<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on Søren&#39;s Blog</title>
    <link>https://soeren.one/tags/security/</link>
    <description>Recent content in Security on Søren&#39;s Blog</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-US</language>
    <lastBuildDate>Thu, 09 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://soeren.one/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Minimize Phishing Risk</title>
      <link>https://soeren.one/2026/minimize-phishing-risk/</link>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://soeren.one/2026/minimize-phishing-risk/</guid>
      <description>&lt;p&gt;As technically savvy people, we tend to feel immune to phishing attacks. After all, it&amp;rsquo;s obvious when a Nigerian prince asks for my credit card details or when invoices in a foreign language are sent to my private email address.&lt;/p&gt;
&lt;p&gt;But it&amp;rsquo;s not always that simple. We recently had a case in the family and it wasn&amp;rsquo;t recognized until just before the credit card details were about to be entered. By then, the name and address had already been submitted into a fake form.&lt;/p&gt;
&lt;p&gt;A good opportunity to summarize my tips once again.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;In general:&lt;/strong&gt; Stay alert. Read carefully. That alone helps in most cases and would probably have prevented this particular incident as well. Does the URL match the provider&amp;rsquo;s official domain? Are there spelling or grammar mistakes in the message (thanks to AI, those are becoming rare)? Things become dangerous when a message &amp;ldquo;fits the situation&amp;rdquo;, for example, if I&amp;rsquo;m expecting a package and the message appears to come from the delivery service.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lots of email addresses.&lt;/strong&gt; I use my own domain, which makes it easy to have separate email addresses for different services: &lt;a href=&#34;mailto:elon@domain.com&#34;&gt;elon@domain.com&lt;/a&gt; for X, &lt;a href=&#34;mailto:mark@domain.com&#34;&gt;mark@domain.com&lt;/a&gt; for Facebook, and &lt;a href=&#34;mailto:daniel@domain.com&#34;&gt;daniel@domain.com&lt;/a&gt; for LinkedIn (all fictional, of course, since I &lt;a href=&#34;https://soeren.one/2024/give-up-social-media/&#34;&gt;don&amp;rsquo;t use any of these platforms&lt;/a&gt;). So if my supposed bank suddenly sends an email to &lt;a href=&#34;mailto:shady-store@domain.com&#34;&gt;shady-store@domain.com&lt;/a&gt;, I immediately know - no matter how authentic it looks - that it can&amp;rsquo;t actually be from my bank, because they only know &lt;a href=&#34;mailto:bank@domain.com&#34;&gt;bank@domain.com&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In Gmail, you can achieve something similar using &amp;ldquo;+ addresses.&amp;rdquo; Fastmail offers &amp;ldquo;&lt;a href=&#34;https://www.fastmail.com/features/masked-email/&#34;&gt;Masked Email&lt;/a&gt;,&amp;rdquo; and iCloud provides &amp;ldquo;&lt;a href=&#34;https://support.apple.com/en-gb/guide/icloud/mm9d9012c9e8/icloud&#34;&gt;Hide My Email&lt;/a&gt;.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lots of passwords.&lt;/strong&gt; My third recommendation: use a unique password for every service. Of course, I don&amp;rsquo;t memorize them all. I store them in a password manager. If I ever fall for a phishing attack and enter my credentials on a fake website, only that single password is compromised instead of all my accounts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Lots of fake memories.&lt;/strong&gt; I haven&amp;rsquo;t seen this in a while, but some services still use security questions for password recovery. Questions like your mother&amp;rsquo;s maiden name, the name of your first pet, and so on. I treat those exactly like passwords. I never use real answers. Instead, I generate random ones and store them in my password manager. Yes, I&amp;rsquo;m absolutely certain that my mother&amp;rsquo;s maiden name is &lt;code&gt;&amp;lt;,$}¥sifnrl/&amp;amp;,‘&amp;gt;&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;I wanted to link to Kev&amp;rsquo;s article about how he set up his email domains because I think it&amp;rsquo;s an excellent approach. While looking for it, I stumbled across &lt;a href=&#34;https://kevquirk.com/i-was-nearly-phished&#34;&gt;this post&lt;/a&gt; again. It serves as a good reminder: we all need to stay vigilant.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Stay save&lt;/strong&gt;&lt;/p&gt;
&lt;br&gt;
&lt;hr&gt;
&lt;br&gt;
Thank you for subscribing to this RSS feed. 
&lt;b&gt;&lt;a href=&#34;https://soeren.one/&#34;&gt;https://soeren.one/&lt;/a&gt;&lt;/b&gt; is &lt;a href=&#34;https://soeren.one//about/&#34;&gt;søren&lt;/a&gt;&#39;s personal blog. 
If you want to get in touch, please &lt;b&gt;&lt;a href=&#34;mailto:hej@soeren.one?subject=Reply to: Minimize%20Phishing%20Risk&amp;body=Link to post: https%3a%2f%2fsoeren.one%2f2026%2fminimize-phishing-risk%2f&#34;&gt;reply to this post via email&lt;/a&gt;&lt;/b&gt;. 
</description>
      
    </item>
  </channel>
</rss>
