2. Accounts and Identity

2.1 Authentication (passwords, MFA, passkeys, biometrics)

Core Concepts: Protect Yourself, Protect Your Data

When you log into a computer or website with a User ID and password, you are authenticating; proving you are who you claim to be. Get this topic right and you block 90% of account compromises.

2.1.1 Understanding Authentication

Authentication answers the question "who are you?" A User ID is your unique identifier (often an email address). A password is a single verification factor paired with your User ID. Together, they prove you're the legitimate owner of an account.

2.1.2 The Basics

Use a Password Manager

A password manager stores all your login credentials, auto-fills them when you need them, and can generate secure, random passwords for each account. This means you only need to remember one password, the master password for your password manager, or vault.

Why use a password manager?

NEVER use your browser's built-in password storage. While modern browser password managers have improved, dedicated password managers offer superior security features including cross-platform sync, security audits, secure sharing, and breach monitoring. Browser-based storage also creates a single point of failure if your browser is compromised.

Important: DO NOT FORGET YOUR MASTER PASSWORD! You can share this with a friend or family member who can store it in their vault in case you forget. If you use a password manager which offers account recovery, set it up and carefully protect the recovery information.

Recommended: Bitwarden (https://bitwarden.com/). It's web-based so you can access it anywhere, has browser plugins, mobile apps, and offers both free and premium service. It includes all the features mentioned above.

If you want, you can use my self-hosted Bitwarden service at https://pass.landisfam.org. This offers the same protections as Bitwarden’s official service, but less likely to be targeted by attackers. However, I still cannot recover your account if you forget your master password.

Once enrolled, install the applications in your browsers and on your mobile devices. Enable auto-fill, and start populating your vault by logging into each email, financial, and health related accounts, since those contain your most sensitive information. When doing this, I recommend you reset each password, most password managers have a password generator, and secure them in your password manager. If you use a browser extension, most password managers prompt you to automatically add information for websites not already in the vault.

While going through this process, I also recommend you go through each site’s security settings. Review your security questions (see that topic below) and force logout of all devices. Note that afterward you will have to log in again on all devices.

Create Strong Passwords

Passwords that are easy to remember tend to be easy to guess. The solution is to make them long, using a phrase you can remember, but would take an attacker a very long time to guess or to use brute-force methods to crack your account. Follow this link and experiment with different passwords: https://www.security.org/how-secure-is-my-password/

How to Create a Strong Password:

There is an adage in Bridge (a card game for old people), “length over strength.” A long, simple password is more secure than a short, complex password. Think of a line from your favorite song, poem, or quote. Take a few words from that line, capitalize some letters, mix in numbers, and add a special character or two.

Example: From Robert Frost's "The Road Not Taken":

Email accounts deserve the highest level of protection. When you forget a password, most sites send a reset link to your email. This means if someone gains access to your email, they can potentially reset passwords for all your other accounts. I recommend 16+ characters for email passwords.

Account Type

Password Length

Password Manager

20+ characters

Email

16+ characters

Everything else

12+

Of course, if you use a password vault, you can have the best of all words, and use unique, 20+ character, complex passwords for all your accounts without ever having to worry about forgetting them. Again, just make sure the password for your password manager is also strong, and have a recovery method in case you do forget it.

Never Reuse Passwords

Use a unique password for every account. If one site gets breached, attackers will try that password on other popular sites. Reused passwords mean one breach potentially compromises all other accounts which use that same password. Your password manager, once populated, can verify that all your accounts have unique credentials.

Handle Security Questions Carefully

Security questions are a weak way to verify your identity. The answers are often public information or easy to find through social media. When forced to use them:

Your password manager likely has a “notes” section for each item in your vault, or a separate “notes” folder. You can put your security questions in one of those.

Set Up a Recovery Email

Create a secondary email account to use as a recovery address for your primary email. If you can't access your main email, you can use the recovery email to regain access to your primary email account. Keep this secondary email account highly protected too, and only use it as a recovery account; do not use it for any other purpose.

Enable Login Alerts

Turn on notifications for new logins. Most services offer this. When enabled, you'll get an email or text when someone logs into your account from a new device or location. If it wasn't you, you'll know immediately. You can typically fine this option in security settings.

2.1.3 Better Protection

Expand Password Manager Use

Once you have your critical applications vaulted (email, financial, and health-related accounts), you’ll want to go back and begin adding other important sites and applications like cloud storage (Google drive, iGloud, OneDrive, Dropbox), social media, and shopping accounts. Follow the same process to change the password using the password manager’s password generator, forcing logout of active logins, and updating security questions.

