The Water Trough- We can't make you drink, but we will make you think!

Don’t Be the Weakest Link: Cybersecurity tips from Shayne Kawalilak

Ed Drozda

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 32:05

Send us Fan Mail

Unlock the secrets of digital security with Shayne Kawalilak! 🌐 Learn how to safeguard your personal information in today's tech-driven world. Discover practical tips and insights from our latest conversation. Dive into the full discussion and grab a free digital copy of his book today, Don't Be the Weakest Link: How to Protect Your Personal Information in a Digital World. #CyberSecurity #PrivacyProtection

Ed Drozda

Welcome to The Water Trough, where we can't make you drink, but we will make you think. My name is Ed Drozda, The Small Business Doctor, and I'm really excited you chose to join me here as we discuss topics that are important for small business folks just like you. If you're looking for ideas, inspiration, and possibility, you've come to the right place. Join us as we take steps to help you create the healthy business that you've always wanted. Good morning, folks. This is Ed Drozda The Small Business Doctor. Welcome back to The Water Trough where I'm joined by Shayne Kawalilak. Shayne has been happily married to his ex-wife for over 20 years, and she's been happily married to him too for much of that time as well. He currently resides in St. Albert Canada where he is helping to homeschool the last of their nine children. Shayne has been a professional geek, a writer, and a public speaker for much of the past 25 years. His prime professional goal is to teach people how to protect their personal information, in a digital world. Shayne, welcome.

Shayne Kowalilak

Good morning.

Ed Drozda

And how are you, sir?

Shayne Kowalilak

Fantastic. It's wonderful weather here today.

Ed Drozda

What is wonderful weather there like?

Shayne Kowalilak

It's above freezing, so the snow is melting.

Ed Drozda

It's above freezing, okay. And what province is St. Albert in?

Shayne Kowalilak

Alberta. We're about seven hours straight north of Montana.

Ed Drozda

There we go. Okay. Okay. So Shayne, personal information in the digital world. That's one heck of a big challenge. Where would you like to start talking about protection?

Shayne Kowalilak

The most basic thing, and I cover this in all my presentations, is making sure people are doing the key things for their fundamentals. Set your password, make it a great one. Make sure you're using a password manager. Make sure you're using MFA and make sure you're not trusting a geek to give you the gold because IT professionals have done more in the last 20 years to make people and companies insecure than anything else.

Ed Drozda

Hold on. You're a geek. You're a self-proclaimed geek. What are you trying to tell me? Don't talk to or listen to somebody like yourself?

Shayne Kowalilak

I think you should listen to us, but don't trust us. Go do your own research That's where this comes from. I started doing these presentations probably eight, nine years ago, because clients were saying oh, that's different than we've always been taught. And I'm like okay, so I know that someone's told you that every 90 days your password's supposed to expire. I'm telling you from this day forward your passwords will never expire again. And if you see an email that a password's expired, I want you to call me immediately because that's a scam. That's someone trying to destroy the company that you work for or destroy your personal life. And it takes a while. People get the emails and like oh, I thought there was one more. Oh, I thought you didn't mean that for everything. I thought that was just for Microsoft 365. It's hard. You program people for 20 years with this email that in order to be secure, reset your password. We started that in 2001. Microsoft said this is a new best practice. Previously I'd been teaching our team this is what security's like. This is what you should be doing. We reset passwords and within six months I started seeing sticky notes on the walls, passwords written under keyboards, and I'm like I have never seen anyone in this company do this. What is going on? And they're like oh, if I gotta reset my password every 90 days I'm trying to find a good system for it. I don't want you to find a system for it, because that's what hackers are looking for. And now with AI, finding patterns is what AI does best. So, I don't want you to have a pattern. I want you to make a great password. Has to be long, 15, 20, more characters. I want it to have all four character types and I want it to never be repeated, ever. And that's where a password manager comes in. If you're doing those three things, don't reset it. Unless you think it's been breached or unless you think that someone saw you type it, that password should last you a decade.

Ed Drozda

What happens when the reminder to change your password comes from your own company or some other known entity, such as a bank or credit card company? The IT department says, you gotta change your password. It's been 90 days, six months, whatever, and you can verify that they're the ones reminding you. Is it because the IT department hasn't yet caught on that It's not necessary? What is it?

