Not all two-factor authentication works the same way. Some methods are more secure, some are more convenient, and some leave you open to sneaky attacks like SIM swapping. Here's my breakdown of hardware keys, authenticator apps, texts, email, and voice codes so you can pick what fits you best.
(Image: Google Flow)
Question: Use two-factor; I get it. But there are several kinds. Which one should I use?
There are several approaches to two-factor authentication, and it can be confusing. Some are simpler, some are more convenient, and some are more secure than others.
Let’s compare the various ways two-factor authentication, or 2FA, can be implemented.
Whether you forgot your password, got hacked, or can't verify your identity while traveling, I'll point you to the steps to try if you're locked out of your Microsoft account.
(Image: Google Flow)
As longtime readers know, I get a lot of reports of Hotmail account theft and compromise. As Hotmail has transitioned to Outlook.com, so too have the questions. As Microsoft makes Microsoft accounts nearly mandatory for Windows installations, the number of these accounts has ballooned.
Every day, there are reports of everything from simple password loss to email being sent “From” your email address to attempts to scam your contacts.
Depending on exactly what’s happened, the available remedies may be simple, difficult, or completely impossible; your account and everything in it may be lost forever.
I’ll review the various scenarios and direct you to more detailed articles on Ask Leo! that cover the options for each.
A bad Windows Update can cripple your computer. Once it happens to you, it's tempting to swear off updates forever. I'll explain why that's the wrong move, and share one habit that makes any update failure, from Windows or anything else, easy to recover from.
(Image: Google Flow)
Question: I recently took an update via Windows Update, and after doing so, my machine wouldn’t even boot. It took a technician hours to get it working again. That’s not something I can afford to have happen again. I’m avoiding Windows Update from here on out.
That’s a conglomeration of many questions and problem reports I’ve received over the years. The pace picked up when Windows 10 was released.
Windows Update has a reputation for occasionally causing working systems to fail. The good news is, it’s almost always a tiny percentage of machines affected. The bad news is, that’s no solace if you’re affected.
I absolutely sympathize. I can understand why you’d be skittish about ever taking an update again.
Ever wonder why hackers don't get locked out after a few failed password attempts, the way you do? It turns out they rarely even try. I'll describe the sneakier "back door" methods -- data breaches, malware, and phishing -- that hackers use to break into accounts, and what you can do to stop them.
(Image: Google Flow)
Question: I have a question about passwords for online accounts. If I type my password wrong three times in a row, I can get locked out of my email account until it’s been reset. So if hackers rapidly try the whole dictionary, why doesn’t the account get blocked and I get notified of the intrusion? I’ve read your articles, but they don’t address why an intrusion notification or lockout doesn’t happen if many different passwords are tried in rapid succession.
Yup, after a few failed attempts at the login page, most services lock either the account or the IP address from which the attempts are being made.
Here’s the thing: that’s not how hackers hack, and it’s certainly not how they perform brute force attacks that try every possible password.
Nope. Instead of knocking politely at the front door, hackers try to barge in the back.
NAS or cloud? Each has real strengths and real risks, and a recent story about a broadcaster losing 50TB of archives shows what can go wrong. I'll detail pros and cons for each and show how combining both keeps your data safer than relying on just one.
(Image: Google Flow)
Question: What is the advantage of a NAS over cloud storage?
The advantage of NAS (Network Attached Storage) over cloud storage is only a quarter of what’s important to consider, which include the advantages of cloud storage over NAS and the risks involved in using either.
My updated guide cuts through the hype with four no-nonsense steps to keep your PC safe. Learn what works, what to avoid, and how to stay secure without overspending or overcomplicating.
(Image: Google Flow)
Question: What security software should I use? What anti-virus is best? How about a firewall? And what about spyware? Should I use one of the all-in-one packages that claim to do everything? Is there anything else I need?
I get these questions constantly. There’s a fair amount of churn and drama in the security industry; things change over time.
It’s time once again for my periodic update. Not a lot has changed in the last year, but there are some new things to consider.
Windows Update can get stuck, and it's rarely obvious why. I'll walk you through Microsoft's troubleshooter, and provide a full manual reset using command line tools, so you can get your updates flowing again.
(Image: Google Flow)
Question: I returned from vacation and found that Windows Update would not download any of 90 available updates (even though it sat for many hours saying “downloading,” nothing was coming). I eventually used the Windows Readiness program and was able to get 15 or so downloaded and installed, but trying the next group again, it is not downloading anything. There is no error message, just no action at all.
While it works well most of the time, problems with Windows Update can be very frustrating. There’s often no specific fix for whatever situation you’re faced with other than to “keep trying” or “let it run”… neither of which helps in many cases.
Fortunately, Microsoft has added a troubleshooter and outlined what I’ll call the nuclear option: resetting Windows Update completely. Regardless of the problem, if it involves Windows Update, I suggest you give this a try.
