Skip to main content

On Accounts and Passwords

I have some well-formed opinions on account security.  They have evolved over time as I have better understood the risks.  Unfortunately, I think the following list is good for all users everywhere.

The basic principle is to assume that nothing is secure.  Even if you keep your username and passwords secure doesn't mean that your bank, ISP, or Email provider keeps its systems secure.


Login Practices
  • Always check for proper HTTPS/SSL security.
  • Never use a link published in an email.
  • Use disposable accounts whenever possible.  Your account for your knitting forum shouldn't have any relationship to your account for your bank.
  • Only access sites with a good reputation, and a reputation that they need to uphold.

Password Practices

  • Never use the same password more than once.   If a hacker steals your password from DumbCo, you don't want that hacker to try that password at BigBucksBank.
  • Change your passwords.  People steal encrypted passwords.  Over time, they could crack those encrypted passwords.  By changing your passwords occasionally, you diminish that attack vector.
  • Use two-factor authentication whenever possible.
  • Never let anyone know your passwords.
  • Long and complicated passwords are better.
  • Avoid on-line account managers that result in a large store of passwords.
Email Practices
  • Keep your email accounts very secure.  If you can reset your passwords over email, then so can a bad person.
  • Use more than one email account.  Don't use the same email account for your knitting forum or Facebook that you use for your bank.
  • Never open or read junk mail.  Assume that it will infect your computer.
  • Never trust email from your friends.  Their accounts could have been compromised.
  • Avoid webmail services
Computer Practices
  • Minimize the number of devices you use.  The more devices you use, the more work is required to keep them secure and the higher the odds are that one of them is compromised.
  • Trust less trustworthy computers less.  Your home Windows XP machine is more vulnerable than your iPad.  Be more skeptical of less secure environments.
  • Never log in from an unknown machine.  That means you should never trust the computer in the hotel lobby, the computer at school, or even the computer at work.  Assume that there are keyloggers and screen-sharing technologies on each device you use.
  • Do not let others use or maintain your computer without strict oversight.
  • Use a quality browser that has anti-phishing capabilities.  Keep that browser up-to-date.  Avoid browser plugins.
  • Encrypt your computer's hard drive, and use a long and complicated password.
  • Put a password on your computer's login screen.  Do not let users share accounts.
  • Do not give day-to-day user accounts administrative privileges.
  • Shutdown your devices when not in use.
  • Scan for malware on all of your devices often.
  • Keep your software and OS up-to-date.
  • Do not install any software that hasn't been fully validated by a reputable party.
  • Be very hesitant in giving administrative rights to any software.
  • Back up your devices often, and keep control of your backups.  Keep your backups elsewhere (assume your neighborhood will burn down).
  • For encrypted files, use very long and complex passwords in order to minimize the odds that someone will be able to crack the file in years to come.
  • Use WPA2/AES security on your home WIFI network.  If your devices don't support WPA2/AES, upgrade your devices.

General Practices
  • Keep an off-line list of your accounts so you can easily take action if one account is compromised.
  • Watch over your account activity.
  • Be very concerned about account access issues or "odd behavior".
  • Remember that your network is compromised - your ISP, in combination with web site providers can access nearly all your network communications.
  • Do not trust the manufacturer of your home wireless router, handset, operating system, or third party software.  Again, all your data runs through these devices.
  • Never trust a 3rd party that can send you an email with your password within it.
  • Keep in tune with security vulnerabilities and compromises.


Popular posts from this blog

Fixing a SodaStream Jet, part 1: Disassembly Guide

I've had my SodaStream Jet for years, and once in a while something has gone wrong. Disassembly is the first step to repair.  Start with this article to see how to disassemble the SodaStream, and then once you have that down, scroll through my other articles to see how I repaired specfic SodaStream problems. SodaStream Jet Disassembly Guide Tools Required Flat head screwdriver Phillips head screwdriver 1. Remove the Carbonator.  Duh. 2. Remove the black panel lever The front big black tilt lever needs to be removed first. Removing this panel is tricky, but it isn't impossible. Looking up at the bottom of the black panel, there are two tabs, one on the left and one on the right. These tabs fully secure the panel in place. The trick is to use a flat-head screwdriver under the plastic to gently lever the tabs out of the way.  Note in the pictures how I approach these tabs with my screwdriver.  I usually release the left side first, and then I release ...

