Account Security Best Practices

Discussion in 'Site News, Questions and Feedback' started by Myke, Nov 18, 2016.

  1. Myke

    Myke Administrator Staff Member Content Manager Kage

    PSN:
    Myke623
    XBL:
    Myke623
    This announcement is a reminder of the best practices for maintaining account security. This applies not only to your account on this site but -- very importantly -- your accounts on other forums, online services and sites.

    Avoid Password Reuse
    These days, many account compromises happen through password reuse. Billions of user records have been compromised on a variety of sites and this data is available to anyone who wants to go looking for it. In many of these cases, it's possible to look up a user by username or email and find their plain text password. To give you an idea of the extent of compromised data, try looking up your email on Have I Been Pwned?. If you reuse a password from a compromised site, your account is not secure. Ideally, you would use a unique password on each site.

    Use a Strong Password
    Coming up with passwords is hard. If you're choosing your own password, chances are it's not going to be that strong. There are techniques to help you generate stronger passwords, but unfortunately, many memorable passwords are simply not strong enough to hold up to password cracking tools (such as would be used when someone downloads a compromised database). Wikipedia has an extensive page discussing password strength: https://en.wikipedia.org/wiki/Password_strength

    The strongest passwords are literally random strings. As these are far from memorable, you will need a tool to store (and generate) these passwords. These are known as password managers. With them, you choose one (very strong) master password and then have it generate unique passwords for every site. This means the site only receive a strong password that is unique to it, solving both the strength and reuse issues.

    There are a variety of password managers to choose from. A few include:

    Enable Two-Step Verification
    Whenever you have the option, you should enable two-step verification (also known as two-factor authentication). Should your password ever be compromised (either through a compromised site or something like a keylogger), two-step verification can help keep an attacker from logging into your account.

    If possible, you should do two-step verification through your phone using an app such as Authy (or some other hardware-based method). This would generally require an attacker to physically have your phone/your token to complete the two-step verification. Other methods (such as email verification) provide some benefit but are not as safe as using a separate device for verification.

    Visit your profile to enable Two-step Verification here on VFDC.

    Enforce Protection of High Value Accounts
    Your accounts on different sites may have varying levels of "importance" based on the information they protect. You should be absolutely sure that you are taking as many steps as possible to protect high value accounts. Generally speaking, this would include any email account (as password reset mechanisms mean email accounts are master keys) and financial accounts (banks, PayPal, etc).



    By taking as many of these steps as possible, you will significantly increase the security of your accounts across the internet!
     
  2. Ellis

    Ellis Well-Known Member

    PSN:
    Ellis_Cake
    Also i think its a good practice (tho not always a clear hint in some cases),
    to look at the actual adress a link posts to; does the main web domain seem reasonably legit, does it use any extra "mumbo jumbo" besides the actual link to a domain (like script and script options) and so forth.

    Like, be silently supersceptic.

    Imma hope we won't see anymore junk like that,
    thanks for the pro-active stance on this myke and mods ^^
     
    jimi Claymore likes this.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice