External security/bs: Difference between revisions

From xat wiki
(Created page with "===Stvaranje jake lozinke===")
(Updating to match new version of source page)
(13 intermediate revisions by 2 users not shown)
Line 1: Line 1:
{{shortcut|es}}
{{shortcut|es}}
<languages/>Vanjska sigurnost je svaka mjera sigurnosti koja je izvan kontrole xata i nalazi se u rukama korisnika, kao što je korištenje jake lozinke i zaštita e-maila.
<languages/>
<div style="float:right; margin: 15px 0 15px 15px">__TOC__</div>
Vanjska sigurnost je svaka mjera sigurnosti koja je izvan kontrole xata i nalazi se u rukama korisnika, kao što je korištenje jake lozinke i zaštita e-maila.


Dakle, ovi savjeti nisu direktno povezani s xatom i na kraju je korisnikov izbor da slijedi ove savjete i koji se mogu primijeniti na bilo koju web stranicu. Ti su savjeti ključni za čuvanje vašeg xat računa i preporučujemo da ih koristite.
Dakle, ovi savjeti nisu direktno povezani s xatom i na kraju je korisnikov izbor da slijedi ove savjete i koji se mogu primijeniti na bilo koju web stranicu. Ti su savjeti ključni za čuvanje vašeg xat računa i preporučujemo da ih koristite.
Line 16: Line 18:
===Stvaranje jake lozinke===
===Stvaranje jake lozinke===


Making a strong password can be difficult, however generally a strong password consists of at least 8 characters that are a combination of letters (both uppercase and lowercase) and numbers. The more characters your password contains, the stronger it will be.
Stvaranje jake lozinke može biti teško, ali generalno jaka lozinka se sastoji od najmanje 8 znakova koji su kombinacija slova (velikih i malih slova) i brojeva. Što više znakova sadrži vaša lozinka, to će biti jača.


You may be using the following generator to instantly create a secure and random password (which works with xat) that you can use for your account: https://www.privacytools.io/password.html
Možda ćete koristiti sljedeći generator da odmah napravite sigurnu i slučajnu lozinku (koja radi na xatu) koju možete koristiti za svoj račun: https://www.privacytools.io/password.html


===Regularly Changing Your Password===
===Redovno mijenjanje vaše lozinke===


In a fast paced and forever changing place like the Internet, it is recommended that you change your password every 3 - 6 months so that in the event there is any sort of data breach, your account will likely not be affected.
Na brzom i zauvijek promjenjivom mjestu kao što je Internet, preporučuje se da promijenite lozinku svakih 3-6 mjeseci, tako da u slučaju da postoji neka vrsta provale podataka, vjerovatno neće uticati na vaš račun.


==Email Security==
==Sigurnost e-maila==


Email security is doubly important, as this is basically your centre of communication and links all of your accounts together, be it xat or any other social networking site.
E-mail sigurnost je dvostruko važna, pošto je ovo u osnovi vaš centar komunikacije i povezuje sve vaše račune zajedno, bilo da je to xat ili bilo koja druga stranica za društvene mreže.


===2-step verification===
Most of the suggestions below cover the four major email providers: [http://gmail.com Gmail], [http://hotmail.com Outlook/Hotmail], [http://icloud.com iCloud] and [http://mail.yahoo.com Yahoo Mail]. If your email provider is not listed, contact them and ask about their extra security features to protect your account.


The main email providers allow you to use 2-step verification to secure your email accounts. It requires you to give to your provider your phone number. Each time someone (including you) tries to access your email account, you will be sent a security token to your phone to then enter on your email login which will allow you to continue. This way, only someone with your phone is able to login into your email account.
'''Note''': If you are a paid user (have purchased xats before) you can request an email change by [http://xat.com/Ticket opening a ticket].


Here is a list of some providers who provide their users with 2-step verification:
=== Our recommendation ===
 
We recommend that you use Gmail as your primary email for xat. Gmail has several security methods to protect you from unauthorized access and they do not allow the reuse of email addresses. In addition, Gmail is the provider with the least occurrence of problems with receiving e-mails from xat.
 
'''We recommend you take a closer look at these security methods below to prevent third party access to your email.'''
 
===Verifikacija u 2 koraka===
 
Glavni provajderi e-maila vam omogućavaju da koristite verifikaciju u 2 koraka kako biste osigurali svoje e-mail račun. To zahtijeva od vas da svom provajderu date svoj broj telefona. Svaki put kada neko (uključujući i vas) pokuša da pristupi e-mail računu, na vaš telefon će biti poslan sigurnosni token da biste zatim unijeli vašu prijavu putem e-maila koja će vam omogućiti da nastavite. Na ovaj način, samo se neko sa vašim telefonom može prijaviti na vaš e-mail račun.
 
