Don’t have your account hijacked. Secure your online accounts with more than a password.

เผยแพร่เมื่อ: 23 พ.ค. 2562 · ฝ่ายสนับสนุน · 3 นาทีในการอ่าน

Research published at the end of last week argues that the typical user can significantly harden the security of their online accounts by linking a recovery phone number that can send an alert if there is suspicious activity on the account.

The research, conducted by a team from Google alongside researchers from New York University and the University of California, San Diego, found that when a Google account was linked to a phone, account takeover attacks by automated bots were prevented 100% of the time.

What is more, as a blog post from Google’s security team describes, there’s clear evidence that using two-step verification via a smartphone can help prevent the majority of vast majority of even targeted account takeover attacks:

“We found that an SMS code sent to a recovery phone number helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks. On-device prompts, a more secure replacement for SMS, helped prevent 100% of automated bots, 99% of bulk phishing attacks and 90% of targeted attacks.”

The research, which examined over 350,000 real-life hijacking attempts on a sample of 1.2 million users, underlines the importance of being proactive in using *some* method to protect your online accounts – even if you aren’t prepared to enable two-step verification or Google’s Advanced Protection feature for users who might be at most risk.

Google claims that during its study it found no users who exclusively used hardware security keys to authenticate logging into its online services fell victim to targeted phishing attacks.

Securely protecting an email account is, of course, of paramount importance to even the typical internet user as it is the centre of their online life.

A compromised email account doesn’t just allow a malicious hacker to peruse through your private communications, steal the addresses of contacts, and even send emails appearing to come from a particular individual. It also opens a backdoor into other online accounts, many of which will be using your email address as your username, and be willing to send the hacked email account a password reset link.

And if, for any reason, you haven’t shared your number with Google and enabled a recovery phone number to harden the security of your account, automated bots can still often be defeated through knowledge-base challenges (such as asking you to confirm your last sign-in location or secondary email address if you are logging in from a different device or part of the world)

Unfortunately, such information can itself be coaxed out of unsuspecting users in phishing or targeted attacks which aim to trick users into revealing additional identifying information.

So, why doesn’t Google simply make security challenges compulsory? Why isn’t it forcing its many millions of users into solving a challenge when they log into the system in order to keep malicious hackers out?

The answer, of course, comes down to human nature.

In its experiments, the academic researchers found that 38% of users did not have access to their phone when challenged. Another 34% were unable to recall their secondary email address.

“Our results illustrate that login challenges act as an important barrier to hijacking, but that friction in the process leads to 52% of legitimate users failing to sign-in – though 97% of users eventually access their account in a short period.”

Personally I have enabled two-step verification or two-factor authentication on all accounts where it is supported, and have never felt frustrated that I might need to take a few extra seconds entering a six digit number alongside my username and password at login. In some of my most critical online accounts I also defend them with a hardware key.

If that’s not for you though, please do *something*. Have some additional level of security enabled if possible – even if it’s just an additional security question asking you a question that a hacker is unlikely to know the answer to.

Some hackers are getting more devious and more sophisticated in their attacks. It’s time for you to modernise how you protect your accounts against them.

ทดลองใช้ Bitdefender ฟรี 30 วัน

การป้องกันที่ได้รับรางวัลสำหรับทุกอุปกรณ์ของคุณ

รับเลยตอนนี้

ต้องการความช่วยเหลือ?

ช่างเทคนิคของเราพร้อมให้บริการคุณตลอด 24 ชั่วโมงทุกวัน

ไปที่ฝ่ายสนับสนุน

บทความที่เกี่ยวข้อง

ปิดอัพเดท windows 10  (วินโดว์ 10) | วิธีปิด Windows Update

ปิดอัพเดท windows 10 (วินโดว์ 10) | วิธีปิด Windows Update

เผยแพร่เมื่อ: 23 ก.ค. 2569

มีทางแก้หลายทางที่จัดการกับปัญหาที่น่ารำคาญ และก่อกวนกับเครื่องคอมพิวเตอร์ของคุณ หนึ่งในนั้นคือ การปิดการอัปเดตอัตโนมัติ (Automatic Updates) ของ Windows 10 เราจะทำให้คุณดูว่าจะมันทำอย่างไรและช่วยให้คุณมีสามารถควบคุมเครื่องคุณได้มากขึ้น

อ่านต่อ
สปายแวร์คืออะไร (Spyware)?

