10 Things Making Your PC Easy to Hack The Grumpy Sysadmin https://www.youtube.com/watch?v=ZRtNPJO3wXY Transkript (automatisch erstellt) 0:00 Most people don't get hacked by some hoodiewearing genius pounding away at a keyboard in a dark basement. They get hacked because they reuse the same 0:10 password 12 times, click the link that practically screamed scam, and approved a security prompt without reading a single word. And before you'd say, "I'd 0:20 never fall for that," understand something. Almost everybody who falls for it said exactly the same thing. So today I'm showing you 10 ways ordinary 0:30 people make life ridiculously easy for criminals and exactly what to do instead. 0:39 Welcome back everyone. Grumpy Cisman here, the guy who fixes problems Microsoft swears doesn't exist. None of this requires a cyber security degree, a 0:50 $5,000 firewall, or wrapping your house in aluminum foil. You simply need to stop leaving every digital door open and then acting 1:01 surprised when somebody walks through. Let's shut a few of those doors. Number one, stop reusing the same damn password. 1:12 This is number one because it's still one of the easiest ways to turn one small breach into a complete disaster. You use the same password for your 1:21 email, Microsoft account, bank, Amazon, Facebook, and some website you joined in 2017 to download a free wallpaper. Then that forgotten website gets breached, 1:32 and your email address and password land on a criminal's list. Nobody has to crack a password. A computer simply tries that same combination against 1:43 hundreds of other sites. It doesn't get tired or bored, and it doesn't stop for lunch. That's called credential stuffing, and most of it's completely 1:53 automated. Every important account needs its own unique password. Use a password manager so you don't have to remember all of them. If you absolutely refuse to 2:03 use one, a password manager, that is, write the passwords down and lock the list somewhere physical. And no, a sticky note attached to the monitor 2:13 isn't somewhere secure. Using the same password everywhere isn't convenient. It's turning one stolen key into a master key for your entire life. 2:24 One leaked password should cost you one account, not all of them. Number two, stop protecting your email with only a password. Your email isn't just email. 2:37 It's the master reset switch for your digital life. Forget your bank password, the reset link goes to your email, Microsoft account, email. Shopping 2:47 accounts, email. Somebody owns your inbox, they can start collecting the rest of your accounts like Pokemon. Turn on two-step verification, also known as 2:59 two-factor authentication or 2FA, on your email first, then your Microsoft account, financial accounts, and anything else that matters. Use an 3:09 authenticator app or a physical security key when the account supports one. Text message codes are still better than nothing, but they aren't the strongest 3:19 option. We'll get to that in a bit when we talk about your phone. If your email still has nothing but a reused password protecting it, you don't have security. 3:28 You have optimism. Number three, stop ignoring the router running your entire house. Your router is the front gate for nearly every 3:39 connected device you own. Computers, phones, TVs, cameras, doorbells, printers, and every so-called smart gadget you drag home because apparently 3:50 the toaster needs internet access. now. And plenty of people haven't logged into that router since the technician installed it years ago. Do three things 4:01 today. Change the router's administrator password. That's the password used to manage the router, not your Wi-Fi password. Check the firmware updates. 4:12 Then confirm the wireless network uses WPA2 or WPA3 encryption. Put smart home and other untrusted gadgets on a guest or isolated network if your router 4:24 supports it. Those devices don't need to mingle with the PC holding your taxes, family photos, and every important document you own. If you haven't touched 4:34 your router this decade, congratulations. You've entrusted your entire home network to whatever settings happened to be there one afternoon years 4:43 ago. Those first three are the locks on the house. Now, let us deal with the people knocking on the door while pretending to be your bank, Microsoft, 4:53 or somebody else you're afraid to ignore. Number four, stop [snorts] believing caller ID. Caller ID isn't identification. It's a label, and 5:05 criminals can make that label say almost anything that they want. Your phone rings and the screen says it's your bank. The caller says there's fraud on 5:14 the account. The problem's urgent and you must verify something immediately. Maybe the call is legitimate. You still don't trust the person who called you. 5:25 Hang up. Get the real number from the back of your card, a statement, or the company's official website, and call it yourself. If the original call was 5:35 legitimate, you'll reach the same organization. If not, you may have just saved yourself one hell of a mess. Nobody legitimate needs payment and gift 5:45 cards, security code that just appeared on your phone, and Microsoft isn't calling out of the kindness of its heart to remove a virus from your computer. 5:56 If a stranger calls you and asks to remote into your PC, the answer is no. Not maybe, not after they explain it again. No. Period. Number five, stop 6:10 letting random messages choose where you log in. Your package couldn't be delivered. There was an unusual sign in. Your account will be closed in 24 hours. 6:21 There's always a crisis because urgency keeps you from stopping long enough to think. You tap the link, land on a page that looks exactly right, enter your 6:32 username and password, and hand both of them directly to a criminal. Stop admiring the logo and telling yourself the message looks professional. Scammers 6:42 have logos, too. Copying Microsoft's colors isn't exactly an advanced technical achievement. If you think the warning might be real, open your 6:52 official app, use your existing bookmark, or type the address yourself. Check the account from there. Also, look at the sender's actual email address, 7:02 not merely the friendly name displayed at the top. Never let an unexpected message choose where you log in. And if you're already thinking, "Good grief, 7:13 now I have to remember all this. I'M GOING TO KILL MYSELF." >> You don't. I took passwords, two-step verification, routers, scams, phone 7:25 security, backups, and the exact steps to follow when something goes wrong, and organized it all into secure your digital life in seven days. It's seven 7:35 focused missions, one per day, covering your PC, accounts, phone, home network, files, and a recovery plan. These are checklists you work through while 7:47 sitting at the computer, not a pile of theory you read once and forget. This is the complete security system I'd hand to a family member who said, "Just tell me 7:56 what to do." The links in the description. Do it before a criminal gives you a much less pleasant reason to start. 