Shayne Kowalilak

Yeah, that's exactly what's happening, and that's why I'm saying don't trust your IT department. I talked to an IT guy the other day and they're set in old ways. They hear something from Microsoft, that's the Bible, this is the level we're looking for in our security. And Microsoft started the password reset 26 years ago, and there's guys that still stand by it as the law, but even Microsoft in the summer of 2024, right when I was wrapping up my book I was like oh my God, thank you. And it's just some little tiny sub note on one page where they say, oh by the way if you're an IT professional it might not be the most secure thing to reset your passwords. And I'm like dude, you guys started this. This shouldn't be a footnote. This should be on the front page, an email to everyone who's ever gotten a Microsoft certification in their life. Nope. They buried it on page 30, and I wasn't happy about it, but at least I could link to it and put it in the book, and I'm like yes. A little bit of vindication.

Ed Drozda

So, it's just a leftover thing, one of those status quos that doesn't go. We live with that, and of course we believe, naturally we believe that the IT department or whatever is telling us the truth. But I think what you're also saying is there's nefarious characters that can send that same email requesting that you change it and possibly hijack it if you open some link in their email. Is that correct?

Shayne Kowalilak

Yeah, think about the billions of dollars stolen by people every year. The ransomware, the hacks, and still over half start with that phishing email that says, hey your password's expired. Click here, give it to me, and I'll take care of everything.

Ed Drozda

Because they're not being vigilant about the source. I guess they assume that it's gonna be changed periodically, right? Therefore, there must be some legitimacy to this request.

Shayne Kowalilak

It's the same email they've been getting every 90 days for every service that they signed on for. I've got little sheets that you can download from the website. They're little printouts, and one of them is about red flags and I want you to learn about these red flags. How do I tell you that getting that email itself is a red flag if you get one every month or two, I mean...

Ed Drozda

Something's fishy. So what are you advocating for? You mentioned password managers, for example. Elaborate on that if you will. I happen to use one, but I'm sure there's a lot of people that don't.

Shayne Kowalilak

A password manager could be anything. In my presentations I show a video and I make jokes about having a little book called a Password Manager. But I tell people, I let you write down a password in two situations. Number one, your master password for your password manager. Write it down, put it in a safe until it's in your head and ingrained. Go ahead and write it down, 'cause if you lose that it ain't a good thing. The second thing, if you have an elderly member of your family and their bank password and their social media account are more secure than their memory, sit down with that person and log into everything with them and write down that information. It's a personal thing I've gone through and I wouldn't wish it on anybody, 'cause it's like you lose another piece of the person after they're gone. And so much of it is the government. I need that information. I need that form. And I can't log into the bank and now I'm taking death certificates to a bank. God help you getting your Google account or your Facebook account back. The person's passed away. Prove it. And you send the certificate, well prove that's the person that had the account. That's their name. It's not something that someone needs to go through, you know? And sometimes you gotta go through it before the person's gone. Write it down. But other than that, don't write passwords down. I don't wanna see 'em on paper anywhere. Use that password manager. I think my password manager's got 1400 or 1700 passwords in it and let it do its job. It remembers any character length. Most of my passwords are between 20 and 30 characters and it has no problem remembering them, but in my presentation I go hard on telling people, this password manager is your last line of defense. I tell 'em the story about how it saved me. 2:30 in the morning prepping for a big presentation. I was busy, busy, busy, and I just set up a new company a couple months ago and I get this email. Your password's expired and I'm like what? My password, how on earth did I forget to set it up on my password? And unbelievable, I clicked the link and it brought up the page and I'm sitting there and I'm like, I gotta get to bed. What the heck? My password manager's not working. I click the button. Usually I've got, I think there's 140 accounts in the Microsoft 365, and there's nothing. So I try to log in, I try to guess the password, I'm like I don't know this password. I haven't seen it in years. I log into my password manager to see why it's not syncing up and the URL's different. I'm not at microsoft office.com. I'm at microsoftofficereset.com and I'm like, oh my God. Not only did my password manager try to save me by saying, yeah, I don't recognize this website, so I'm not offering you any passwords. I tried to bypass it and actually manually log in, but I didn't know the password. And I'm like, you are the guy that wrote the book telling people not to do this. It was horrible. That password manager saved my butt. I tell people all the time you need to be using these tools and you're talking about five bucks a month, and there's free stuff out there. People ask what's your favorite password manager, and I'm like do you want one for price? Do you want one for a family package? Do you want one that's easy to use? Do you want one that's not cloud-based? I don't know what the best one for you is. Answer those questions and pick one

Ed Drozda

Absolutely, everything should be designed to fit your needs. I think generally speaking, people ask because they figure as the expert you should know what constitutes a good password manager. But you're right. If you did recommend something and it didn't quite fit their needs you're gonna look like a, well you know what you're gonna look like.

Shayne Kowalilak

The same thing I'd look like if I actually logged into that website and gave away my email account.

