# 2. Accounts and Identity

# 2.1 Authentication (passwords, MFA, passkeys, biometrics)

*Core Concepts: Protect Yourself, Protect Your Data*

When you log into a computer or website with a User ID and password, you are authenticating; proving you are who you claim to be. Get this topic right and you block 90% of account compromises.

## 2.1.1 Understanding Authentication

Authentication answers the question "who are you?" A User ID is your unique identifier (often an email address). A password is a single verification factor paired with your User ID. Together, they prove you're the legitimate owner of an account.

## 2.1.2 The Basics

- Use a password manager
- Create strong passwords
- Never reuse passwords
- Handle security questions carefully
- Set up a recovery email
- Enable login alerts

### Use a Password Manager

A password manager stores all your login credentials, auto-fills them when you need them, and can generate secure, random passwords for each account. This means you only need to remember one password, the master password for your password manager, or vault.

**Why use a password manager?**

- Creates strong, unique passwords for every account automatically
- Bypasses the clipboard, protecting against keyloggers
- Detects when you change passwords and can automatically update them
- Can store payment cards and bank accounts ("wallet" feature)
- Allows secure password sharing with family without revealing the actual password
- Provides emergency access features if you're hospitalized or otherwise incapacitated
- Can store additional information as notes, like answers to your security questions

**NEVER use your browser's built-in password storage.** While modern browser password managers have improved, dedicated password managers offer superior security features including cross-platform sync, security audits, secure sharing, and breach monitoring. Browser-based storage also creates a single point of failure if your browser is compromised.

**Important:** DO NOT FORGET YOUR MASTER PASSWORD! You can share this with a friend or family member who can store it in their vault in case you forget. If you use a password manager which offers account recovery, set it up and carefully protect the recovery information.

**Recommended: Bitwarden** (https://bitwarden.com/). It's web-based so you can access it anywhere, has browser plugins, mobile apps, and offers both free and premium service. It includes all the features mentioned above.

If you want, you can use my self-hosted Bitwarden service at [<u>https://pass.landisfam.org.</u>](https://pass.landisfam.org./ "https://pass.landisfam.org.") This offers the same protections as Bitwarden’s official service, but less likely to be targeted by attackers. However, I still cannot recover your account if you forget your master password.

Once enrolled, install the applications in your browsers and on your mobile devices. Enable auto-fill, and start populating your vault by logging into each email, financial, and health related accounts, since those contain your most sensitive information. When doing this, I recommend you reset each password, most password managers have a password generator, and secure them in your password manager. If you use a browser extension, most password managers prompt you to automatically add information for websites not already in the vault.

While going through this process, I also recommend you go through each site’s security settings. Review your security questions (see that topic below) and force logout of all devices. Note that afterward you will have to log in again on all devices.

### Create Strong Passwords

Passwords that are easy to remember tend to be easy to guess. The solution is to make them long, using a phrase you can remember, but would take an attacker a very long time to guess or to use brute-force methods to crack your account. Follow this link and experiment with different passwords: [<u>https://www.security.org/how-secure-is-my-password/</u>](https://www.security.org/how-secure-is-my-password/ "https://www.security.org/how-secure-is-my-password/")

**How to Create a Strong Password:**

There is an adage in Bridge (a card game for old people), “length over strength.” A long, simple password is more secure than a short, complex password. Think of a line from your favorite song, poem, or quote. Take a few words from that line, capitalize some letters, mix in numbers, and add a special character or two.

*Example:* From Robert Frost's "The Road Not Taken":

- Simple version: Tw0r04ds! (would take 1 hour to brute force)
- Strong version: tworoadsdivergedinayellowwood (85 sextillion years)

Email accounts deserve the highest level of protection. When you forget a password, most sites send a reset link to your email. This means if someone gains access to your email, they can potentially reset passwords for all your other accounts. I recommend 16+ characters for email passwords.