Sodastream Carbonator Leakage, Usage, and Weight

SodaStream 60L "Carbonator" CO2 cylinders have a specific weight when empty, plus about 410 or so grams for the CO2 they should have when they're "full".  A little while ago I went to buy a replacement Carbonator from my local hardware store. The dealer pulled a new Carbonator out of the box and sensed it was lighter than usual.  He put the "light" Carbonator in the "empty" pile and sold me a different one.  At that moment I concluded that it would be smart of me to weigh both new and empty SodaStream carbonators.  Here are the results. Weighing a SodaStream Carbonator - for both Science and Consumer Protection.       The dealer told me that sometimes the carbonators leak after they leave the SodaStream filling facility.  That means there could be an opportunity for customers like me to get ripped off! The SodaStream cylinders I buy claim to have a net product weight of 410 grams - and that means that a full Soda Stream Carbonator shou...

Fixing my Wahl 9918 Groomsman Beard and Mustache Trimmer

Not everyone would bother repairing a $25 beard trimmer, but why not fix something for under $5 instead of spending another $25? My  Wahl 9918 Groomsman Beard and Mustache Trimmer  has admirably performed its beauty duty for many years, but the time came when the battery just wasn't holding a charge any more.  Most people would just put the trimmer in the trash and buy a new one, but I figured I could repair my otherwise excellent Wahl and save some money. In fact, even high priced trimmer and rotary shaver brands, like Norelco and Remington, can be easily repaired using a process similar to the one I used to fix my Wahl.  Read on to find out how. I opened up the Wahl by popping off the black plastic faceplate with a tiny flathead screwdriver, which revealed two screws.  By removing the two screws I was able to easily open up the unit, revealing the guts of the device. Backplate off, Revealing the screws The internals are rather simple: a motor, a...

Repairing a MagSafe Charger's Cord

Here is how to repair the cord of Apple MacSafe power adapters. There are three common failure modes of a magsafe wire: The base of the cord becomes frayed where the wire enters the power brick.  This is usually caused by repeatedly wrapping the cord far too tightly around the brick's "ears". The head of the magsafe connector becomes frayed.  This is usually caused by repeatedly removing the magsafe magnet by yanking on the cord. Chewed up cord.  This is where a pet or other pinching device weakens the cord. These types of failure are usually repairable at home using the technique described here. Tools Required: A beginner's Soldering kit, like this one, including a low-wattage soldering iron, rosin-core Solder, and wire strippers. Heat shrink tubing .   Any color works, but these days I use white to repair a MagSafe cord. One Soldering Sleeve, appropriate for 22 or 24 AWG wire Heat gun (optional.) Process:   The general process is t...

MacBook: burnt out magsafe connector repair

My MacBook (A1342 model from 2009-2010) stopped working, thanks to a cheap knockoff magsafe charger. The magsafe connector looked burnt with heat-distorted melted plastic and some black carbon surfaces.  Plugging in the charger resulted in no lights and no action.  My MacBook was dead. First I tried to clean up the connector with some Q-Tips, tooth picks and solvent, but that did little, as seen in this "after" picture (below).   The heat generated by the aftermarket charger permanently deformed and distorted the MacBook's magsafe connector.  Clearly the damage was significant. Burnt Magsafe Connector - Replacement Required! Looking at iFixIt , I determined that it would not be difficult to replace only the magsafe connector with the right tools.  I hoped and prayed that the problem was isolated to the connector assembly and not the logic board. I bought a replacement magsafe connector assembly (available from Amazon) for under $20 and started to rep...

The Trick to Properly Fixing the Rubber Feet of a MacBook Pro

A black rubber foot of my trusty old MacBook Pro finally broke off, and I didn't like how it made the laptop wobbly.  A fix was needed, and quick! First I bought some replacement feet, the kind that just stick on.   These feet are nice because there is no need open up the machine to fix a broken foot.  They're very inexpensive, and the ones I bought have adhesive tape already applied - just peal and stick.  I bought feet like the ones found here. I have read many complaints about how the adhesive doesn't stick, but I think that's because people don't know the two tricks required to get the new feet to stick properly. New Feet to replace a lost Foot Important Trick 1: Make sure to remove all remnants of the old foot - including the pieces in the hole.   My factory-installed foot was attached both mechanically and with adhesive, but when the old foot sheared off, some pieces of the old foot remained in the hole.  Those plastic bits would h...

Other Posts

Show more