Latest
Anthropic Bans Cruelty Toward Claude: What It Means for WritersWork-for-Hire Contracts: What the Asimov’s Cover Fight Teaches FreelancersGenre Fiction vs Literary Fiction: Don’t Confuse Taste With SkillFlorida Hurricane Prep Rituals: The Grocery Run, the Water Pallet and the Generator in the BoxThe Most Insulting Line of Dialogue Ever Written for the ScreenLoki Through the Ages: From Norse Myth to Marvel, The Mask and Dogma“You Are Utterly Disgusting”: A Book Festival, an AI Cover Ban and a Pile-OnWho Rewrote the Sligachan Legend: AI or the Tour Buses?Why I Don’t Like Reedsy for Ghostwriting: The NDA ProblemLayers: How I Ride Out Florida Power Outages in My ApartmentThe Enshittification of AmazonPublishers Cancel Books Over AI While Using It in SecretI Was Getting 100 Spam Emails a Day. $4.50 a Month Fixed It.World Mental Health Day: Nothing Was Wrong With MeKessler Syndrome: How Space Debris Could Close Earth’s OrbitAmazon Is Blocking Real Readers From Book ReviewsShould a Novella Get a Paperback, or Go Ebook Only?BookFunnel Download Problems: Fixes, Scams and AlternativesSir Sean Connery: A TributeHow to Find Plot Holes in Your Novel (Most Are Character Holes)Reshoring: The Factory Is the Easy PartMost of the Books I Was Forced to Read in High School Were CrapPlot Armor: Signs Your Hero Is Too Safe, and How to Fix ItShould You Sell Lifetime Rights to Your Self-Published Book for a Modest Advance?Shame Doesn’t Stop Artists From Using AI. It Stops Them From Telling You.AI Labels on TikTok and Meta Are Flagging Human WorkAuthor Richard Lowe Completes Peacekeeper, a Four-Book Science Fiction Series He Started at Age 14Sir Sam Neill: A TributeFan Art Copied by AI: Glass Houses, Copyright and the Pile-OnReal Names in a Book: Who Gets Sued, the Author, the Publisher or the Ghostwriter?When Characters Take Over the Plot, Let ThemDoes Human Writing Have a Soul?“You’re Not a Real Author”: The Pile-On Over AI-Assisted BooksDoes AI Have a Soul? Wrong QuestionHumor in Book Marketing: Getting Attention Without BeggingHow Long Should a Chapter Be? Manuscript Habits That Save You LaterThe Business Novel and the Companion Workbook: Two Formats Business Authors OverlookThe Back of the Book: Index, About the Author, Acknowledgments and Back Cover CopyI Build My Own Software Tools With Claude, and Some of Them Bit MeWhat Years of Buying From IT Vendors Taught MeI Write Books for a Living. I Barely Read Them Anymore.Three Management Habits That Waste Good PeopleThe Coach and the Webinar That Sold Me NothingThe Work I’d Cringe At Now, and Why I’m Glad I DoWho Is Your Book For? Build a Reader Avatar Before Chapter OnePreface, Prologue, Foreword or Introduction: What Goes WhereWhy I Won’t Build a Ghostwriting Business That ScalesHow I Hire a Virtual Assistant: Do It, Script It, Hand It OffThe Mail Carrier Who Thought Flipping Houses Was EasyWhat Wedding Photography Taught Me About Pricing Creative Work
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

I Got Caught Hacking in 1981. The Professor Made Me Head of Security.

TL;DR: Home security doesn’t fail at the technical seam. It fails at the human one. A company with card readers, cameras and alarms lost everything to a brick propping a door open for smoke breaks. Your house has somewhere between 25 and 60 connected devices you bought one at a time, and the defenses that work are the dull ones you can keep doing.

In 1981 a college professor caught me trying to break into the school’s computer system. He didn’t suspend me. He said, since you hacked our computer, you’re now in charge of system security, and handed me the job.

That was the most useful thing anyone has ever done for my career, and not because it taught me about computers. It taught me that the only reliable way to protect a system is to look at it the way somebody trying to get in would look at it. Not the way the person who built it sees it, and definitely not the way the brochure describes it.

Thirty-three years in enterprise technology later, twenty of them running computer operations at Trader Joe’s, that habit has never stopped paying. It’s also the reason I find most home security advice close to useless. It describes products. It doesn’t describe how anybody gets in.

How does a company with cameras and card readers still get breached?

