We may receive a commission on purchases made from links.
As cybercriminals evolve their attacks and new protection tools become more available, it’s worth reassessing your cybersecurity hygiene to improve your digital security. The idea may seem intimidating, but you don’t need to completely rethink your cybersecurity strategy. This simply means that some security tips that were once considered essential to online safety have become obsolete. They’re not completely useless, but on their own or when factoring in your digital needs, they’re simply no longer effective at keeping you safe. Fortunately, before cybersecurity experts declare that these tips are no longer effective, there is usually a solution.
For example, changing your password regularly is now considered riskier than having a single strong password. Since staying away from public Wi-Fi can sometimes be inconvenient, it’s best to know the tools that can keep you safe when you can’t avoid it completely. Additionally, with the rise of AI-based malware, sticking to traditional antivirus software that doesn’t use machine learning to combat it has become a security risk. While there’s no need to be paranoid, it’s essential to know what works and what doesn’t to avoid falling victim to cybercriminals’ ever-changing tactics.
Change your passwords regularly
On the surface, the advice to change your password regularly, usually within 60 to 90 days, makes sense. If hackers steal your credentials, they are only useful for a limited time, because once you change them, they immediately become obsolete. This is theory, but in practice, human error can make this useful tip less effective, even if it has merit. Asking a human to change the dozens of passwords they have these days every few months is tedious. So what do they end up doing? Use a variation of the old password on multiple sites so they can remember it easily. Hackers use tools (now AI-based) to spot these patterns in your passwords. So if they discover your old password, they will probably discover your new one.
Rather than changing passwords regularly, it is better to use a password manager that allows you to generate strong and unique passwords for all your accounts. Even if you have no problem creating strong passwords, you should still store them in the password manager so that you can enter them securely. If the website has it, use multi-factor authentication (MFA). In particular, passwordless options such as passwords and security keys are not only more convenient but also more secure since the authenticated session is tied to your device.
Stay away from public Wi-Fi
Public Wi-Fi networks, like those found in airports, hotels and restaurants, are risky. This is not up for debate, but it is not practical to stay away from it completely. So, in cases where you have no choice but to use public Wi-Fi, you may find yourself unprotected. On public Wi-Fi, hackers use Man-in-the-Middle (MitM) attacks, in which they exploit network vulnerabilities to put themselves between you and the network. This may allow them to see data you send over the Internet from an unsecured device. But if your device is secure, you don’t have to fear public Wi-Fi.
You can use a VPN, which encrypts your data before sending it to a VPN server through a secure tunnel. The VPN server decrypts it and then sends it to its intended destination. If the hacker intercepts the data, the encryption renders it useless because only the VPN server can decrypt it. There are several VPN providers you can choose from, but you can also use browsers with free built-in VPNs like Firefox and Opera.
If you need to connect a device that can’t natively install a VPN, like a Nintendo Switch 2, you can use a VPN router like the TP-Link ER605 V2. It encrypts data from connected devices before sending it to the VPN server. You will, however, need to configure a VPN profile, using that of your VPN provider.
Traditional antiviruses are still enough
In addition to AI causing the global RAM shortage and driving price hikes in consumer technologies, it is also causing problems in cybersecurity in the form of adaptive malware. Its description may sound like science fiction, but the threat is real.
Adaptive malware uses machine learning to constantly evolve to avoid detection. It achieves this in particular by manipulating its code in real time (via integrated AI models), which makes it difficult to identify antiviruses that rely on pattern recognition. It can also scan and assess the specific vulnerabilities of targeted devices before launching an attack to come up with a tailored exploit that has a high chance of avoiding detection.
Stopping this is beyond the capabilities of traditional antivirus software, which is why companies like Bitdefender are also using machine learning to combat these threats. Bitdefender is just one example, but many AI-based antiviruses leverage the power of AI models to create defenses unique to your phone or computer. So if you’re still using traditional antivirus software, know that we’re past the age of traditional malware. They may offer little or no defense against adaptive malware.
Two-factor authentication is sufficient protection
You probably use two-factor authentication (2FA) to log in to some very important online accounts. This could be your Google, Facebook, or PayPal accounts, where you first enter your password and then receive a code on your phone as a text message or push notification, or you get it from an authenticator app. This is one of the most secure methods because it eliminates the need to rely solely on a password, adding an extra layer of protection that forces a cybercriminal to resort to tactics such as phishing. However, two-factor authentication isn’t as secure as it used to be: hackers don’t need to trick you into providing them with the 2FA code.
Basically, they trick you into signing into the website. As soon as you do this, your browser stores information about the connection in data files called session cookies. It does this so that you automatically log in to the website without the need for authentication. This is what cybercriminals are now stealing to access your accounts and steal your information, including your passwords, addresses, phone numbers, credit card details and private messages, without needing to go through 2FA. Instead of relying solely on 2FA, you can try passwords and security keys, as these are stored on the device and have a better chance of protecting you from unauthorized access.
Did you find this useful? Join our free weekly newsletter for smart tech purchases and products to avoid.