Security @home
Our top 10 IT security tips for security @home!
The IT security tips are best suited to work through them step by step. Some of the points are quickly done. Maybe you already have a few behind you? All the better!
Still passwords like "password", "qwerty", "12345678", "iloveyou" in use? Then it is high time to change them! It will only take a few minutes for an attacker to guess the password. A strong password protects your account from quick brute force attacks. One that you can remember And not to use the same passwords on different platforms! Keep it safe? Sure! With other parts? Better not!
A big IT security problem is the multiple use of passwords. Multiple email and password combinations are quickly tested on different websites. This happens partly fully automatically. We have already looked at a tool for this in the past. More information can be found here.
Even though it is no longer recommended to change the password every 90 days, of course this does not mean that the password should not be changed at all. If someone has to manage many passwords, we recommend a password safe at this point. KeePass is a recommendation - and a free open source solution!
Updated software with fixed bugs and vulnerabilities is simply safer. The risk of a successful attack is reduced. Even though quick updates can cause problems, we recommend installing them as soon as possible. Outdated software is one of the biggest security risks on the net. And in the private sphere, you are in demand and responsible yourself!
Do not share personal and sensitive information via social media. Some information should simply not be shared. It is not very advisable to publish photos of your passport, driver's license or official documents, bank cards, tickets. However, if you feel the need to share this information, all personal data should be carefully hidden and/or blacked out. And be sure to check for bar, bar and QR codes!
Be prepared! It is always better to have a backup of valuable data. Because if data is blocked, deleted or otherwise destroyed by ransomware attacks, the business stands still. Cloud storage is one solution - but you have to take a leap of faith with the service provider or vendor.
A classic backup is still a good way to gain access to lost files. All you need is an external hard drive. This should be slightly larger than the hard drive in your computer. Another important point: Connect the hard drive only as long as necessary! In case of a ransomware attack, the external hard drive would otherwise be encrypted as well.
Antivirus software helps to protect the operating system from viruses and malware. Modern antivirus software has additional features such as safe surfing, protection of sensitive files, secure password storage and webcam spy detection. This greatly increases personal IT security.
The onboard resources of Windows 10 are sufficient for easy protection against malware. This is also confirmed by current tests: Windows Defender is completely sufficient as free virus protection! Only with the already mentioned additional functions a paid solution makes sense.
You have received an e-mail with an attachment or link from an unknown address - note that this could be an attempt to manipulate your identity or devices and install software to spy on you. Before revealing the constantly used e-mail address, you should think about using a trash mail.
Even antivirus software is not a panacea. Stay suspicious, don't click on unknown attachments and only click on links if you can't help it. The 3-second check from the BSI is useful at this point: Do I know the sender? Does the subject make sense? Do I expect an attachment?
The encrypted connection of data is slowly becoming the standard on the Internet. But occasionally you will come across websites that do not offer this encryption. Anyone can recognize it by "HTTPS" or "HTTP".
If the S is missing, the data is transferred in plain text over the Internet - a good opportunity for criminals to intercept and abuse this data. Modern phishing websites rely on encrypted connections. However, a green lock does not mean that the website is trustworthy! Especially for young people, access to the Internet should be restricted. For this purpose there are so-called youth protection filters.
In the city, in a café or at the train station. There are many places where free WLAN is welcome. But you should be sceptical if you don't need information to log in. Attackers can use sniffing tools to access unprotected channels, intercept and manipulate data. Nor should WIFI QR codes be scanned indiscriminately. Here too, the source and seriousness is crucial.
If you need the WLAN, e.g. if you are travelling abroad and your own SIM card does not work, you should reduce data traffic to the absolute minimum. For an increased security in foreign WLAN networks, point 10 is interesting for you!
The settings of the operating system, the software used and the established services change regularly. New functions are added, others are deleted, some are merged.
All this leads to the fact that the settings are no longer set as I would agree with them. For this reason the settings should be checked regularly. Simple, but still important enough to mention them in the Top 10 IT-Security Tips!
A VPN tunnel encrypts incoming and outgoing data traffic. It is more difficult to identify and track people. However, you should choose a trusted VPN to ensure secure and encrypted communication. We have compiled a selection of VPN providers. At this point it should be mentioned that they do not offer anonymity.