12 comments on “Why You — Yes, You — Are a Target of Hackers”

  1. You wrote “2: Choosing not to bank online could even put you at greater risk, as you’re left relying on older, less secure alternatives.”

    I would suggest not having an online account set up may put you at more risk, especially if you still use checks, which show all the information needed to set up an online account.

    If you don’t do it, someone else may set up an online account for you, and you would not know until you get that monthly statement in the mail.

    Reply
  2. I’m posting this here rather than “staying safe on the internet” where this will be near the top and not buried under years of comments.

    DO NOT RELY ON YOUR ISP’s ROUTER ALONE! At a minimum, install your own router between your ISP’s router* and your personal network. Or install two routers in series; the bandwidth loss will be negligible. Do your research, do not install two ‘identical’ routers from different OEMs. Additionally, buy your own router and replace the one from your ISP. Use vastly different, max length passwords/pass phrases for each. Yes, this is more work, but it’s “one-and-done.”

    If your router has provisions for MAC address filtering, use it! If it doesn’t, get a newer router. This will go a long way to prevent wireless break-ins, but there are no absolutely safe methods against hacking. Again, more work but one-and-done until you purchase a new device. This is especially crucial in high density cities or suburbs where you may sense 20 or 50 wireless networks, so they also ‘see’ you; simply not broadcasting your SSID will not stop a hacker.

    *Your ISP’s router is likely a combination modem/codec/router which unscrambles their internet signals (DSL, cable, etc) and provides the more common local internet via hardwired connectors (Rj-45) and wireless.

    Reply
  3. I’m a VITA volunteer tax counselor. Unfortunately, every year several tax payers learn that their identity has been compromised when their e-filed return is rejected because someone else filed with their SSN. Correcting the problem is difficult and will delay any refund by 10-14 months. (It doesn’t delay the requirement to pay, if due.)

    Reply
  4. I’m a retiree, so I don’t have to access a corporate network. If you must access one use a VPN to do so (and suggest to your supervisors that they should require everyone to use a VPN for remote access).

    I try to lock down my computers as much as I can with the security tools available to me (Windows 10/11 Pro). For starters, my Microsoft account is secured with 2FA (Microsoft Authenticator), and I have activated ‘password-less’ access (I use Windows Hello to log onto my computer. Since I have a biometric fingerprint scanner on all three of my computers, I have set up Windows Hello fingerprint scanning to log on – so now, it’s my finger or my PIN to get me in).

    I have a desktop PC and two laptops, one of which will never meet Windows 11’s hardware requirements (although it does have Secure Boot and TPM2 enabled – the CPU’s too old), so it runs Windows 10 Pro. My desktop PC and my newer laptop both run Windows 11 Pro. All three PCs have a Windows System partition, and (on an external drive) a data and a backup partition (for a total of three partitions each). I have encrypted all three partitions on each PC with BitLocker (the two partitions on the external drives have a password so I can access them in the event I can’t boot Windows. I have saved the recovery keys for all nine partitions to my Microsoft Account and printed them too. The printouts are stored in a safe in my home office. On my desktop PC, Windows will lock the screen after 5 minutes of inactivity if I forget to lock it when I leave my desk. Both of my laptops lock the screen when I close the lid (I found a small utility called lidlock on Downloads.com. I have used it for over a year with no issues. Reputation-based protection and SmartScreen are both enabled on all three devices, and I have never received an alert about lidlock on either laptop, so AFAIK it’s safe).

    On the first day of each month (as one of my System/Security Maintenance routines), I go through the security settings in the Windows Security dashboard to make sure everything that should be turned on, is (this almost seems like a waste of time, but if I ever get any malware, it may pay off).

    I use Macrium Reflect to back up my computers. On Monday, I generate a full system image, then I generate a differential image every other day of the week. I keep four image sets (a set consists of one full system image, and six differential images). Since they are written to an encrypted drive, I have little fear that in the event any of my computers get stolen, my data will be at risk. The one thing I wish could be possible would be to have a setting that disables the ability to clear the CMOS memory/TPM storage areas on my motherboard without entering an administrative password (if one is set), so a thief would be unable to install an OS to sell the machine. As it stands, I can short two pins on my motherboard to clear any password(s) I configure in the UEFI/BIOS system.

    I keep all three computers as up to date as possible. I use Windows Update to keep Windows up to date on each patch Tuesday (IIRC, the second Tuesday of each month), and I have Patch my PC installed to keep my apps updated (I check it the first day of each month too).

