Crisp PhaseHelp with antivirus questions

Accounts, passwords and logins

Six questions about the part of online safety that software cannot do for you, in the order they usually come up.

More harm reaches ordinary people through their accounts than through their computers. An account does not need anything installed on your machine to be taken over; it needs only a password that someone else has, obtained from a service that was breached years ago or from a convincing imitation of a login page. That is why these questions sit on a site about antivirus software: because the honest answer to many security worries is that the account matters more than the device, and no subscription covers it.

The good news is that the habits that matter are few and durable. Unique passwords, a second factor on the accounts that matter, and knowing the order to work in when something goes wrong will cover the realistic situations described below.

How do I know whether one of my passwords has been exposed?

Short answer

Usually you find out indirectly: a notice from the company, a sign-in alert from an account, or your browser or password manager telling you a stored password appears in a known breach. Treat any password you have reused as exposed, whether or not you have been told so.

How exposure happens

Companies store password records, and when a company is breached those records are taken. Modern services store them in a form that resists being read back, but older or poorly built ones did not, and many breaches are years old before they circulate. The practical consequence is not that one account is at risk; it is that the same email address and password are then tried automatically against hundreds of other services. If you used that pair anywhere else, those accounts are the ones that fall.

This is the mechanism behind almost every account takeover people describe as mysterious. The computer was never involved.

What to do, at no cost

  1. Use the password checkup built into your browser or password manager, which compares your saved passwords against published breach data without sending the passwords themselves.
  2. Start with the accounts that can be used to reset others: your email, then your phone account, then banking.
  3. Change any password that appears in more than one place, starting with the most important account.
  4. Turn on sign-in alerts where the service offers them, so an unexpected login produces a message you will see.
  5. Sign out of sessions you do not recognise in each account's security settings.

If an Australian organisation was breached

Under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act 1988 (Cth) must notify affected individuals and the Office of the Australian Information Commissioner when a breach is likely to result in serious harm. The OAIC publishes information about the scheme and about what to do if you are notified.

My account has been taken over. What order do I do things in?

Short answer

Email first, then anything financial, then everything else. Within each account: regain access, change the password, remove the recovery details and app permissions you do not recognise, then sign out all sessions.

Why email comes first

Whoever controls your email can reset the password on nearly every other account you own, because that is what the reset process is designed to do. Securing email first removes that capability. If you cannot get into your email at all, every major provider has an account recovery process; use it before working on anything else.

The order to work in

  1. Regain access. Use the provider's recovery process rather than any link sent to you in a message.
  2. Change the password to something not used anywhere else.
  3. Check the recovery settings. Remove any alternative email address, phone number or security question you did not set. Leaving one in place means the account can simply be taken again.
  4. Check mail forwarding and filters. A rule quietly forwarding or deleting messages is a common way access is retained after a password change.
  5. Review connected apps and revoke anything you do not recognise or no longer use.
  6. Turn on two-factor authentication before moving on.
  7. Sign out of all sessions, which ends any access that was already open.
  8. Repeat for financial accounts, then for anything that shares the old password.
  9. Tell the people who might be contacted in your name, since messages sent from a taken-over account are often the next step.

What to watch out for

Do not use a service that advertises account recovery for a fee. Recovery is handled by the provider itself and does not cost money. Approaches offering to recover an account or lost funds, particularly after you have discussed the problem publicly, follow the same pattern as the original incident.

Where to report it

Account takeover can be reported through ReportCyber, run by the Australian Cyber Security Centre. If money was taken, contact your bank first: they have time-sensitive processes and the delay while you report elsewhere costs more than it gains.

Is it safe to let the browser remember my passwords?

Short answer

It is considerably safer than reusing one password everywhere, which is the realistic alternative. The browser's password store is encrypted and tied to your device or account sign-in. A dedicated password manager offers more, but using the browser's is better than using nothing.

What the trade-off actually is

The objection to browser-stored passwords is that anyone with access to your unlocked computer and your sign-in has access to them. That is true, and it is why the device's own password or PIN matters. The objection has to be weighed against what people do otherwise: choose passwords simple enough to remember, and use the same one in many places. That habit causes far more account takeovers than browser storage does.

