Great post for a great topic. I'd like to add to this, specifically on the password issue.
Regardless of how strong your password is, if you reuse it, it is inherently weak. Different passwords for different services, always.
Without going into too much detail, as a rule of thumb, the longer the password, the better.
Similarly, passwords rooted in reality (anything anyone who knows you knows about you) are inherently weak.
Remembering long, obscure passwords that are unique to each service is too difficult for almost everyone. My best suggestion is to use a password manager. There are many to choose from, including LastPass, KeePass, and Apple's upcoming iCloud Keychain, etc.; however, my personal choise is 1Password from AgileBits. Yes, it's expensive to fully implement across all of your devices, but AgileBits has fantastic support, applauded security, and great design and implementation. Make the decision for yourself, but I implore you to improve your password security in one form or another.
If you decide to go the password manager route, you only need to remember a handful of strong, secure passwords.
TheBeastDam raises a great point in two-factor authentication. You should enable it on any service that offers it. Gmail, paypal, and Apple are a few that spring to mind. There has been some discussion about the actual usefulness of Apple's two-factor auth, but something is better than nothing.
Good reading on the subject of digital security:
Comment has been collapsed.
I've been using KeePass for quite some time and it's great. Only feature 1Password has that's missing from KeePass is the specific credit card entries, but those can be stored as passwords. I don't think that feature is worth $50 considering that 1Password seems to only have AES-128 encryption compared to KeePass' AES-256. KeePass also has plugins to add more features.
Comment has been collapsed.
I DO enjoy the credit card feature. Regarding 128 v 256: http://blog.agilebits.com/2013/03/09/guess-why-were-moving-to-256-bit-aes-keys/ So it'll have that soon. What plugins do you use for KP?
Comment has been collapsed.
I guess the credit card feature is handy, if you have several credit cards and make a lot of online purchases.
Couple of backup plugins and a plugin to "integrate" the password database with my browser. I also use MiniKeePass on my phone.
Comment has been collapsed.
I see. 1P has a built in backup feature, and I set up a symbolic link in my dropbox so just in case somethings happens to my primary pc. Ditto browser plugin, just comes with the app. Had to buy the iOS version though, that sucked. I wholly agree that 1P is expensive, but I feel like I get a premium, polished experience and thus haven't felt like it was money poorly spent. Yet. :)
Comment has been collapsed.
Great advice. I just use gmail with phone verification so if other than my pc logs in my email, it sends a code in my phone to enter. Of course all my passwords are different but the only weird ones which I remember are my email and my paypal. Also, I have different email for games and another for the rest, all housed under the roof of outlook.
Comment has been collapsed.
I want to add. Take lots of evidence that you own before hand and make physical copies. I have an envelope filled with it. I printed out the email with my first purchase on steam, some other purchases, keys I've activated, everything.
Also the email I have link on steam is linked with 2 other emails all with different passwords with steamguard on also so they'd have to get all 3 of my emails to get to my steam account.
Comment has been collapsed.
Don't know your password (yeah, I mean it), use an offline password manager like keepass. Let it generate your passwords for you, and use it only when required (it also auto cleans the clipboard, and uses AES 256 bit compression, so veery secure app).
Also alter your passwords regularly.
Comment has been collapsed.
Another useful thing could be if you're not using an english keyboard or you have modified it so you can enter "exotic" characters, use them: most of the strange or composite characters aren't present on your average account thief or their brute-force characters list.
Also change your password periodically if you're particularly paranoiac or you fear somebody could have had access to wherever you write your password (the best place is always your brain at any rate - nothing's really forgotten if you take care to remember it).
Comment has been collapsed.
Very good advices. You shoud take into account and add the suggestions below but make it shorter and simpler so that people that aren't very good at english have a chance to understand. Also a bit of formatting would be good, as well as a section that would list the steps to take if one thinks one's account security has been compromised.
Not trying to tell you what to do, just suggesting. Nevertheless, good initiative and good job !
Comment has been collapsed.
It doesn't matter how big password you have, none actually hacks other peoples steam accounts, they just send keyloggers all over the place and take passwords, so no matter how big it is, he's gonna have it. Best way to do it is have Steam guard on and Gmail with 2-way protection on (Send you code to your phone if you want to access email)
Comment has been collapsed.
But what if someone asks really nicely for my password and promises he won't muse it for anything bad?
Comment has been collapsed.
"4. Install firewalls and anti-virus software so even if you download a trjoan, a keylogger etc. (with or without your knowledge) it will stop you from running it"
No shame in buying a good anti-virus, its maybe $20-40 a year and well worth it over the free ones
Comment has been collapsed.
I've actually read several articles saying that a lot of the free ones work even better than many paid ones. I guess many of them catch more and are therefore more effective, plus a lot of them are less invasive and use less resources.
Free doesn't necessarily mean inferior.
Comment has been collapsed.
maybe, but in my experience when I used free and switched to paid, the paid found things the free ones never did. I trust my AV and would rather support them then downgrade to save $40/yr
Comment has been collapsed.
I've been using Microsoft Security Essentials and Windows Firewall for about 2 years now and it certainly was better than F-Secure, which I had before. F-Secure used a lot more resources and gave many false positives.
Best way to avoid malware is to use common sense and not run or open anything you don't know to be safe.
Comment has been collapsed.
"Best way to avoid malware is to use common sense and not run or open anything you don't know to be safe."
Naturally, I worked in an electronics store and the amount of people with computer problems where just not paying attention to what they where clicking on :/
I use kaspersky(have for a few years now-love it), it runs well with all my microsoft/windows programs/firewall. I tried F-secure once and didnt like it. Nortan is just annoying and full of bloatware.