**Recommended password lengths:**

<table border="0" cellpadding="0" cellspacing="0" id="bkmrk-account-type-passwor"><tbody><tr><td width="312">**Account Type**

</td><td width="312">**Password Length**

</td></tr><tr><td width="312">Password Manager

</td><td width="312">20+ characters

</td></tr><tr><td width="312">Email

</td><td width="312">16+ characters

</td></tr><tr><td width="312">Everything else

</td><td width="312">12+

</td></tr></tbody></table>

Of course, if you use a password vault, you can have the best of all words, and use unique, 20+ character, complex passwords for all your accounts without ever having to worry about forgetting them. Again, just make sure the password for your password manager is also strong, and have a recovery method in case you do forget it.

### Never Reuse Passwords

Use a unique password for every account. If one site gets breached, attackers will try that password on other popular sites. Reused passwords mean one breach potentially compromises all other accounts which use that same password. Your password manager, once populated, can verify that all your accounts have unique credentials.

### Handle Security Questions Carefully

Security questions are a weak way to verify your identity. The answers are often public information or easy to find through social media. When forced to use them:

- Don't pick anything that could be public record (first car, school names, family names)
- Consider using false or ironic answers. The system only compares how you answer when prompted with what you entered when you created the answer; it cannot validate if the answer you provided is actually true
- Example: "What was your first car?" Answer: "Matchbox"

Your password manager likely has a “notes” section for each item in your vault, or a separate “notes” folder. You can put your security questions in one of those.

### Set Up a Recovery Email

Create a secondary email account to use as a recovery address for your primary email. If you can't access your main email, you can use the recovery email to regain access to your primary email account. Keep this secondary email account highly protected too, and only use it as a recovery account; do not use it for any other purpose.

### Enable Login Alerts

Turn on notifications for new logins. Most services offer this. When enabled, you'll get an email or text when someone logs into your account from a new device or location. If it wasn't you, you'll know immediately. You can typically fine this option in security settings.

## 2.1.3 Better Protection

- Expand password manager use
- Enable Multi-Factor Authentication (MFA)
- Use passkeys when available
- Understand when is best to use biometrics
- Check for compromised accounts regularly

### Expand Password Manager Use

Once you have your critical applications vaulted (email, financial, and health-related accounts), you’ll want to go back and begin adding other important sites and applications like cloud storage (Google drive, iGloud, OneDrive, Dropbox), social media, and shopping accounts. Follow the same process to change the password using the password manager’s password generator, forcing logout of active logins, and updating security questions.

### Enable Multi-Factor Authentication (MFA)

MFA adds a second step to logging in; usually a code sent to your phone or generated by an authenticator application. If you use MFA, even if someone steals your password, they can't access your account without this second factor.

**Common MFA methods (from least to most secure):**

- SMS text codes: Simple but vulnerable to SIM-swap attacks
- Email codes: Better than nothing but relies on email security
- Authenticator apps: Generate time-based codes even without cell service. Examples include Google Authenticator, Microsoft Authenticator, RSA Authenticator
- Passkeys: Biometric, cryptographic, or physical devices you plug into your device (covered in Extra Credit)

**Where to enable MFA:**

- Password manager (highest priority)
- Email, financial, and health service accounts
- Cloud storage (Google Drive, iCloud, Dropbox, OneDrive)
- Social media accounts
- Shopping accounts
- Any other account with sensitive personal information

**Recommended:** Google authenticator is used very broadly, is available in both android and apple app store, and has a cloud backup feature in case your device is lost, stolen, or breaks.

The option to enable MFA on a website or application is typically in security options. You will usually be offered a choice of authenticator the site supports. Select the authenticator you have installed on your phone, open that application on your phone, and scan the QR code provided by the website by clicking the `+` icon on the authenticator application.

**Important:** When you enable MFA, you'll receive recovery codes (usually 8-10 random codes). Store these safely, like in your password manager, as they're the backup if you lose your authenticator; phones break, can get stolen, or get lost. You can also install the authenticator application on multiple devices, such as a tablet, so if you lose one device you do not lose access. Plus it is easier to restore to a new device that way.

