ConceptionJFG
All articles
Technology2 min read

Security: protecting your logins and passwords

The little HTTPS padlock is a start, not a finish. Your site’s real security comes mostly down to your passwords and who holds the keys.

By Jean-François Gauthier

When people talk about website security, many think right away of the little padlock in the address bar: the famous HTTPS. It matters, but it’s only one door among several. The vast majority of hacked sites aren’t hacked because of some mysterious technical flaw, but because a password was too weak or lying around in the wrong place. The good news: protecting yourself takes no technical background and no big budget.

HTTPS: necessary, but not enough

The HTTPS padlock means the exchanges between your visitor and your site are encrypted: no one can spy on what travels between them. It’s the bare minimum today, and most hosting offers it for free. But be careful: that padlock doesn’t protect your admin account. It secures the journey, not the keys to the house. For that, you have to look elsewhere.

Strong, unique passwords

The worst enemy of your security is the recycled password. If you use the same one everywhere, it only takes one service getting hacked for all your accounts to become vulnerable. A good password is long, unique to each site, and impossible to guess. The simplest trick: a password manager, which creates and remembers them for you. You only have one master password left to memorize.

  • A different password for each important service.
  • Long passwords, rather than a short complicated string.
  • A password manager to remember them all for you.
  • Two-factor authentication turned on wherever possible.
  • Never a password sent by message or stuck on a sticky note.

Two-factor authentication: your second lock

Two-factor authentication is a second code asked for on top of your password, often sent to your phone or generated by a small app. Even if someone guessed your password, they’d stay locked out without that second code. It takes two minutes to turn on and blocks the overwhelming majority of hacking attempts. It’s probably the single best security move you can make today.

A site is rarely hacked through the front door. Almost always, it’s through a key someone left lying around.

Controlling who holds the keys

Over time, we hand out access to just about everyone: the intern, the former designer, the cousin who “knows this stuff.” Then we forget. Clean house now and then: who still has access to your site, and do they really need it? Give each person just what they need, not full powers, and remove access as soon as the collaboration ends. The fewer keys in circulation, the fewer risks.

If you’re not sure your logins are well protected, or you’ve lost track of who can touch your site, write me: we’ll look at it together, calmly, and put in place the few habits that keep your mind at ease.

Share this article
  • security
  • passwords
  • two-factor authentication
  • access
  • protect your site

A web project in mind?

Like these ideas? Let's put them to work on your site. You'll be talking directly with the founder.