Ed Drozda

Yeah well, and you share that story with clients and with guests at your presentations.

Shayne Kowalilak

Yeah, I share it almost every presentation. I'm not infallible. I'm telling you, I built these systems, I use systems other people have built, and I use them to make me safe. I don't need you to build these things. This is what's available. Use the tool. The tool will save your butt.

Ed Drozda

If people hear someone like yourself did this I suppose it has to serve as a reminder just how vulnerable we all are. For those of us that are not as acutely aware, certainly those of us that have not been affected, and then this guy, it's like well there for the grace of God go I and all that kind of stuff. Right? When you're presenting to folks about these things, passwords are obviously a big part of it, but there's so much more to personal information in this current time, and it's not necessarily all password protected. It's more than that because information is readily available in general. Can you talk more about personal information with or without the password protection?

Shayne Kowalilak

The number one thing is find out what's stolen from you, because everyone thinks oh, those hackers are after my password. That's not what they want. Your password, if you're doing it right helps me get into one site. But if I get your birth date, your favorite color, your username, your GPS location, all this stuff together I've got a database with 50 data points on Ed Drozda, I can sell that, and I can sell it over, and over, and over. If I've got Ed's username and his password for Netflix how many times can I sell that? Who wants that one thing, you know? So, they can go to the website dontbetheweakestlink.com. On the Tools the first link is Hacked. Click that link and that'll change as there's better sites out there, right now it's going to a site called Have I Been Pwnd. Put your email address in, it's a safe site. It's gonna come back and show you all the stuff where your passwords have been breached, which information's been breached. A famous one was MGM. MGM lost my physical address, my name, so much information. No user or password, I didn't have accounts, I just stay at their hotels a lot, and all the information they had from me gone. And you're thinking, this is really personal stuff. You shouldn't have just given this away. Then a few months ago, WestJet gave away all my login info for the airline, including my passport. They gave away photos of my passport. If I have to scan my passport and send it to you to prove that I'm me, delete that crap when we're done. I've done it. I've proved it. Verify my account and delete that data. I wasn't happy that WestJet still had it. Why are they holding onto my passport? I gave it to you five years ago.

Ed Drozda

I wanna understand. You said they gave it away, it wasn't hacked, it was given away. Like sold?

Shayne Kowalilak

Well not sold, not big companies like that. Google and Facebook, all social media, they'll sell your stuff at the drop of a hat. They've got programs in place. People don't realize companies like Google and Amazon sell your stuff. Amazon's primary income source? It's selling your information. Advertising is the number one profit center for Amazon. It's been the number one profit center for Google for over a decade. If you're getting something for free, like your Gmail account, you have to understand you are the product in the transaction. Right now there's a big story about LinkedIn has been giving away your browser information for years, and they're like, oh, this is the biggest privacy breach ever. And I'm like, I don't think so. If you thought you were logging into LinkedIn for free and getting all the business social media services that LinkedIn gives for free and they weren't taking your browser data, I'm utterly shocked that all these professional geeks are shocked about this. How did you not assume this was happening? Now you have evidence, great. But you haven't been assuming that LinkedIn's been stealing this stuff since the day Microsoft bought them. That's what Microsoft does. They want your data. It's a hard thing to live with the idea that everyone's out to steal stuff from you, but it's where we're at in this world. Someone has to pay for all of Google servers. Those search engines, they're supported by ads. I use a free Google email account. I know that it's not as bad as when they started where the agreement said we have rights to use anything that you send in an email. I'm like, what? You don't have rights to that. I know you're looking at it. Microsoft 365 started OneDrive and they were all about privacy. Nobody has access to your files. We don't have them. We're not gonna look at them. So don't worry about your safety, but if you have child porn, we're closing your account. We're never gonna look at your file, but if you have this particular file we're killing your account. Well, then you're looking at my files.

Ed Drozda

It's such a pervasive thing. Is it even possible to protect our personal information? Again, the password is just the tip of the iceberg. Even that people don't manage well, but that's at the top in your face kind of thing. How do you protect your personal information then? Really? Or can you?

Shayne Kowalilak

It's a great question, Ed.

Ed Drozda

I mean seriously Shayne, you have to at least make the assumption that there's some things that you can do safely, but I realize in many cases that's stretching it. So I try to apply all the things that I know. I never take something in an email and call that number. I go back and I find the number of the thing I think I got it from and I call them on that number, stuff like that. I consider myself very aware. But I'm beginning to wonder if that's enough.

