Security Tips – Etisk Hacker

🔐 Security Tips

Key takeaways and real-world insights on passwords, data breaches, and browser habits.

1. Stop Reusing Your Usual Passwords

Wondering if the 1–3 passwords you have always relied on are still safe? The answer is NO!

You are definitely not alone in using “Liverpool” combined with numbers—over 14,000 people do just that in Norway alone. And an awful lot of people have a dog named Rex. Passwords like these are highly likely to already exist in public data breaches.

2. Build Unique Passphrases

The standard complex passwords recommended by many services are almost impossible to remember without a serious diagnosis.

Instead, create a unique sentence. Then tweak a part of it so it directly references the specific service you are logging into. This makes it far less likely that anyone else shares your exact password.

3. Password Managers Have Flaws Too

Think built-in managers—especially Apple’s—are foolproof? In January, Apple’s password manager suffered a critical vulnerability: sending a specific string of emojis via SMS to an iPhone could trigger the device to send stored usernames and passwords straight back.

Tools can fail, which is why forming solid, unique passphrases remains essential.

4. Enable 2FA on Personal Accounts

Always turn on two-factor authentication (2FA) across your private services and social media profiles.

Attackers very frequently gain initial access into a company's infrastructure by compromising an employee's personal accounts first.

5. Keep Work Emails Away From Private Sign-ups

We have a terrible habit in Norway of using our work email addresses to register for personal services.

The lunsj.no Breach: When lunsj.no suffered a breach, 40,000 email addresses and passwords were leaked to the dark web. An analysis revealed that 87% were corporate email addresses.

Using modern AI, attackers can take all 40,000 credentials and cross-reference them against 100,000 services with a single keystroke. If you reused that password for Microsoft 365 at work, they have instant access.

6. Never Let Your Browser Store Passwords

Having Chrome pop up and ask to store your login details is undeniably convenient, but it introduces huge exposure.

A Real Demonstration: Marius sent a picture of a kitten over Microsoft Teams. Simply clicking the photo was enough—the very next image returned was a complete list of every single username and password stored in Chrome.

Never leave your stored credentials sitting inside your browser.

© Etisk Hacker AS – Practical Security Insights

Skroll til toppen