Minimize Phishing Risk
As technically savvy people, we tend to feel immune to phishing attacks. After all, it’s obvious when a Nigerian prince asks for my credit card details or when invoices in a foreign language are sent to my private email address.
But it’s not always that simple. We recently had a case in the family and it wasn’t recognized until just before the credit card details were about to be entered. By then, the name and address had already been submitted into a fake form.
A good opportunity to summarize my tips once again.
In general: Stay alert. Read carefully. That alone helps in most cases and would probably have prevented this particular incident as well. Does the URL match the provider’s official domain? Are there spelling or grammar mistakes in the message (thanks to AI, those are becoming rare)? Things become dangerous when a message “fits the situation”, for example, if I’m expecting a package and the message appears to come from the delivery service.
Lots of email addresses. I use my own domain, which makes it easy to have separate email addresses for different services: elon@domain.com for X, mark@domain.com for Facebook, and daniel@domain.com for LinkedIn (all fictional, of course, since I don’t use any of these platforms). So if my supposed bank suddenly sends an email to shady-store@domain.com, I immediately know - no matter how authentic it looks - that it can’t actually be from my bank, because they only know bank@domain.com.
In Gmail, you can achieve something similar using “+ addresses.” Fastmail offers “Masked Email,” and iCloud provides “Hide My Email.”
Lots of passwords. My third recommendation: use a unique password for every service. Of course, I don’t memorize them all. I store them in a password manager. If I ever fall for a phishing attack and enter my credentials on a fake website, only that single password is compromised instead of all my accounts.
Lots of fake memories. I haven’t seen this in a while, but some services still use security questions for password recovery. Questions like your mother’s maiden name, the name of your first pet, and so on. I treat those exactly like passwords. I never use real answers. Instead, I generate random ones and store them in my password manager. Yes, I’m absolutely certain that my mother’s maiden name is <,$}¥sifnrl/&,‘>.
I wanted to link to Kev’s article about how he set up his email domains because I think it’s an excellent approach. While looking for it, I stumbled across this post again. It serves as a good reminder: we all need to stay vigilant.
Stay save