A dedicated password manager adds a separate master password, cross-browser and cross-device access, secure sharing, and breach checking. Whether that is worth the extra step depends on how many accounts you hold and whether you move between devices.

Comparing the common approaches to remembering passwords.
ApproachIn its favourAgainst it
One password reused everywhereNothing to set upA single breach anywhere exposes every account
Written in a notebook at homeNot reachable over the internetInconvenient, easily lost, no help on a phone
Browser password storeFree, already there, encrypted, warns about reuseTied to one browser; depends on device sign-in security
Dedicated password managerWorks across browsers and devices; separate master passwordAnother product to set up, and often another subscription
Passkeys, where offeredNothing to type and nothing to steal from a breached databaseSupport is still uneven across services

Where a paid product comes into it

Paid security subscriptions often bundle a password manager, which can be a reasonable way to get one without a separate arrangement. Whether the bundled one suits you depends on whether it works in the browsers and on the devices you use, so it is worth checking that before deciding.

Visit the Norton AntiVirus Plus website to read what the vendor lists as included in the subscription.

Paid affiliate link. ORYNA s.r.o. is paid a commission on purchases made through it, and your price is unaffected.

What does two-factor authentication actually protect against?

Short answer

It protects against someone who has your password but not your device. That covers the overwhelming majority of account takeovers. It does not protect against approving a prompt you should have refused.

The different kinds, and how they compare

A code sent by text message is the weakest common form, because phone numbers can be transferred to another device through the mobile carrier. It is still far better than no second factor. A code from an authenticator app is stronger, because the code is generated on your device and never travels. A hardware security key is stronger again, and also resists imitation login pages, because the key checks which website is asking before it responds.

The gap in all app- and code-based methods is you. If a convincing page asks for the code at the moment you expect to be asked, it can be passed straight through to the real service. Treat a code request that arrives when you were not signing in as a signal that someone else has your password.

What to do, at no cost

  1. Turn it on for email first, then banking, then any account holding payment details or personal documents.
  2. Prefer an authenticator app over text messages where the service offers the choice.
  3. Save the backup codes the service gives you somewhere you can reach without the phone.
  4. Never read a code aloud to a caller or type one into a page you arrived at from a message.
  5. If a prompt appears that you did not initiate, refuse it and change the password immediately.

What makes a password good, and how often should I change it?

Short answer

Length and uniqueness matter more than complexity. Change a password when there is a reason — a breach, a suspicion, a shared device — rather than on a schedule. Routine forced changes tend to produce weaker passwords, not stronger ones.

Why the old advice changed

The familiar rules about mixed characters and quarterly changes were written for a different threat. In practice they produced predictable variations, with people appending a number that increments each quarter. Current guidance from national bodies, including the material published by the Australian Cyber Security Centre, emphasises long passphrases that are unique to each account, with changes prompted by events rather than by the calendar.

What to do, at no cost

  1. Use a passphrase of several unrelated words for anything you must type from memory, such as your device sign-in and your password manager.
  2. Let the browser or password manager generate long random passwords for everything else, since you will not be typing them.
  3. Keep each one unique. This is the rule that does the real work.
  4. Change a password promptly when a service reports a breach, when you have entered it somewhere you should not have, or when someone else has had access to your device.
  5. Do not build passwords from names, dates or anything that appears on your public profiles.

What should I do about accounts on a device I no longer use or am passing on?

Short answer

Sign out of everything and remove the device from your accounts before you erase it, then erase it properly using the manufacturer's own reset process. Deleting files is not the same as erasing a device.

What to do, in order

  1. Sign out of browsers, mail clients and any app holding an account, and turn off device-finding features tied to your account.
  2. In each important account's security settings, remove the device from the list of recognised or trusted devices.
  3. If the device was a second factor for any account, set up a replacement before you erase it.
  4. Use the built-in reset: Reset this PC on Windows, or Erase All Content and Settings on macOS. Both remove data in a way that a manual delete does not.
  5. Remove any SIM or memory card before the device leaves your hands.

Old devices still in a drawer

A phone or laptop that is no longer used often remains signed in to accounts and continues to receive verification codes. Working through the steps above on devices you have retired is a short job that closes a gap most people have never considered.