
I have of late, found myself pondering the security of my online accounts more and more. The seed of this was planted a few years ago, when I had signed up to a little known service; HaveIBeenPwned. (The same service that provides Firefox Monitor, their information). No sooner had I signed up, I received an email informing me that my details had, in fact, been breached and that my email address and password were now public knowledge. The big issue here is that, back then, I used the same email address and password combination for absolutely everything. It was easy to remember, after all!
Something had to change. All of my accounts online were now at serious risk. I made a list of all the websites where it would have a significant impact on me, personally if I lost control of that account. I then made a list of very strong passwords, one for each account. Once done, I used KeePass to document all of my accounts and their new, stronger passwords. With everything written down, I set about updating all of my passwords.
Not long after this, I had a scare with my Playstation Network account. Someone had managed to not only get into my account, but had reset the password themselves and taken total ownership of the the account. Thanks to the support at Sony, I got my account back and added extra security in the form of 2-Step, SMS code authentication.
The Three Factors of Authentication
- ‘Something you know’ – A password, answers to security questions
- ‘Something you have’ – An SMS code, a code from an authenticator app, a USB security key.
- ‘Something you are’ – Biometrics, e.g. fingerprint, facial recognition or iris scan.
All of these, are factors of authentication which contribute individually to increase account security. Individually, they are weak, but when you combine factors of authentication, you begin to build up a very strong cyber defence.
Improving Account Security
With my PSN account shored up and back in my own hands, I began to research other methods of improving security. I read about tools such as Google and Microsofts Authenticator apps. Being tied to a vendor, especially like the afore mentioned giants, didn’t win me over. A smaller, vendor-neutral offering filled me with more confidence though – SAASPASS. A fantastic, light-weight authenticator app that will provide 2FA codes, for a lot of major online services. But why choose this method over say, receiving the same code to your phone via SMS?
Not all methods of authentication are created equal. What if you lose your phone? Have you considered the possibility of having your SIM card cloned allowing a hacker to intercept SMS’ containing your 2SA codes? With an authenticator app, at least your account can’t be cloned, but there’s still a risk at losing your phone. Your authenticator app account can be cloned to a secondary device, however. This eliminates the risk of losing one device, but increases your surface area for having devices compromised.
More secure than an authenticator app, is the USB security key. I have recently acquired a couple of Yubico Yubikey 5 NFC keys, and I have to say I’m very impressed. Very easy to configure, and obviously very secure, as you have to physically have the key to access accounts configured, it’s another step up in increasing account security. For example, to login to my laptop, I simply enter my credentials, plug in the Yubikey and I’m in. To get access to Twitter, I simply enter my credentials, plug in the key and touch the capacitive gold plate to prove I’m a human and not a bot. Similarly, to access Twitter on my phone, I enter my credentials, and when prompted, use the NFC capability of the key to swipe near my phone and I’m in.
What’s Next for Security?
Yubico have announced that they will soon be introducing the Yubikey Bio. This will, in all likelihood set the bar for three-factor authentication. To access accounts secured with the Yubikey Bio, you will need your password (something you know), your Yubikey Bio (something you have) and also your fingerprint (something you are).

The Naysayers
The evidence is there for all to see; Multi-factor authentication improves account security. It might then, surprise you, to learn some of the big names who aren’t implementing this.
Paypal, is right up there; A giant in online payment services. I have contacted their support on a number of occasions to glean why they are not taking greater steps toward protecting their customers. According to their responses, they feel that 2-Step, SMS-based Authentication provides enough protection and will not be changing this any time soon.
Online Banking, particularly in the UK (I can’t comment on banks in other countries), very few offer 2FA for their online accounts. In fact, consumer information organisation, Which?, were quite scathing of the UK banking sector in an article written in November ’19; shaming TSB, Co-operative Bank, Metro Bank, Santander and Yorkshirebank/Clydesdale Bank as being particularly bad in this regard.
Gaming Services are another industry who simply are not doing enough to secure their customers accounts. PSN, still only uses 2-Step SMS-based Authentication. Steam offer 2FA, but only if you use their Steam app on your phone.
Finally, I will make a passing nod at both Microsoft and Apple. Both of whom provide 2FA, but only on their own terms. As of the moment of publishing this post, Microsoft will allow you to register an authenticator app. They won’t however, allow you to register a Security key. Even though there’s a link for this, it’s a dead-end and doesn’t let you register. Apple too provide 2FA, but only if the 2nd factor is their own method, provided on an iPad or iPhone.
My Account Security Recommendations
Make all of your accounts as secure as you possibly can. Remember that your account is only as secure as the weakest form of authentication. You might well have a security stick, but what if someone hacks your account because they intercept an SMS code left on as a backup method?
- Strong passwords are important in the first instance. Where practically possible, use at least 15 characer passwords/passphrases. Use combinations of uppercase, lowercase, numerical and special characters.
- Use a Password Manager like KeePass.
- If possible, set up a second factor. SMS authentication is better than no second factor at all.
- Look for Authenticator Apps such as SAASPASS to provide your 2FA.
- Upgrade your 2FA to a security key if you can.
- Review your security options on all your accounts every so often, e.g. 3-6 months.
- Sign up to Firefox Monitor or HaveIBeenPwned to see if your details have been leaked.
Edit: Follow up
Since the time of writing, it has come to my attention that the version of Windows 10 is very important to Microsoft’s support of Security Keys as a second factor of authentication. Having updated my OS to Version 1909 of Windows 10 (version 1903 is the version which adds support for Security Keys) I am happy to announce that my Microsoft account is now secured with my Yubikey. “Great!” I hear you all cheer, amid rapturous applause and glorious, trumpeting fanfare. “Not so fast” is my quick response. Microsoft has let me register my keys, but now they have a massive FAIL on their part for their lackadaisical implementation. When I attempt to login using my security key, I get a sad face and the message “Something went wrong” with the only option being to refresh my browser page, which produces the same sad face.
Thankfully, there is a work-around to this issue. If you are getting the endless loop of sad face, navigate to account.microsoft.com, which should let you in and from there you can navigate to wherever wouldn’t let you in, presumably Outlook Live. If anyone from Microsoft reads this, fix your nonsense please!

