3 ms·
By now I assume that any service where I've registered for an account is being actively targeted and that any organisation that's not a Google, Microsoft or the
by korginator 5y ago
By now I assume that any service where I've registered for an account is being actively targeted and that any organisation that's not a Google, Microsoft or the likes has already been breached. MFA is your friend, and even plain vanilla SMS based MFA is better than just a username and password for authentication. I've enabled hardware based MFA anywhere it's supported.
15-20 years ago it was fun to sign up for dozens of new services and we reused passwords everywhere. Now every one of these accounts is a liability and a potential vector for bad things to happen. The worst case scenario is when an account of yours is breached and abused for a long time, possibly with legal and financial ramifications, and you don't find out until much later.
A couple of months ago I happened to glance at my Gmail's spam folder by chance, and one email way down the list immediately grabbed my attention. The subject line had *my password* for an old and unused account that I'd forgotten long back and the sender was trying to extort bitcoin if I wanted the account back.
The big issue is with online shopping. The sender has your name, address, email, phone number and possibly your CC number, a prime target for identity thieves.
- kevincox 5y ago> even plain vanilla SMS based MFA is better than just a username and password for authentication I'd be careful with this because a lot of services will allow you to reset your password with just SMS verification once they have your number. So while Password+SMS is stronger in practice this usually becomes Password+SMS OR Customer Support+SMS which is decidedly weaker.
- BlueTemplar 5y agoIt is very annoying how more and more shops force you to give a phone number... IMHO (unless product defect) only the transporter should get that !
- Avamander 5y agoTwitch (Authy), eBay and Amazon come to mind as the most annoying examples. My god just give me TOTP or stop pestering me for my number. eBay is so idiotic that it even asks for security questions. The 2000s called, they want their obsolete security back.
- stef25 5y agoAbout 10 years ago I found this feature of Gmail where you could see the login history, with lots of entries with IPs from China, the US and various other countries. That really drove the point home for me. Since then it's all unique passwords stored in Keepass. And it still doesn't feel 100% secure.
- mardifoufs 5y agoMy old outlook account receives log in attempt every ~5mins (!!) from all over the world. It's actually crazy that the attempts have not stopped after failing for so long, probably indicates it's from different attackers. The email has been on a couple of leaks but even then, the sheer amount of attempts is so crazy that I'd assume they are using a lot of password leaks that aren't publicly known yet.