Shayne Kowalilak

The problem is when you go to that website, you type in your email, and you see you've been breached six times, you have to understand that's not you. That's not your fault. Home Depot got hacked. Adobe got hacked. That's LinkedIn. So you didn't lose the stuff. They lost your stuff on your behalf. That's why I said the number one thing that I want people to do is go out and know what's been taken. Because I could have a 30 character password. It has all four character types. It's never been used on any site ever before. But if it was my Adobe password in 2015, it's gone. And if you don't know it's been stolen, you probably haven't changed it. You probably think it's still a secure password. And somebody can use that password if there's no MFA on the account. They can go in and look at all the other stuff. Your secure hints. What's your mother's maiden name? I make people raise their hand if you've ever seen this question before. I said, okay keep your hand up and let me know have you seen it on more than one site? If you've seen that on two different services keep your hand up. If you use the same question, it makes sense. It's your mother's maiden name. It's your grade one teacher, your first car. It's in your head, you remember it. Now, keep your hand up if you put the same answer in for both questions. Nobody lowers their hands. If you put it up once you kept it up for all these questions, and I'm saying understand, IT professionals, me, came up with this idea for these secure hints, and we thought this is a way to add security to your account. But we know that a password's not secure if you've used it multiple times. Then by design, this special system of secure hints is forcing you, well making you use the same question, the same answer. So I tell people, use your password manager. In the book I use the example, your mother's maiden name. Look around your office. You see a large green plant. That's your mother's maiden name, large green plant. What's your first car? Large green plant. Grade one teacher? Large green plant. Answer's done. Go into your password manager, put secure hint, colon: large green plant. It's a pain in the butt when you're driving down the highway, the bank calls you and they say can you answer some security questions? I'm thinking yeah I'll answer security questions. Which one do you have? What's your mother's maiden name? Oh crap hang on, and I gotta pull over. I gotta log into my password manager 'cause I don't know my mother's maiden name. It's a hundred different things on a hundred different sites, you know? I still have IT guys, it's easy to convince them of this because they know they should never reuse a password. So when they see that oh that is a flaw in that system that we promote people to use the same secure hints everywhere, it's a flaw. That's the solution I've been using for years.

Ed Drozda

I understand you've developed something called a response ranking. Tell me about that.

Shayne Kowalilak

I co-wrote the book with Charles. We were perfectly in sync in everything related to technology. Both been doing this for over 25 years. I thought we were two brothers from another mother. One day I went to his computer, we were sitting in his office, and I said, "Oh, let me show you this thing." And I start typing, and I said, I'm gonna show you this thing I put on Facebook." And he's like, "Oh, you can't log into Facebook. My computer will never go to facebook.com. I don't want Facebook to know my computer exists." I thought about that for days. Here's this guy that I thought we were perfectly in sync in everything, and I've got three Facebook accounts, and he won't go to the URL. Seven days later, I had the hook for the book. We created the weakest link scale, where we rate your knowledge ranking. It's an A to F scale, and Charles and I, both A's. But then there's a response ranking, and when I thought about how Charles was responding to his knowledge of social media, where was the disconnect? The disconnect was in that response ranking. I'm not saying "Ed Drozda, you can't have a Facebook account." If you don't have a Facebook account, you're clearly more secure than I am. But if you say, "I need Facebook," or "I need Instagram to keep in touch with my kids, to promote my business, to sell products online," hey, those are all great reasons to have a social media account. But now, because you're opening yourself up to that insecurity of social media, there's tips and tricks you should be putting in place so that you are more secure. I hate saying being secure on social media because, if you're logging in for free you have to understand there's a product in this relationship, and if you're not paying Facebook or Gmail, you're the product, and they are stealing everything they can from you. And Charles gets it, and he's not willing to have it stolen

Ed Drozda

He's definitely more secure than I am, no question about it. But I think it's interesting to make that distinction between your knowledge and the way that you respond. Would you say generally speaking, that people with more knowledge are more apt to respond appropriately, or is it kind of a mishmash?

Shayne Kowalilak

I'd love to say yes, more knowledge is key because, like I said if you don't even know what's stolen how do you secure it? But the people with the most knowledge in the world are the guys that came up with secure hints, you know? And these are not secure. The guys with the most knowledge in the world are the guys that have been saying for 20 years, "You need to reset your password for your email every 90 days." Right now today, that is the number one most insecure thing that we do in the technology world. Don't reset your password, but the guys with the most knowledge are still touting it in some places. So I think knowledge is really important, but to assume that somebody that's an A is more secure, that would be a poor assumption in my mind.

