4 ms·
Most "non-tech" people have a reasonably small attack surface, so my approach has been to try and milk the Pareto principle: Here are some things I've found wh
by secretsinger 9y ago
Most "non-tech" people have a reasonably small attack surface, so my approach has been to try and milk the Pareto principle:
Here are some things I've found which are simple enough to implement but actually offer substantial gains. Learned mainly from helping partners and parents:
1. Move them to Gmail. Email seems to still be the primary vector for most attacks and Gmail's filters are awesome.
2. Get them on a less permissive OS. Shifting from Windows to OSX/iOS has made a huge difference.
3. Teach them a reasonable password-generating method (correct-horse-battery-staple or some such). They are gonna forget and reset passwords regularly, which is OK. I gave up on getting them to habitually use a password manager.
4. Force (coerce/bribe/cajole) them to use 2FA on critical accounts (email, FB)
5. Tell them lots of anecdotes about hacks, things I spotted in my email, etc. As someone else pointed out, you can work in a lot of useful info in a memorable way in these anecdotes.
Tech does seem to be only part of the solution (and probably not even the major part). I've been doing some gig work for a company [http://www.popcorntraining.com http://www.popcorntraining.com] that does story-based security awareness videos, mainly for corporates. They have pretty good results based on fairly small time investment by the participants.
Sadly, most of the players in this market seem to be focused on big companies at the moment, with a few starting to aim at SMEs. We've bounced around the idea of trying to help the consumer market, but its not yet been worthwhile for them.