Secure your Internet Accounts!

In my experience, avoidance, prevention and preparation are paramount for changing disaster to inconvenience when preparing for or dealing with having an Internet-based account hacked or taken over. What follows are my recommendations for Internet-based account security, in so far as the steps a user can take to safeguard an account:

1. Avoidance

  • The best way to avoid your account being hacked or taken over is to do everything in your power to prevent it in the first place.

2. Prevention

  1. Use unique, long, strong passwords consisting of random characters for every Internet-based account you have:
    1. Securely store all passwords in a manager to mitigate or eliminate many security threats.
  2. Activate 2FA for all Internet-based accounts (prevents most account take-over attacks):
    1. If an account doesn’t offer/support 2FA, consider seeking an alternative that does.
  3. Use passkeys where available:
    1. Store passkeys in your password vault:
      1. Allows access from multiple devices.
      2. Mitigates issues when adding/upgrading to a new device.
  4. NEVER share account passwords or other personally identifiable information with ANYONE:
    1. Includes long-term friends/family members!
    2. Exceptions exist:
      1. Medical, Insurance, and Government providers/services, etc.
  5. When collaboration or information sharing are desired or required:
    1. Consider self-hostable or Internet-based software/services:
      1. Whiteboards, cloud storage, self-hosted storage servers, etc.
    2. A group can share access to cloud storage, etc. with caveats:
      1. Access passwords MUST change when any member departs the group.
    3. See Avoidance (above) for additional recommended actions.

3. Preparation

  1. Backup everything that matters, or is irreplaceable:
    1. If it’s in fewer than three locations, it’s not backed up (3-2-1 rule):
      1. On your local drive for normal access.
      2. In an image stored on an external drive, or on locally hosted server storage (on your LAN).
      3. On storage hosted by a cloud service, preferably which offers true end-to-end encryption.
    2. Implement an automated backup regimen using the utility of your choice.
  2. Implement everything above to establish a well-rounded security paradigm.

Perfect security is impossible so it cannot exist under any circumstances, and particularly with respect to Internet-based accounts (email, cloud services. etc.). However, if you implement everything I’ve outlined here, the likelihood that any account you have will ever become compromised as the result of a failure on your part will be eliminated, and the likelihood that any account you have will ever become compromised at all will be as minimized as possible. That’s the best you can ever hope for in our world as it is today. Further, consider this my ‘I-told-you-so’ message if you fail to follow my recommendations, and you lose access to any account you currently have!

Ernie

Comments

Popular posts from this blog

How to - Enable/Set-up secure boot on Arch-based distributions

Common Debian App Commands With Descriptions

Completely remove OneDrive from your Windows computer/installation