Hi everyone,

I’ve implemented strong security measures like 2FA, password managers, and even security keys to protect my accounts. Despite all this, I’ve still experienced hacking incidents that don’t seem to fit common explanations like session hijacking or phishing.

I’m trying to understand what advanced attack vectors or vulnerabilities might be at play here, and what steps I can take beyond the usual advice to secure myself better.

Has anyone faced similar issues or can share insights on deeper cybersecurity operations, attack methods, or advanced defenses? What should be the next steps when standard protections fail?

Thanks in advance for your expertise!

  • AA5B
    link
    fedilink
    arrow-up
    2
    ·
    3 days ago

    You’re using very secure options for a few specific areas, but security is about being systematic and comprehensive. There’s a lot of complexity, so a lot of potential holes. You probably don’t need better security on the places you already make good choices, you need to find a way to cover more possibilities.

    If you’re talking about cloud accounts, there’s not much else you can do: it’s al up to the vendor.

    Minor possibility: I use unique generated email addresses/usernames, in addition to unique generated passwords or passkeys. There’s authentications are hard to guess, different at every site, intruders can’t even easily connect my accounts at different cloud vendors

    • red_teamer@infosec.pubOP
      link
      fedilink
      arrow-up
      1
      ·
      3 days ago

      Could you maybe suggest some services and explain their usage in more detail? That would be more helpful than having me research and potentially choose the wrong one.

      • AA5B
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        2 days ago

        Probably not. It’s an Apple thing that comes with iCloud. iPhones aren’t very popular here but maybe someone else can recommend generic/Android/Windows/Linux equivalents

        This might even require a specific level of iCloud subscription, I don’t know, but I use

        • password generator, including family sharing and cross device sharing. I believe even cross device passkeys but I’ve never tried
        • “Hide my email” generates a unique forwarding email per site
        • “private relay” maps me to a general location not tied to my mobile vendor

        Whether through an app or web browser on any Apple or windows device, it autofills a login with unique generated email, unique generated password or passkey, and anyone trying to find my location through my connection will get a regional answer

        For example, my login here is a unique address not used anywhere else and not tied to me any other way.