Security is a complex topic, so this short chapter provides a dictionary-like overview of the often confusing terminology and related concepts you'll encounter as we discuss online accounts and security throughout this book.
Account. An account is a digital identity that you use to access a system like a PC, an online service, or a website.
Online account. An online account is an account you create on a remote system, like an online service or website, while online (connected to the Internet).
Username. An account has an associated username. For an online account, this is typically an email address.
Password. An account can also have an associated password, a string of characters known only to the account holder that’s used to authenticate that person and verify that they are the account holder. For online accounts, a password and/or other forms of authentication (as discussed below) are mandatory.
Sign in. To authenticate yourself, you sign in to an account using the username and a password and/or other forms of authentication. When you successfully sign in to an account, you gain access to whatever data it may contain and rights it provides.
The problem with passwords. Passwords are insecure. They can be easily guessed, and malicious actors use social engineering in the form of phishing attacks to impersonate a legitimate person, business, or other entity to fool you into revealing your password or other personal information.
Identity theft. If a malicious actor obtains your username and password, they gain access to the information contained by, and the rights associated with, that account. They can then steal that information or use it to impersonate you in what’s called identity theft.
Accounts associated with your identity need more scrutiny. Hacking and identity theft are particularly problematic for online accounts like those provided by Amazon, Apple, Google, and Microsoft because they often contain credit card numbers, shipping addresses, and other deeply personal information.
Multi-factor authentication (MFA). To prevent this type of crime, security organizations invented an additional layer of account protection called multi-factor authentication (MFA). The most common form of MFA requires a password and a second form of authentication (identity verification), and so you will typically see it described as two-factor authentication (2FA) or two-step authentication.
Why MFA works. The second authentication method you use with an MFA-protected account will be something you know (a PIN, a one-time password or other code, the answer to a secret question, and so on), something you have (a phone or a hardware security key), and/or something you are (a biometric sign-in provided by your PC, phone, or other device, like facial or fingerprint recognition).
Common forms of MFA include:
One-time password (OTP). This is a code that is sent to you via a text message, email message, phone call, or other...
With technology shaping our everyday lives, how could we not dig deeper?
Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.