Side Questing - Don't Get Hacked! (Issue 195)
How to set up better online security systems and practices
A week doesn’t go by without seeing one of my friends or family members post something like this…
“Don’t click any links in a message you received from me! I got hacked!”
Most modern websites and apps provide features to enable better security for your accounts. But many people don’t use them for a variety of reasons:
They don’t even know these security features exist.
They don’t know that a password isn’t enough to keep your account safe.
They don’t understand multi-factor authentication or think it’s too complicated.
They know about it, but think it’s too tedious to set up and use.
However, do you know what is even more tedious and painful?
Losing access to your account.
Letting your friends know you were hacked.
Trying to recover your account from a hacker.
Losing money when hackers gain deeper access (e.g., to your bank account).
The small amount of friction you experience when you set up and use better security for your accounts is well worth the investment. Believe me!
For many years, I hosted several WordPress sites. They are such a target for hackers! I had to install all kinds of security plugins and configure things to be more secure. Yet hackers still found ways to upload and inject malicious code. I had a few sites hacked that I had to reset and clean up. Some were so bad that I just deleted everything and started over. Eventually, I gave up on WordPress and moved my websites elsewhere.
I’ve also been using email and social media forever. I can’t even begin to tell you how many times hackers try to get into my accounts. For example, almost every day, someone attempts to reset my Instagram password so they can take over my account. Luckily, I’ve configured things to not make that easy for them.
My security practices
I use a complex and unique password for every account, and a good password manager makes that a lot easier. I also use two-factor authentication and a hardware security key whenever possible (sadly, not all services provide this).
I’m also in the habit of doing things to keep security tighter and avoid typical hacker attempts. Do you know how websites ask if you trust this computer/device and want to save your username and stay logged in?
I never allow that.
Call me paranoid, I guess. But if someone steals my laptop, the last thing I want is them being able to get into my accounts that are still authenticated in the web browser.
When I’m away from home (e.g., working at a coffee shop, airport, or hotel), I’m very careful about using the official Wi-Fi networks. I’m sure you’ve noticed all kinds of strange Wi-Fi networks when you look for one to join in a public environment. Some of them even use names to pretend to be the official Wi-Fi network. So, I use a virtual private network (VPN) from Proton to encrypt my internet data while I’m using someone else’s Wi-Fi.
Also, I never click links in emails. I’m always receiving some sort of notification about some account every day. Some of those are hacking attempts (e.g., you can see that the sending email is not the real domain). Of course, some are legitimate. But I don’t want to get into the bad habit of clicking links in emails and making a mistake one day.
If the service is using email to inform you of an issue or problem (e.g., your credit card has expired, an order is delayed, you need to accept new terms, etc.), that same info will be available on their website after you log into your account. Don’t click the link in the email. Navigate to the official website in your browser (e.g., enter the URL manually or use your trusted bookmark), use your usual security methods to log in (e.g., password and two-factor auth), and look for the message or notification on the website to address the issue. This is way safer than clicking links in an email that can be spoofed!
I don’t claim to be the world’s leading expert on internet security, so I've included a bunch of useful resources below. I hope they help!
Some helpful resources
1Password - Password management service
Why SMS texts to your phone aren’t that secure for two-factor authentication
Stop SIM Swappers Cold: Protect Your Phone Number With These 7 Tips
Larry Cornett, Ph.D. | Empowerment coach, psychologist, nature lover, and fitness freak. I help you escape the “hustle trap” to create an empowered life that fits who you are and what you want most. From Silicon Valley exec to self-employed entrepreneur, I’ve also followed this path to freedom, so now I can help others find their way.
➡️ Want to design your path? Book a free call with me!
📕 Check out my Invincible Daily Journals!


