Online Account Security

As Internet becomes more widespread and essential to our daily life, websites/services can contain tons of our personal information and credentials. It is increasingly important to ensure all your online accounts are secured enough to prevent unwanted access.

Use Strong Passwords

Password is one of the simplest and oldest authentication methods in the world. It is the primary way to secure your accounts and information in the Internet. Therefore, using a strong password is the essential first step to improve the overall security. You should NEVER use easily-guessable words/phrases/numbers as the password, such as your own birthday or name. With widespread social profiles online, hackers can acquire those personal details and try accessing your accounts.

Rules to create a better password:
  • At least 8 to 10 characters. Longer passwords are stronger against brute-force attacks.
  • No common sequences or orders. For example, ABCDEFGH, 12345678
  • A mixture of uppercase and lowercase letters, numbers and symbols (special characters).

Do Not Reuse Passwords

It is not recommend to use identical password for every online account. This is a commonly-ignored problem for most people. According to a security survey by Google in 2019, about 65% of people reuse the same passwords on one or more accounts. If your password was hacked or leaked from one of your accounts, you will risk losing the rest of your other accounts and the crucial information inside them.

Use A Password Manager

Getting a password manager can be extremely useful for storing all the passwords from different online accounts. It can help save you a lot of time to remember and enter every single password. Some password manager applications also provide users a password generator to create more complex passwords with randomized symbols, numbers and capitalized letters.

Dashlane and LastPass are some of the reputable offerings in the market, but we personally use Enpass, since it stores all the password data offline without uploading to the company’s servers.

Activate Two-Factor Authentication If Available

Password is the so-called single-factor authentication method, whoever knows your password will be able to access the accounts. There is only one way to verify your identity, in this case the password (something you know).

Two-factor authentication (2FA) adds an additional layer of protection to the process with either something you have (smartphone or security device) or something you are (fingerprint or face). With 2FA enabled, both the password and your chosen secondary code/biometric are required simultaneously to login to the accounts. Nowadays, most websites and services will offer users the options to use their smartphone authentication app, SMS messages and emails for 2FA.

It is recommended to use a 2FA app like Google Authenticator and Microsoft Authenticator, if possible. It will continuously generate a new code every 30 seconds with the Time-based One-Time Password (TOTP) protocol. Receiving 2FA’s one-time code via SMS and emails is less secure, as they are relatively easy for hackers to intercept the messages by malware or SIM-swap fraud.

Use Virtual Private Network (VPN) If Necessary

It is not advised to access any of your websites/services, especially online banking, when connecting to a public/free Wi-Fi hotspot. Hackers may be able to steal your sensitive information, like bank accounts and credit card credentials, by packet sniffing or injecting virus. If you really have to login to those services quickly, you should use a VPN to encrypt the data for better security. We recommend Surfshark VPN, because of its comprehensive features and affordable pricing.

