TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Account security best practices for 2021?

2 点作者 ketanmaheshwari超过 4 年前
I have some questions about security of my various accounts:<p>1. What are your online accounts security best practices guidelines?<p>2. How often do you update your password?<p>3. Are all your accounts have the same password or different or differential?<p>4. Do you let your browser retain &#x2F; save your passwords?<p>5. How long should a password be? Are 8-character passwords still OK?<p>6. Do you write your passwords on paper? If so, how do you secure that paper?<p>7. Is 2-factor &#x2F; multi-factor authentication an absolute must or can I skip that option for accounts that allow me to skip?

2 条评论

bradknowles超过 4 年前
I don’t have all the answers. But I do know a few things.<p>Eight character passwords are not okay. Any password that a human can generate on their own, and can remember on their own, is simple enough that it can probably be easily guessed by attackers. Use a good password manager and keep the passwords randomly generated, and as long as the remote system will allow. Protect the password to the password manager with good 2FA, like a hardware token.<p>As for 2FA, do not use SMS. IMO, that makes things weaker than not having 2FA at all. Use a hardware token instead. Yubikey makes some nice ones, but they’re not the only solution on the market. Do your homework.<p>Individual passwords for sites should also be protected by 2FA with a hardware token, where that is available. Of course, you’ll need to have a backup hardware token, and a solution for use in emergencies when the hardware tokens are not available at all. Work this out in advance, before you need it.<p>And practice your backups. Like it or not, when the time comes, you will operate as you have practiced, and if you haven’t practiced, then you won’t operate very well.
ianceicys超过 4 年前
LastPass with auto-rotating 56 character passwords every 10 days plus 2FA MFA (with SMS text message options disabled so only using authentication app), and using Yubikey security tokens for Gmail (Advanced Protection Program = Free. <a href="https:&#x2F;&#x2F;landing.google.com&#x2F;advancedprotection&#x2F;" rel="nofollow">https:&#x2F;&#x2F;landing.google.com&#x2F;advancedprotection&#x2F;</a> )<p>I literally don&#x27;t know any of my passwords to any of my sites, save my last pass master password. I also use alias email email accounts that are unique for each account so that when I get spam I know which site leaked the email address.<p><a href="http:&#x2F;&#x2F;blog.lastpass.com&#x2F;2015&#x2F;05&#x2F;auto-password-change-now-available-in-the-lastpass-security-challenge&#x2F;" rel="nofollow">http:&#x2F;&#x2F;blog.lastpass.com&#x2F;2015&#x2F;05&#x2F;auto-password-change-now-av...</a><p>Break into one of my accounts, and I&#x27;d be super interested to know how.