Enable Multi-Factor Authentication (MFA)

MFA adds a second step to logging in; usually a code sent to your phone or generated by an authenticator application. If you use MFA, even if someone steals your password, they can't access your account without this second factor.

Common MFA methods (from least to most secure):

Where to enable MFA:

Recommended: Google authenticator is used very broadly, is available in both android and apple app store, and has a cloud backup feature in case your device is lost, stolen, or breaks.

The option to enable MFA on a website or application is typically in security options. You will usually be offered a choice of authenticator the site supports. Select the authenticator you have installed on your phone, open that application on your phone, and scan the QR code provided by the website by clicking the `+` icon on the authenticator application.

Important: When you enable MFA, you'll receive recovery codes (usually 8-10 random codes). Store these safely, like in your password manager, as they're the backup if you lose your authenticator; phones break, can get stolen, or get lost. You can also install the authenticator application on multiple devices, such as a tablet, so if you lose one device you do not lose access. Plus it is easier to restore to a new device that way.

Use Passkeys When Available

Passkeys are a newer, phishing-resistant way to sign in. They use cryptography instead of passwords, and are built into many devices. They're easier to use than passwords and more secure than MFA. Enable them when offered. Major sites like Google, Microsoft, Apple, and others now support passkeys. To start using passkeys, enable them in the website or application, typically in security options. Once enabled, you will be prompted to generate a passkey, typically through fingerprint or facial recognition. Passkeys are device-specific, but can be linked across all your devices.

Understanding Biometrics

Fingerprints, Face ID, and other biometrics are convenient but come with trade-offs:

Pros:

Cons:

Best practice: Use biometrics as a second factor alongside passwords, not as your only authentication method. For banking apps with very sensitive data, consider using a PIN instead of biometrics for unlocking the app on your phone.

Exception - Passkeys: Passkeys are different. When you use biometrics to unlock a passkey, the biometric stays on your device and only unlocks a cryptographic key. The website never sees or stores your biometric data. This makes passkeys with biometric unlock more secure than traditional biometric-only authentication, and it's safe to use them as your primary sign-in method.

Check for Compromised Accounts

Visit https://haveibeenpwned.com every few months to see if your email addresses have appeared in recent, known data breaches. If you find your information was compromised:

2.1.4 Extra Credit

Use Hardware Security Keys

Hardware authenticators like YubiKey https://www.yubico.com are physical devices you plug into your computer or tap against your phone. They're the most secure form of MFA because they can't be phished, intercepted, or duplicated.

Hardware keys are ideal for:

Tip: Set up two keys and keep one in a safe place as a backup. That way if you lose your primary key, you'll still have access.

Use One-Time Passwords for Apps

Some services let you create app-specific passwords, or one-time passwords (OTP), instead of using your main password. This is especially useful for email accessed through desktop or mobile applications. The password only works once to connect the first device that uses it. Even if malware captures it, it's useless to an attacker.

Set these up for any critical applications that contain sensitive information. It may take a little hunting to find these settings. In Gmail, for example, “App Passwords” are within the 2-step verification settings, beneath the list of second steps. Once you generate the one-time password, log out of that application on your device, then log back in using the one-time password. Repeat this for all devices (phone, tablet, desktop, and laptop applications).

Review Account Security Regularly

At least quarterly, check your important accounts:

Separate Email for Sensitive Accounts

Consider using a separate email account exclusively for your most sensitive sites (financial and health portals) that you never use for anything else (shopping, social media, or regular communication). This makes it much harder for attackers to find or target this email, since it won't be in typical data breach lists. Ideally, you should have a total of 3 or 4 email accounts. One, primary account you use for regular communication, a secondary email for sensitive sites like financial and health portals, and a recovery email address which you use to recover your email accounts if you lose access. A fourth email can be used to split out messages from shopping, social media accounts, and so forth, since those generate the most spam.

When providing an email address to a company you can also use https://10minutemail.com. This is a service which offers disposable email accounts; they are only valid for 10 minutes by default, although you can extend 10 minutes at a time. While this account is active you can send and receive email like any other email account. Using this keeps your regular email private if you just want to try out a service but aren’t certain you want to use it long-term. Once you register this email address with any service, if you decide to keep that service, you can always change your email address to one of your others.

2.2 Scam and Social Engineering Defense

Core Concepts: Protect Yourself, Protect Your Data

Humans are the weakest link in security. Even perfect technical security fails if you're tricked into handing over credentials or sending money. The good news is most scams use the same playbook, so learn to recognize the patterns.

2.2.1 Understanding Social Engineering

Social engineering is the art of manipulating people into giving up confidential information or taking actions that compromise security. Attackers exploit human psychology, our trust, fear, curiosity, and desire to be helpful, rather than technical vulnerabilities.

Common tactics attackers use:

Your defense: Slow down. Verify. Be skeptical. Trust your gut; if something feels off, it probably is.

2.2.2 The Basics

Recognize Phishing Emails and Texts

Phishing is a fake message designed to trick you into clicking a link, opening an attachment, or sharing sensitive information. Here's how to spot them:

Before clicking any link in an email or text message:

On desktop:

On mobile:

A quick note about QR codes, since those are really just links. Legitimate examples of these can be found on company advertisements, restaurant menus, business cards, etc. Scammers also sometimes use QR codes to bypass email security filters and trick you into visiting malicious sites. This is called “quishing.”

How it works:

Protection:

Never Open Unexpected Attachments

Attachments are a common way to deliver malware. Follow these rules:

Verify Unexpected Requests

If you receive an unexpected request whether by email, text, phone, or social media, pause and verify:

Example: Your bank sends a text saying your account is locked. Don't click the link in the text. Instead, call the number on the back of your credit or debit card.

Watch for Caller ID Spoofing

Scammers can make their phone number appear as any number they want on your caller ID, including your bank, the IRS, or even your own number.

Protection:

Recognize Gift Card and Wire Transfer Scams

No legitimate organization will ever ask you to pay with gift cards or wire transfers. Gift cards are untraceable, and both gift cards and wire transfers are non-refundable. That's why scammers love them. If someone asks for payment this way, it's a scam, no exceptions!

Spotting Tech Support Scams

Tech support scams come in many forms. Pop-up warnings with messages like "Your computer is infected! Call this number immediately!" These are fake. Real security warnings don’t give you a number to call. Never call this number! Close the browser tab and don’t go back. If it came from a site you think is legitimate, like your bank, notify them immediately.

Cold calls are another type of scam. Someone claiming to be from Microsoft, Apple, your internet provider, or even from the FBI or local police, stating that they have detected a problem with your computer. They usually ask for remote access to “fix” the problem. What they want is access to your computer to install malware, steal files, or extort money for fake "repairs." Never give remote access to unsolicited callers. Real tech companies don't call you unsolicited about computer problems; hang up immediately. Block the number if they keep calling back.

Watch for Impersonation on Social Media

Scammers create fake profiles impersonating:

Red flags:

Verification: If a friend messages you with an unusual request, call or text them directly (not through the suspicious message) to verify.

2.3 Identity and Cloud Account Safety

Core Concept: Protect Yourself, Protect Your Data

Your identity and your cloud accounts are two of your most valuable digital assets. Your identity can be used to open accounts, file fraudulent tax returns, and ruin your credit. Your cloud accounts, Google, Microsoft, Apple, hold years of emails, photos, documents, and are often the gateway to resetting passwords for everything else.

A compromised identity or cloud account can create a cascading failure across your entire digital life. This section covers how to protect yourself.

2.3.1 Understanding the Risks

What is identity theft?

Identity theft is when someone uses your personal information, social security number, name, date of birth, address, etc, to impersonate you.

Common identity theft scenarios:

How identity theft happens:

2.3.2 The Basics

Guard Your Personal Information

Do not ever give out any information to someone who calls you! If you receive a call asking you to confirm your identity by providing personally sensitive information, explain that you do not provide this on a call you did not initiate.

Before you ever give sensitive, personal information out to anyone, ask these questions:

Review Third-Party App Access

Apps you've authorized can access your cloud account data. Review and revoke unnecessary access.

How to review:

Google:

Microsoft:

Apple:

Do this quarterly.

Configure Account Privacy Settings

Cloud providers collect extensive data about you. Limit what they collect and share. Do the same for social media accounts, such as facebook, instagram, etc.

Google:

Microsoft:

Apple:

Shred Sensitive Documents

Physical documents can reveal your identity.

Documents to shred:

Shredder type: Use cross-cut or micro-cut shredder, not strip-cut (too easy to reconstruct).

2.3.3 Better Protection

Opt Out of Pre-Approved Credit Offers

Pre-approved credit offers in the mail can be stolen and used to open accounts.

How to opt out:

This reduces mail clutter and risk of identity theft

Use Privacy Services for Online Signups

Avoid giving your real email and phone number to every website.

Email masking:

Phone masking:

Review Cloud Storage Sharing

Make sure you're not unintentionally sharing files or folders.

How to check:

What to look for:

2.3.4 Extra Credit

Opt Out of Data Brokers

Data brokers collect and sell your personal information. You can opt out, but it's tedious.

Major data brokers:

DeleteMe https://joindeleteme.com is a paid service that handles opt-outs (~$130/year)