Account Security
7 steps · one page
In short
Almost nothing about account security is about the password.
Scope. This article is practical and stays practical. No security product, application, vendor or service is named, because a named recommendation would be a recommendation, and because the useful content here is about mechanisms rather than brands. It covers protecting an account against someone else taking control of it. Money handed over voluntarily to a fraudulent operation is a different problem and belongs to the fraud articles in this pillar.
Accounts are rarely taken over by guessing a password. They are taken over through the recovery path, which exists precisely so that someone who cannot supply the password can still get in. Which means the question worth asking is not how strong the password is, but who else could complete a password reset.
The chain nobody maps
A brokerage account is protected by the brokerage. It is also protected by whatever protects the email address that can reset it, and by whatever protects the phone number that can reset the email.
| Link | What it can do | How well most people protect it |
|---|---|---|
| The brokerage account | Move money and sell holdings | Usually the best protected |
| The email address on the account | Reset the brokerage password | Often less well |
| The phone number | Reset the email, and receive second-factor codes | Frequently not at all |
| The account with the mobile carrier | Move the phone number to a different device | Almost never considered |
The consequence, which is the single most useful idea on this page. An account is only as protected as the least protected link in its recovery chain, and the chain runs outward from the thing you were trying to protect. Effort spent on a long brokerage password while the email account uses a reused password and the phone number can be moved by anyone who persuades a carrier is effort spent on the strongest link. The attacker does not have to break the brokerage. They only have to reach the carrier. Which is why the most valuable half hour available to most readers is spent on the email account and the carrier account rather than on the investment account itself.
Second factors are not equivalent
All second factors are better than none. They are not interchangeable, and the difference is what an attacker has to obtain.
A physical security key must be in someone's hand. Remote compromise does not produce possession of an object.
A code generated on your own device requires control of that device. The code is never transmitted, so there is nothing in transit to intercept or redirect.
A code sent by text message requires only control of the phone number, and a phone number can be moved to another device by someone who convinces a carrier to do it. This is the weakest of the three and remains considerably better than nothing.
Where an account offers more than one option, the ranking above describes what each actually requires of an attacker. It is not a recommendation of any product.
The exposure that comes from elsewhere
Reusing a password means a breach of an unrelated service becomes access to this one. Credentials disclosed in one place are tried systematically in others, which requires no skill and no targeting.
The mechanical remedy is that no two accounts share a password, which for most people requires storing them somewhere rather than remembering them. Password managers as a category exist for this; this portal names none and expresses no preference between them.
Settings that matter more than they look
Where a firm offers a list of approved withdrawal destinations, adding to that list should be slow. A delay before a newly added payee can receive funds is protective precisely because it creates a window in which an unexpected change can be noticed.
Notification of changes is worth more than notification of activity. An alert when the email address, phone number or bank details on an account change is the alert that catches a takeover in progress — and it is worth more than an alert about a trade, because a trade can be a legitimate action by the account holder while a change of bank details rarely is.
Inbound contact cannot be authenticated by the person receiving it, and this is a structural fact rather than a caution. Telephone numbers can be displayed falsely. Email sender names can be set to anything. A message can refer accurately to a recent transaction, because that information may already have been obtained. So there is no test a reader can apply to an incoming approach that establishes who is on the other end. What is verifiable is outbound contact: ending the call and dialling the number printed on a statement or on the firm's own site reaches the firm regardless of who called. A caller who objects to being called back, or who says the matter is too urgent to permit it, has supplied the only information a reader needs. No legitimate firm asks for a password, and none asks a customer to move money to a safer account.
The detection layer
Unauthorised activity is found by reconciliation, not by intuition. Reading statements is the only mechanism that reliably surfaces a transaction the account holder did not make — which is one of the legitimate reasons to look at an account that has nothing to do with trading, as noted in An Information Diet.
What none of this does. Security measures reduce the probability of a takeover. They do not eliminate it, and they do nothing at all about money a person has been persuaded to send voluntarily. That is a different mechanism, described in How Investment Fraud Works and Fraudulent Platforms, and no password protects against it. Anyone who believes their account has been accessed should contact the firm using a number they have obtained independently, and should report it.
Frequently asked
8 questions
Is a strong password the main thing?
No. Accounts are rarely taken over by guessing a password. They are taken over through the recovery path, which exists so that someone who cannot supply the password can still get in. The question is who else could complete a password reset.
What is the recovery chain?
The brokerage account can be reset by the email address, the email can be reset by the phone number, and the phone number can be moved by the carrier account. Protection runs outward from the thing you were trying to protect.
What follows from that?
That an account is only as protected as the least protected link. A long brokerage password combined with a reused email password and an unprotected carrier account is effort spent on the strongest link. The attacker does not have to break the brokerage, only reach the carrier.
Are all second factors the same?
No, and the difference is what an attacker must obtain. A physical key must be in someone's hand. A code generated on your own device requires control of the device and is never transmitted. A code sent by text requires only control of the phone number, which can be moved by someone who convinces a carrier. That last is the weakest and still much better than nothing.
Why does password reuse matter so much?
Because a breach of an unrelated service becomes access to this one. Disclosed credentials are tried systematically elsewhere, which requires no skill and no targeting.
Which notifications are worth having?
Notification of changes rather than of activity. An alert when the email address, phone number or bank details change is what catches a takeover in progress, and it is worth more than a trade alert, because a trade can be legitimate while a change of bank details rarely is.
How do I tell whether a caller is really my firm?
You cannot. Numbers can be displayed falsely, sender names can be set to anything, and a message can accurately reference a recent transaction. What is verifiable is outbound contact: end the call and dial the number printed on a statement. A caller who objects to being called back has told you what you need to know.
What does none of this protect against?
Money sent voluntarily to a fraudulent operation. That is a different mechanism and no password addresses it. Security measures reduce the probability of a takeover rather than eliminating it.
References
- Investor.gov (SEC) — Investor Alert: Protecting Your Online Investment Accounts —
- FINRA — Account Takeover: what it is and how firms and customers respond —
- Federal Communications Commission — Cell Phone Fraud, including SIM swapping and port-out fraud (the carrier link) —
- Cybersecurity and Infrastructure Security Agency — multi-factor authentication guidance (the relative strength of factor types) —
Educational and informational only — not investment advice, a recommendation, or an offer to buy or sell any security. Investing involves risk, including the possible loss of principal. Worked examples use fictional companies and figures.