Protecting Personal Information
Over the weekend, I got asked a question about what to do if you think someone has gotten into your personal data. Before I get into that, let’s go back over my past advice about sensitive information. Yes, all of this is very inconvenient in a society used to high levels of convenience. But how inconvenient will it be if your identity is stolen and your credit destroyed? Just do it.
For all of us, we often have client information, too, which makes this even more important. Don’t blow it off. Yes, maybe the information we have is public record anyway, but how embarrassing is it to have that information get out because we weren’t secure? If that happened to you as a client of a professional, like an accountant, wouldn’t you question everything about how that professional does business? It’s never harmless – if someone can get even harmless information from you, then your security will be immediately questioned. That happened with many clients who blocked us after the October attack, even though we didn’t lose a bit of information to anyone. We worked hard to get that trust back.
1. Cloud drives, like Dropbox, Box, Google Drive, OneDrive, Citrix Files, and many more, are very convenient. They let you access your information anywhere you have an internet connection and, with satellite based internet, there’s probably nowhere on Earth where that can’t happen. But they all come with a risk—they are connected to the internet and vulnerable to the bad guys. Avoid putting personal information like SSN, bank information, passwords, etc. on a cloud drive. If you do that for a temporary purpose, like transmitting it to an accountant, remove it as soon as you know the recipient has received and downloaded it.
2. For the same reasons, it’s not even a good idea to put that information on your laptop, PC, phone, or tablet. Any device connected to a network that can be accessed through the internet – even indirectly through a third party – is vulnerable.
3. Keep your sensitive information on a portable hard drive with a padlock, like this: Padlock Hard Drive
4. If you must store information on network connected devices, then make sure you’ve password protected your most important files and activated any multi-factor authentication that might be available. Really, if the cloud drive doesn’t use multi-factor authentication then you shouldn’t be using the service. Turn on notifications from the service – they’ll let you know when someone tries to log in.
5. Never email personal information to anyone without at least one layer of protection like a password or encryption. Email is as vulnerable as it comes, especially internet based email like icloud, Google, or Yahoo. Yahoo has been breached multiple times and I’m always amazed when I see someone still using it. If you think email is safe, then you probably have no problem putting that information on a neon sign in South Beach.
6. Never, never, never use passwords that can be guessed for important information. The bad guys know that people can’t remember complex passwords and, therefore, have a strong tendency to use things that are familiar. This means that the bad guys can surf your social media and on-line life to find out what those things are. Then, they use “brute force” to try password after password until they find the combination you thought would be “good enough.” Good enough is never good enough when it comes to your personal information. You must use the best security available.
7. Also, never, ever use the same password for every service. Once the bad guys get it for one site, then they have it for all of them. Whoops. And they will try to get into everything you have as fast as they can before you can detect it.
8. A very easy way to use complex passwords and only remember one of them is a password vault. All you need is one master password, which might be easier to remember if it tells a short story you know. LastPass suggests things like this: WSHCB!isthebest1placeieverworked. That’s not too hard to remember, but it is very hard to guess. Nothing in social media would give that away. It also contains enough characters to make it nearly impossible to break by a program working through every possible combination.
9. Sign up for LifeLock and make it your goal to use as much of their monitoring service as you can. Sure, LifeLock can probably be hacked, just like anyone else. Nothing is invulnerable. But they have $1,000,000 in liability insurance to help out if anything happens, including if they screw it up. It works. I recently made a big purchase and my phone blew up within minutes with notifications from LifeLock about credit checks and everything else related to the process.
So, let’s say you have ignored all my advice (or felt that my advice is much too long to bother with) and now, you’ve been boarded by pirates. All is not lost, but time is of the essence:
1. Immediately change the password of the compromised service.
2. Figure out what information was available to the bad guys and start monitoring credit cards and the like. This isn’t hard, every credit card allows you to see your account whenever you want. You can see transactions in real time in most cases.
3. Sign up immediately for a monitoring service like LifeLock. Make sure that LifeLock is looking at the information you know was exposed.
4. Follow the advice listed above for everything else. Change the passwords, etc. If the bad guys got enough personal information, then your entire online life is very vulnerable until you close and lock the doors.
Comments
Post a Comment