Ransomware can lock up every file on your computer and hold it hostage until you pay. I'll discuss defenses that work, why backups are your best insurance, and why you should never, ever pay the ransom.
(Image: Google Flow)
Question: How can I prevent criminals from encrypting files on my hard drive and then demanding a ransom to unlock the data? Is having a router and software firewall enough?
In other words, how do you avoid ransomware?
Let’s look at ransomware — software that holds your data hostage until you pay up — and how best to protect yourself.
Is the cloud really dangerous, or is that just a lack of understanding? I'll break down what "the cloud" actually is, why it's no riskier than email or online banking, and the simple habits that keep your data safe no matter where it lives.
I think a lot of people feel that way to varying degrees.
I strongly disagree. Using the cloud can absolutely be safe.
I also think that believing the cloud is dangerous prevents you from taking advantage of the things it can do for you — things like protecting your data.
It also ignores the fact that you’re already doing things “in the cloud” safely and have been for years.
Most people who lose an account never get it back, and it's usually their own fault. I'll discuss why alternate email addresses and phone numbers are the key to account recovery, and the habit most people forget that locks them out for good.
(Image: Google Flow)
Literally1 not a day goes by that I don’t hear from someone in the middle of an account recovery process that isn’t working.
While I try to help out to the degree that I can — usually with instructions that are often no more than the service provider’s instructions translated into clearer English — it’s not uncommon for those account recovery efforts to fail and access to the account never be regained.
Ever.
And, at the risk of being seen as blaming the victim, to be super blunt about it, most of the time it’s the account owner’s own fault.
Wonder why software makers make the choices they do? Me too. But asking "why" rarely brings relief... except in one case.
(Image: Google Flow)
I was helping a friend the other day with some Windows issues, and a not-uncommon question came up, one that I often dread.
“Why?” As in, “Why did they do that?”
It’s a common question that gets applied to computers and software of all generations and iterations. Recent versions of Windows have certainly generated a healthy share of “Why?” questions — but trust me, it’s nothing new.
The problem is, asking “Why?” is most often a frustrating and fruitless exercise.
Changing your Windows sign-in PIN isn't a setting in your Microsoft account; it's set on each device. I'll show you where to find it, why a PIN is safer than you might think, and when you should change it.
(Image: Google Flow)
Question: How do I change my PIN? The one I use to sign in to my machine. I can’t find how anywhere in my Microsoft account.
It’s not part of your Microsoft account. It’s unique to each device you use it on.
To change the PIN (Personal Identification Number) you use to sign in to a machine, you need to change it on that computer.
Getting locked out of your own email is scary, and the fallout can spread to your bank, social media, and contacts. I'll walk you through the steps to take right now: recovering your account, locking it down, and protecting everything connected to it.
(Image: Google Flow)
It seems like not a day goes by when I don’t get a question from someone that boils down to their email account having been hacked.
Someone, somewhere, has gained access to their account and is using it to send spam, access other online accounts, hassle contacts, and more. Sometimes passwords are changed, sometimes not. Sometimes traces are left, sometimes not. Sometimes everything in the account is erased — including contacts and saved email — and sometimes not.
If that’s happening to you, your email account has been hacked.
A big pop-up that claims your computer is infected and pushes a specific download cleanup tool can be scary. I'll show why these warnings almost always come from a website, not your PC, and what steps will keep you safe from real threats.
(Image: Google Flow)
Question: I’ve recently started getting a new warning message when I visit some sites. It says that my computer is tracking all the adult sites I’ve visited and that this will affect me in various ways. It recommends that I install a drive-cleaning program to remove these tracks. Does this mean that my computer was infected by a virus, trojan, or some kind of tracking software? Have I been hacked by someone? And do you recommend that I install the drive-cleaning software? Is it safe?
Do not install that software.
If you get a message that says you are infected and recommends a specific product to fix it, the answer is simple: don’t do it.
You may need to do a few other things, but following some random pop-up message’s instructions to download a specific product isn’t one of them.
If malware has you ready to give up and buy a new computer, don't. I'll explain why your old one can be completely restored to a malware-free state, using steps to wipe out even the worst infections without spending a dime on new hardware.
(Image: Google Flow)
Question: I give up. My computer has been infected with malware — lots of it — and I can’t seem to get rid of it all. I’m ready to throw in the towel. Should I just get a new computer? Wouldn’t that just solve everything?
You never need to buy a new computer just because of malware.
I regularly hear from people with machines infected with multiple pieces of malware. Their computer is crippled, and they just want it to work.
If that’s you, and you’re at the point where you’re considering getting a new computer because of it, STOP.
Before you get out your credit card, let me clear up some confusion and save you some cash.