Facebook account hacks happen. Here's how to recover access, lock down your password and recovery info, warn your friends, and protect yourself from it happening again.
(Image: Google Flow)
It’s not uncommon for someone, somewhere, to gain access to someone else’s Facebook account and use it to post spam or worse. Sometimes the account password is changed; sometimes not. Sometimes traces are left; sometimes not.
Sometimes the entire account is permanently destroyed.
If you think that has happened to you, here’s what you need to do next.
The hard truth is that you can never fully prove your computer is malware free... but you can still stack the odds in your favor. I'll discuss why, the habits that keep you safer online, and what to do if something slips through.
(Image: Google Flow)
Question: How do I find out or know that my computer is free of keyloggers? Would Windows Defender or MalwareBytes find them if there are any, or do you have a referenced article on the topic where I can read about it? Understand that this is the biggest security concern I have about my computer nowadays.
How do you know your computer is free of keyloggers? You don’t.
That’s not the answer most people want to hear, but it’s the true bottom line.
I’ll talk about what you and I need to do in the face of this rather grim reality.
Find out when a manual scan makes sense, and how often you should run one for peace of mind.
(Image: Google Flow)
Question: I’m confused. You keep saying I should have up-to-date anti-malware tools, great. But how often do I use them? Don’t I need to scan every so often? How often?
The short answer is that with proper security software, you need to do nothing. The security software will scan automatically. I’ll expand on that in a moment.
The longer answer is that even with good security tools, you might want to occasionally run a scan. The definition of “occasionally” depends on your level of concern and whether or not you think you’re experiencing a malware-related issue on your computer.
Worried that ransomware could sneak past your defenses and encrypt your backups? Most ransomware won't, but it's not impossible. I'll discuss how ransomware picks its targets, why your backup image files are usually safe, and one simple habit to keep your files protected.
(Image: Google Flow)
Question: I wonder if a backup system that uses an external disk is safe from ransomware. I have Acronis True Image, paid version, and do a full backup once a month and an incremental daily. Can ransomware get to that backup? It is, in reality, just another disk in my system.
The best we can say is… maybe.
And maybe has been slowly changing over time to something closer to possibly.
It depends on a lot of things, including the type of backup, where it’s stored, and most importantly, the specific ransomware involved. There are many types (or variants) of ransomware, each with different characteristics.
Fortunately, there’s an easy way to keep your backups safe.
I'll explain when driver updates matter, why most scanning tools aren't worth your trust, and where to find real updates when you truly need them.
(Image: Google Flow)
Question: I downloaded three separate ‘check drivers’ programs. Each program identified seven drivers as being outdated. However, my Device Manager says they’re OK. It’s been very difficult to find the drivers, and if they are outdated, I will have to purchase one of the driver programs. Do I need to update these drivers? If so, how do I find the sites to download them?
Device Manager will not tell you whether or not a device driver is out of date; that’s not its job. What it tells you is if the device driver is installed and working at some basic level.
Finding out whether your device drivers are out of date isn’t easy, and neither is getting the updates.
You may have heard that hackers can sometimes beat two-factor authentication. It's true, but that doesn't make it useless. I'll describe how each type of two-factor works, which ones hackers can trick, and why skipping 2FA is still the riskiest choice of all.
An exploit kit that allowed a phishing attack to hijack a two-factor-secured login was published.
Various media outlets declared, “Two-factor has been hacked!”
Unfortunately, these instances led some to believe that two-factor authentication is pointless. To quote a reader: “This makes 2SV quite useless in many cases.”
NO! Just… no. That’s a seriously mistaken conclusion.
I’m revisiting this topic because I want to make this clear: two-factor authentication is not useless. In fact, two-factor authentication — SMS-based or otherwise — is significantly more secure than not using two-factor authentication at all.
Every online account you own is valuable to criminals looking to steal your identity, spread malware, or empty your accounts. Here's why you're a target no matter what, and how to protect yourself before it's too late.
Even Barnaby’s a target. (Image: Google Flow)
Question: Why should I bother with all this complicated security stuff? I have nothing hackers would want! I don’t have anything to hide, so why would anyone come looking for me? I don’t do banking on the computer, and I don’t have much money anyway.
I hear variations on this all too often. Many people feel that because they don’t have things they think a hacker would want, they’re not a target.
Wrong. Everybody’s a target.
You definitely have things hackers want. I don’t say this to scare you; I want to motivate you to protect yourself and continue to use the internet safely and happily.
ClickFix is a scam that turns a simple "prove you're human" (or other fake message) pop-up into a malware trap, using your own keystrokes to install it. I'll discuss how it works, where you'll find it, and the one red flag that gives it away every time.
(Image: Google Flow)
You’re surfing along on the internet, and you get another one of those “prove you’re human” pop-up messages. Instead of being an obscure “click every square that has a bicycle” CAPTCHA (yay?), this has instructions that are easy to follow: click here, type that, and prove your humanity.
Malware can slip past even a good antivirus program. Using my silliest metaphor yet, I'll explain vulnerabilities, exploits, and what actually keeps you safe. Learn how infections happen and what you can do about it.
(Image: Google Flow)
Question: Why would an exploit not be caught or detected by my antivirus program? If not detectable, how much damage can the exploit actually do if users follow prudent operating precautions? Would System Restore be usable if infected? I also follow your advice and routinely image my Dell laptop.
Your question is a good one: how can malware get past anti-malware programs and infect your PC?
And more importantly, what can you do to protect yourself?
Let’s define some terms with what may be my silliest metaphor ever, and then talk about how to stay safe.
Two-factor authentication keeps your accounts safe, but what happens if you lose your phone or key fob? I'll walk you through what you need to do now so you never need to worry about being locked out later.
(Image: Google Flow)
I’m a big believer in using two-factor authentication to log in to online accounts.
Two-factor authentication (also referred to as multi-factor authentication, 2FA, or MFA) adds the requirement of “something you have” to “something you know” to log in.
The risk is that “something you have” could turn into “something you’ve lost”. If you need it and don’t have it, you might not be able to sign in.
Not all passwords are created equal. Some resist hackers for centuries; others fall in seconds. I'll rank six password techniques from strongest to weakest, including one horrible password I still remember from 45 years ago, and how even that can be made secure.
(Image: Google Flow)
After over 45 years, I can still remember the password we used to access a status terminal in the computer center at school.
iforgot
A memorable but horrible password.
It was appropriate at the time because it was a public-access terminal — anyone could sign in — and for some reason, a password of some sort was required. They made it simple and posted it on the terminal itself.
There was zero security.
You want something better. There are several techniques for generating strong passwords. I’ll review some from best to worst.
Windows Update usually keeps your PC current, but not always right away. I'll show you how to check for updates until none are left, so you can be confident your Windows computer is as up to date as it can be.
(Image: Google Flow)
Question: When trying to solve a problem, one of your steps is to “make sure Windows is as up to date as possible.” Doesn’t Windows do that automatically?
Yes.
And no.
Even with Windows Update turned on and working properly, you might find more updates are available. Let me explain what I mean by “Make sure Windows is as up to date as possible.”
Sharing a link seems simple, but some methods create long, broken, or trackable URLs. I'll show you how to copy clean links, strip out tracking codes, shorten long URLs, link to a highlight or video moment, and check that the link will work.
(Image: Google Flow)
We all share links from time to time. We discover a webpage we want others to see, so we use some sharing technique to send that page to our friends via email, social media, instant messaging, or something else.
Some of those techniques are less efficient/more fragile ways to share links, and some are better.
Let’s make sure we’re sharing links in the best ways possible.
Ransomware can lock up every file on your computer and hold it hostage until you pay. I'll discuss defenses that work, why backups are your best insurance, and why you should never, ever pay the ransom.
(Image: Google Flow)
Question: How can I prevent criminals from encrypting files on my hard drive and then demanding a ransom to unlock the data? Is having a router and software firewall enough?
In other words, how do you avoid ransomware?
Let’s look at ransomware — software that holds your data hostage until you pay up — and how best to protect yourself.
Is the cloud really dangerous, or is that just a lack of understanding? I'll break down what "the cloud" actually is, why it's no riskier than email or online banking, and the simple habits that keep your data safe no matter where it lives.
I think a lot of people feel that way to varying degrees.
I strongly disagree. Using the cloud can absolutely be safe.
I also think that believing the cloud is dangerous prevents you from taking advantage of the things it can do for you — things like protecting your data.
It also ignores the fact that you’re already doing things “in the cloud” safely and have been for years.
Most people who lose an account never get it back, and it's usually their own fault. I'll discuss why alternate email addresses and phone numbers are the key to account recovery, and the habit most people forget that locks them out for good.
(Image: Google Flow)
Literally1 not a day goes by that I don’t hear from someone in the middle of an account recovery process that isn’t working.
While I try to help out to the degree that I can — usually with instructions that are often no more than the service provider’s instructions translated into clearer English — it’s not uncommon for those account recovery efforts to fail and access to the account never be regained.
Ever.
And, at the risk of being seen as blaming the victim, to be super blunt about it, most of the time it’s the account owner’s own fault.
Wonder why software makers make the choices they do? Me too. But asking "why" rarely brings relief... except in one case.
(Image: Google Flow)
I was helping a friend the other day with some Windows issues, and a not-uncommon question came up, one that I often dread.
“Why?” As in, “Why did they do that?”
It’s a common question that gets applied to computers and software of all generations and iterations. Recent versions of Windows have certainly generated a healthy share of “Why?” questions — but trust me, it’s nothing new.
The problem is, asking “Why?” is most often a frustrating and fruitless exercise.