{"id":2026100387,"date":"2020-05-23T02:45:00","date_gmt":"2020-05-22T19:45:00","guid":{"rendered":"https:\/\/danieel.id\/?p=2026100387"},"modified":"2026-10-03T19:35:55","modified_gmt":"2026-10-03T12:35:55","slug":"11-ways-to-secure-digital-accounts","status":"publish","type":"post","link":"https:\/\/danieel.id\/en\/11-ways-to-secure-digital-accounts\/","title":{"rendered":"11 Ways to Secure Digital Accounts: From Passkeys to Recovery"},"content":{"rendered":"<div style=\"font-family: 'Comic Sans MS', 'Comic Sans', cursive; font-size: 12pt; line-height: 1.7;\">\n<p>Email, WhatsApp, social media, online shopping, and digital wallets: come on, how many accounts do we have these days? The ways we secure digital accounts keep evolving, too. Passwords are still around, but now we also have <em>passkeys<\/em>, biometric verification, and options to sign in with Google or Apple.<\/p>\n<p>If one account gets hijacked, the trouble can spread. Scammers could contact our family pretending to be us, read private information, or try to take over other services. That\u2019s why I prefer to think of security as several layers of protection working together.<\/p>\n<p>Here are eleven steps we can take. Start with your main email and accounts connected to your money, then work through the others one at a time. You don\u2019t have to finish everything in one go. What matters is actually doing it.<\/p>\n<h2>Create long passwords that are hard to guess<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/01-password-panjang.webp\" alt=\"A padlock and a long row of password symbols on a laptop screen\" width=\"600\" height=\"450\" \/><figcaption>Password length and uniqueness matter more than complicated-looking patterns that are easy to guess.<\/figcaption><\/figure>\n<p>For services that still use passwords, choose something long and hard to guess. A practical target is at least 15 characters if the service supports it; a random password from a password manager makes that much easier. Alternatively, use a passphrase made of several randomly chosen words, rather than a famous quote or a story about your family.<\/p>\n<p><a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63b.html#passwords\" target=\"_blank\" rel=\"noopener\">NIST\u2019s authentication guidelines<\/a> require a minimum of 15 characters for passwords used as the only authentication factor. This is guidance for service providers, not a guarantee that every app follows it.<\/p>\n<p>Avoid birthdays, your partner\u2019s name, number sequences, and simple patterns with an exclamation mark tacked on. Follow the service\u2019s rules if it requires a mix of characters, but don\u2019t assume a short password is strong just because it looks busy.<\/p>\n<h2>Use a different password for every account<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/02-password-unik.webp\" alt=\"Separate keys represent protection for email, shopping, messaging, and digital wallet accounts\" width=\"600\" height=\"450\" \/><figcaption>One breach shouldn\u2019t open the door to all your accounts.<\/figcaption><\/figure>\n<p>Using one password for every account is certainly easy to remember. Unfortunately, if one service suffers a breach, attackers can try that same email and password combination elsewhere. Simple variations, such as adding an app\u2019s name to the same password, aren\u2019t a good idea either.<\/p>\n<p>When we secure digital accounts, our main email deserves special attention because it\u2019s often where password reset links arrive. Keep its password separate from those for shopping, social media, and financial services.<\/p>\n<p>If a password has been leaked, reused, or entered on a fake website, change it immediately on every affected account. However, changing passwords every three or six months without signs of a problem is no longer NIST\u2019s general recommendation. Password quality and a quick response to a real risk matter more.<\/p>\n<h2>Secure digital accounts with passkeys and biometrics<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/03-passkey-biometrik.webp\" alt=\"A man using a passkey and fingerprint verification on his phone to secure digital accounts\" width=\"600\" height=\"450\" \/><figcaption>Biometrics authorize passkey use; your fingerprint isn\u2019t a password sent to the website.<\/figcaption><\/figure>\n<p><em>Passkeys<\/em> use a pair of cryptographic keys tied to a service, making them more resistant to phishing than passwords. We authorize their use with a fingerprint, facial recognition, or the device\u2019s PIN. When signing in to Google with a passkey, biometric data stays on the device rather than being sent to Google.