[ad_1]
October is Cybersecurity Awareness Month and a good time to take down your online accounts.
Angela Lang / CNET
Cyber Security Awareness Month! One of the many made-up celebrations of October – there’s also Bat Appreciation Month and International Walk-to-School Month – the occasion is a necessary, if somewhat artificial, reminder to make sure you’re cybersmart.
Being cybersmart means setting strong and unique passwords for all of your online accounts, enabling two-factor authentication whenever possible, and doing your best to keep as much information as private, well, private.
Receive the CNET Now newsletter
Spice up your chat with the latest technology news, products and reviews. Delivered on weekdays.
If Cybersecurity Awareness Month asks you to revisit your cybersecurity, the party is worth celebrating. The sophistication and rate of automated password breaches, data breaches and phishing schemes continue to increase, says Guemmy Kim, Google’s director of security and account security.
“The reality is that passwords alone are no longer effective at protecting users,” he said in an email interview. Two-factor authentication is a must, he added.
Another important reason to check your cybersecurity: Many of your accounts are linked together, a fact hammered home by the massive outage that blocked Facebook, Instagram, and WhatsApp for a big chunk on Monday. Some people use Facebook to log into other apps and sites. If Facebook goes down, it can be difficult to get into those. There are also data privacy implications for linking accounts.
This means that you need to block those accounts and understand what other information is related to them. And, ideally, set up new apps and site logins that aren’t tied to a social media network.
To celebrate Cyber Security Awareness Month, here are some simple ways to protect your online accounts.
Use strong passwords
Passwords must be long, random, and unique. About 15 characters will protect you from most password cracking software. To make them easier to remember, you can use a passphrase of three unrelated words put together, such as “GrandmafootballCheeseburger” or “lamppostParisHotsauce”.
Avoid personal details that can be easily guessed. Your dog’s name, your first car model, or the university you graduated from may be important to you, but they are bad password material. Don’t launder your passwords and use them across multiple accounts, no matter how good you think they are. This way, you limit the fallout if one of your passwords gets compromised.
If this all sounds daunting, sign up for a password manager. It will keep all your logins organized and safe. Using the password generator and manager built into the browser is fine too. Although most browsers require you to log in to get the full list of saved passwords, individual passwords will be filled in automatically, depending on your browser.
Some of the options in the browser have been clunky in the past, but they’ve improved. For example, you can now use Google’s Chrome Browser to auto-fill passwords into apps on an iPhone. Chrome’s automatic password generation feature will work on iOS apps soon. Google says it will be similar to how Google AutoFill currently works on Android devices.
Always use 2FA when available
If your password is compromised, a second layer of protection will go a long way in protecting your account. Two-factor authentication, also called 2FA, multi-factor authentication, and two-step verification, requires someone trying to log into your account to enter a second form of identification before logging in.
2FA works in many different ways. It could be an app-generated code, biometrics like a fingerprint or Face ID, or a physical security key that you enter into your device. Yes, 2FA slows down the login process. But if 2FA is available, activating it is a must.
Google said earlier this year that it would initiate automatic user account registration in 2FA. On Tuesday it said it plans to add 150 million Google users to the 2FA ranks by the end of the year. It will take an additional 2 million YouTube users to activate 2FA within the same time frame.
To make things easier, the company has also integrated security keys into its Android devices. With this key creation, a user doesn’t have to think much about two-factor authentication and is therefore more likely to use it, says Kim.
“Ultimately, we want to bring our users to a place where authentication is seamless,” he said.
A word of warning: if you can, avoid 2FA systems that send a code to your smartphone. Why? SIM swapping, where cybercriminals steal your phone number by calling your wireless provider and having them transfer your number to a new phone and a new SIM card. It happens, and if the criminals take your phone number, they’ll get that text message too.
Avoid using social media as a universal login
Logging in with the Facebook, LinkedIn, or Google account you’re already logged into on your phone or computer can be incredibly easy.
This convenience, however, comes at a cost. As we saw earlier this week, if your login service goes down, like Facebook did, you may need to find a different way to log into your linked non-Facebook accounts.
In terms of security, it’s not a big leap to say that the Facebook and Google of the world probably have better security than that little game or app you’re trying to access, but there have been hacks. The more accounts you link to your Facebook or Google account, the more eggs you put in the proverbial basket.
The main sacrifice, however, comes in the form of privacy. Using the services of giant companies to access apps gives big people access to even more data, because they can see what the apps collect. Apps, in turn, can learn more about you by requesting access to things like your Facebook profile, friends list, or contact information.
While Facebook and other companies give you some control over the data apps can collect, it’s up to you to keep an eye on those requests and reject them when you don’t think they’re justified.
|
Sources 2/ https://www.cnet.com/tech/cybersecurity-awareness-month-time-for-a-cybersafety-check/ The mention sources can contact us to remove/changing this article |
[ad_2]