### Use Passkeys When Available

Passkeys are a newer, phishing-resistant way to sign in. They use cryptography instead of passwords, and are built into many devices. They're easier to use than passwords and more secure than MFA. Enable them when offered. Major sites like Google, Microsoft, Apple, and others now support passkeys. To start using passkeys, enable them in the website or application, typically in security options. Once enabled, you will be prompted to generate a passkey, typically through fingerprint or facial recognition. Passkeys are device-specific, but can be linked across all your devices.

### Understanding Biometrics

Fingerprints, Face ID, and other biometrics are convenient but come with trade-offs:

**Pros:**

- Can't be forgotten
- Quick and convenient
- Better than weak passwords

**Cons:**

- Can't be changed if compromised
- Can be forged (though it's difficult and expensive)
- Can be compelled by court order (unlike passwords, which are protected speech)
- Someone with physical access to you can use your biometrics (passed out at a party, etc.)

**Best practice:** Use biometrics as a second factor alongside passwords, not as your only authentication method. For banking apps with very sensitive data, consider using a PIN instead of biometrics for unlocking the app on your phone.

**Exception - Passkeys:** Passkeys are different. When you use biometrics to unlock a passkey, the biometric stays on your device and only unlocks a cryptographic key. The website never sees or stores your biometric data. This makes passkeys with biometric unlock more secure than traditional biometric-only authentication, and it's safe to use them as your primary sign-in method.

### Check for Compromised Accounts

Visit [<u>https://haveibeenpwned.com</u>](https://haveibeenpwned.com/ "https://haveibeenpwned.com") every few months to see if your email addresses have appeared in recent, known data breaches. If you find your information was compromised:

- Change the password for that account immediately
- Review recent account activity for unauthorized access
- If you reused that password anywhere else, change those too
- Enable MFA if you haven't already


## 2.1.4 Extra Credit

- Use hardware security keys
- Use one-time passwords
- Use separate email accounts
- Conduct full account audits periodically

### Use Hardware Security Keys

Hardware authenticators like YubiKey [<u>https://www.yubico.com</u>](https://www.yubico.com/ "https://www.yubico.com") are physical devices you plug into your computer or tap against your phone. They're the most secure form of MFA because they can't be phished, intercepted, or duplicated.

Hardware keys are ideal for:

- Password managers
- Email accounts
- Financial accounts

**Tip:** Set up two keys and keep one in a safe place as a backup. That way if you lose your primary key, you'll still have access.

### Use One-Time Passwords for Apps

Some services let you create app-specific passwords, or one-time passwords (OTP), instead of using your main password. This is especially useful for email accessed through desktop or mobile applications. The password only works once to connect the first device that uses it. Even if malware captures it, it's useless to an attacker.

Set these up for any critical applications that contain sensitive information. It may take a little hunting to find these settings. In Gmail, for example, “App Passwords” are within the 2-step verification settings, beneath the list of second steps. Once you generate the one-time password, log out of that application on your device, then log back in using the one-time password. Repeat this for all devices (phone, tablet, desktop, and laptop applications).

### Review Account Security Regularly

At least quarterly, check your important accounts:

- Check recent login activity for suspicious locations or times
- Review authorized devices and remove any you don't recognize or are no longer using
- Verify your recovery information (email addresses, phone numbers) is current
- Look for third-party apps with access and revoke any you don't use

### Separate Email for Sensitive Accounts

Consider using a separate email account exclusively for your most sensitive sites (financial and health portals) that you never use for anything else (shopping, social media, or regular communication). This makes it much harder for attackers to find or target this email, since it won't be in typical data breach lists. Ideally, you should have a total of 3 or 4 email accounts. One, primary account you use for regular communication, a secondary email for sensitive sites like financial and health portals, and a recovery email address which you use to recover your email accounts if you lose access. A fourth email can be used to split out messages from shopping, social media accounts, and so forth, since those generate the most spam.

When providing an email address to a company you can also use [<u>https://10minutemail.com</u>](https://10minutemail.com/ "https://10minutemail.com"). This is a service which offers disposable email accounts; they are only valid for 10 minutes by default, although you can extend 10 minutes at a time. While this account is active you can send and receive email like any other email account. Using this keeps your regular email private if you just want to try out a service but aren’t certain you want to use it long-term. Once you register this email address with any service, if you decide to keep that service, you can always change your email address to one of your others.