<\/p>\n<p>To give it a try, open your account\u2019s security settings and look for a passkey option. Follow <a href=\"https:\/\/support.google.com\/accounts\/answer\/13548313\" target=\"_blank\" rel=\"noopener\">Google\u2019s passkey guide<\/a>; Apple users can read <a href=\"https:\/\/support.apple.com\/en-us\/102195\" target=\"_blank\" rel=\"noopener\">Apple\u2019s explanation of passkey security<\/a>. Support depends on the service, device, browser, and your workplace account policies.<\/p>\n<p>Create passkeys only on devices you own. Protect the PIN and the account used to sync them, and prepare a recovery option. A face scan alone doesn\u2019t prove that an app uses passkeys; biometrics may simply unlock the app or fill in a saved password.<\/p>\n<h2>Organize your credentials with a password manager<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/04-pengelola-password.webp\" alt=\"A digital vault organizes account keys for use on a laptop and phone\" width=\"600\" height=\"450\" \/><figcaption>A password manager helps create and store unique credentials.<\/figcaption><\/figure>\n<p>Remembering dozens of long passwords can be a headache. A password manager helps us secure digital accounts by generating random passwords, storing credentials, and filling in login details at the matching address. Some also support passkeys. Choose a service with clear security documentation, regular updates, and a recovery process you understand.<\/p>\n<p>Protect the vault with a strong master password and additional authentication where available. Check the website address before using autofill. For shared family access, use a dedicated sharing feature rather than sending passwords in an ordinary chat.<\/p>\n<p>Saving half a password and remembering the rest yourself adds hassle and makes it easier to forget. For most readers, keeping complete credentials in a well-protected password manager is more practical. You still need to protect both the manager and your devices; no app removes every risk.<\/p>\n<h2>Enable additional authentication where supported<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/05-autentikasi-dua-faktor.webp\" alt=\"Two separate locks on a door represent two-factor authentication\" width=\"600\" height=\"450\" \/><figcaption>Choose a strong authentication method, then prepare a backup way in.<\/figcaption><\/figure>\n<p>If you still sign in with a password, enable two-factor or multifactor authentication. Prefer phishing-resistant methods such as FIDO2 security keys where available. Codes from authenticator apps are still useful, but fake login pages can steal them. SMS is better than no additional factor, although it has risks such as someone taking over your phone number.<\/p>\n<p>Some passkeys already combine possession of a device with local verification, so a service may not ask for another one-time password, or OTP. Don\u2019t judge security solely by how many screens you go through. Each service has its own support and login flow.<\/p>\n<p>I\u2019ve previously written about <a href=\"https:\/\/danieel.id\/?p=900008\">the importance of two-step verification<\/a>. The protection principles still help, but menu names in older articles may have changed. Use the latest official instructions when setting up your account.<\/p>\n<h2>Use Sign in with Google or Apple wisely<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/06-login-google-apple.webp\" alt=\"A protected main account connects several trusted apps\" width=\"600\" height=\"450\" \/><figcaption>Protect your identity provider account because it opens the door to other services.<\/figcaption><\/figure>\n<p>The <em>Sign in with Google<\/em> or <em>Sign in with Apple<\/em> button lets us access another service through an identity provider\u2019s account. This is different from passkeys or biometrics. All three can work together: biometrics authorize authentication to the main account, which is then used to sign in to another app.<\/p>\n<p><a href=\"https:\/\/support.google.com\/accounts\/answer\/12849458\" target=\"_blank\" rel=\"noopener\">Sign in with Google<\/a> reduces the need to create a new password for every app. <a href=\"https:\/\/support.apple.com\/en-us\/102609\" target=\"_blank\" rel=\"noopener\">Sign in with Apple<\/a> also offers an option to hide your personal email address. Still, check what information and permissions the app requests.<\/p>\n<p>Protect your Google or Apple account with strong authentication and recovery options that are ready to use. If you lose access to the main account, signing in to connected services may also be affected. Review connected apps regularly; before disconnecting one, make sure you can still sign in another way if needed.