The company had spent thousands on card readers, security cameras and alarm systems. Every door logged every entry. Every corridor was covered. On paper it was excellent. An employee got tired of digging his badge out every time he stepped outside for a smoke break, so he propped the door open with a brick. That was the whole breach. Everything upstream of that door became decoration.

I’ve thought about that brick for years, because it’s the shape of nearly every failure I’ve seen since. The technical controls were fine. The seam was a person doing something reasonable to make his day slightly easier. Criminals know this better than most security professionals do. They don’t build attacks around beating your antivirus. They build attacks around what you already know and keep postponing. You know you should install that update. You keep clicking remind me later, because you’re busy and it’ll restart your machine and you have things to do.

The remind-me-later button is a dumb feature. Software makers put it there because people hate restarts, and criminals profit from it every week. Each postponed update is a door you already know is unlocked, and you’re betting nobody tries the handle before you get around to it.

What does an ordinary neighborhood look like from the attacker’s side?

Some years ago I drove through a suburban neighborhood with a laptop running network scanning software. Not doing anything, just looking, the way somebody who wanted in would look. In twenty minutes I found 127 home networks still using their default passwords and 43 with no password at all. Dozens of routers hadn’t been updated in years. Any teenager with ordinary computer skills could have been inside most of those houses’ internet connections that afternoon. None of those families thought of themselves as targets. That’s exactly why they were easy ones.

I ran a version of the same test at a cybersecurity conference, a room full of people who do this for a living. I set up a wireless network called Free Conference WiFi and left it running.

Within an hour I’d captured login credentials from seventeen different smart devices, because their owners’ phones had connected automatically and the devices had followed. Most of those people had no idea their gear hands over credentials to anything that looks familiar enough.

How many connected devices are in your house right now?

I counted the devices using my own internet connection once, expecting maybe fifteen. There were 47. Phones, tablets, computers, smart speakers, security cameras, thermostats, the refrigerator. I’d bought every one of them separately, over several years, each for its own reason. At no point did I sit down and design a network. It assembled itself out of individual purchases that each made sense on their own.

Most families are somewhere between 25 and 60 devices without ever having counted. Each one contains a computer more capable than the systems that ran entire corporations in the 1980s. Each one talks to servers belonging to companies you’ve never heard of.

That part is worse than any single gadget. Manufacturers ship these things with default passwords and quiet connections home, and nobody in the house agreed to any of it in a way they’d recognize. When one of those devices gets taken over, the family finds out last, if it finds out at all.

The strangest one I’ve found belonged to a family who called me about mysterious activity on their router.

We checked every computer, every phone, every obvious smart device, and found nothing. It turned out to be their two-year-old microwave. It had never been set up for internet access, so it had attached itself to a neighbor’s unsecured network and was phoning the manufacturer every night.

You can’t protect an inventory you’ve never taken. That’s the first real step, and almost nobody does it.

The book on this: Family Cybersecurity is 231 pages on protecting a household instead of a company: the devices, the habits, the backups, and the conversations with the people you live with.

Does paid security software protect you better than the free one?

I ran a comparison of Windows Defender against four commercial antivirus products. Defender detected 99.2 percent of the malware samples, had the lowest false positive rate of anything tested, and used less memory and processor than most of the paid alternatives. The free thing already on the machine outperformed the subscriptions.

I think most of the money people spend on paid security suites goes to the wrong place. The subscription feels like protection, and the vendors are glad to sell that feeling. The protection that works is the dull maintenance nobody advertises: updates, backups, and passwords that aren’t the factory default.

A small business owner I know of postponed his updates for three months because restarting interrupted his work. Criminals eventually exploited a vulnerability Microsoft had patched two months earlier. The attack encrypted everything and the ransom demand was fifty thousand dollars.

He paid it and never received working decryption keys. Three years of customer records, gone, and the business rebuilt from nothing.

Ten minutes of restart, spread across three months, against the whole company. That’s the real exchange rate, and it never feels like that in the moment.

Why do so many breaches start with somebody being helpful?

