13 ms·
> 1. Have a really, really good password, and change it often. Even better, use a password manager. > 2. If possible, use a separate computer (an old one or a
by ploggingdev 10y ago
> 1. Have a really, really good password, and change it often.
Even better, use a password manager.
> 2. If possible, use a separate computer (an old one or a cheap one purchased for this purpose) for things like banking; if your family computer is the same one that you use for bank transactions you risk having your kids click on a bad link that results in a hacking.
Not necessary, use an up to date computer with Windows defender turned on and create a non-admin account for your kids.
> 4. Have antivirus software on your computer
Only use Windows defender, which is what the security community recommends.
Also use 2FA on all services which offer it.
Regarding the domain registrars, I would recommend Namecheap. They have a great support team and also offer 2FA, but I think it's only SMS based 2FA.
- brianmartinek 10y agoI really wish domain registers offered a Google Authenticator option for 2FA. All of the ones I have seen that offer 2FA are SMS based.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- ams6110 10y agoSMS is far better than nothing. Your average script kiddie is not going to be able to intercept your SMS messages. If you are specifically targeted by sophisticated attackers, maybe.
- seccess 10y agoMy biggest gripe with SMS 2FA is that it is prone to locking me out of my accounts on travel, if I suddenly need to log in to something and my phone number isn't the same abroad.
- deleted 10y ago[deleted]
- whyagaindavid 10y agois it such a pain taking a small burner phone? Alternately, you can install 2FA app in your smartphone. And if you traven that frequently you need to revisit your security choices. There is no security without any efforts from _you_. Google/MS/Apple can only do so much.
- CodeWriter23 10y agoThey'll just social engineer your carrier into the transfer of your phone number to a different SIM card
- whyagaindavid 10y agoIs it only me who is surprised that in the US no one has the notion of buying pre-paid SIM cards - which are unconnected to your SSN or credit card or bank account?
- jonas21 10y agohttps://www.name.com https://www.name.com lets you use Google Authenticator for 2FA.
- emusan 10y agohttps://www.gandi.net/ https://www.gandi.net/ does as well and has been pretty great in my (somewhat limited) experience.
- Curnee 10y agohttp://www.namecheap.com http://www.namecheap.com offers their own 2fa service, as well.
- bubblethink 10y agoYeah, that's the point. Everyone tries to re-invent 2FA or use SMS, both of which are bad for the end user. Even 2FA companies like Duo use some non-standard protocol which only their client can implement.
- sverige 10y agohttps://www.dynadot.com https://www.dynadot.com offers both Google 2fA and SMS, with a big push toward the Google solution. Dynadot has been a great all-around solution in my experience. Gandi is also excellent.
- Veratyr 10y agoOf my registrars, Namecheap does not but Gandi.net and Hover.com both offer the standard TOTP option.
- epc 10y agoPairNIC (https://pairnic.com https://pairnic.com) now offer TOTP 2FA (use Google Authenticator or whatever else you want).
- altano 10y agowww.nearlyfreespeech.net (mainly a host but you can register domains with them) offers Google Authenticator 2fa and control over what recovery options are allowed, including none, which is something I wish anyone that supports 2fa would offer.
- j_s 10y agoJust another happy customer giving those guys a big thumbs-up!
- orthecreedence 10y agoNFS also emails you if someone tries an incorrect password on your account. Kind of a nice feature.
- dvdhnt 10y agoname.com offers a choice between Google Authenticator and SMS for 2FA.
- pm24601 10y agositeground.com
- james_pm 10y agohover.com offers both SMS and TOTP (authenticator).
- samch 10y agoI use Google: https://domains.google.com https://domains.google.com
- vmp 10y agoIf only it were available in Germany. :(
- stevekemp 10y agoAmazon does ..
- meej 10y agoHover supports 2FA with authenticator apps.
- el_benhameen 10y agoIs there an industry favorite password manager these days? Every time I read something like this I re-commit to getting a manager, but then I can never decide on a product. I just want something that's secure and preferably non subscription-based.
- codegeek 10y agoI like keepassx. It just works and no need for any online account. You use a good master key/password and rest of the passwords, don't even remember.
- el_benhameen 10y agoHow do you personally handle passwords on multiple devices? Just host it somewhere publicly accessible and use a really strong master?
- dannysu 10y agoI use Tresorit (https://tresorit.com https://tresorit.com) to sync across machines and phones.
- Ajedi32 10y agoMy setup is to store the database itself in a cloud storage service that supports 2FA like Dropbox, and encrypt it with a file/password combo key. The key file I manually copy to every device I use, and the master password is stored in my head. This way it's safe to store the database in the cloud without having to worry about attackers trying to brute force my master password if Dropbox gets compromised (since they'd also need the key file, which is only stored locally), and even if the key file is stolen the attacker would still need my master password to access the database.
- defined 10y ago+1 for keepassx. I use it on all platforms (well, keepass droid too). All passwords are randomly generated except the one for the keepassx db (and that also needs the key file).
- desireco42 10y agoSee I was all for 2FA, but there were a number of high profile heists that actually used 2FA to gain control first of your mobile number, then email, then anything else they valued. Since mobile operators care even less then hosting companies, I am not sure having 2FA with sms code to be a good security practice. I do have yubikey keyfob but sites that are supporting it are very few unfortunately. Gmail being one, which is great.
- Avernar 10y agoMany don't consider mobile phone two-factor authentication as real two factor authentication. The reason being is that while the phone looks like "something you posess" it is really just an interface for another "something you know" which is your phone account information. As you said, this info can be compromized to intercept or take control of your SMS. Real 2FA uses a token generator device or an app like google authenticator which does the same thing. This is a real "something you possess" as it can't be compromized without getting access to the device.
- snakeanus 10y ago> > 4. Have antivirus software on your computer > Only use Windows defender, which is what the security community recommends. Just don't use windows.
- revmoo 10y ago> Not necessary, use an up to date computer with Windows defender turned on and create a non-admin account for your kids. You're a complete idiot
- whyagaindavid 10y agoThe article is sparse in details. Which email service did she use? did she get any phishing emails?