Comment has been collapsed.
You could mention the incognito mode that exists in some browsers.
Comment has been collapsed.
One thing I think Valve should maybe do is give everyone the option to receive a unique lock code, similar format to a key.
If you realized your account had been compromised, you go to a page on Steam, put in your account name and lock code and your account is locked until support gets round to dealing with your problem. It could be in the same place as where you report to support.
This way you can minimize the damage that the hacker can do while waiting for support.
Comment has been collapsed.
on other services just remember to print codes if it allows and only supports gauth. I forgot to print codes on dropbox and when i lost my phone i locked out myself from my own account for good.
google is specially strong on that apart from gauth and printable codes, it allows to register actual phone numbers that can be sent sms or voice called (which i found fantastic)
if you have a secure computer at home you can also set up chrome with a gauth to help if you lose your phone
Comment has been collapsed.
Profit?
Steam client will log in automatically, lastpass will log in to steam api in browsers. Would be hackers need your phone to get any of your passwords.
Comment has been collapsed.
Also, write down the cd keys you activated on your steam account, support might ask for that as a proof that you are the real owner of the account.
Comment has been collapsed.
Let me also add a few tips that aren't so well known:
Comment has been collapsed.
So, what about people like me who don't want to trust those password generator thingies, and I can't think of a new password? I have only had one account hacked and that was my Facebook and I was given a notification immediately so I locked them out, and changed my 10 character password (with numbers symbols and letters) to a 21 character password. But I currently have 3 passwords I use, one is a crappy one for sites that don't allow symbols (believe it or not they still exist) and then my two safe ones... The 10 character is used for most sites, and the 21 character is for like two or three sites... Anyone know what I could do to remember or come up with new passwords?
Comment has been collapsed.
I have a 20 character password that I use for any service as my base password. After Using that password as the base, I then take something I will definitely not forget and that is in some way connected to the service the password is used for and add that + a unique special character string. So I have like 30+characters and still easily remember them because I got the base password in all of them. It is certainly not the most secure thing, but I just want it to be hard to brute force. I got a decent firewall and antivirus, javascript blocker and a really strict rules set for my browser. Add regular malware scans on top, and I'm a happy camper.
Comment has been collapsed.
That's all nice and dandy, but you can't just never log in to your email at university. It's pretty much required, and I'm not going to change my password every time...
I mean, many of these tips are good, but some of you may be overdoing it :p
Comment has been collapsed.
Another option is to use a separate email account for registrations. Make sure it's not linked to your main email. That way, if someone steals your main email they can't use it to steal your other accounts with password resets. Of course, the downside to this is that now you have to remember the password to your separate email account which you never use...
Comment has been collapsed.
I can tell you from experience with accounts, using a university email is not a good idea for account sign ups. Once you stop going to school that email will be closed and you'll be unable to receive communications about your account and if you forget the password it's difficult to reset. I've had more than one customer lose access to an account because they forgot the password and couldn't access a university email any longer once they graduated or dropped out of school.
Same goes with ISP emails and work emails. Using an email that will be disabled or deleted at some point is never a good idea unless you are very good about updating your info once the email is deleted to ensure you can receive communications.
However, when you log in on a shared computer you just want to be sure to log out and not save the password. I've used shared computers at work to check my email before, but I make sure to log out when I'm done. If the computer allows it, clearing cookies and temp files is a good idea to be sure your stuff is gone.
Comment has been collapsed.
I don't. I always open my e-mail at home. And if you absolutely have to do that then I suggest you just create another account for the stuff you need at the university and have a separate one for Steam and other accounts. Better safe than sorry ;)
Comment has been collapsed.
use a system like lastpass to be able to generate and store unique passwords for each site so that you don't have to repeat passwords constantly. That and especially if you use a service like lastpass, having dual factor authentication set up.
Comment has been collapsed.
725 Comments - Last post 22 minutes ago by leecee
1,951 Comments - Last post 1 hour ago by diehard
148 Comments - Last post 1 hour ago by jiggakills
13 Comments - Last post 2 hours ago by yush88
9 Comments - Last post 3 hours ago by yush88
5 Comments - Last post 6 hours ago by yush88
30 Comments - Last post 7 hours ago by cpyd
38 Comments - Last post 5 minutes ago by Xeradan
202 Comments - Last post 6 minutes ago by SJkr8
133 Comments - Last post 9 minutes ago by EinAnderer
219 Comments - Last post 11 minutes ago by Aerctaure
79 Comments - Last post 25 minutes ago by Vincer
790 Comments - Last post 39 minutes ago by grez1
89 Comments - Last post 42 minutes ago by herbesdeprovence
Those topics pop up every few days around here and I don't know if people are so gullible or just ignorant. I'm not trying to attack anyone here but let's face it - if you take good care about your accounts and the security of your PC then they won't be compromised. Either way here's a few tips which will lessen your chances of being hacked:
To some of you they may seem trivial but not everyone has the same knowledge about this kind of stuff. Other might say "why, but this point is irrelevant, I always do that and I'm fine!" - irrelevant. Just because you're fine so far doesn't mean you will be fine forever. Besides, it applies to me as well. I've never been hacked but maybe someday I will. Maybe some day some smart alec hacker guy will outsmart me and my security precautions. But precautions don't cost you anything and they can save you a lot of money you put into your Steam, Origin, Uplay and other accounts. The choice is yours.
Cheers!
Comment has been collapsed.