Why breaches start with somebody being helpfulA family donated an old computer to a charity, having deleted their files first and believing it was clean. Deleting is not erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost fifteen thousand dollars and two years of credit repair. Nothing technical failed. They did a generous thing without knowing that the delete key is a suggestion instead of an instruction. The same lesson turned up on a home network, where a gaming console connecting at three in the morning every night turned out to be a neighbour teenager who had guessed the WiFi password and consumed nearly half a month of data before anybody looked.Why the breach started with a kindnessNothing technical failed. Delete is a suggestion, not an instruction.1A generous actAn old computer donated to charityFiles deleted first, believed clean2Deleting is not erasingThe data was still on the driveand the drive was sold on3Five years recoveredTax returns. Bank statements.Personal photographs.4The cost$15,000 and two years of credit repairfrom doing something kindNothing technical failed here. The failure was in what nobody had been told.
Why breaches start with somebody being helpfulA family donated an old computer to a charity, having deleted their files first and believing it was clean. Deleting is not erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost fifteen thousand dollars and two years of credit repair. Nothing technical failed. They did a generous thing without knowing that the delete key is a suggestion instead of an instruction. The same lesson turned up on a home network, where a gaming console connecting at three in the morning every night turned out to be a neighbour teenager who had guessed the WiFi password and consumed nearly half a month of data before anybody looked.Why the breach started with akindnessNothing technical failed. Delete is a suggestion,not an instruction.1A generous actAn old computer donated to charityFiles deleted first, believed clean2Deleting is not erasingThe data was still on the driveand the drive was sold on3Five years recoveredTax returns. Bank statements.Personal photographs.4The cost$15,000 and two years of credit repairfrom doing something kindNothing technical failed here. The failure was inwhat nobody had been told.

A family I helped donated an old computer to a charity. They’d deleted their files first and believed it was clean. Deleting isn’t erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost them fifteen thousand dollars and two years of credit repair. Nothing technical failed there. They did a generous thing and didn’t know that the delete key is a suggestion instead of an instruction.

Don’t count on anyone else to wipe a machine before it leaves your house. That job is yours. Erase the drive properly or pull it and destroy it, because a stranger with free recovery software can read everything you thought you’d deleted, and the people who pay for that mistake are the family whose names are on those tax returns.

Even my own network taught me this one. I noticed a gaming console connecting at three in the morning, every night. It was my neighbor’s teenager, who had guessed my WiFi password and had been downloading games for months. He’d consumed nearly half my monthly data before I looked.

What should you do first, and in what order?

If you take one thing from this, take the order. Most people start with the most visible step instead of the most effective one.

Count your devices. Open your router’s admin page and look at the list. You’ll find things you forgot about and probably something you don’t recognize. That list is what you’re protecting.

Change the router’s default password. Then check when it was last updated. This is the front door and it’s the one people skip.

Turn on automatic updates and stop postponing them. The restart is the price. It’s a low price.

Back up the things you can’t replace, and keep one copy somewhere that’s not attached to your network. Ransomware encrypts what it can reach.

Talk to the people you live with. Every technical control in your house runs through somebody’s judgment at some point. The brick is always a person, and the fix is a conversation instead of a purchase.

None of that is exciting and none of it costs much. That’s rather the point. The professor who caught me in 1981 was right about the method: look at your house the way somebody trying to get in would look at it. What you find will be duller and more fixable than you expect.

Families lose years of records and photographs to attacks that a changed password or a routine restart would have stopped. An industry that keeps selling them another gadget without ever mentioning either fix owes them better.

Frequently Asked Questions

What is the first thing I should do to secure my home network?
Take an inventory. Open your router’s administration page and look at what is connected. Most households have between 25 and 60 devices and have never counted them. You can’t protect a list you don’t have, and the list usually contains at least one surprise.
Is free antivirus good enough?
For most households, yes. In a comparison against four commercial products, Windows Defender detected 99.2 percent of malware samples, had the lowest false positive rate, and used less memory and processor than the paid alternatives. The bigger gains come from updates and backups instead of from a subscription.
Why do security updates matter so much?
Because most successful attacks use vulnerabilities that were patched weeks or months earlier. One small business owner postponed updates for three months, lost everything to ransomware, paid a fifty thousand dollar ransom and never received working keys. The patch had been available for two months.
Is deleting files enough before I give away a computer?
No. Deleting removes the pointer, not the data. A family who donated a computer after deleting their files had five years of tax returns, bank statements and photographs recovered from it, leading to fifteen thousand dollars of identity theft. Use secure erasure software, or physically destroy the drive.
Do smart home devices really pose a risk?
They do, and often without anyone noticing. At a conference I set up a network called Free Conference WiFi and captured credentials from seventeen smart devices within an hour. One family’s two-year-old microwave had attached itself to a neighbor’s unsecured network and was contacting the manufacturer nightly.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment