How Do You Maintain Secure Passwords?

by csm
9 replies
This might be a bit off-topic for a marketing forum, but I'm sure everyone here has to manage multiple passwords for multiple accounts, many of which contain secure information and, of particular importance, financial information.

I'm currently dealing with a Paypal security issue that seems to be deeper than I first imagined, and I now know that I need to change passwords for all of my important accounts (banks, credit cards, etc.). I'm in a dilemma trying to figure out how best to manage these to be secure, but also not over-burden myself with a multitude of different passwords that are not memorable.

Last week, my Paypal account was hacked into, someone changed the password, and also made a $1700 purchase against my AmEx account that was set up as my primary credit card in Paypal. All has been resolved in terms of the funds credited back, and I've changed the password to something gibberish, and now I only copy & paste it into the password field when I log in instead of typing it in (Paypal suspected a key logger, which I don't really believe since I'm on a Macbook Pro and I did scan the machine for spyware, key loggers and viruses).

Anyway, today I discovered a temporary authorization on my VISA account from Paypal. What was strange about it, is that this particular VISA account is *not* set up in my Paypal account. When I spoke to Paypal, they now tell me that on the same date as the AmEx fraud, someone tried to enter my VISA account number into my Paypal account and use it, but it was somehow declined. This is spooky stuff, to think that someone has the VISA account number AND my Paypal account information, when the two were never related.

So now I am paranoid about changing the passwords on all of my bank accounts, credit card access accounts, Paypal, etc. -- anything with sensitive information. But I have at least 15 different accounts (if not more) that should be protected.

Does anyone have any tips for how to come up with passwords that are safe but can also be remembered? Do I really need to set up separate passwords for each one, using upper/lower case, numbers, symbols and all random and different for each account? How do you keep these handy?

Susan
#maintain #passwords #secure
  • Profile picture of the author Maria Gudelis
    Hey Susan - try 'roboform' - it truly is a great tool for password management.
    Signature

    Brand NEW: How To Dominate Facebook SEO - LIVE Coaching - Closes SOON! Get In Now Click Here


    {{ DiscussionBoard.errors[348536].message }}
    • Profile picture of the author csm
      Hi Maria,

      I work from several different computers including my PC at work on which I don't have Administrator access (so cannot install any private software), a Macbook Pro, and a netbook (Windows). So I don't really want an application tied to a computer. I often log into these accounts from multiple locations.

      Susan
      {{ DiscussionBoard.errors[348543].message }}
      • Profile picture of the author sylviad
        You're only talking 15 accounts - get a notebook and write them in, or open a Word document and store them there. If you put them in Roboform, there's a risk of someone hacking into them. I never keep financial-related passwords in my computer. I use Roboform for everything else, but not those.

        Apart from the keyword issue, it sure sounds like your personal info has been stolen - either someone has access to your computer when you aren't there, it's being hacked from outside, or someone got their hands on your wallet or receipts for goods purchased on your credit card.

        Always make sure you SHRED or BURN any personal information that you toss out. It's becoming increasingly easy for people to steal your identity from recycling bins you leave by the curb. Remember, once you put that out there, it's free game for anyone who wants it. There are no laws against people taking stuff from your garbage once it's at the curb - unless it's to steal your identity or defraud you in some way.

        I would recommend Roboform (it's fantastic) to store your non-private passwords. It has a neat feature that will generate passwords for you. You can set it produce passswords at different levels of security. Then, store the actual login elsewhere, as I said.

        Sylvia
        Signature
        :: Got a dog? Visit my blog. Dog Talk Weekly
        :: Writing, Audio Transcription Services? - Award-winning Journalist is taking new projects. Warrior Discounts!
        {{ DiscussionBoard.errors[348580].message }}
        • Profile picture of the author csm
          Yeah, Sylvia, the whole thing is really spooky. The VISA account that was compromised is a rarely used account.

          I live in Denmark and have a second home in the U.S., where we are for only 6-7 weeks a year. The VISA is registered to my U.S. address, but I don't get any hard copy account statements; all online. Also, I only use it as a back-up if someplace doesn't take my AmEx which is my card of choice. This year, I think I've only used the VISA to fill up the rental car with petrol when we've been in the U.S.

          There is no way anyone got a hold of my computer as it is never anywhere public. We also have our broadband connection protected at home. The only security risk we can think of is when we're traveling in the U.S. and use an unsecured free wireless connection from a hotel or cafe.

          I believe I'm really careful.

          Susan
          {{ DiscussionBoard.errors[348605].message }}
          • Profile picture of the author sylviad
            Did you know that hackers can sit in a car outside your home and gain access to your tech connections? There was a documentary on that recently where the computer pro demonstrated it. He had his laptop open with some program running. As he drove down the street, he got a hit when someone had a computer on. Once he got that hit, he would have been able to log right onto the info being transferred from the computer.