# 2.2 Scam and Social Engineering Defense

*Core Concepts: Protect Yourself, Protect Your Data*

Humans are the weakest link in security. Even perfect technical security fails if you're tricked into handing over credentials or sending money. The good news is most scams use the same playbook, so learn to recognize the patterns.

## 2.2.1 Understanding Social Engineering

Social engineering is the art of manipulating people into giving up confidential information or taking actions that compromise security. Attackers exploit human psychology, our trust, fear, curiosity, and desire to be helpful, rather than technical vulnerabilities.

**Common tactics attackers use:**

- Urgency: "Act now or your account will be closed!"
- Authority: Impersonating your bank, the IRS, or your boss
- Fear: "Your computer is infected!" or "You owe taxes!"
- Greed: "You've won a prize!" or "Make money fast!"
- Curiosity: "See who viewed your profile" or "This video is about you"
- Helpfulness: "Can you do me a quick favor?"

**Your defense:** Slow down. Verify. Be skeptical. Trust your gut; if something feels off, it probably is.

## 2.2.2 The Basics

- Recognize phishing emails and texts
- Check links before clicking
- Never open unexpected attachments
- Verify unexpected requests through another channel
- Watch for caller ID spoofing
- Recognize gift card and wire transfer scams
- Spotting for tech support scams
- Watch for impersonation on social media

### Recognize Phishing Emails and Texts

Phishing is a fake message designed to trick you into clicking a link, opening an attachment, or sharing sensitive information. Here's how to spot them:

- Generic greetings: "Dear Customer" instead of your name
- Urgent language: "Act immediately" or "Within 24 hours"; they want you to act before you have time to think about whether or not it is a scam
- Threats: "Your account will be suspended" or "You'll be charged"
- Too good to be true: Free money, prizes you didn't enter, inheritance from unknown relatives
- Spelling and grammar errors: Professional companies proofread their communications
- Mismatched sender addresses: The display name says "PayPal" but the email is from "paypa1-secure@gmail.com"
- Suspicious attachments: Especially .exe, .zip, or files you weren't expecting
- Requests for personal information: Real companies never ask for passwords, SSN, account numbers, or any other personal information via email
- Unexpected delivery notifications “there was a problem with your package” when you didn’t order anything

### Check Links Before Clicking

Before clicking any link in an email or text message:

**On desktop:**

- Hover your mouse over the link (don't click!) and look at the URL that appears
- Does it match what you expect? If an email claims to be from Amazon, the link should go to amazon.com, not amaz0n-secure.net
- Watch for look-alike domains: paypal.com vs. paypa1.com (that's a number one), or apple.com vs. app1e.com

**On mobile:**

- Press and hold the link to preview where it goes
- When in doubt, don't click - go directly to the company's website through your browser or app instead

A quick note about QR codes, since those are really just links. Legitimate examples of these can be found on company advertisements, restaurant menus, business cards, etc. Scammers also sometimes use QR codes to bypass email security filters and trick you into visiting malicious sites. This is called “quishing.”

**How it works:**

- You receive an email with a QR code claiming to be from your bank, IT department, or a package delivery service
- You scan the code with your phone
- It takes you to a fake login page that steals your credentials

**Protection:**

- Be skeptical of unexpected QR codes in emails
- Before scanning, ask yourself if you were expecting this
- After scanning, check the URL before entering any information
- When possible, access services directly rather than through QR codes in emails

### Never Open Unexpected Attachments

Attachments are a common way to deliver malware. Follow these rules:

- Don't open attachments from unknown senders, period
- If you get an unexpected attachment from someone you know, verify with them through a different channel (call them) before opening
- Be especially wary of: .exe, .zip, .scr, .com, .bat, .js files
- Even seemingly safe files like PDFs and Word documents can contain malware, verify before opening

### Verify Unexpected Requests

If you receive an unexpected request whether by email, text, phone, or social media, pause and verify:

- Don't use contact information from the suspicious message
- Look up the organization's official phone number or website independently
- Call or message through a verified channel
- Ask: "Did you send me a message about \[topic\]?"

