Welcome!

Wearables Authors: Liz McMillan, Elizabeth White, Yeshim Deniz, Pat Romanski, Rostyslav Demush

News Feed Item

F-Secure Shares How to Avoid Changing All Your Passwords Every Time There's an Online Attack

Security Experts' Dirty Little Secret: They Don't Change Their Passwords Very Often, Because They Don't Need To...

SAN JOSE, CA -- (Marketwired) -- 08/19/14 -- Did you know 1.2 billion passwords were reportedly stolen by Russian hackers? Before that it was Heartbleed. After a widespread, nonspecific data breach, the conventional wisdom is that people should change all their passwords. But according to F-Secure Labs, there's a better way. With the right password management habits, you won't need to change all your passwords every time you hear about an online attack.

"Changing all one's passwords won't hurt, but it is cumbersome. Not only that, it's a Band-Aid fix that stops short of offering a stronger and more long-term solution," said Sean Sullivan, security advisor at F-Secure Labs. "Data breaches are the new reality, and it's no longer a question of if it happens to you, but when." Sullivan says rather than being told to change all their passwords, consumers need practical advice worth following. So when the next breach is disclosed, they will be in control and will only need to change those passwords they know are affected.

"The dirty little secret of security experts is that when there's a data breach and they recommend to 'change all your passwords,' even they don't follow their own advice, because they don't need to," continued Sullivan. "Unless I find out about a breach with a specific account, I don't worry about my passwords. That's because I use a tool to remember my passwords for me, and a few simple techniques that help to manage my accounts so as to minimize the risk."

So what are the successful strategies to avoid the hassle of changing passwords constantly? Sullivan points out a few key things:

Diversify to reduce your risk. Segregate your accounts by creating separate email addresses for different functions. For example personal, professional, financial. That way if one email is broken into, it won't compromise all your other information too. "Why not have a separate email address for your financial accounts? Then don't give that address to anyone but those financial institutions," Sullivan shares. A bonus: if you get banking-related email in your personal account, you'll know immediately that it's not legit.

When possible, use a different username than your email. Some services let you pick a unique username other than your email. When possible, it's good to take this option as it's that much more info a hacker needs to know. And use two-factor authentication when available.

Use a unique password for each online account. Using the same password to access different accounts is rolling out a red carpet for hackers. If a password for your Facebook account is stolen, criminals can hop over to your email and other accounts and try the same password there.

Don't give online accounts any more data than is absolutely necessary. The less that is there to be compromised, the better.

If you are notified about a breach to a specific account, change that password. This goes without saying.

Changing your account password habits may take a little effort, but in the long run it's easier and less stressful than having to change all passwords after news of every breach. And it's worth it to keep your personal data and online identity safe. Sullivan suggests starting small, taking care of one account at a time and building up until all your passwords are handled.

"This is the post-PC issue people need to worry about because all their accounts are in the cloud," states Sullivan. "There are two types of people in the world: Those that manage their accounts well, and those who are going to be in a world of trouble. Which group do you want to be in?"

It's easy with the right tools

Then how does one remember so many unique passwords and log-ins, and manage them effectively? F-Secure's password manager, F-Secure KEY, makes sure proper password management is as easy and painless as possible. With F-Secure KEY, there's just one master password to remember, so it's easy to have a unique password for each account. Usernames, passwords, PIN codes, and other important data are stored in one secure app.

F-Secure KEY now has a completely updated and refreshed mobile version. The new mobile user interface features a Favorites ring that makes it easy and fast to access all one's most commonly used account credentials. All versions of F-Secure KEY help you generate unique, strong passwords. KEY includes a news feed from F-Secure Labs, so you can stay up-to-date on major hacking incidents. Strong encryption protects all your data.

F-Secure KEY is free to download and use on any device -- Android, iOS, Windows, and Mac. To use Key with the same master password on an unlimited number of devices and sync passwords across devices via a secure European cloud, upgrade to the premium version, starting from $1.84 per month. F-Secure KEY is available via the Apple App Store, Google Play, and at f-secure.com/key.

Get the app!

More information
Infographic: Dealing with Passwords
Safe & Savvy: 1.2 Billion Passwords Stolen, But Does it Affect Me?

F-Secure -- Switch on freedom

F-Secure is an online security and privacy company from Finland. We offer millions of people around the globe the power to surf invisibly and store and share stuff, safe from online threats. We are here to fight for digital freedom. Join the movement and switch on freedom.

Founded in 1988, F-Secure is listed on NASDAQ OMX Helsinki Ltd.

f-secure.com | twitter.com/fsecure | facebook.com/f-secure

Media Contact:
Mark Karayan
LEWIS PR for F-Secure
415.432.2400

More Stories By Marketwired .

Copyright © 2009 Marketwired. All rights reserved. All the news releases provided by Marketwired are copyrighted. Any forms of copying other than an individual user's personal reference without express written permission is prohibited. Further distribution of these materials is strictly forbidden, including but not limited to, posting, emailing, faxing, archiving in a public database, redistributing via a computer network or in a printed form.

IoT & Smart Cities Stories
The deluge of IoT sensor data collected from connected devices and the powerful AI required to make that data actionable are giving rise to a hybrid ecosystem in which cloud, on-prem and edge processes become interweaved. Attendees will learn how emerging composable infrastructure solutions deliver the adaptive architecture needed to manage this new data reality. Machine learning algorithms can better anticipate data storms and automate resources to support surges, including fully scalable GPU-c...
Predicting the future has never been more challenging - not because of the lack of data but because of the flood of ungoverned and risk laden information. Microsoft states that 2.5 exabytes of data are created every day. Expectations and reliance on data are being pushed to the limits, as demands around hybrid options continue to grow.
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO's dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get...
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO and DXWorldEXPO are two of the most important technology events of the year. Since its launch over eight years ago, @CloudEXPO and DXWorldEXPO have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors! In this blog post, we provide 7 tips on how, as part of our world-class faculty, you can deliver one of the most popular sessions at our events. But before reading...
If a machine can invent, does this mean the end of the patent system as we know it? The patent system, both in the US and Europe, allows companies to protect their inventions and helps foster innovation. However, Artificial Intelligence (AI) could be set to disrupt the patent system as we know it. This talk will examine how AI may change the patent landscape in the years to come. Furthermore, ways in which companies can best protect their AI related inventions will be examined from both a US and...
The challenges of aggregating data from consumer-oriented devices, such as wearable technologies and smart thermostats, are fairly well-understood. However, there are a new set of challenges for IoT devices that generate megabytes or gigabytes of data per second. Certainly, the infrastructure will have to change, as those volumes of data will likely overwhelm the available bandwidth for aggregating the data into a central repository. Ochandarena discusses a whole new way to think about your next...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of ...
DXWorldEXPO LLC, the producer of the world's most influential technology conferences and trade shows has announced the 22nd International CloudEXPO | DXWorldEXPO "Early Bird Registration" is now open. Register for Full Conference "Gold Pass" ▸ Here (Expo Hall ▸ Here)