
In a person’s life, an annoying moment may come when his electronic devices are a desktop, a laptop, a smartphone, to put it mildly, will be out of access. This is very unpleasant. This is a failure in work, budget blow, time loss and stress. Let's figure out how to effectively respond to such an incident. How to "resurrect from the ashes", spending a minimum of resources. What to do with the equipment if it was returned.
“All my technique is reliably protected. No one will get to my data. I have backups, ”I repeated when I myself was in such a sad situation. In the spring of 2020, at the Paris station, the gang of crooks elegantly and brazenly stole a backpack right from under my nose. My laptop disappeared with things. The technique was sorry, but the knowledge that the data was in full security was comforting me.
Well, if your data is protected. At least the most important, including passwords to accounts. It is wonderful when there are backup copies. If this is not the case, read articles on the website of the greenhouse , Roskomvoboda , in other sources . Increase your level of knowledge in advance.
Your life will not stop due to the lost computer. Most likely, you will acquire new equipment. So, do not torment yourself with experiences and associate your immediate plans with what is lost. It is better to survive this moment and move on.
And here. You cannot completely exclude attempts by an attacker to hack your technique. But modern means of protection allow you to create a technically insurmountable barrier in its path. Do not wind yourself up. The egg -headed geeks will not connect the seized laptop to an expensive supercomputer and patiently, break passwords for long hours on an ominous black screen with disgusting green beams. This is a plot for the Hollywood series about the FBI and terrorists.
Get out at least with a smartphone and a SIM card. (We will not discuss in this article how to buy and who to register SIM cards for.) If you are a prudent person, you have a “reserve kit” ready. Of course, it is necessary to regain control of your number, but then. Efficiency is more important now.
Enter accounts that are attached to the lost number. Tie the accounts to the new number, delete the previous one. So you will not allow the attacker to "restore forgotten passwords."
Change passwords. Even those where the attacker, according to common sense, should not access. In a stressful situation, you could forget about any vulnerability. And changing the password, in the end, is very simple.
Complete sessions on lost devices.
If two -factor authentication is used in the accounts, and the lost smartphone is used as a second factor, you need to untie it from the account. Tie a new smartphone. Do not forget about disposable reserve codes: the previous ones need to be reset, new to create and save in a safe place.
First, make sure this is true. In stress and haste, it happens that a person mistakenly enters the password. Or tries to log in to the resource, where he himself closed the account.
Is there reason to believe that the attacker has captured your account, and you can’t change anything in the settings? Try to use the access recovery procedure. Some services have it ( Google example ). Maybe you have to answer questions like “when you last entered your account?”, Or call friends in the photographs that the service will show you.
Problems with access recovery can help solve the organization of Access Now . At least, the account can be temporarily “frozen”.
If nothing comes out, report the incident to those sites where you entered with this account (for example, chats, forums). Perhaps you will find an understanding of administrators. At least warn users. And, of course, your relatives, friends, acquaintances.
After the champagne is drunk, you need to decide what to do with the returned equipment. If she was in the hands of attackers for whom the goal is you and your data (and not just equipment), you may get rid of the equipment. Clean it from data and your user programs, reset the settings to the factory (if it is a smartphone), and then sell, give, throw it away. And buy a new one (if you haven't bought it yet).
But maybe your resources are limited. Then let's look at what was returned to us.
Check the serial number (for smartphone also IMEI ) with the one that you have recorded. Is it your device for sure? (You recorded serial numbers and IMEI your devices and store them in a safe place? What does it mean "no"? Then the time is to see and write down.)
Next - external inspection: seals, stickers, screw heads. If the laptop did not open themselves, and scratches and burrs are noticeable on the screws, perhaps someone was digging inside. “You can color the screws of your laptop in advance with colorless nail polish,” says Gleb Suvorov, consultant in safety. - Then it will be easier to detect an extraneous invasion. You can weigh the device on ordinary kitchen weights. If the weight has grown by 20-30 grams, this is also an alarming signal. And do not connect equipment to the Internet until the end of the check. ”
What is written in this section, in my opinion, is better to entrust a person who is well versed in computer and mobile technology.
Disassemble the device, inspect it on the subject of "there is nothing superfluous inside." Instructions on manufacturers' sites (an example of describing the Gigabyte motherboard ), video from YouTube on how to make out a particular device (examples of disassembling the Xiaomi smartphone ) , forums for repairmen and just users (example of the Samsung smartphone forum) can be a good help.
If this is a computer, look at BIOS/UEFI . Perhaps you should go with LiveUSB ( LiveCd ) and reflash a fresh version.
Install the operating system “from scratch” (on a smartphone and laptop, discharge to factory settings).
Install the necessary programs/applications and return the necessary data from the backup.
If the device has an unsystematic disk (in the computer) or a memory card (in a smartphone), note that it has changed on this medium. Perhaps it makes sense to “clean it”.
It makes sense to deal with vulnerabilities on fresh traces.
For example, a backup turned out to be four months ago. Perhaps it is better to make backups more often. The archive of photographs was not at all stored on a laptop. Next time you will move him to the cloud. Somewhere a weak or repeated password was discovered. Somewhere they forgot about backup codes for two-factor authentication. And so on.
Carry out “Work on errors” so that the next time do not step on the same rake.
We did not set the task of analyzing in one article all the possible options “What did the villains do with my device?”. But if you think that we missed something important, please write in the comments.
The author thanks Gleb Suvorov, a digital security consultant, for valuable comments and tips in preparing an article.