สปายแวร์คืออะไร (Spyware)?

เผยแพร่เมื่อ: 23 ก.ค. 2569

คำจำกัดความโดยทั่วไปของสปายแวร์สามารถอธิบายอย่างง่ายๆ คือ สปายแวร์จะทำหน้าที่เหมือนสายลับในภาพยนตร์ที่คุณเคยดู แต่แทนที่จะบุกเข้าไปในอาคาร และติดตั้งสายดักฟัง พวกมันจะเจาะเข้าไปในคอมพิวเตอร์ หรืออุปกรณ์มือถือของคุณ กล่าวอีกนัยหนึ่งก็คือสปายแวร์เป็นหนึ่งในประเภทของมัลแวร์นั่นเอง

อ่านต่อ
ความปลอดภัยสำหรับธุรกิจขนาดเล็ก | แนวทางการป้องกันภัยไซเบอร์ สำหรับผู้ใช้อินเทอร์เน็ต

ความปลอดภัยสำหรับธุรกิจขนาดเล็ก | แนวทางการป้องกันภัยไซเบอร์ สำหรับผู้ใช้อินเทอร์เน็ต

เผยแพร่เมื่อ: 23 ก.ค. 2569

มันเป็นการง่ายที่จะคิดว่าเพราะคุณเป็นเพียงธุรกิจขนาดเล็ก อาชญากรทางไซเบอร์จะไม่โจมตีบริษัทของคุณ ความคิด“ ไม่มากที่จะถูกขโมย” นั้นเป็นเรื่องปกติสำหรับเจ้าของธุรกิจขนาดเล็ก ที่เกี่ยวข้องกับความปลอดภัยในโลกไซเบอร์ แต่มันก็ไม่ถูกต้องและไม่สอดคล้องกับความปลอดภัยในโลกไซเบอร์ของบริษัท ขนาดเล็กในปัจจุบัน

อ่านต่อ
ไวรัส โทร จัน? เทคนิคการป้องกัน การตรวจสอบ และการกำจัด

ไวรัส โทร จัน? เทคนิคการป้องกัน การตรวจสอบ และการกำจัด

เผยแพร่เมื่อ: 23 ก.ค. 2569

Remote Access Trojans (RAT) ได้แสดงให้เห็นแล้วว่า เป็นความเสี่ยงที่ยิ่งใหญ่ของโลกนี้ เมื่อพูดถึงการโจรกรรมข้อมูลคอมพิวเตอร์ หรือแค่เพียงเล่นตลกกับเพื่อน RAT จัดเป็นซอฟต์แวร์ที่เป็นอันตราย ที่ช่วยให้ผู้ควบคุมเครื่องนั้น สามารถโจมตีคอมพิวเตอร์ และเข้าใช้งานจากระยะไกล (Remote) โดยไม่ได้รับอนุญาต RAT มีมาหลายปีแล้ว และเราก็ขอยืนยันว่า การหา RATs บางอย่างนั้น เป็นงานที่ยากยิ่งสำหรับซอฟต์แวร์ Antivirus ที่ทันสมัยทุกยี่ห้อ

อ่านต่อ
มัลแวร์เรียกค่าไถ่คืออะไร (Ransomware คือ) - ไวรัสเรียกค่าไถ่?

มัลแวร์เรียกค่าไถ่คืออะไร (Ransomware คือ) - ไวรัสเรียกค่าไถ่?

เผยแพร่เมื่อ: 23 ก.ค. 2569

มัลแวร์เรียกค่าไถ่ หรือไวรัสเรียกค่าไถ่นั้น ถือเป็นมัลแวร์ประเภทหนึ่ง ทันทีที่หลังจากเครื่องเป้าหมายติดมัลแวร์ดังกล่าว คอมพิวเตอร์จะถูกเข้ารหัส หรือบล็อกการเข้าถึงข้อมูลบนดิสก์ของคุณ แล้วแจ้งหรือยื่นข้อเสนอให้เหยื่อ สำหรับโอกาสความเป็นไปได้ของการกู้คืน แน่นอนว่ามันไม่ได้ถอดรหัสได้ฟรี แต่จะให้เหยื่อทำการโอนเงินไปยังบัญชีที่ระบุของผู้ไม่ประสงค์ดี

อ่านต่อ
Don’t have your account hijacked. Secure your online accounts with more than a password.