Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Ask HN: Account security best practices for 2021?
2 points by ketanmaheshwari on Dec 26, 2020 | hide | past | favorite | 2 comments
I have some questions about security of my various accounts:

1. What are your online accounts security best practices guidelines?

2. How often do you update your password?

3. Are all your accounts have the same password or different or differential?

4. Do you let your browser retain / save your passwords?

5. How long should a password be? Are 8-character passwords still OK?

6. Do you write your passwords on paper? If so, how do you secure that paper?

7. Is 2-factor / multi-factor authentication an absolute must or can I skip that option for accounts that allow me to skip?




I don’t have all the answers. But I do know a few things.

Eight character passwords are not okay. Any password that a human can generate on their own, and can remember on their own, is simple enough that it can probably be easily guessed by attackers. Use a good password manager and keep the passwords randomly generated, and as long as the remote system will allow. Protect the password to the password manager with good 2FA, like a hardware token.

As for 2FA, do not use SMS. IMO, that makes things weaker than not having 2FA at all. Use a hardware token instead. Yubikey makes some nice ones, but they’re not the only solution on the market. Do your homework.

Individual passwords for sites should also be protected by 2FA with a hardware token, where that is available. Of course, you’ll need to have a backup hardware token, and a solution for use in emergencies when the hardware tokens are not available at all. Work this out in advance, before you need it.

And practice your backups. Like it or not, when the time comes, you will operate as you have practiced, and if you haven’t practiced, then you won’t operate very well.


LastPass with auto-rotating 56 character passwords every 10 days plus 2FA MFA (with SMS text message options disabled so only using authentication app), and using Yubikey security tokens for Gmail (Advanced Protection Program = Free. https://landing.google.com/advancedprotection/ )

I literally don't know any of my passwords to any of my sites, save my last pass master password. I also use alias email email accounts that are unique for each account so that when I get spam I know which site leaked the email address.

http://blog.lastpass.com/2015/05/auto-password-change-now-av...

Break into one of my accounts, and I'd be super interested to know how.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: