, and I don't need any other fancy feature such as cross-device sharing because of the above mentioned recovery procedure always being available in extreme cases.

Plus I was under the assumption that Authenticator data was backed up via iOS backups or iOS keyring, but I admit I've never tried it so I'm just speculating.

Post reply on HN