Skip to main content

Artisan Spirit: Fall 2025

Page 30

It’s (Not) Me Password Security

I

n the distilling business, protecting your hard work and investments is second nature. Yet, many overlook how vital it is to safeguard the digital keys to that business and your personal life. We are talking about the keys to your kingdom: passwords. Most distilleries have one or more people who serve as a public face of the brand. This can be vital to building a community of fans, but it also exposes real personal information about you that makes you a target for digital attacks. That’s a reality of the job, so let’s have a proactive look at how to make yourself a little bit safer online.

A Close Call The first time I was almost hacked was through my Steam account. For those who don’t know, Steam is an online store for computer games. It features many AAA titles, which often go on sale for a percentage off. If you play enough video games — or if you’ve been gaming long enough — you’ve probably spent a lot of money on games in that program, which makes an account valuable to an attacker. Some people might think this is just a gaming account and that having it hacked doesn’t matter. However, you’d be wrong.

Written by DOUG ILIJEV

Someone compromising the account proves they know your username and password. What saved me from the Steam hack? Steam had automatically enrolled me in two-factor authentication (2FA), emailing a code to my email address on record. That email address — username@gmail.com — was uncannily close to the compromised account username. The password to that email account? I’d rather not admit how close to the same password it was.

Reused Passwords I think I’m in a minority of people who, back in 2017, kept a spreadsheet of the usernames and passwords — as well as connected emails, addresses, phone numbers, and credit cards — that I’d ever made. When I looked into it, I learned the following: I had just under 300 online accounts I’d made between 1998 and 2017. Many of those — almost 100 accounts — used the exact same username and password combo. That, in itself, is horrifying to me today. A few dozen of those had real potential value to an attacker (address, phone number, credit card, bank account information, etc.). Many more were tied to

the email address that basically matched my compromised username (username@gmail.com) and the same password. Many more beyond that were the same username with a small variation on the password (something obvious like putting “fb” at the end for my Facebook login). Some still beyond that had a different username or email and used either the same password or a small variation on it. In total, a little over 150 of my nearly 300 accounts used the same or similar password, same or similar account name, or one easily guessed from my name. In addition, that password was weak to begin with — nine characters long and containing my initials and part of my phone number. Imagine my panic as I realized how vulnerable I was. I can tell you all of this now because I left that password long behind me eight years ago — which still doesn’t feel long enough. It’s still scary to me how irresponsible I was with my online account security posture. I spent the next week changing all of my passwords and finally following my own advice about passwords — advice I already knew was good: never reuse a password. Even better, don’t reuse a password that’s even close.

What to Do About It? First, let’s secure your accounts. This can be tough if you don’t have a list, but consider making this a project. I think of it as a scavenger hunt: What’s that website where you paid for an e-greeting card that one time? What about that site where you ordered your fancy printed wedding photo album? Go through the years in your mind, or old digital photos from your phone. Figure out what was going on in your life and think about your online activities around those times. Enable two-factor authentication (2FA) or multi-factor authentication (MFA) — which mean basically the same thing — whenever you can. Most often this will be a texted (SMS) six- to eight-digit code of numbers or a mix of numbers and letters, or an email containing the same type of information. Update your passwords. Use long, randomly generated passwords. Passphrases are great for any account where you might need to type in a password on a computer or phone you don’t own, without access to your password manager. Some accounts use legacy systems that require short passwords. For those, you must use a randomly generated password. A password that is eight

We are talking about the keys to your kingdom: passwords. 30

W W W . ARTISANSPIRITMAG . C O M


Turn static files into dynamic content formats.

Create a flipbook
Artisan Spirit: Fall 2025 by Artisan Spirit Magazine - Issuu