skip to main | skip to sidebar

Sunday, August 21, 2011

You Can Think of to Account Security? No Password, and Login!

Once again to further protect your accounts from hacking into some of the interactive customer resources Web 2.0, you can do this.

One of the vulnerable factors in the security of the Internet can not only be too simple password, and in addition thereto it is known to many around your e-mail.

Unfortunately, so are arranged, for example, Google and mail.google.com. From their e-mail accounts "grown up" social networks - and they coincide with the login authentication login address.

But there are systems in which as a login, you can use e-mail, not associated with the very resource. This is the case, for example, Facebook and several other social networks.

A similar situation, for example, in a variety of technological and technical Internet services - for example, many systems of contextual advertising. In the same way with the authorization process is organized in many famous Russian shops.

We make a general preliminary conclusion: safe / not safe by themselves may not be password or login name individually, but as if it was a pair of "login - the password." Since the password is something attackers can even pick up, but the login ...

The Internet is a set of email services - ordinary "mail" to find them easily. Register for one of them myself e-mail address and use it solely as a login in order to log into these systems. On it will receive messages of one kind only - incoming service announcements on these systems.

Yes, of course, superfluous "e-mail" - it is a pain, but think about what is more important: the additional security or conditional carelessness. Let this be your kind of network "door" to which only you will know and only you, because you are because of her no "show" - it will only work on the entry.

In this case:
- Never, to anyone, under any circumstances, does not tell your e-mail address;
- In any case, do not post it on your business cards;
- Never with anyone he did not write;
- Never "prescribe" the account to the POP3-and SMTP-settings for your email, use this almost exclusively through the web interface;
- In this case (see previous item) is always the "exit" from the email account for its next use.

You can, of course, to make such an address in the system of corporate e-mail domains - the system administrator of the company (organization, institution), where you say, work.

But a little-known in the remote mail system of various e-mails can be tens of thousands (and it also may be a dozen different to writing e-mail domains), and individual user nobody, in fact, is not needed.

But your extra corporate mailing address can easily know your system administrator. Even if it is - an absolutely honest man, your e-mail may be accidentally "seen the world", say, from a certain list of email addresses of employees who, being prepared for the banal reason that may later come to be in the trash.

The main conclusion: as a login in order to log into any interactive online system is to use e-mail, which in principle will be known solely to you.

When used as such, known to many of your mail write an attacker to "break" only a password.

In our more perfect case of need to know more and login.