As we leave winter behind in March and head into tax filing month, April, this may be an opportune time to reflect on one of the basics of our internet age: online accounts and their security.
Here in Canada, we still haven’t heard the end of the nightmarish user account compromises that have plagued the Canada Revenue Agency, sometimes leaving innocent users owing the CRA for bogus refunds issued in their names or using their online accounts.
That story is for another day, but in the interim, readers may want to check out the summary from the excellent recent CBC Fifth Estate investigation, “Who’s Hacking CRA Accounts,” first broadcast March 7. The CBC’s journalists explored the notion that these CRA hacks are not the result of user carelessness but rather of hacks into the loosely regulated private tax filing industry.
Keeping our online accounts safe and secure is an ongoing battle. There is no shortage of scams and scammers operating locally, nationally, and internationally. The common threat vectors remain emails, compromised websites, bogus text messages, and phone calls. This latter category, phone calls, used to be largely confined to landlines but nowadays hits mobiles equally well.
Recently I received a call on my mobile, the caller claiming to be from the phone company. I was in a slightly noisy environment, which the caller noted. That raised a bit of a red flag for me. My standard response to calls from the phone company, landline or mobile, is that unless the caller is phoning to announce a reduction in the monthly bill, there is no point in further conversation. This call was intended to capture my voice for use in automated scams down the road. I hung up and called the number back to confirm it was indeed a scam.
I see no let-up in email-based scams and in “cheap item” scams on the Facebook platform. Most of these are as laughable today as they were 10 years ago, and yet there are new victims every day. I’ve written about many of these in this space previously. The latest Facebook variants involve a too-good-to-be-true item for sale—for example, a snow blower for $15. A reputable retailer is mentioned, and the posts generally have a few hundred positive, although fake, comments. Stay clear!
I maintain multiple email accounts. The Outlook email address linked to this column is a honeypot of sorts. It attracts a huge volume of spam and junk emails, which Microsoft, unlike Google with its Gmail service, seems unable to manage. It doesn’t bother me too much, as it gives me a window into current scams—some of which I occasionally engage with, on a Chromebook, to see how they are structured.
AI tools are a boon to scammers. Sophisticated-looking materials and websites are easily produced by such tools. As the Trump tariff wars cause Canadians to rethink travel plans, expect to see vacation resort scams targeting other countries. As always, if it looks too good to be true, it surely is. Besides, this rejigging to other destinations is already causing prices to rise. Supply and demand economics is still reliable and predictable, tariffs or not.
In addition to continual vigilance in the online world, it is good practice to have a password manager for all the various accounts you use. Whether you use a browser-based password manager such as the one in Google Chrome or a dedicated password manager, let it suggest passwords when you set up new accounts or when you want to strengthen access to existing ones.
In my own case, I’ve used password managers for almost 20 years. About three years ago I switched to the Canadian company 1Password, primarily because it offers two identical services: one where data remains strictly in Canada, on Canadian servers (1Password.ca), and another where data is stored internationally (1Password.com).
Commercial password managers have a bit of a checkered history, and some have seen their data servers hacked by malicious actors. 1Password has not had this happen, but you can imagine there are frequent attempts—both at the company level and at the individual user level through social engineering emails.
My 1Password.ca manager presently holds some 190 records. It frequently reminds me that about 15 of those accounts have weak passwords. These are mostly for low-interest, obscure websites. Eventually I will deal with those. I’d rather delete the accounts, but account deletion seems to be non-existent for many websites.
As of this writing, a 1Password.ca account is priced at $50.40 (with 12% tax) for a year—so about a dollar a week. Given the number of accounts I’m maintaining, I see this as reasonable value. I also appreciate being able to use the manager across multiple devices: desktop computer, Chromebook, and Android phone.
For access, 1Password requires a password, but it also requires, on varying occasions—particularly on unrecognized devices—a secret key. Neither the password nor the secret key is known to the company. Without that secret key, the account information stored by 1Password stays encrypted.
One other highly useful feature is that 1Password keeps an eye on data breaches and will push a notification suggesting an immediate password change if it spots a user account of yours in such a case.
For now, consider your own practices when it comes to online security. And good luck with your tax return!
Follow me on Twitter/X (@PeterVogel) or on Bluesky (petervogel.bsky.social).
pvogel@outlook.com
Your voice matters! Join the conversation by submitting a Letter to the Editor here.