<div class="mw-translate-fuzzy">
Evo spiska nekih provajdera koji svojim korisnicima pružaju verifikaciju u dva koraka:
</div>


*Gmail - https://support.google.com/accounts/answer/185839?hl=en&rd=1
*Gmail - https://support.google.com/accounts/answer/185839?hl=en&rd=1
*Yahoo! Mail - https://email.about.com/od/yahoomailtip1/qt/How-to-Protect-Your-Yahoo-Mail-Account-with-Two-Step-Authentication.htm
*Yahoo! Mail - https://email.about.com/od/yahoomailtip1/qt/How-to-Protect-Your-Yahoo-Mail-Account-with-Two-Step-Authentication.htm
*Hotmail/Outlook - https://account.live.com/Proofs/Manage
*Hotmail/Outlook - https://support.microsoft.com/en-us/help/12408/microsoft-account-how-to-use-two-step-verification
*iCloud/Me/Mac - https://support.apple.com/kb/HT5570
*iCloud/Me/Mac - https://support.apple.com/kb/HT5570


'''Note:''' We do '''not''' recommend Yahoo or Hotmail/Outlook due to their policies which allow their users to re-use email handles if they become inactive.
=== Authentication ===
 
Gmail and Hotmail/Outlook allow you to use Authentication to secure your email account. Authentication is the industry standard for time-based or one-time passcodes (also known as TOTP or OTP). It requires you to download the authenticator app of your specific provider and activate it through your e-mail settings.  Each time someone (including you) tries to access your email account, you will be asked to type a temporary security token from the application to be granted access. These codes can also be generated offline which is useful if your device has no internet access.
 
'''Note:''' On Gmail, a QR code and a time-based key (which will be shown when you click on "can't read the code?") will be generated so that you can activate your application. You should save both of them in a safe place, so that if you lose your phone, you will be able to activate it on another device.
 
Here is a list of links with guides from Gmail and Hotmail/Outlook on Authentication:
*Gmail - https://support.google.com/accounts/answer/1066447?hl=en
*Hotmail/Outlook - https://support.microsoft.com/en-us/help/12408/microsoft-account-how-to-use-two-step-verification
 
=== Other methods ===
 
Gmail and Hotmail/Outlook also provide other methods to secure your email account. They are:
 
*'''Backup codes''': These are unique passwords that allow you to log in when you are away from your smartphone, such as when you are traveling. They can also be used in emergencies, and when all other methods fail. We recommend that you print or save them in offline storage units (i.e. USB drive).
 
*'''Access requests through the app''': You can prompt an access request that will appear via pop-up on your smartphone instead of entering your password.
 
*'''Backup phone (Gmail only)''': If you lose access to your phone and do not have any other recovery methods activated, this allows you to send a security code to an alternative phone.
 
*'''Physical security key (Gmail only)''': This method allows you to use a device as a physical key to access your email account. This can be done via your smartphone using Bluetooth or connecting directly to your computer's USB port, or by using an offline storage unit.
 
Here is where you will be able to setup these methods:
*Gmail - https://myaccount.google.com/u/3/signinoptions/two-step-verification
 
*Hotmail/Outlook - https://account.live.com/proofs/manage/additional
 
{{Color|#FF0000|<span class="mw-translate-fuzzy">'''Napomena:''' Mi '''ne''' preporučujemo Yahoo ili Hotmail/Outlook zbog svojih pravila koja omogućavaju korisnicima da ponovo koriste e-mail adrese ako postanu neaktivne.</span>}}


{{Category|Security}}
{{Category|Security}}
__NOTOC__

Revision as of 13:51, 20 July 2020

Vanjska sigurnost je svaka mjera sigurnosti koja je izvan kontrole xata i nalazi se u rukama korisnika, kao što je korištenje jake lozinke i zaštita e-maila.

Dakle, ovi savjeti nisu direktno povezani s xatom i na kraju je korisnikov izbor da slijedi ove savjete i koji se mogu primijeniti na bilo koju web stranicu. Ti su savjeti ključni za čuvanje vašeg xat računa i preporučujemo da ih koristite.

Zapamtite da xat neće nikada tražiti vaše lične podatke.

Lozinka

Lozinke su ključne riječi sigurnosti računa i imati jaku lozinku od velikog je značaja prilikom korištenja xata ili bilo koje druge web stranice. Imajući jaku lozinku sprečava ljude da pogađaju i brute forcing vašu lozinku.

Da biste bili sigurni da niko ne može pogoditi vašu lozinku, izbjegavajte da koristite vaše ime ili imena članova porodice, vaše korisničko ime, datum rođenja, ponovljene znakove ili bilo koje uobičajene riječi koje se nalaze u rječniku. Ne zaboravite da koristite različitu lozinku od lozinke svog e-maila.

Napomena: Na xatu, svi ne-alfanumerički znakovi će biti uklonjeni iz vaše lozinke, tako da se uvjerite da sadrži samo alfanumeričke znakove (a-z, A-Z, 0-9).

Stvaranje jake lozinke

Stvaranje jake lozinke može biti teško, ali generalno jaka lozinka se sastoji od najmanje 8 znakova koji su kombinacija slova (velikih i malih slova) i brojeva. Što više znakova sadrži vaša lozinka, to će biti jača.

Možda ćete koristiti sljedeći generator da odmah napravite sigurnu i slučajnu lozinku (koja radi na xatu) koju možete koristiti za svoj račun: https://www.privacytools.io/password.html

Redovno mijenjanje vaše lozinke

Na brzom i zauvijek promjenjivom mjestu kao što je Internet, preporučuje se da promijenite lozinku svakih 3-6 mjeseci, tako da u slučaju da postoji neka vrsta provale podataka, vjerovatno neće uticati na vaš račun.

Sigurnost e-maila

E-mail sigurnost je dvostruko važna, pošto je ovo u osnovi vaš centar komunikacije i povezuje sve vaše račune zajedno, bilo da je to xat ili bilo koja druga stranica za društvene mreže.

Most of the suggestions below cover the four major email providers: Gmail, Outlook/Hotmail, iCloud and Yahoo Mail. If your email provider is not listed, contact them and ask about their extra security features to protect your account.

Note: If you are a paid user (have purchased xats before) you can request an email change by opening a ticket.

Our recommendation

We recommend that you use Gmail as your primary email for xat. Gmail has several security methods to protect you from unauthorized access and they do not allow the reuse of email addresses. In addition, Gmail is the provider with the least occurrence of problems with receiving e-mails from xat.

We recommend you take a closer look at these security methods below to prevent third party access to your email.

Verifikacija u 2 koraka

Glavni provajderi e-maila vam omogućavaju da koristite verifikaciju u 2 koraka kako biste osigurali svoje e-mail račun. To zahtijeva od vas da svom provajderu date svoj broj telefona. Svaki put kada neko (uključujući i vas) pokuša da pristupi e-mail računu, na vaš telefon će biti poslan sigurnosni token da biste zatim unijeli vašu prijavu putem e-maila koja će vam omogućiti da nastavite. Na ovaj način, samo se neko sa vašim telefonom može prijaviti na vaš e-mail račun.

Evo spiska nekih provajdera koji svojim korisnicima pružaju verifikaciju u dva koraka:

Authentication

Gmail and Hotmail/Outlook allow you to use Authentication to secure your email account. Authentication is the industry standard for time-based or one-time passcodes (also known as TOTP or OTP). It requires you to download the authenticator app of your specific provider and activate it through your e-mail settings. Each time someone (including you) tries to access your email account, you will be asked to type a temporary security token from the application to be granted access. These codes can also be generated offline which is useful if your device has no internet access.

Note: On Gmail, a QR code and a time-based key (which will be shown when you click on "can't read the code?") will be generated so that you can activate your application. You should save both of them in a safe place, so that if you lose your phone, you will be able to activate it on another device.

Here is a list of links with guides from Gmail and Hotmail/Outlook on Authentication:

Other methods

Gmail and Hotmail/Outlook also provide other methods to secure your email account. They are:

  • Backup codes: These are unique passwords that allow you to log in when you are away from your smartphone, such as when you are traveling. They can also be used in emergencies, and when all other methods fail. We recommend that you print or save them in offline storage units (i.e. USB drive).
  • Access requests through the app: You can prompt an access request that will appear via pop-up on your smartphone instead of entering your password.
  • Backup phone (Gmail only): If you lose access to your phone and do not have any other recovery methods activated, this allows you to send a security code to an alternative phone.
  • Physical security key (Gmail only): This method allows you to use a device as a physical key to access your email account. This can be done via your smartphone using Bluetooth or connecting directly to your computer's USB port, or by using an offline storage unit.

Here is where you will be able to setup these methods:

{{{2}}}