Data Privacy Day Made Me Actually Fix My Accounts

Data Privacy Day Made Me Actually Fix My Accounts

Tutorials passwords privacy security two-factor-authentication

Yesterday was Data Privacy Day, which I only remembered because my RSS reader (yes, I still use one, no I will not be taking questions) was full of posts from Google and Microsoft reminding everyone to "review their settings." I almost scrolled past it the way I scroll past every other manufactured tech holiday. But I didn't, and I ended up spending about two hours last night actually going through my accounts instead of just nodding along to the idea of doing it someday. So here's what I actually did, in case anyone else wants to steal an evening for this instead of watching another rerun.

Google first, because it has the most on me

I went into my Google account settings and turned on 2-step verification. I'd been putting this off for probably a year because I assumed it would be annoying, and it kind of is, the first time. You link your phone number, it texts you a code, you type the code in, and now every new device needs that extra step. But once it's set up it's not bad at all, and honestly I feel a little dumb for not doing it sooner given how much lives in that one account — Gmail, Calendar, half my documents, Reader (RIP eventually, probably, if the rumors keep swirling, though nothing's official).

While I was in there I also looked at the "Account Activity" page, which shows recent sign-ins by device and location. Mine were all boring and expected. Still, it's worth a look once in a while just so you know what normal looks like for your own account.

Facebook is where this gets annoying

Facebook's privacy settings are a maze, and I say that as someone who's used the site since college. Every redesign moves things around, and there's always some new sub-menu buried three clicks deep that quietly resets to a more public default. I went through the "Who can see my stuff" section, tightened up the default audience for future posts, and turned on Login Approvals, which is Facebook's version of two-factor. It's not hard to find once you know it exists, but nothing about the interface points you there. I genuinely think this is by design, not incompetence, and it bugs me every time.

Passwords, the boring but important part

I'm not going to pretend I have some elegant system. I use LastPass for most things and I have for a couple years now, and last night I finally went in and killed off a batch of reused passwords on smaller sites I don't care about but that still have my email address on file. If one of those gets breached, I don't want that password working anywhere else. It's tedious work, clicking into account after account, changing one string of characters at a time, and I did about fifteen of them before I gave up and told myself I'd finish the rest this weekend. We'll see.

A couple of things on my mind

Apple's stock took a real beating last week after their earnings call, which is a strange thing to watch happen to a company that posted record profits. Wall Street wanted more, I guess. Doesn't change anything about how I use my phone, but it's a weird reminder that "record quarter" and "good news" aren't always the same sentence anymore.

And tomorrow's the big BlackBerry day. They're rebranding the whole company from RIM to BlackBerry and showing off BlackBerry 10 at events in something like six cities at once, which is a lot of theater for a company that's been mostly written off for two years now. I'm rooting for them a little, honestly, mostly because I don't love a world where there are only two phone platforms that matter. I'll believe the comeback when I see actual sales numbers, not launch-day hype, but I'll be watching the coverage tomorrow regardless.

Anyway. Go turn on two-factor on whatever you use most. It takes ten minutes and it's the kind of thing you'll be glad about exactly once, on the one day it actually matters.