Live data from Hacker News

Ask HN: Please critique my personal digital security strategy

news.ycombinator.com

11–20 of 23 posts

Re: Ask HN: Please critique my personal digital security strategy

#11
post #9

I always wonder what has higher risks: me, hosting my own mail, maybe getting hacked, or a gmail user, risking being locked out forever due to posting something inappropiate in a youtube comment.

Haha I hope you're not being serious. If I had to estimate the probability of Google ever blocking my account over my life time I'd say 0.01%, whereas the probability of someone successfully attacking my mail server/dns records/... if I really became a target would be easily 100%.

Re: Ask HN: Please critique my personal digital security strategy

#12
post #11
post #9

I always wonder what has higher risks: me, hosting my own mail, maybe getting hacked, or a gmail user, risking being locked out forever due to posting something inappropiate in a youtube comment.

Haha I hope you're not being serious. If I had to estimate the probability of Google ever blocking my account over my life time I'd say 0.01%, whereas the probability of someone successfully attacking my mail server/dns records/... if I really became a target would be easily 100%.

Oh, I'm completely serious. Random bots attacking my server, sure, but that's not what I meant, the real problem is targeted attacks and spearfishing. The difference is: I can move my domain, I can move my server to another system, build defenses, if needed, whereas who's gmail address gets blocked or reused (though this latter is more frequent with tumblr and instagram handles), there are no options.

Also, I wasn't asking for chances, but for risks.

Re: Ask HN: Please critique my personal digital security strategy

#13
post #5

And if (God forbid, because it could never happen) Google arbitrarily froze you out of your email account and you could not talk to a human at Google to remedy the situation . . . ?

Thanks for your reply. That is a possibility, I might be naive but I consider it on the very unlikely side. What I would imagine in that case is that I would reset the important other accounts such as the bank ones by showing up in some physical office with my passport, or something similar, while waiting to solve the situation with Google. What alternatives would you suggest? Spreading the accounts over different em…

You could set up for gmail with a custom domain. That way you get all of the benefits of hosting with google but if they decide to lock your account for some reason you have a back out strategy

Re: Ask HN: Please critique my personal digital security strategy

#14
post #12
post #11

Earlier quoted context omitted.

Haha I hope you're not being serious. If I had to estimate the probability of Google ever blocking my account over my life time I'd say 0.01%, whereas the probability of someone successfully attacking my mail server/dns records/... if I really became a target would be easily 100%.

Oh, I'm completely serious. Random bots attacking my server, sure, but that's not what I meant, the real problem is targeted attacks and spearfishing. The difference is: I can move my domain, I can move my server to another system, build defenses, if needed, whereas who's gmail address gets blocked or reused (though this latter is more frequent with tumblr and instagram handles), there are no options. Also, I wasn't…

[deleted]

Re: Ask HN: Please critique my personal digital security strategy

#15
Storing seed for 2FA on your phone (google authenticator) leaves you vulnerable to anyone who compromises your phone. If someone compromised your phone, your likely would not know they are generating the same 2FA codes as you do. To tackle this problem you could store your 2FA secrets on secure device (e.g. Yubikey NEO) and use phone as display.

Lastpass is cloud service and they had some issues in the past, I consider more offline/app approach for password manager as bit more secure alternative.

Re: Ask HN: Please critique my personal digital security strategy

#16
post #5

And if (God forbid, because it could never happen) Google arbitrarily froze you out of your email account and you could not talk to a human at Google to remedy the situation . . . ?

Thanks for your reply. That is a possibility, I might be naive but I consider it on the very unlikely side. What I would imagine in that case is that I would reset the important other accounts such as the bank ones by showing up in some physical office with my passport, or something similar, while waiting to solve the situation with Google. What alternatives would you suggest? Spreading the accounts over different em…

A simple alternative would be using an existing email address on a domain you own as a POP3 account within GMail. That way you get all the benefit of GMail without being dependent on it in case something at Google goes awry.

Re: Ask HN: Please critique my personal digital security strategy

#17
For your more critical passwords, enable the setting where lastpass prompts you to re-enter your master password. This ensures that:

1) you are less vulnerable to leaving your laptop unlocked.

2) you have to enter your master password frequently, preventing you from forgetting it.

Re: Ask HN: Please critique my personal digital security strategy

#18
post #9

I always wonder what has higher risks: me, hosting my own mail, maybe getting hacked, or a gmail user, risking being locked out forever due to posting something inappropiate in a youtube comment.

I'm all in with Google. All my business email and services are as a paying G-Suite customer. I have my business email pull in email from all my other non-biz accounts.

The experience as a paying Google customer seems to eliminate the oft-repeated complaints people have about Google. ¯\_(ツ)_/¯

I get technical support, with a real person, should I need it. (and I've needed it) The experience was fantastic. YMMV, of course.

I keep a backup copy of my email, off of Google infra, should any of the worst-case scenarios take place.

It's orthogonal to this discussion, but if I could do all of my coding from a Chromebook, the experience would be complete. I've had issues in the last 24 hours with both a Mac, and a Windows machine and it was Chromebook to the rescue. It just doesn't have the same level of functionality, as you already well know.

Re: Ask HN: Please critique my personal digital security strategy

#19
post #8

Just a word of caution on google Authenticator - the iOS version didn't seem to be maintained and it didn't have any sort of export or backup feature. I lost all my codes due to a factory reset of my phone. I've ever since (dec 2016) switched to using Authy for my codes.

Furthering this, I would use "Duo". It's such a better MFA app. It has lots of better usability features, and should you want they just added iOS back up.

By having just your one Gmail account you are making yourself vulnerable. Google does allow up to 99 character passwords, but still your laptop might be left open and things like that.

I would suggest starting to use email aliases such as those offered by 33mail or Blur which forward to Gmail. Basically instead of using the same username everywhere you now have say 10 or 20 usernames. A lot of people forget that usernames can be as effective as passwords, they in a sense are credentials to.

Also read any of the books by Michael Bazzell.

Also also going all the way here I would get a VPN service for your phone. Then I would go to FladhRouters.com and order a DD-WRT router and embed that VPN (easy to do) in the router, or even better another VPN service.

Re: Ask HN: Please critique my personal digital security strategy

#20
Overall you have a great security posture. I would not recommend using LastPass due to the service having a history of really bad security vulnerabilities. If you must use a cloud-based password manager, 1Password is the most secure choice, otherwise use KeePassX. As others have mentioned, less reliance on Google will do you some good. Look into using Duo MFA. Migrate high-security accounts like banking to a separate email account. Don't store credit card details with shopping sites. Disable Touch ID.
Post reply on HN