Showing posts with label password security. Show all posts
Showing posts with label password security. Show all posts

Friday, June 27, 2014

Here are five tips to protect your identity online.

1. Change passwords once a month. Passwords are the keys into your life. If a criminal gets access to your email or any of your online accounts, it's surprisingly easy for them to worm their way into other aspects of your life.

Assume your passwords will periodically get compromised. Adobe, AOL, eBay, Kickstarter and Yahoo have all had major security glitches in the past few months.

2. Give the wrong contact information at checkout. Recent data breaches, like last year's Target hack, show that companies aren't responsible enough to safeguard that information. Every time a store clerk asks for your zip code or phone number, that data gets aggregated. So retailers not only have databases that show where you live. They can find out much more about you, like your salary, credit history and birthday.

3. Need photo ID? Don't show your driver's license. This is a general rule for privacy. Don't reveal more than you have to. A driver's license shows your birthday and address.

Next time your doctor's office asks for identification with a photo, show them something else, like your office building badge.

4. No banking apps. Be particularly careful about access to your bank accounts. Although most credit cards have fraud protection, your checking and savings accounts don't.

Because of how easy it is for a computer to get infected with a malware that spies on you, we don't recommend shopping and banking on the same computer.

5. Keep one email account for junk mail only. When companies demand an email address, give them a dummy address. That way you don't have to be bothered with all the spam and annoying advertisements; and it shields your real email from junk. Plus, if those companies get hacked, your real account remains safe.

Wednesday, August 7, 2013

Do you save passwords in Google Chrome? Maybe you should reconsider...

You might want to think twice before you let someone borrow your computer.

The most obvious risk of allowing someone else access to your desktop is that they can impersonate you, using any app where you’re already signed in. They could send prank messages using your default email client, or profess your undying love for Justin Bieber using your logged-in Twitter account.

That’s annoying, but far from fatal.

But the situation becomes considerably worse if you use Google Chrome to save and sync passwords for easy logins at your favorite websites. An intruder who has unrestricted access to your computer for even a minute can view and copy all of your saved passwords just by visiting an easy-to-remember settings page: chrome://settings/passwords.

That link opens the local copy of your saved password cache, which is synchronized to every machine where you sign in with your Google account.

And the funny thing is, anyone who visits that page can see the plaintext version of every saved password just by clicking a button.

The saved password list shows the web address, username, and password for each saved set of credentials. Initially, the saved password is displayed as a row of asterisks. But if you click the masked password, you see a “Show” button that you can click to immediately display the saved password.

A malicious or spiteful intruder who can lure you away from your computer briefly can see your saved passwords, then close the settings page. And you have no idea that your credentials have been compromised.

Source: ZD Net