<\/p>\n<h2>Protect your OTPs and watch out for phishing<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/07-otp-phishing.webp\" alt=\"A man rejects a suspicious call while protecting his phone from a phishing lure\" width=\"600\" height=\"450\" \/><figcaption>Don\u2019t share codes or approve logins you didn\u2019t initiate.<\/figcaption><\/figure>\n<p>Scammers can pose as bank staff, couriers, friends, or support teams. They try to make us panic or tempt us with an offer, then ask for a password, OTP, recovery code, or login approval. Don\u2019t read out or send these codes to anyone else. Enter them only in an official process you started yourself.<\/p>\n<p>To secure digital accounts, get into the habit of opening the official app or typing the website address yourself when an urgent message arrives. Check the full domain, not just the name or logo. HTTPS indicates an encrypted connection, but scam websites can have it, too.<\/p>\n<p>Reject login approval notifications you didn\u2019t request. Watch out for QR codes that ask you to link a device or sign in to an account, too. If a family member suddenly asks for a money transfer, verify the request through another channel before acting.<\/p>\n<h2>Use public Wi-Fi with sensible precautions<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/08-wifi-publik.webp\" alt=\"A laptop user in a caf\u00e9 uses a protected connection on public Wi-Fi\" width=\"600\" height=\"450\" \/><figcaption>An encrypted connection helps protect data, but it doesn\u2019t guarantee that the destination website is trustworthy.<\/figcaption><\/figure>\n<p>Free Wi-Fi doesn\u2019t automatically mean someone can read everything on your device. <a href=\"https:\/\/consumer.ftc.gov\/articles\/are-public-wi-fi-networks-safe-what-you-need-know\" target=\"_blank\" rel=\"noopener\">The FTC explains<\/a> that widespread website encryption generally makes public Wi-Fi safer than it used to be. Still, make sure you\u2019ve chosen the right network and don\u2019t ignore certificate warnings.<\/p>\n<p>Avoid installing apps, configuration profiles, or certificates offered by a hotspot without a clear reason. Turn off file sharing when you don\u2019t need it. For sensitive transactions, mobile data or a personal hotspot can be a practical choice.<\/p>\n<p>A trustworthy VPN can help protect your traffic from the local network, but it won\u2019t make a fake website safe. Keep checking destination addresses, app permissions, and the actions you\u2019re asked to take.<\/p>\n<h2>Update your operating system, browser, and apps<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/09-update-perangkat.webp\" alt=\"A laptop and phone receive updates to fix device security vulnerabilities\" width=\"600\" height=\"450\" \/><figcaption>Avoid putting off security updates again and again.<\/figcaption><\/figure>\n<p>Updates aren\u2019t just about new features. Operating systems, browsers, apps, and extensions need updates to fix security vulnerabilities. Enable automatic updates where available, then give your device time to finish installing them and restart.<\/p>\n<p>Also check whether your device still receives security support. A system that\u2019s no longer supported needs a migration plan, especially if you use it to access your main email or financial services.<\/p>\n<p>It\u2019s easier to secure digital accounts when the work becomes a small routine. Instead of repeatedly clicking \u201cremind me later,\u201d choose a time that won\u2019t interrupt your work. As you tidy up your device habits, you can also read my thoughts on <a href=\"https:\/\/danieel.id\/en\/beware-of-gadget-addiction-being-more-fully-present-in-the-real-world\/\">gadget addiction<\/a>; enjoying technology should go hand in hand with staying in control of how we use it.<\/p>\n<h2>Choose trustworthy apps and limit their permissions<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/10-aplikasi-tepercaya.webp\" alt=\"A user chooses apps from trusted sources and avoids suspicious downloads\" width=\"600\" height=\"450\" \/><figcaption>Check the source, developer, and permissions before installing an app.<\/figcaption><\/figure>\n<p>Download apps from official stores or a developer\u2019s website you can verify. Official stores help screen apps, but they don\u2019t guarantee that every app is risk-free. Check the developer\u2019s name, the app\u2019s purpose, and the permissions it requests.<\/p>\n<p>Avoid APK files disguised as \u201cinvitations,\u201d \u201cdelivery receipts,\u201d or \u201cphotos\u201d in messages from unknown senders, along with pirated software and unnecessary browser extensions. Don\u2019t grant accessibility access, SMS-reading permissions, or remote control just because someone claims to be helping.