How to protect your online accounts
Read the original in Spanish →
In an increasingly connected world, it is essential to protect our data and online accounts. From social networks to online banking, we all have valuable information that we must protect from cyberattacks. In this post, we share some tips and tricks to keep your data safe.
Tip 1: Forget your passwords
Many people use the same passwords on multiple sites, making them easy to memorize, but it is likely that these and the usernames are published and available for use in so-called “credential stuffing“. To find out if this is your case, you can use the service Have I Been Pwned and check if your email has been published.
The solution is to use a password manager, these allow you to have unique and secure keys for each of your accounts. In addition, they usually include other functions such as automatic generation of complex passwords, synchronization across devices, and alerting of possible password leaks. They also offer greater convenience by storing and managing passwords centrally. Finally, if you have heard something similar to “if they steal the manager, they will steal all my passwords”, that person is simply misinformed and does not know how these types of services work, which use strong encryption on all their records.
Some of the best managers are: 1Password, Dashlane, KeePass, Keeper or Bitwarden.
Tip 2: Use multi-factor authentication (MFA)
MFA adds an extra layer of security to your accounts. This means that in addition to entering a password, a code sent to your phone or an authenticator app is required to access your account.
The dilemma is how to ensure that this process does not also involve excessive hassle. In this sense, there are services that request authentication only when an access attempt occurs on a device other than those normally used. It is also usually faster to use the application than to wait to receive an SMS. The best solution is to try several providers and choose the one that best suits your needs. The best solutions include: Google Authenticator, Microsoft Authenticator, YubiKey, Lastpass Authenticator, Twilio Authy or FreeOTP.
As a last tip, remember to backup or export the tokens to a file. This backup will come in handy if you lose your phone or if the app stops working after an update.
Additionally, if you plan to implement a multi-factor authentication service in your organization, planning and asking yourself some questions is vital:
Does your organization’s authentication service support multiple identity providers?
If a provider is not available, is there a backup provider? How quickly can you change providers?
What is the disruption for users? Will it close current sessions or will it be continuous and take effect on the next login?
If MFA is configured, what are the options available? Are there multiple methods to verify the user and if one is removed, does the authentication service degrade?
Tip 3: Be alert to phishing and malware
Staying alert to phishing and malware is essential to protecting the security of your data and devices. Phishing is a deception technique in which attackers impersonate trusted companies or entities to obtain sensitive information, such as passwords or banking details. For its part, malware is malicious software that is installed on devices and can steal information, spy on online activities or damage files. To prevent these risks, it is important to not click on suspicious links, verify the authenticity of websites before entering confidential information, and keep security systems and programs up to date.
Tip 4: Protect your social media, email, and online banking accounts
In addition to following the tips above, it’s important to take specific steps to protect social media, email, and online banking accounts. This includes configuring the privacy of social media profiles, verifying the privacy of email accounts and directly ignoring any emails or SMS that impersonate our bank.
As long as we continue to have to use passwords, although they probably won’t have as much left, it is vital that, at the very least, we have the minimum culture necessary to use them.
Stay safe online!