Is it safe to allow a tech support company to control your computer from far away? It depends on who they are, how you found them, and whether they called you first. I'll share the one rule you must never violate.
(Image: Google Flow)
Question: Is it safe to allow remote access to a tech support person from a reputable firm to solve a problem? I recently had an issue that required me to contact such a company, and I permitted the tech to view my desktop. My problem was solved, but I couldn’t help thinking that this was a bad idea. Can they browse around inside your computer if you give them this kind of access?
Yes, they certainly can. This question boils down to: How much do you trust them?
All other issues aside, this is entirely a matter of trust.
Does that email feel a little off? Maybe AI wrote it, maybe it didn't. I'll discuss why the old warning signs are disappearing and what matters when judging any message.
(Image: Google Flow)
Question: I got an email that smells fishy. Something isn’t right, but I can’t put my finger on it. Could it have been written by AI?
Sure.
It could also have been written by a human.
While there might be subtle clues in today’s AI-generated text, as I keep saying, it’s only getting better.
Using one password for every account doesn't save time; it adds risk. Hackers count on you doing it. I'll show you why a single stolen password can unlock your email, your bank, and everything else, and share the easy way to use strong, different password on every site without having to remember them all.
(Image: Gemini)
Question: Is it safe to have the same password for all of my email accounts? If one has an account in Yahoo! mail, Gmail, Rediff mail, etc., and sets the same password for all of them, will it be easier for a hacker or phisher to find out about it?
Using different passwords is much safer than using one password everywhere. In fact, it’s critical.
Why?
Because hackers know that most people have more than one account and that most people don’t take the trouble to set different passwords.
From just a few minutes of audio, AI can clone a voice well enough to fool people who know that voice well. I'll share real examples, explain how easy it is to do, and share tips for staying alert as this technology keeps improving.
(Image: Gemini)
I ran an experiment on some friends, and the results were not quite what I expected.
The question was simple: “Is this me?”
The answer, as the clickbait headlines might say, will surprise you.
Do you need someone to physically look at your computer but don't know who to trust? I'll walk you through smart ways to find local help you can count on, from asking around to reading reviews. Also, why the big chain stores are a gamble.
(Image: Gemini)
Question: My computer has a problem that I’ve not been able to figure out. I don’t even know how to ask the question. What I’d like to do is take it to someone local, but I don’t know who to trust. Should I go to one of the chain stores? Office supply stores? If not, how do I find someone that I can actually trust with my time, my money, and my data?
Sometimes, someone needs to physically look at your computer to diagnose whatever’s ailing it. There’s only so much that can be done over email or phone, and even remote access (only with someone you trust!) can’t handle every situation.
Sometimes, there’s no substitute for what I facetiously refer to as “laying hands” on a device.
If you're worried your computer might have malware, running a full scan with Windows Security is one of the best ways to check. I'll walk you through updating, launching, and completing a full scan, plus explain why it's not a guaranteed fix on its own.
(Image: Gemini)
When we are faced with the hint, suspicion, or removal of malware, one of the more common recommendations is to run a full, up-to-date scan with your security software.
I’ll walk you through the process of doing that with Windows Security (also known as Windows Defender or Microsoft Defender).
Data removal services promise to erase your personal information from the internet. Can they? I'll break down how these services work, where they succeed, where they fall short, and what that means for protecting yourself once your data is out there. (Spoiler: it's already out there.)
(Image: Gemini)
Question: What about the so-called “data removal” services being touted all over the internet and in many YouTube videos? If internet users lose all control of their post contents, how can these services find your specific posts and remove them? I’m very skeptical. Do these services really work?
Once again, there’s no black-and-white, yes-or-no answer.
These services do remove some of your information from the internet. But it’s impossible to remove everything, no matter what their marketing materials imply.
The old advice was eight characters, including uppercase, lowercase, digits, and symbols. Modern computers can crack those passwords in hours. I'll describe why length matters more than anything and how long your passwords really need to be.
(Image: Gemini)
For a long time, the common thinking was that the best, most practical passwords consisted of a random combination of upper- and lowercase letters, numbers, and a special character or two. If so composed, the password length needed to be only eight characters.
Randomness remains important, but as it turns out, size matters more. Much more.
And eight characters isn’t enough these days. It’s not even close.
We worry a lot about privacy, but our concerns are often misplaced. The biggest risk to our personal privacy is right under our nose -- and that's good.
Flashing the world! (Image: Gemini)
I write a lot about various aspects of technological risk to privacy. The computers and services we use, the systems running them, and the applications and tools we rely on each add risk of some kind to our privacy.
And yet, in my experience, the greatest risk has little to do with technology.