    I use LastPass here. I decided to wait and see what they do in response to the hack. At this point, I am satisfied with their behavior (so far), so I will keep them for now (this could change). I changed (and lengthened) my password, then took the steps they suggested to update my account’s security, so now (unless I misunderstand) everything should be safely encrypted. I check my vault monthly to ensure there are no duplicate passwords (another monthly system/security maintenance routine). I use the LastPass Authenticator for 2FA with my LastPass account/vault (not Microsoft Authenticator) to keep things under their own roof.

    I have gone through all my Internet accounts (using LastPass), and enabled 2FA where it’s supported. For the few accounts that do not support 2FA as well as those I no longer use, I have requested that my account be deleted. All have complied, so now I can say that I use all the Internet accounts I have, and that they are all protected with 2FA. As a result, if some miscreant should somehow get the password to any of my Internet accounts, they will not be able to get in unless they have my phone too. Another monthly Maintenance/Security routine is me going through all my accounts in LastPass and canceling/deleting any I no longer want/need (this usually means I change nothing, but at least I know that I have no unused accounts). For the most part it’s easy, I log in to the site, go to my profile/account settings and choose the option to delete my account (if it exists – if not, I send an email to the webmaster to make the request). After I am notified that my account is deleted, I remove it from my LastPass vault (so far, no site that I have an account with lacks the ability to remove/delete my account).

    Following the infamous Experian hack, I decided to freeze my accounts with the ‘big three’ credit reporting bureaus, Experian, TransUnion, and Equifax. Then when Leo published that there were other agencies, I also froze my accounts with them (so now, my credit is frozen with at least six reporting agencies. If my identity gets stolen, (IIUC) it’s unlikely the thief will be able to get an ID or open any account of any kind in my name. While I understand that my identity may still get stolen, at least the thief will not be able to get money in my name, and perhaps it will be much harder for him/her to get a legally recognized ID (driver’s license, social security card, etc.). Since I have no need to get a new credit card any time soon, all this works very well for me (and if I should decide that I want/need a new/different credit card, I can always temporarily unfreeze my account with whichever bureau will be used by the creditor – a little extra bother, but well worth it for the added security), YMMV :).

    Finally, and perhaps, most importantly, I employ what I call ‘Cognitive Security’. It involves never blindly trusting anything on the Internet. Rather, I hover my mouse over any link I want to click (be it in an email, or on a web page) to check where it will take me. If I have ANY doubt, I DON’T click! I never blindly believe anything others post, especially when what they say re-enforces what I already believe. Instead, I fact check, using several sites I have learned to trust (factcheck.org, the associated press’s fact checking site, and a few others). Then I search the Internet for keywords I find in the post to try to learn where it came from. I don’t trust far-right or far-left sources. After doing my due diligence, if I find that the post is accurate, I still take it with a small grain of salt (I never know what the poster’s agenda may be). For the most part, I try to make up my own mind about politics, religion, and most anything else I see on the Internet.

    For the most part, these are the things I do to keep myself secure. Everything I have done so far has been intended to make it as hard as possible for the bad guys. You may not want to go as far as I have, but you can feel free to use what I’ve written here as a general guide. Hopefully, doing so will help you to remain more secure on the Internet (and less susceptible to the propaganda of others).

    Ernie

    Reply
    • I don’t see a major advantage in using a VPN to access a corporate network. Most, if not all, corporate networks use an HTTPS:// (SSL) connection which is already encrypted end-to-end. That’s even safer than a VPN connection by itself, because a VPN connection is not encrypted between the VPN and the computer you are accessing, unless the site you are accessing uses SSL, which would make the VPN redundant.

      Reply
  5. I gotta say Ernie, that if (and that is a pretty big IF at this point), you do get hacked or compromised in some way, nobody is going to say you did nothing to prevent it. When you wrote about the 3 credit agencies, I immediately thought to ASKBOBRANKIN’s article where he wrote about the 6 of them, but then you mentioned Leo having written about them. I’ve been reading Bob’s stuff since he was publishing his TourBus. Having just recently found Leo’s newsletter, I feel confident to say that subscribing to both Leo and Bob will cover a large range of topics . I, too, am retired (as in like the past year, officially). I started with computers back in college and had to use punch cards to create 1 line of code (or data). Boy was I happy when I got a job in the computer lab (my job was to take the other students’ punch cards and run them through the Univac 1106 card reader so their job could be created. And then of course, hand them out when done. Good times. A perk of the job was that I got an online account. So no more 500-card COBOL decks for me. Oh, and text version D&D.

    Reply
  6. Your Social Security number if you live in the US is probably your most important “password”: Anyone who has that number can open bank accounts and credit cards as you.
    An ex-friend who got ahold of my Social Security number opened a credit card in my name and I was thousands of dollars in debt. I was able to get this resolved by threatening him with prison, but it took hours of phone calls to resolve. This would be exponentially more difficult if it were a stranger, especially if they were in a different country.
    If someone has your SSN, they own your financial life.