8:05 All right, back to the list. Number six, stop using an administrator account for everything. The first Windows account is commonly an administrator, and most 8:17 people keep using it forever. Browsing, email, downloads, and everything else. Modern Windows doesn't give every program full administrative access 8:28 automatically. User access control puts a prompt in the way. But when your everyday account's already an administrator, Elevation may require 8:37 only one distracted click on yes. Create a separate standard account for everyday use and keep a separate administrator account for, you guessed it, actual 8:48 administration. Then when something asks for elevated access, Windows requires the credentials for that other account. That extra interruption may be the thing 8:58 that makes you stop and ask, "Why did a PDF reader suddenly want control of the entire computer?" Yes, this is slightly less convenient. So is rebuilding a 9:09 compromised PC all weekend. Number seven, stop disabling security because something told you to. An installer tells you to disable the 9:20 antivirus. A forum post says smart screens annoying. Some technician on the phone wants the firewall turned off just for a minute. That's the moment you 9:31 should stop and ask why. Leave Windows security on. Leave smart screen on. Leave the firewall on. If a legitimate program triggers a false positive, 9:43 verify the publisher, download source, and file before creating an exception. If some random installer can work only after you blind Windows security, 9:54 perhaps the installer is the problem. Don't rip the smoke detector off the wall because it's making noise. Find out what's burning first. Your PC's mostly 10:05 handled. Now, we need to deal with the computer in your pocket and the backup people swear they have until the day they actually need it. Number eight, 10:15 stop leaving your phone wide open. Your phone contains your email, bank apps, saved passwords, photos, and the codes used to approve loginins everywhere 10:26 else. Yet, people protect all that with 1 2 3 4, their birth year, or absolutely nothing. Use a strong passcode, at least six digits, and preferably a longer PIN 10:39 or password. Enable find my device or find my iPhone so you can locate, lock, or erase it remotely. Hide message contents on the lock screen so 10:51 verification codes aren't displayed to whoever happens to pick up your phone. A SIM PIN can protect the physical SIM if it's removed or the phone restarts. It 11:02 doesn't stop somebody from convincing your carrier to transfer your number to a different SIM. for that. Secure the mobile carrier account with a strong 11:12 account PIN and enable a number lock or port out lock when the carrier offers ones. If a criminal steals your number through a SIM swap, every security code 11:22 sent by text goes to them instead of you. Your phone isn't just another device. In many cases, it's the key ring for everything else. Number nine, stop 11:34 calling it a backup when it's always plugged in. Maybe you copy your files to an external drive. Good for you. You're already ahead of most people. But if 11:45 that drive stays connected to the computer all the time, ransomware may encrypt the backup right alongside the original files. I've watched people 11:54 proudly point to their backup drive while the same attack destroyed both copies. Keep more than one copy of anything important and keep at least one 12:04 copy disconnected or somewhere else entirely like an unplugged external drive, another physical location, or a reputable cloud backup service that 12:15 preserves versions. Then test the backup. Restore a few files and make sure they actually open. Don't wait for a disaster to discover you've been 12:25 faithfully backing up corruption, empty folders, or nothing at all. A backup you've never restored from isn't a backup. It's a wish. Number 10, stop 12:38 having no plan for when something actually goes wrong. Eventually, something will happen. A password leaks, a card gets skimmed, malware gets 12:49 through, an account gets taken over. The people who recover quickly aren't necessarily luckier. They know what to do first and they don't panic click 12:59 their way into an even bigger disaster. Start from a device you know is clean. Secure your primary email account first. Change the password. Sign out of other 13:10 sessions. Remove devices you don't recognize. And check the recovery email address and phone number. Then inspect the mailbox for forward settings and 13:21 rules you didn't create. Attackers sometimes add rules that quietly hide password resets, bank notices, and security warnings. Changing the password 13:33 isn't enough if the bastard's already added his own recovery address or arranged for every warning to disappear. Change passwords anywhere the 13:42 compromised password was used. enable two-step verification and save fresh recovery codes. And while you're at it, contact your bank using a known 13:53 legitimate number if money or card information may be involved. In the US, freeze your credit with all three credit bureaus if identity information's been 14:04 exposed. A credit freeze is free and helps stop new accounts from being opened in your name. You don't need to know everything. You need to know the 14:14 first few correct moves before panic takes over. I want to give a quick genuine thank you to the channel members watching this one early. You're the 14:24 reason I can keep doing this without smiling at sponsors I don't believe in. I really appreciate you. Sincerely notice what most of this didn't require. 14:35 Expensive hardware, an IT department, or living in constant fear. It required unique passwords, a second step to log in, a router that's been touched 14:46 sometime this decade, working backups, and enough suspicion to stop before clicking whatever some stranger shoved in front of you. Security is rarely one 14:57 clever thing. It's 10 boring things you bothered to do before some criminal tested them. Do the boring work now or do the miserable cleanup later. If you 15:08 want the entire process laid out as 7 days of step-by-step checklists, that's secure your digital life in 7 days. Links in the description along with a 15:18 free security checklist to help you get started. Hit like, subscribe, and I'll see you in the next one. And remember, my friends, stay grumpy. 15:31 Click the link that they pract another physical location or a reputable Oh yeah. 15:45 [music]