Site icon What's New On The Net

Basic account hygiene: how it will keep you safe, according to Google – News

keeping Google account safeA year long joint study by Google, New York University & the University of California, San Diego has shown that by just adding a phone number to a Google account was enough to block up to 100% of automated bots, 99% of bulk phishing attacks, & 66% of targeted attacks that occurred during the period of investigation.

Earlier this year, Google had suggested how just 5 simple steps like adding a recovery phone number were enough to keeping Google account safe. The study was an effort to prove it in practice, according to a post on Google’s Security blog.

Here’s what was said:

If you’ve signed into your phone or set up a recovery phone number, we can provide a similar level of protection to 2-Step Verification via device-based challenges. We found that an SMS code sent to a recovery phone number helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks. On-device prompts, a more secure replacement for SMS, helped prevent 100% of automated bots, 99% of bulk phishing attacks and 90% of targeted attacks.

 

Both device- and knowledge-based challenges help thwart automated bots, while device-based challenges help thwart phishing and even targeted attacks.
 

If you don’t have a recovery phone number established, then we might fall back on the weaker knowledge-based challenges, like recalling your last sign-in location. This is an effective defense against bots, but protection rates for phishing can drop to as low as 10%. The same vulnerability exists for targeted attacks. That’s because phishing pages and targeted attackers can trick you into revealing any additional identifying information we might ask for.

Signing off, the writers added to keeping Google account safe: As our research shows, one of the easiest things you can do to protect your Google Account is to set up a recovery phone number. For high-risk users—like journalists, activists, business leaders, and political campaign teams—our Advanced Protection Program provides the highest level of security. You can also help protect your non-Google accounts from third-party password breaches by installing the Password Checkup Chrome extension.


 

Exit mobile version