I often wonder how much the security of email (and by extension, every other account online) depends on people just not knowing how simple and easy it is to break into. If everyone knew, we'd be living in chaos right now, right?
I often wonder how much the security of email (and by extension, every other account online) depends on people just not knowing how simple and easy it is to break into. If everyone knew, we'd be living in chaos right now, right?
email recipient: Pasword123
me: thanks.
JOB DONE :-)
"Hey, how are you?"
"Pretty good. We're thinking about getting a dog so I went to the shelter this morning."
"Oh really?"
"It's tough to find one that's a good match though."
"Definitely"
"You ever have a dog?"
"Nah, wife's allergic. Had a snake as a kid though...called him Mr. Slithers."
Here's how I deal with sites that require them:
site: "What is your first teacher's name?"
me: "'Fx|<n8K@W8#[_,[ (1p)jqPC"
The answer is a password equivalent, so I just treat it like a password.
Or is this for when the account is locked for some random reason?
In return I assert a well deserved facepalm when I see a friend log in on his e-mail account with a variation of "Password1".
Just use a strong password ( https://xkcd.com/936/ )
The funny thing with having email as a username is, how sometimes people can use social engineering to gain control of your account, non of that fancy "hoaxer" stuff are needed when your service providers put untrained people in charge of your accounts. Hacking human stupidity is a more effective way in to get in to a secure system.
( as an example, this was on reddit just yesterday https://www.youtube.com/watch?v=lc7scxvKQOo )
Also worth mentioning my e-mails are not hosted on gmail or any big cloud player. I actually pay for my imap, when you don't pay you probably in some way are the product...
Paranoid? Maybe
Safe? More than others
Not if they self provide their own email (by running their own mailserver).
Emails from residential modems are not even worth scanning - they are practically guaranteed to be from botnets. Emails from commodity hosting providers are also pretty suspect, because they're very easy for spammers to get their hands on.
If you want your mail delivered, you need to send it from IP addresses that don't have those obvious red flags, don't have a reputation for sending spam any time in the distant past, and also have a long-term positive reputation for sending non-spam email.
In practical terms, you need to be in the professional mail server administration business full-time (be extremely careful to shut down abusive customers/tenants rapidly, never make a mistake that would let an attacker run an SMTP server on your network, etc.) or you need to pay someone who is, and who trusts you to cloak yourself in their reputation and not ruin it.
Some of them are lightweight virtualizations where a priviledged outside user can run processes inside the VM without requiring authorization or without being logged.
How is this a meme that needs to die?