We don’t often consider it, yet I see privacy compromised more often due to this factor than for any other reason.
Hotel internet isn't necessarily private. Wired or wireless, it's as exposed as any open hotspot, and the people running it can watch what you do. I'll describe why hotel networks are risky and list the steps that keep your activity safe wherever you connect.
(Image: Gemini)
Question: My friend’s husband has been getting into her email even though she’s not given him her password. He confronted his sister about an email, and when asked how he got into the email, he said that where he works (a large hotel chain), they have a program that searches emails for keywords and brings up info. Could that be true? Can they snoop on hotel internet traffic?
Yes.
Hotel internet security is one of the most overlooked risks travelers face. And I’m talking about any internet connection provided by your hotel, not just wireless.
In fact, I’m writing this in a hotel room, and yes, I have taken a few precautions.
How do you know that download you want is safe? Before you run it, I'll show you how to scan it, when to trust the results, and the simple habits that keep malware off your machine for good.
(Image: Gemini)
Question: Someone’s pointing me to a downloadable program as a solution for a problem I’m having. I’m really hesitant to download and run unknown EXE files. Is there any way I can scan it or otherwise be certain it’s clean or riddled with subtle spyware, viruses, or whatever else could be bad?
I was somewhat taken aback by this question. It’s a perfectly good question, and one that more people should be asking more often.
My reaction was due to the lack of a good answer.
It turns out it’s fairly difficult to tell whether or not a download is about to play havoc with your system without actually downloading it.
Good news for Windows 10 holdouts: Microsoft quietly extended its Extended Security Updates program by another year. Here's what changed, why Microsoft may have done it, and what you need to do next (spoiler: probably nothing).
(Image: Gemini)
If you’re running Windows 10 and you’ve signed up for the Extended Security Updates (ESU) program, apparently you have another year of support coming your way.
Believing and spreading manure -- lies, falsehoods, and misleading implications -- makes you look bad and makes the internet a dumber place. Become more skeptical, even of things you agree with.
(Image: canva.com)
Supposedly, in a report a few years ago, Google admitted you should have no expectation of privacy whatsoever when using their services. The internet went crazy. Many sources proclaimed, “How outrageous! We told you so! Google is evil!” Mainstream news outlets picked up stories from smaller publishers, and they all confirmed the entire sordid mess.
Except the internet was wrong. Manure, to use a polite term, was being spread far, wide, and fast.
I'll explain how keyloggers work, why a virtual keyboard doesn't help, and how to keep your typing safe.
This keyboard has other problems, and it still won’t help. (Image: Gemini)
Question: Will using the on-screen keyboard in Windows stop keyloggers?
No, it will not.
I get a surprising amount of pushback on this, but the truth remains: while virtual keyboards might stop some keylogging, it’s nothing you can count on to be 100% effective. It doesn’t stop most keyloggers these days.
Keyloggers are malware that record your keystrokes. The goal is to capture login usernames and passwords so hackers can get into your accounts. Let’s look at the various ways your keystrokes can be intercepted and logged.
Your files are in OneDrive, so are they backed up? Not necessarily. Cloud storage and cloud backup are not the same thing, and confusing the two can cost you everything. I'll give you four simple rules that keep your files safe.
(Image: Gemini)
Question: I now have 1 TB of Microsoft OneDrive storage. How should that affect my backup strategy? Most of my data files are now on OneDrive; do those need to be backed up? Can I use OneDrive space as my “external hard drive” for backups of my other files? How about for image backups? Can/should Macrium Reflect put a system image onto OneDrive? Any other advice re the wise and safe use of cloud storage?
The availability of “cloud” (or online) storage has greatly expanded our options for keeping data both safe and accessible.
While it’s expanded our cloud backup options, it’s also expanded our ability to get it wrong. It’s now easy to think you’re backed up when you’re not, or to accidentally expose yourself to additional risks.
Let’s review some rules about backing up and about cloud backup specifically.
BitLocker encrypted your drive, intentionally or otherwise, but now you want it gone. Turning it off is easy whether you run Windows Home or Pro. I'll walk you through both, explain what you're giving up, and remind you why saving that recovery key matters.
Corgi adjusting my BitLocker settings, the rascal! (Image: Gemini)
Question: I don’t need or want BitLocker, yet it’s been turned on. How do I turn off BitLocker?
I’m going to assume you’re talking about BitLocker’s full-disk encryption, which can be turned on unexpectedly in Windows Home and Pro editions.
It’s important to understand that with BitLocker turned off, anyone who steals your computer can access all the files on it, even without knowing your Windows login password. That said, not everyone needs the security of full-disk encryption.
Turning off BitLocker and decrypting your drive is a snap.