Yesterday's story about Collection #1 - a package of hacked email passwords, is actually now reported to be a few years old, so the damage is not as great as previously believed. But Leo still says that it's a wise idea to go to HaveIBeenPwned.com/passwords and see if your account has been hacked. And then change your password. In fact, it may be a good idea to change it anyway, and turn on 2 factor authentication while you're at it.
2 factor authentication
Carmine has 2 factor authentication on most of his systems, but some use SMS, and he thinks that's not very secure. Leo says that there will always be a trade-off between security and convenience. But SMS is far easier to crack than independent authentication through an authenticator. Leo says to contact the cellphone company and have them put their additional layer of authentication on her phone.
Cheryl is concerned that with the recent Facebook security breach, her account will be hacked. Leo says it's more likely that someone will counterfeit her account, lifting her images, and change it just slightly to fool people she knows to friend it. Facebook has reset all 30 million accounts so that users would have to change their passwords. Leo also would recommend turning on 2 factor authentication.
Facebook reported this week that 50-90 million user accounts were hacked or compromised through three bugs in their interface that would allow a hacker to bypass password challenges through a stolen access token, video downloader access. Facebook says they have fixed the bug and made access tokens unusable for the 90 million compromised accounts. So if you had to re-log in this week, chances are that your account was compromised. Leo also says this is a good time to change your password and turn on 2 Factor Authentication in your Facebook settings.
Linda thinks her email accounts on Google and Yahoo have been hacked. She tried to log in, and it says "account no longer exists." What can she do? Rich says she may or may not have luck recovering it because Google has billions of accounts, and there's no deal tech support. Here's a good place to start to recover her account: https://support.google.com/accounts/answer/7682439?hl=en.
When visits Facebook, he's been having issues where the page scrolls on its own. Leo says if it happened everywhere, it could be a stuck down key, but since it only happens on Facebook, that's an indicator for software. Could someone be taking over his account? Leo says probably not. Just in case, however, he should go into his Facebook settings and turn on 2nd factor authentication. Then if someone tries to hack his account, it'll send him a notification asking if he's logging in. If it's not him, they can't log in.
Melanie finally got Google to reset her password and now she wants to know how she can prevent having her account hacked in the future. Leo says that the first thing is to have a recovery phone number and a different email for recovery. Then she should turn on 2-factor authentication. Making her password really difficult to crack is a good idea. Leo recommends using a password vault, like LastPass, and have it generate her passwords. Then she only has to remember LastPass's password and it will take care of the rest.
Sending unsolicited text messages is bad form, and Facebook got caught using their 2 Factor Authentication database to send out ads and other notifications.
Facebook admitted their faux pas and apologized. Leo says that's become the modus operandi of Facebook: move fast and break things, then apologize. In other words, better to ask forgiveness than ask permission.
Melanie's email account was hacked so she changed her password and set up 2-factor authentication. Now when she logs in, it tells her there's been "too many attempts" and it logs her out. Leo says that there is a Google help chat where she could get it reset. There's also a phone number that she can call. She should check under Google Help.
Tom wants to know how Apple's 2 Factor Authentication works with Find My Phone. When he logs into iCloud to look for his phone, it'll send his 2 Factor Authenticator to his phone. But how can he find his phone that way? Leo says that Apple does 2 Factor different from everyone else. If he has another Apple device like an iMac or iPad, then he could do it. It'll send the code to all of his Apple devices. Not just the iPhone. He can also use trusted phone numbers and enroll a landline or his wife's phone that they will call and give him the number audibly.