Serious talk: Your Cybersecurity. I was inspired by the Kieran Drew story.


ARTEM BONDAR


NEWSLETTER

A few weeks ago, I got an email from Kieran Drew with a scary story.

He is traveling in Argentina now. While walking down the street and speaking with his friend on the phone, his iPhone was suddenly snatched from his hands by strangers, who disappeared.

In a fraction of a second, the thieves got an unlocked iPhone with his SIM card inserted.

He quickly returned home and, using his iCloud account, changed the password to his Apple ID and locked the stolen phone. He thought he was safe.

Apparently, he was not.

The next morning, he discovered that he was logged out of all his accounts and devices, that his MacBook and backup phone had been fully reset, and that he couldn't log in to Gmail or any of his bank accounts.

He was fully disconnected from his digital world.

Thieves gained access to his email and drained his business bank account.

This story caught my attention.

I realized that if the same thing happened to me, I would become a victim, just as Kieran did.

Just think about it! All the thief needs to break into your digital life is your Gmail account and your SIM card to reset your passwords.

I thought that I took my cybersecurity seriously. Apparently, it was not serious enough. This story motivated me to examine the security gates in place.

After some research, I found many useful tricks to make phone thieves' lives harder. Just in case (I hope not) something like this happens to you.

Note: these recommendations are mostly for iPhone users, but you can find similar alternatives on Android devices.

Security Gates to Your Digital Life

  • iPhone: Enable Face ID instead of a PIN code. It's rare, but there are still people who use just a 4-digit pin code. What's even worse, they use the same code on their debit card and SIM card transfer pin.
  • iPhone: Lock the Messages app and Gmail app with Face ID. Long-press on the app icon -> Require Face ID
  • iPhone: Disable message and email previews in the phone's notification settings when the phone is locked.
  • Replace the 4-digit PIN with a 6-digit PIN, or, even better, an alphanumeric PIN. It will be harder for someone to peek at your PIN as you enter it.
  • Apple ID: Enable two-factor authentication, and check trusted devices. Add the second trust number of your closest relative.
  • Apple ID: Add recovery contact. A trusted person who will be able to help you get access to your account in case of an emergency
  • Apple ID: Generate a Recovery Key, print it, and save it in a secure place. Without this key, it's impossible to reset your Apple ID password, even with a SIM card.
  • iPhone: Disable the Apple ID menu option and hide the Face ID menu item from the iPhone settings. Select Screen Time -> Content & Privacy, enable it, and set a 4-digit pin code. Important! It should differ from the device PIN code. Then select Accounts and Passcode & Face ID, set "Don't Allow" for both. With this protection, it's impossible to access your Apple ID or Face ID on a stolen, unlocked device without knowing your second PIN.
  • Phone Number: enable maximum SIM protection with your cell phone provider, so it will be harder to port your phone number to a new SIM card without your authorization.
  • long and use password managers if you are still not. Use a strong generated password everywhere. Your master password should be impossible to guess. You should keep it only in your head and print it in your safe. Not anywhere else.
  • Don't use password managers from the same provider as your main account. For example, don't use Gmail or Apple's password manager. Use a 3-rd party provider: LastPass, 1Password, Bitwarden, NordPass, etc.
  • Set up two-factor authentication everywhere. Use Authenticator apps, for example, Google Authenticator or similar. Make sure those apps are protected by Face ID as well.
  • Create two secret emails that no one knows about. Use a different email provider for this type of email. For example, if your main email is on Gmail, create a second email at iCloud, Fastmail, Proton, etc. The provider is not important. What is important is that this email is impossible to guess, so don't put your name on it.
  • Use one secret email for all your bank accounts. Use the second secret email as a recovery email address for your primary email.
  • Gmail: enable two-factor authentication with your trusted devices. Have an old laptop that collects dust on your shelf? Add it. You never know when you may need it. It is how Kieran, for example, regained access to his Gmail account. He remembered the old iPad in his apartment that was logged in.
  • Gmail: If you use a password manager, most support Passkeys. Add a passkey for two-factor authentication.
  • Gmail: The maximum level of protection is to enroll in "Advanced Protection". It's free. This option is not available in Google account settings. Just Google "Google Advanced Protection" to learn how to enable it. Note: With this protection enabled, you will have difficulty logging in on a new device, even with a trusted device nearby. You will need to turn it off first.
  • Top-level: FIDO2 physical passkeys like YubiKey. The maximum level of cybersecurity available today. Requires investment in several keys and the responsible storing of those. If you lose all keys, you will lose access to your accounts forever.

And I believe this is mostly it.


I hope a cyberattack never happens to you. There is no such thing as 100% cybersecurity. Everything can be hacked. But your goal is to create maximum friction, so the attacker gives up on attacking you.

Stay safe and secure.

Talk soon.


Artem

600 1st Ave, Ste 330 PMB 92768, Seattle, WA 98104-2246
Unsubscribe · Update your profile

Artem Bondar

I'm a software test engineer, and I teach QA professionals how to build automated tests you can trust. In this newsletter, I share my thoughts on test automation and everything in between to help you become a better automation engineer.

Read more from Artem Bondar
I'm done with Page Objects.

ARTEM BONDAR NEWSLETTER About a month ago, I made a controversial post on LinkedIn that got a lot of attention. Not that I wanted to go viral. It was my honest opinion. The more I use coding agents to write tests, the more I realize that I don't want to use Page Objects anymore. Let me explain. Why do engineers use page objects? It's not to show your colleagues how smart you are. Page objects have (had) a clear goal: group test steps into reusable components (methods) so they can be reused in...

QA istn't dying. It's transforming.

ARTEM BONDAR NEWSLETTER It's been a little over 2 months since I migrated Bondar Academy to a new platform I built myself. From scratch. Using Claude Code. Previously, I was paying almost $300/month to LearnWorlds. Now it's around $35/month for my own LMS: - Fly.io hosting $6/mo - Supabase for database $25/mo - CloudFlare for video storage and streaming for less than $3/mo Overall, the "vibecoding" experience with Claude Code was quite mindblowing. In the first couple of weeks, I could not...