@AriDavidPaul on Twitter
I've Spent 40+ Hours Ove...
I've spent 40+ hours over last 2 weeks doing primary research into cybersecurity. No easy answers (including from top cybersecurity specialists). Here's my intermediate conclusions. Please add/improve/disagree: /1 (View Tweet)
2/ Phone numbers - AT&T best of the big 3, make sure to have sim swap lock and passcode set up with account. Niche providers that sit on top like Efani may be an upgrade. (View Tweet)
3/ ideally accounts can't be linked to you, but I haven't found great ways to effectuate this efficiently. Problem is if you open account in a friend's name for example, that creates headaches going forward since you may need to drag your friend into a store to show ID. (View Tweet)
4/ would love specific ideas on the "accounts not in your name" piece. For email: microsoft, google, cloudflare, protonmail, all secure if used properly - with hardware 2FA and settings configured to maximize security (no third party app access, force 2FA for every login, etc). (View Tweet)
5/ hardware security is where I've made the least progress. If your hardware is compromised, very hard to address. Can mitigate with multiple segregated devices. Ultimate recovery email can be an email address you never log in to, initialized on "clean" device. (View Tweet)
6/ biggest weak point is that most big companies (especially banks) don't support hardware 2FA, so even if your phone and email are locked down, can still be trivial for someone to socially engineer your bank. Currently researching providers on this. (View Tweet)
7/ for password storage, 1password is industry best for teams/companies and might be okay for individuals, but cloud based, vulnerable. Strongbox (mac), KneepassXC (windows) probably best for individuals. (View Tweet)
8/ specific recommendations around any category of service provider very welcome. (including cybersecurity consultants/firms that can think practically). (View Tweet)