Ed Drozda

I appreciate that insight. I think that many of us, especially those of us that are B's, C's, D's, or F's- would expect that the A's would have that leg up on us. But it's good to know that maybe that's not the case. If anything else, it provides a little humility. Hopefully.

Shayne Kowalilak

I'm like, dude, I have three different Facebook accounts and you won't even let me look at Facebook in your computer. We look at that threat totally different. I know that Facebook's a threat. I know they give away information on me that's astounding. I know that hackers and predators use Facebook to steal everything, including people. But I also believe that it's a necessary evil for me to be involved with, to reach more people. Charles, doesn't care about reaching those people. Our responses are different. So the response ranking is on a one to five scale. A one would be someone who wants to live in a cabin in the woods and the government doesn't know their address and nobody knows their real name. I joked about Charles being that guy in the cabin. And he's like, yeah that'd be okay with me. I'm like you would do that? He's oh, in a heartbeat. I do not want them to know who I am. I'm an A four. I don't know how many times my wife has had to reset my Netflix password 'cause some clown in Italy keeps changing the default language to Italian. I don't really care 'cause what's the harm, right? Then you find out that Netflix has a store. I'm on the phone with Netflix trying to explain that I didn't buy these two Stranger Things hoodies. I had no idea they had a store. What's the guy gonna do, upgrade my account? That level of security that I give to my email or to my password managers did not transfer to Netflix. My wife could've have cared less. I didn't care about it, and it was a problem for us for a little while. Whereas Charles? Charles would never go through that.

Ed Drozda

Charles may be able to keep his personal information safe.

Shayne Kowalilak

Much easier than you or I probably.

Ed Drozda

I take for granted that things are okay. I realize that there's certain things I know to be looking for, but that's inbound. I don't know about the outbound. I think that's the difference there. I scrutinize everything that comes in, but what goes out, I realize no.

Shayne Kowalilak

Yeah, well the problem is it's not going out from you. 99.94% of the crap that people take from you doesn't get taken from you. It gets taken from that Adobe hack. That's why number one, you have to go onto that website. Go there every three, six months, whatever, and just update and say, oh look, this has been taken. When you see someone has taken your secure hints be sure that those secure hints are in your password manager, that there's something stupid, like large green plant. If you go to your password manager and there's no secure hints in there, that likely means that the secure hints they just took from Adobe are the real answers. Log into your Adobe account, see what those questions are, and if one of them is your mother's maiden name, you need to go to your banks immediately and make sure that your password questions are not those questions, and that the answers aren't what they expect.

Ed Drozda

The site you're referring to is poned. P-W-N-D, is that correct?

Shayne Kowalilak

P-W-N-E-D.

Ed Drozda

I have been there before. I get something from them saying you've been poned periodically.

Shayne Kowalilak

You can put your email address in there and they let you know every time that email address has been found for sale on the internet. And we found it in a database with your home address, your GPS location, and it's astounding some of the stuff that's been stolen from you. I've gone through and looked, tried to find some of it, like verifications.io. This is a company I'd never heard of, but big companies, think Meta, Alphabet, Facebook and Google. These companies pay this company to hold onto my information so they can verify who I am. You'd think they'd secure it. But they didn't. No passwords, but again people gotta get it outta your head. Passwords are not what they want. They want all those other pieces of information. And once they feed that stuff into AI? AI it recognizes patterns, and if you use the same password, or password, 1, 2, 3, on that site password 1, 2, 4, that is not secure. My God password can't be in your password.

Ed Drozda

But surprisingly it is for many. Or not surprisingly, for that matter. Shayne, our time has come to an end. Before we part company, is there anything you'd like to leave us with?

Shayne Kowalilak

You know what, my goal in life outside of my family is to make the lives of hackers more difficult. I don't do this stuff for the money. I do it to share the knowledge. If you don't wanna read the book, that's a free digital copy, go to the website, get all that stuff. We're working on a second edition of the book as well.

Ed Drozda

Shayne, it's been a pleasure to be with you today. I really appreciate it.

Shayne Kowalilak

Hey, I appreciate it too, man. Thank you for having me on.

Ed Drozda

It's been a lot of fun. folks, this is Ed Drozda, The Small Business Doctor, and once again I'd like to thank my guest today, Shayne Kawalilik, all the way from Alberta, Canada, to the coastal regions of North Carolina. Thank you for enlightening us about our personal information in a digital world that's run amuck. But that's okay because we're doing our best. Most importantly, we have to be vigilant. Correct?

Shayne Kowalilak

Absolutely.

Ed Drozda

We will do that. Thanks to you, we can be a bit more than we were before. Folks, I want to wish you a healthy business as always, and I ask you please be very cautious and careful about your information.