            Yes, you have good reason to be scared. Hi tech is getting far too sophisticated and thieves are making good use of it.

            Thieves can steal your credit card info, too. Have you not heard of people being able to scan your card and return it to you without you ever finding out? Shifty store clerks have been caught doing this to steal from people's accounts. It only takes them a second. They keep their own little scan device in their pocket which stores your info on a flash disk. They can then take it to their computer and download your info to gain access to your account.

            You can never be too careful.

            If you think your card is being used illegally, contact your CC co. BTW, they don't even need to scan your card - all they need is your card number which they can then manually enter into the computer to buy things under your name.

            Always keep your eye on your CC when you shop. That's about all you can do... short of not using it at all.

            Sylvia
            Signature
            :: Got a dog? Visit my blog. Dog Talk Weekly
            :: Writing, Audio Transcription Services? - Award-winning Journalist is taking new projects. Warrior Discounts!
            {{ DiscussionBoard.errors[348637].message }}
          • Profile picture of the author tj
            Originally Posted by csm View Post

            Yeah, Sylvia, the whole thing is really spooky. The VISA account that was compromised is a rarely used account.

            I live in Denmark and have a second home in the U.S., where we are for only 6-7 weeks a year. The VISA is registered to my U.S. address, but I don't get any hard copy account statements; all online. Also, I only use it as a back-up if someplace doesn't take my AmEx which is my card of choice. This year, I think I've only used the VISA to fill up the rental car with petrol when we've been in the U.S.

            There is no way anyone got a hold of my computer as it is never anywhere public. We also have our broadband connection protected at home. The only security risk we can think of is when we're traveling in the U.S. and use an unsecured free wireless connection from a hotel or cafe.

            I believe I'm really careful.

            Susan
            There is a possibility that when you used the CC at the Gasstation the copy of your CC went into the trash and someone else got a hold of the copy and your cc number - it's also called dumpster diving."

            Timo
            {{ DiscussionBoard.errors[348791].message }}
  • Profile picture of the author Kelvin Brown
    Hi Susan,

    Roboform has a multi computer solution. Roboform2go.

    You only need to install it on one computer. Transfer everything to flash drive supplied by roboform. When u go to the office just insert the flash drive, roboform runs from the flash. So nothing is installed on the PC. When u finish at that PC remove the flash drive, and it's like you were never there.


    I use this when i work at clients computers, because i have access to all my accounts, URLs etc.


    FYI: roboform is used or can be used for much more than security
    Signature

    Kelvin Brown

    {{ DiscussionBoard.errors[348710].message }}
  • Profile picture of the author TheRichJerksNet
    Hi Susan,
    Sorry for your trouble...

    Always, always, always make sure you type in paypalcom in your browser window. Never click on any links in your email to go to paypal, not even from real customers. It is good practice just not to click on any paypal link in email at all.. Always type it in.

    As for storing password.. The good old fashion way is the best way. Get a pen and paper and write them down..

    DO NOT USE ANY ROBOFORM - Store Your Passwords Offline and Off your Computer !!

    James
    {{ DiscussionBoard.errors[349057].message }}
    • Profile picture of the author csm
      Thanks all for the input.

      James -- I've never clicked on an email link to go to Paypal. I'm aware of the phishing schemes and am very cautious to not access my account by clicking on links.

      Timo - The gas station use was at the pump, with no clerk involved and no hard copy receipt. But I have certainly heard of credit card info being stolen from the automatic pumps. But for someone to have stolen the cc info from a gas pump (a manual offline transaction), and then been able to figure out my online Paypal account identity, is just too bizarre. I have to think that the entire theft of both bits of data was somehow online-related.

      Kelvin - Thanks for the extra info about Roboform.

      Syliva - Thanks, yes, I've heard of cards getting scanned when they are out of your hands just for a few seconds. What is odd about this card is that it has never once been handed to a third party. It has only been used at automatic gas pumps (which I know can be compromised), for a total of maybe 5 times this year. I've heard of people's card numbers being stolen that way, but don't know how it could then have been related to the identity of my Paypal account in order for someone to hack in and try to set the card up for use on my own Paypal account. I have already contacted my CC company and the card has been cancelled and a new one is being issued.

      I think my biggest fear is some kind of key logger on my computer that MacScan did not pick up. Because if someone is logging my key strokes, then just changing my passwords is not going to help if they're still accessing private information on my computer.

      Susan
      {{ DiscussionBoard.errors[349273].message }}

Trending Topics