*Example:* Your bank sends a text saying your account is locked. Don't click the link in the text. Instead, call the number on the back of your credit or debit card.

### Watch for Caller ID Spoofing

Scammers can make their phone number appear as any number they want on your caller ID, including your bank, the IRS, or even your own number.

**Protection:**

- Don't trust caller ID alone
- If someone claims to be from your bank or a government agency, get their name, the agency they claim to represent, and whatever topic identifier they can provide related to why you called, (ticket number, case number, incident number, etc)
- Then hang up and call back using an official number (absolutely not one they offer to provide)
- Real organizations won't mind you verifying their identity this way
- Be extra suspicious of robocalls or calls demanding immediate payment

### Recognize Gift Card and Wire Transfer Scams

**No legitimate organization will ever ask you to pay with gift cards or wire transfers.** Gift cards are untraceable, and both gift cards and wire transfers are non-refundable. That's why scammers love them. If someone asks for payment this way, it's a scam, **no exceptions**!

### Spotting Tech Support Scams

Tech support scams come in many forms. Pop-up warnings with messages like "Your computer is infected! Call this number immediately!" These are fake. Real security warnings don’t give you a number to call. **Never call this number!** Close the browser tab and don’t go back. If it came from a site you think is legitimate, like your bank, notify them immediately.

Cold calls are another type of scam. Someone claiming to be from Microsoft, Apple, your internet provider, or even from the FBI or local police, stating that they have detected a problem with your computer. They usually ask for remote access to “fix” the problem. What they want is access to your computer to install malware, steal files, or extort money for fake "repairs." Never give remote access to unsolicited callers. Real tech companies don't call you unsolicited about computer problems; hang up immediately. Block the number if they keep calling back.

### Watch for Impersonation on Social Media

Scammers create fake profiles impersonating:

- Your friends and family members
- Company customer service accounts
- Celebrities or other influencers

**Red flags:**

- New account or very few posts
- Small changes in username (JohnSmith vs John\_Smith or JohnSmith1)
- Requests for money or personal information
- Messages from "customer service" accounts you didn't contact

**Verification:** If a friend messages you with an unusual request, call or text them directly (not through the suspicious message) to verify.

# 2.3 Identity and Cloud Account Safety

*Core Concept: Protect Yourself, Protect Your Data*

Your identity and your cloud accounts are two of your most valuable digital assets. Your identity can be used to open accounts, file fraudulent tax returns, and ruin your credit. Your cloud accounts, Google, Microsoft, Apple, hold years of emails, photos, documents, and are often the gateway to resetting passwords for everything else.

A compromised identity or cloud account can create a cascading failure across your entire digital life. This section covers how to protect yourself.

## 2.3.1 Understanding the Risks

**What is identity theft?**

Identity theft is when someone uses your personal information, social security number, name, date of birth, address, etc, to impersonate you.

**Common identity theft scenarios:**

- Opening credit cards or loans in your name
- Taking over existing accounts
- Filing fraudulent tax returns to steal refunds
- Creating fake IDs with your information
- Using your insurance for medical care

**How identity theft happens:**

- Phishing emails and scam calls
- Data breaches (companies losing your information)
- Data brokers selling your information
- Public WiFi snooping
- Lost or stolen wallet
- Mail theft (stealing statements, pre-approved credit offers)

## 2.3.2 The Basics

- Guard your personal information
- Review third-party app access
- Configure account privacy settings
- Shred sensitive documents

### Guard Your Personal Information

**Do not ever give out any information to someone who calls you!** If you receive a call asking you to confirm your identity by providing personally sensitive information, explain that you do not provide this on a call you did not initiate.

