Online Account Security

Online Account Security

 

It is 6 am and the alarm on your phone is blaring.  Like most mornings, you shut off your alarm and quickly scan through your emails and messages for anything critical or interesting.  It looks to be mostly standard fare until one email pokes its head out at you and wakes you up a bit more.  An email indicating your password has been changed on one of your accounts.  Most likely some type of fishing email, you take a quick gander at the email headers and start to get a sinking feeling as it looks legit.  Your heart racing a little now, you ignore the email and log directly into the account, except you can’t, your login fails.  With increasing clarity, you try again hoping it was a typo, it wasn’t ……

This is a scenario similar to many that plays out throughout the world every day.  In many cases, depending on the online account and settings, there may be no email alert, just somebody lurking on your accounts gathering information to compromise other people you may know.   Or perhaps a complete lockout, whereby all details are changed so that you are unable to recover your account.  These types of attacks are becoming more sophisticated every day.  Luckily, there are good habits and tools you can use to help secure your online presence.  I will review some of the tried and true methods as well as some emerging technologies in account protection.

Tried and True:

  • Do not use the same password on more than one site. Every site should have its own unique password.
  • Passwords should generally be at minimum 8 characters or more, include numbers, letters, uppercase, lowercase and symbols. Not all sites will allow symbols but use where you can.
  • If possible each site should have a separate username. I know many sites simply use an email address as a login and not everybody has the ability to generate a different email for each site.  But use where available.
  • Passwords should not be based on words. Random sequences are much more difficult for hackers to crack.
  • Use two-factor authentication where available. This type of authentication will require your password plus an additional code which changes frequently, usually once per minute or less.  This code may be provided as a OTP (One Time Password or Pin) sent via email, text, or phone call.  These codes can also be provided by mobile apps such as Google Authenticator or Microsoft Authenticator which are setup by scanning a QR code which then allows the app to generate a new single use password every 60 seconds for that particular account.
  • Ensure your mobile device is secured with your fingerprint or a very difficult to guess password.
  • Most sites offer security questions and answers to be used in the event of needing to recover your password. Don’t use easily guessed questions and answers.  You don’t even necessarily need to answer the question asked as long as you remember the answer you provided.

Additional tools and suggestions:

  • Get a good Password Manager or Vault. There are many available, with some examples being LastPass, Norton Identity Safe, Roboform, KeePass.
  • If using an online password vault, ensure it has a good track record of security and also has the ability to utilize two-factor authentication.
  • Also, for online password vaults, use a recovery method other than your normal email address or mobile device. Establish a good, secure email address which you use only for these recovery operations, if possible.  This way if your main email becomes compromised you can still recover your accounts
  • For sites that use email addresses, if you utilize Gmail you can simply add an extra “.” anywhere in the email address for your login username.  Gmail will recognize your email address whether you type my.email@gmail.com or myemail@gmail.com .  It does, however, make a difference with the site login as most sites would see these as two different usernames.  Obviously this won’t stop a determined hacker, but it will help with the casual hacker that has obtained a username and password and tries the combination on numerous popular sites.

There are some new and emerging technologies which are targeting making standard logins a thing of the past or simplifying current security methods.  One such technology, released with the Iphone X is called FaceID.  This will allows you to unlock your mobile device using a scan of your face, vs. passwords or fingerprints.  Though I would imagine in the future this could also be used as an additional requirement for unlocking your mobile device by requiring both a fingerprint and a face scan.  IN the case of the Iphone, however, they did away with finger print scans when they released FaceID, but other vendors may offer both.

Google has been working on Project Abacus which utilizes a combination of items such as typing patterns, walking patterns, location, facial recognition and many others to create a “Trust Score” which is then used to authenticate a user to an application.

Many newer Android devices running also already employ a feature known as “Smart Lock” which allows you to unlock your device when connected to a trusted Bluetooth device, wifi network or via a specific GPS location.

There was an emerging technology from Germany in the works named SkullConduct whereby the vibration signature of your skull caused by an ultrasonic wave can be used as a means of authentication as it is possible that these vibrations may be as individual as a fingerprint, though this technology is in the very early stages, I haven’t seen much information on it recently.

Another new technology which was originally developed at the Institute of Information Security ETH Zurich is called “Sound-Proof”. The second factor of two-factor authentication is provided by matching the ambient sounds detected from your mobile device and from your computer to ensure they are both in the same location.  This software is now available via https://futurae.com/.

Online security threats are very real and it is important to take some simple measures to help prevent your accounts from becoming compromised.  These methods and habits can sometimes be time consuming and confusing but are worth the effort to secure your online identity and accounts.  Luckily, researchers are working hard to develop better and easier to employ methods to help make your online security not only keep up with the ever evolving hacker community but maybe even take a step or two ahead of them.