<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://www.explainxkcd.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Lurrch</id>
		<title>explain xkcd - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://www.explainxkcd.com/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Lurrch"/>
		<link rel="alternate" type="text/html" href="https://www.explainxkcd.com/wiki/index.php/Special:Contributions/Lurrch"/>
		<updated>2026-05-23T19:24:34Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.30.0</generator>

	<entry>
		<id>https://www.explainxkcd.com/wiki/index.php?title=1820:_Security_Advice&amp;diff=138371</id>
		<title>1820: Security Advice</title>
		<link rel="alternate" type="text/html" href="https://www.explainxkcd.com/wiki/index.php?title=1820:_Security_Advice&amp;diff=138371"/>
				<updated>2017-04-05T15:28:25Z</updated>
		
		<summary type="html">&lt;p&gt;Lurrch: /* Security Tip Explanations */ I clarified the section about special characters.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{comic&lt;br /&gt;
| number    = 1820&lt;br /&gt;
| date      = April 5, 2017&lt;br /&gt;
| title     = Security Advice&lt;br /&gt;
| image     = security_advice.png&lt;br /&gt;
| titletext = Never give your password or bank account number to anyone who doesn't have a blue check mark next to their name.&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Explanation==&lt;br /&gt;
{{incomplete|Incomplete. TBD:Complete tip explanations Do NOT delete this tag too soon.}}&lt;br /&gt;
&lt;br /&gt;
The comic depicts a conversation between [[Cueball]] and [[Ponytail]], discussing the fact that giving people security advice has failed to improve their internet security, and in some cases even made things worse (such as requiring complicated passwords leading to people leaving post-it notes with their passwords on their screen, leading to huge security risks). As a result Cueball suggests {{w|reverse psychology|giving bad advice instead}}, in hopes of a positive effect. The last panel contains a list these security tips, which are parodies of actual security tips.&lt;br /&gt;
&lt;br /&gt;
The issue of passwords and computer security was covered in [http://www.explainxkcd.com/wiki/index.php/936:_Password_Strength 936: Password Strength].&lt;br /&gt;
&lt;br /&gt;
The last tip on the image is most likely a reference to Ingmar Bergman's film [https://en.wikipedia.org/wiki/The_Seventh_Seal#Synopsis The Seventh Seal].&lt;br /&gt;
&lt;br /&gt;
===Security Tip Explanations===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!Security Tip&lt;br /&gt;
!Explanation&lt;br /&gt;
|-&lt;br /&gt;
|Don't click links to websites&lt;br /&gt;
|The usual tip is &amp;quot;Don't click on ''suspicious'' website links.&amp;quot; The comic's variation instead implies don't click on any links to any websites, or don't use the internet.&lt;br /&gt;
|-&lt;br /&gt;
|Use prime numbers in your password&lt;br /&gt;
|Long prime numbers are an essential part of modern cryptography and security systems, but don't have any effect when being used in passwords, except for maybe being harder to remember. In addition, if people were to regularly use prime numbers in their passwords, it would actually make passwords ''easier'' to guess, as it would substantially shrink the search space.&lt;br /&gt;
|-&lt;br /&gt;
|Change your password manager monthly&lt;br /&gt;
|It is often recommended to change passwords on a regular basis. However, changing password managers monthly would be quite impractical.&lt;br /&gt;
|-&lt;br /&gt;
|Hold your breath while crossing the border&lt;br /&gt;
|This in its self, wouldn't do anything, but if you hold your breath for too long you could pass out when crossing, or look stressed/suspicious. Overall, this would not help you.&lt;br /&gt;
|-&lt;br /&gt;
|Install a secure font&lt;br /&gt;
|A real tip might be &amp;quot;Install a secure browser&amp;quot; especially when many people used [https://en.wikipedia.org/wiki/Internet_Explorer_6 Internet Explorer 6]. Using a different font on a computer would not help one's internet security.&lt;br /&gt;
|-&lt;br /&gt;
|Use a 2-factor smoke detector&lt;br /&gt;
|A new way to keep accounts secure is 2-factor authentication, which usually means you enter your password, and then look for an email (or go into a mobile app) with a code which you then enter into the website. A 2-factor smoke detector would be useless, because it would require you to verify that there is actually a fire with a code, when the purpose of smoke detectors are to warn you about fires you ''don't'' know about.&lt;br /&gt;
|-&lt;br /&gt;
|Change your maiden name regularly&lt;br /&gt;