<\/p>\n<p>Remove apps you no longer use and revoke excessive permissions. Accounts can be misused through an infected device or a stolen login session, so strong passwords and passkeys need careful installation habits alongside them.<\/p>\n<h2>Protect your devices and prepare for account recovery<\/h2>\n<figure class=\"aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" style=\"width: 600px; max-width: 100%; height: auto; display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/11-pemulihan-akun.webp\" alt=\"A vault holds recovery codes and a spare security key beside protected devices\" width=\"600\" height=\"450\" \/><figcaption>Protection needs to cover devices, backup access, and what to do after an account hijacking.<\/figcaption><\/figure>\n<p>Use a strong screen lock, biometrics where available, and device tracking features. On Windows, <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/security\/windows-security\/stay-protected-with-the-windows-security-app\" target=\"_blank\" rel=\"noopener\">Windows Security<\/a> already includes Microsoft Defender Antivirus. Check that protection is active and up to date. Whether you need extra security software depends on your system and risks; a paid package isn\u2019t essential for every device.<\/p>\n<p>As you secure digital accounts, make sure you still control your recovery email address or phone number. Keep backup codes somewhere safe, separate from your only phone. Where supported, add a spare security key or device and understand how to recover access to your passkey storage.<\/p>\n<p>Enable login alerts and review active sessions and connected devices. If an account is hijacked, use a trusted device to follow the <a href=\"https:\/\/support.google.com\/accounts\/answer\/6294825\" target=\"_blank\" rel=\"noopener\">official recovery instructions<\/a>, change affected passwords, revoke unfamiliar sessions and authenticators, and check for changes to your recovery details. Contact your payment provider immediately if there are unauthorized transactions.<\/p>\n<h2 class=\"no-number\">Start with your most important accounts<\/h2>\n<p>Taking steps to secure digital accounts doesn\u2019t have to make life more complicated. Start today with your main email: use a passkey if available, organize your passwords, and check your recovery options. Then move on to financial, messaging, and social media accounts.<\/p>\n<p>Technology helps, but we still need to stay alert. Don\u2019t rush to hand over codes, install apps, or approve login requests. That\u2019s all for now. I hope these steps help us feel more at ease using digital services.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Email, WhatsApp, social media, online shopping, and digital wallets: come on, how many accounts do we have these days? The ways we secure digital accounts keep evolving, too. Passwords are still around, but now we also have passkeys, biometric verification, and options to sign in with Google or Apple. If one account gets hijacked, the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2026100399,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"page_builder":"","_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[113],"tags":[175,169,171,168,170,172,174,173],"tmauthors":[39],"class_list":["post-2026100387","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-account-recovery","tag-account-security","tag-biometrics","tag-digital-security","tag-passkeys","tag-password-managers","tag-phishing","tag-two-factor-authentication"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/danieel.id\/wp-content\/uploads\/2026\/10\/mengamankan-akun-digital-featured.webp","_links":{"self":[{"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/posts\/2026100387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/comments?post=2026100387"}],"version-history":[{"count":1,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/posts\/2026100387\/revisions"}],"predecessor-version":[{"id":2026100400,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/posts\/2026100387\/revisions\/2026100400"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/media\/2026100399"}],"wp:attachment":[{"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/media?parent=2026100387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/categories?post=2026100387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/tags?post=2026100387"},{"taxonomy":"tmauthors","embeddable":true,"href":"https:\/\/danieel.id\/en\/wp-json\/wp\/v2\/tmauthors?post=2026100387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}