    Reply
  7. Thank you for this article and all you do.
    One thing I know that if you go to a site and order something they have your credit card and pin on file, for some time and maybe a very long time. Think about all the sites you have visited over the years and ordered something with a credit card. In my case that is a lot of sites. Just like us these companies get hacked – probably more than you think and they sell your credit card information (nothing new). So, one thing that might help is “The Identity Theft Resource Center” (IRTC). https://www.idtheftcenter.org/
    They track all the reported sites/companies that have been hack and produce a report of the breach data. I check this report every month to see if any of the sites I used are in the list. If they are, I go in and reset my credentials on that site. Now the hackers already have my credit card and pin, which has been stolen, and has sold it. If I no longer use the site, I go in and delete everything from it and close it out. And carefully check my credit card account.

    Reply
  8. I would add that everyone in the US go to Social Security (ssa.gov) and the Internal Revenue Service (irs.gov) and establish an online account, if they haven’t already. Even if you’re not drawing Social Security or use a tax preparation service.

    It is a bit of trouble to do so today because both agencies now use Login.gov or ID.me to log into accounts but it can be considered a preemptive measure. Also, one can request a taxpayer PIN from the IRS to use when filing taxes. The PINs change each tax year and are snail-mailed to the address on file.

    I had someone file a federal tax return using information obtained through a data breach. Whoever it was filed the return on January 1, which was immediately caught by the IRS. Since then, I’ve locked down most ways that could be taken to use my data for identity theft. Freezes at all credit bureaus, establishing accounts at different agencies with 2FA, and using virtual credit cards online. So far, I’ve had no further problems during the last 15 years since the false tax return.

    Reply
    • You said: “Also, one can request a taxpayer PIN from the IRS to use when filing taxes. The PINs change each tax year and are snail-mailed to the address on file.”

      Thank you for that information! It’s something I didn’t know. IIRC, I have an IRS account, and my annual income falls below the minimum to require I file any longer (I’m in my late 70’s, and I check annually, just to be sure), so I haven’t filed in the past several years, but now I’m going to go and see if I can set up a taxpayer PIN, just to insure my identity can’t be used to file a return.

      Ernie

      Reply
  9. Even though I don’t think I’m all that interesting (I don’t stand out in the crowd), I know that I’m still a target of hackers (as is everyone). As I understand it, the only thing ‘Not being all that interesting’ gets me is not being worth more sophisticated attacks, at least not quite yet (attacks on the level of hacking 2FA, etc.).

    With that said, I still protect myself as best I can. I use:
    Long (16 character), strong, unique passwords,
    Two-factor authentication,
    on every Internet account I have. If I find that a new service I’m setting up doesn’t support 2FA, I look elsewhere. My logic is that if a service cares so little for my account security, can I trust them to properly protect my data?

    On the financial ID theft prevention front, I have my accounts frozen on six credit bureaus; I visit my bank’s customer accounts portal daily to check for unfamiliar transactions; I haven’t investigated whether my bank supports V-cards yet, but if the current trends continue I probably will. I have an account with my state’s motor vehicle’s website that requires ID.me for access; My Social Security account requires ID.me access as do my Medicare/Medicaid accounts; I receive SNAP assistance, so I regularly check my account balance, and recent transactions for anomalies (so far – so good).

    Additionally:
    My router’s WAN ports are all configured for stealth mode (ignore – not deny – incoming connection requests), making my home Network effectively invisible to port scans; it supports WiFi 7, and is backward compatible with WiFi 6; requires WPA 2 or 3 with AES encryption, making radio traffic within my LAN as secure as possible.

    The OSes on my computers are kept as up to date as possible; Windows Update and UniGetUI manage updates for everything on Windows; I run Garuda-update daily (or when I log in if not daily) to do the same for my Garuda KDE-Lite Linux installation; My Proxmox-powered home lab is configured to automatically check for updates periodically, although my Windows 11 and Garuda VMs must be manually updated.

    Most importantly, I employ what I identify as Cognitive Security everywhere (involves skepticism and alertness for anomalies), essentially, I check the URL a hyperlink will take me to with it’s label’s text, if they don’t correlate, I’m unable to decipher the URL, or I don’t completely trust the website, I don’t click; I always keep in mind that the Internet is more ‘public’ than going outdoors, and it NEVER forgets anything! As a result, I never say or do anything on the Internet that I wouldn’t say or do in the presence of my most critical acquaintance, my late parents, or other loved ones.

    I don’t think I’ve missed anything, but if I have, please reply,

    Ernie

    Reply

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.