© Els Paxton LLC. All Rights Reserved

© Els Paxton LLC. All Rights Reserved

© Els Paxton LLC. All Rights Reserved

You’re Never Done Getting More Secure

If you are not yet using 2FA (two-factor authentication) for your accounts and app access, you’re behind. 2FA simply means that whoever is trying to access an account needs to enter credentials through two different means. If someone steals your password, they only have one method. 

The method of using 2FA is traditionally your username/password as the first authentication, followed by receiving and entering a one-time code sent to your phone via text. Since you have physical control of your phone, this second authentication step seems extremely secure. Unfortunately it isn’t anymore.

The New Scam

Fraudsters are contacting cell phone companies posing as people, and convincing the cellular provider to change the cell phone SIM card to one they hold. You have physical control of your phone, but the phone you hold is no longer associated with your number. That’s with the fraudster now, who could use your stolen username and password to pass first authentication, and then receive the SMS one-time code for the second authentication. You don’t realize it. You never see it, until you look into your bank account and see zero balance.

Your Options

So how do you keep up with everything as fraudsters and anti-fraud solutions advance so quickly? Every time a new solution is made, the bad guys start figuring out how to get around it before you’ve started even using it. I believe you have to put the solution in place that you understand and will actually use, even if it isn’t the best anti-fraud solution out there today. Then increase your knowledge and push yourself into the next generation solution. You never actually finish getting to the best level of security…you only move forward to better. 

Understanding the generations of security will help you see where you are today and where you need to go for tomorrow.

  • Gen 1: Use a password to secure your account. This started with writing down your username and password so you wouldn’t forget it. We were told to stop writing it down so no one can find your info under your keyboard. Makes sense, but we’re human so we countered with using the same password for everything. 

  • Gen 2: Move to Password Managers that you can access with a single username/password that you remember, but that puts different usernames and passwords into all your apps/websites/accounts. Nothing is written down, and if one password is compromised your others are safe...unless they cracked your Password Manager.

  • Gen 3: Start using two-factor authentication (2FA). Any time you enter your username and password, you’re completing the first level of authentication from the website. But it then requires a second, often a one-time code that it sends to your cell phone or email. 

  • Gen 4: Increase 2FA’s robustness with authenticators instead of one-time codes sent to SMS text or email. The app with the code is on the cell phone you’re holding in your hand, not as a text message or email that a fraudster might have access to. 

  • Gen 5: Move into Passkeys. You no longer enter a password into your Password Manager at all. Instead the system generates a credential that you don’t actually read or type at all. It’s like a coded message now, the kind of thing spies would have to try to crack. Your device verifies you are the one authorized to use the Passkey through your fingerprint, face, or PIN.

Challenges in getting there abound. Not all websites are enabled for Passkeys or even Authenticator Apps. So you have to be comfortable with a lot of complexity if you want to be the most secure for your setup. If the security option you set up isn’t intuitive to you, you’ll overly frustrate yourself and decide to go backwards. 

To solve it, start by asking yourself “which Password Manager is right for me?” Companies like Google make it easy and frictionless for you. You use their password manager, their email, their browser. Everything is built to work together, so you hardly feel any confusion or additional work. That’s great for efficiency, but what happens if someone gets your Google account? They’ll have all of that info and control, not just your emails. Moving your Password manager to a non-integrated app, like 1Password or Bitwarden, adds a little extra pain on logins sometimes, but a lot more security. But remember, if it’s too hard for you to use, you probably won’t use it. An integrated password manager is better than no password manager at all

 

Next explore your Authenticator App. These can be integrated or non-integrated, much like Password Managers. The integrated versions would be concepts like Google Authenticator or Microsoft Authenticator. But there’s also Authenticator Apps integrated into your stand-alone Password Managers. For instance, 1Password has Authentication as well as Password Management. And there are authenticator apps that are truly standalone, meaning they are not tied into any password manager or account provider. Aegis and Ente Auth are examples.

The same risks/rewards apply: the more integrated your Authenticator App is for you, the easier it is to use. But as soon as someone cracks one piece, they might have your Authentication as well. 

A Personal History

I used to use my Google account for everything. Its password manager syncs effortlessly when I create new accounts on other apps, banks, etc. I combined this with 2FA for every website I could, sending SMS One Time Codes to my cell number on file.

Then I realized that, while easy for me, all of my eggs are in this one basket. If someone ever got access to this Google account they would have every password. I felt better with 2FA protection, but still vulnerable.

So I moved to Bitwarden, and added the Chrome extension to reduce some (not all) of the login friction. It definitely took some getting used to, and is still frustrating sometimes. Chrome doesn’t make it easy (it wants you to stay in Google Password Manager). It’s absolutely been a challenge for my family. But we spent a lot of time together going through the new processes to get them comfortable with it, and we’ve settled in now.

When I learned of the SIM theft scam, I decided to change my 2FA options from SMS one-time codes to an authenticator option. I want to keep my email/storage separate from my password management, and now have to find an alternative to my cell phone being the second authentication method. 

It’s a challenging decision. I know I do NOT want to use Google Authenticator since I’m on gmail. Using it could put my authentication in the hands of any fraudster who broke into my Google account. Microsoft and Apple become options as standalones (along with the likes of Aegis), since I’m not using those accounts. I settled first on my Password Manager app. The authenticator is built into the app, which I’ve gotten used to using.

In the last month I’ve found this easy and frictionless. I’m very comfortable, and that gives me pause. I’ve put too many eggs in this Password Manager basket. If someone cracks into my Password Manager, they would have my username/passwords to enter for the first means of authentication, then easy access to my second method of authentication. So, for me, I’m adding a bit more clunkiness to my log-in concepts to keep my 2FA options as separate as possible.

Your Next Steps

What’s the best option for you? It really does depend on you and the amount of comfort you have in navigating technology. If you are a small business, you have to ask yourself about the technology comfort level your employees have as well. If you are managing the family passwords, you have the same issue. And if it’s just you…well, your comfort here is just as important. When someone just doesn't “get it”, then they’re not going to use it. 

Evaluate the concept: you need to use 2FA, but really should get as much security out of it as you can realistically handle. If you are uncomfortable with complex options, perhaps dedicate some time to learn digital tools and increase your confidence. As your tech comfort increases, you can protect yourself, your family, and your business more. 

A final note: plenty of apps and banks do not even allow for an Authenticator App as the second authentication option in 2FA. Or they may only allow specific options, like Google and Microsoft. If you can get comfortable with using multiple options, you can secure yourself better. And keep an eye out as those banks/apps start to add the capability, so you can shift when they do.