|The usual tip is to change your passwords regularly. Some password recovery procedures ask for a security question, like &amp;quot;what is you maiden name&amp;quot; (which is the family name that you were born with). Since it acts as a second password, it should also be changed regularly. Changing it, however, would be very difficult or even impossible, even more so on a regular basis. Also, maiden names and other trivia typically asked by security questions are not secret, so they are inherently not secure.&lt;br /&gt;
A real tip for dealing with security questions would be to enter false data.&lt;br /&gt;
|-&lt;br /&gt;
|Put strange USB drives in a bag of rice overnight&lt;br /&gt;
|The usual security tip is &amp;quot;Don't plug strange USB drives into your computer,&amp;quot; because sometimes attackers put viruses that infect your system when plugged in. This tip implies that you should &amp;quot;put USB drives in a bag of rice overnight&amp;quot; which is a common technique for drying out water damaged devices, due to rice's absorbent qualities. This would not clean the drive of viruses, and unless the drive was wet (perhaps because you found it outside due to it being called &amp;quot;strange&amp;quot;) it would not do anything.&lt;br /&gt;
|-&lt;br /&gt;
|Use special characters like &amp;amp; and %&lt;br /&gt;
|You can use special characters to increase the entropy/strength of your password, though as describe in [http://www.explainxkcd.com/wiki/index.php/936:_Password_Strength xkcd 936], that often leads to passwords that are hard to remember but not particularly strong.  The password context is missing here, and in everyday situations the characters &amp;amp; and % are not special.&lt;br /&gt;
|-&lt;br /&gt;
|Only read content published through Tor.com&lt;br /&gt;
|[https://en.wikipedia.org/wiki/Tor_(anonymity_network) Tor] is a software solution to provide anonymity on the web for its users. The website [https://tor.com Tor.com] is the website of fantasy and sci-fi book publisher Tor, which has no relation to the Tor-network.&lt;br /&gt;
|-&lt;br /&gt;
|Use a burner's phone&lt;br /&gt;
|A play on using a burner phone (a cheap/disposable cell phone like those purchased at 7-11, often used for drug deals or other activity one might not want traced), and using the cell phone of a burner, i.e. a person who goes to the the Burning Man festival.&lt;br /&gt;
|-&lt;br /&gt;
|Get an SSL certificate and store it in a safe place&lt;br /&gt;
|SSL/TLS is a protocol for securing connections on the internet. To check if someone is who he claims to be you can check the individuals certificate. Such a certificate has to be public, storing it in a safe place makes the certificate useless. You have to store the private key that matches the certificate in a safe place, else someone could steal the identity.&lt;br /&gt;
|-&lt;br /&gt;
|If a border guard asks to examine your laptop, you have a legal right to challenge them to a chess game for your soul.&lt;br /&gt;
|This tip is likely a reference to Ingmar Bergman's film [https://en.wikipedia.org/wiki/The_Seventh_Seal#Synopsis The Seventh Seal]&lt;br /&gt;
|-&lt;br /&gt;
|Never give your password or bank account number to anyone who doesn't have a blue check mark next to their name. (Title Text)&lt;br /&gt;
|The usual security tip here is ''&amp;quot;only trust accounts claiming to be legitimate if they have a blue check mark next to their name&amp;quot;'', which means that the account is verified as legitimate. This tip suggests only giving your ''password'' to verified accounts, although you shouldn't give your password to ''any'' account. &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Transcript==&lt;br /&gt;
{{incomplete transcript|Do NOT delete this tag too soon.}}&lt;br /&gt;
&lt;br /&gt;
:Ponytail: We've been trying for decades to give people good security advice.&lt;br /&gt;
:Ponytail: But in retrospect, lots of the tips actually made things worse.&lt;br /&gt;
&lt;br /&gt;
:Cueball: Maybe we should try to give ''bad'' advice?&lt;br /&gt;
:Ponytail: I guess it's worth a shot.&lt;br /&gt;
&lt;br /&gt;
:Security tips&lt;br /&gt;
:(Print out this list and keep it in your bank safe deposit box.)&lt;br /&gt;
* Don't click links to websites&lt;br /&gt;
* Use prime numbers in your password&lt;br /&gt;
* Change your password manager monthly&lt;br /&gt;
* Hold your breath while crossing the border&lt;br /&gt;
* Install a secure font&lt;br /&gt;
* User a 2-factor smoke detector&lt;br /&gt;
* Change your maiden name regularly&lt;br /&gt;
* Put strange USB drives in a bag of rice overnight&lt;br /&gt;
* Use special characters like &amp;amp; and %&lt;br /&gt;
* Only read content published through Tor.com&lt;br /&gt;
* Use a burner's phone&lt;br /&gt;
* Get an SSL certificate and store it in a safe place&lt;br /&gt;
* If a border guard asks to examine your laptop, you have a legal right to challenge them to a chess game for your soul.&lt;br /&gt;
&lt;br /&gt;
{{comic discussion}}&lt;/div&gt;</summary>
		<author><name>Lurrch</name></author>	</entry>

	</feed>