- Ask them for their name, who they represent, the purpose of the call, and a reference number so you can call back (do not accept a number they provide as valid)
- Look up the number of your bank or other service on their official website or contact card (credit card companies have the fraud reporting numbers on the back) and call that number.
- Do not continue to engage with the caller; if it is a legitimate call they will not threaten, coerce, or be upset at you verifying

**Before you ever give sensitive, personal information out to anyone, ask these questions:**

- "Why do you need this?"
- "Is it required by law?"
- "Can I use an alternative identifier?"
- "How will you protect it?"

### Review Third-Party App Access

Apps you've authorized can access your cloud account data. Review and revoke unnecessary access.

**How to review:**

**Google:**

- myaccount.google.com &gt; Security &gt; Third-party apps with account access
- Review each app, remove ones you don't use or recognize

**Microsoft:**

- account.microsoft.com &gt; Privacy &gt; Apps and services
- Remove apps you don't use

**Apple:**

- appleid.apple.com &gt; Sign-In &amp; Security &gt; Apps Using Apple ID
- Stop using Apple ID for apps you no longer use

Do this quarterly.

### Configure Account Privacy Settings

Cloud providers collect extensive data about you. Limit what they collect and share. Do the same for social media accounts, such as facebook, instagram, etc.

**Google:**

- myaccount.google.com &gt; Data &amp; privacy
- Web &amp; App Activity: Consider turning off or auto-delete after 3 months
- Location History: Turn off unless actively using
- YouTube History: Auto-delete after 3-18 months
- Personalized advertising: Turn off

**Microsoft:**

- account.microsoft.com &gt; Privacy
- Manage your activity data &gt; Clear activity
- Turn off diagnostic data sharing where possible

**Apple:**

- Settings &gt; Privacy &amp; Security (on each device)
- Review Location Services, limit to "While Using" for most apps
- Turn off "Share iPhone Analytics"
- Turn off personalized ads

### Shred Sensitive Documents

Physical documents can reveal your identity.

**Documents to shred:**

- Bank statements
- Credit card offers
- Medical records and EOBs
- Tax documents (after 7 years)
- Insurance documents
- Anything with SSN, account numbers, or personal info

**Shredder type:** Use cross-cut or micro-cut shredder, not strip-cut (too easy to reconstruct).

## 2.3.3 Better Protection

### Opt Out of Pre-Approved Credit Offers

Pre-approved credit offers in the mail can be stolen and used to open accounts.

**How to opt out:**

- Call 1-888-5-OPT-OUT (1-888-567-8688)
- Or visit optoutprescreen.com
- Choose 5-year opt-out or permanent opt-out

This reduces mail clutter and risk of identity theft

### Use Privacy Services for Online Signups

Avoid giving your real email and phone number to every website.

**Email masking:**

- Firefox Relay [<u>https://relay.firefox.com/</u>](https://relay.firefox.com/ "https://relay.firefox.com/")
- Apple Hide My Email (iCloud+ subscribers)
- 10-Minute Mail [<u>https://10minutemail.com/</u>](https://10minutemail.com/ "https://10minutemail.com/") (temporary mailbox)

**Phone masking:**

- Google Voice for a free, US phone number
- Use for non-critical signups, not banking or important accounts so you can refresh it periodically to keep spam calls and texts down

### Review Cloud Storage Sharing

Make sure you're not unintentionally sharing files or folders.

**How to check:**

- Google Drive: drive.google.com &gt; Shared with me / Shared (check both)
- OneDrive: onedrive.com &gt; Shared
- Dropbox: dropbox.com &gt; Sharing
- iCloud Drive: icloud.com &gt; iCloud Drive &gt; Shared folders

**What to look for:**

- Public links you forgot about
- Shares with old colleagues or friends
- "Anyone with link" permissions

## 2.3.4 Extra Credit

### Opt Out of Data Brokers

Data brokers collect and sell your personal information. You can opt out, but it's tedious.

**Major data brokers:**

- Spokeo, WhitePages, PeopleFinder, BeenVerified
- Each has their own opt-out process
- Search your name to see what's listed
- Follow opt-out instructions for each site

DeleteMe [<u>https://joindeleteme.com</u>](https://joindeleteme.com/ "https://joindeleteme.com") is a paid service that handles opt-outs (~$130/year)