Best practices for protecting retirement savings?
Best practices for protecting retirement savings?
Loading saved threads...
Ken - Enough about Monica · External communityPost link
External question — Personal Finance Stack Exchange
Author: Ken - Enough about Monica
Original post: https://money.stackexchange.com/questions/150769
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
Let's say my nest egg is in ETFs in a taxable account and an IRA with the same brokerage.
SIPC insurance may cover me "if the firm fails financially", and only up to $500,000. That is per institution, not account, so I may need multiple brokers.
SIPC will not protect against thievery and based on what I've read, if someone steals my password, logs in to my account, and transfers out all my money, that's my fault somehow, and I don't get the money back.
I could move everything over to several FDIC insured accounts, but then I'd get less return.
I could buy physical bars of gold and bury it, but there are obvious risks.
Are there best practices for protecting one's retirement account, or are we all really just depending on the computer security of our brokers?
Edit: I use 2FA on every account that allows it.
IMO the answer/comments so far that amount to "The bank won't get hacked" or "If your login is hacked somehow, it's your fault" are wrong. This is my view as someone with a twenty+ year background in computer security.
Quote
Report
D Stanley · External communityPost link
External answer — Personal Finance Stack Exchange
Author: D Stanley
Original post: https://money.stackexchange.com/a/150771
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
FDIC does not protect against identify theft either - only a theft against the institution itself (e.g. a bank robbery). If you are truly concerned about someone stealing your identity and draining your retirement savings, then I would make sure you have the highest safety level with your bank (two-factor authentication, phone apps, whatever) to protect from someone stealing your password. Yes it will be more inconvenient when just trying to get your balance, for example, but it may be worth it for extra peace of mind.
There is also identity theft insurance that typically costs about $20 per month, but it only covers the cost of
recovering
your identity - it does NOT reimburse you for the actual amount that was stolen. You'll have to rely on the police and institutions to actually recover the money.
My opinion is that it's wise to protect your accounts as much as is practical, but you're being a bit paranoid. two-factor authentication is much more secure than just a password since hackers would not only need to get your password, but need some form of authentication that is not floating around on the internet like your mobile phone app or your home phone number. Most institutions also alert you via several channels if anything changes that would compromise TFA (like your phone number).
Quote
Report
Aganju · External communityPost link
External answer — Personal Finance Stack Exchange
Author: Aganju
Original post: https://money.stackexchange.com/a/150784
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
I have thought about that too, and not found anything better than using 2FA and unique long random string passwords (use a password safe, of course).
Don’t set your recovery questions to things that could be leaked - just invent another answer, and write it down in the password safe. For example, mother’s maiden name - use a random string or some made-up name. Thus a leak of your personal information doesn’t give it away.
In addition, note that most transactions take a minimum of four business days until your money is gone: a potential hacker needs to add a target checking account (typically 3 business days), sell investments and wait for settlement (T+2), and trigger a transfer out (another day). If you log on once a day (easy with the app), you have four chances to notice and call them.
Not great, but something.
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External question — Personal Finance Stack Exchange Author: Ken - Enough about Monica Source score (net votes, not local likes): 1 Original post: https://money.stackexchange.com/questions/150769 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Let's say my nest egg is in ETFs in a taxable account and an IRA with the same brokerage. SIPC insurance may cover me "if the firm fails financially", and only up to $500,000. That is per institution, not account, so I may need multiple brokers. SIPC will not protect against thievery and based on what I've read, if someone steals my password, logs in to my account, and transfers out all my money, that's my fault somehow, and I don't get the money back. I could move everything over to several FDIC insured accounts, but then I'd get less return. I could buy physical bars of gold and bury it, but there are obvious risks. Are there best practices for protecting one's retirement account, or are we all really just depending on the computer security of our brokers? Edit: I use 2FA on every account that allows it. IMO the answer/comments so far that amount to "The bank won't get hacked" or "If your login is hacked somehow, it's your fault" are wrong. This is my view as someone with a twenty+ year background in computer security.
Checking account access…