An answer from the library

How do I destroy old documents and protect my identity?

Woven from five library pages; the bucket, the three bureaus, the reuse diagnosis and the zero threshold belong to those pages, with their figures.

Paper goes in a bucket, credit gets frozen at all three bureaus, your email address gets checked against the breach list, a password a site emailed you gets changed wherever you reused it, and every transaction sends you a notification. Five pages, and the first one costs nothing.

Water destroys paper better than a shredder does. Water destroys paper better than a shredder does says the way people keep recommending is not a machine, it is a bucket: separate the sheets, soak them overnight, mash the lot into pulp. A shredder does not destroy a document; it converts one into a puzzle whose pieces are all still in the bag, and hand-reassembly of strip-shredded documents has actually been done. Pulp is not a puzzle. If you would rather buy something, read the number, not the adjective: shredder security is graded on a published P-scale, P-1 to P-7, and “diamond cut” or “confetti cut” are marketing phrases with no fixed definition. Before spending anything, a fair number of banks and some office supply shops will shred for free. For the daily trickle, tear it up and split the pieces between bins, because the threat is somebody going through one bag of your trash, not assembling a case. And do not run a marker over an original you must hand on; redact a photocopy. The page’s safety lines if you were about to burn it: no accelerant, check whether open burning is legal where you live, and no improvised chemistry. Old hard drives, phones and discs are a different problem entirely, and nothing on that page applies to them.

Freeze it at all three. Freeze it at all three is for after the breach letter: freeze your credit at all three nationwide bureaus, because many people say a freeze at one leaves the other two open; the three are separate companies and a lender chooses which one to check. Use the free freeze, not a paid lock, which some people say is the same door with a subscription attached. A freeze stops a lender who does not already have you as a customer from seeing your file, so no new account can be opened in your name, including by you until you lift it; it does not touch cards you already have. Since September 2018 federal law has made placing and lifting a freeze free at every bureau, and older people on the page saying otherwise were right when they wrote it. Then read the reports: many people say there is one website the law set up for free reports, annualcreditreport.com, and the sites that look like it trap you into a subscription. The friction is honest: a freeze adds steps to every legitimate application, and if you are mid-mortgage, do not open a dispute, because it makes the score unstable and lenders stop.

Check your email against the breach list. Check your email against the breach list says many people name the same first move: put your email address into a breach-checking service and see which known leaks it appears in, and often which password went with it. The page does not name the site, because people argue both ways about typing an address into any such site, and what decides it is the site’s standing, an established, widely known service against an unknown one; the page’s own line is type an address, never a password. Some people say the leak is not the danger, the reuse is: a leaked pair is tried against every other site. So the order of work is the email account first, because whoever holds your mail can reset the rest, then every account that shared the leaked password, each given its own, then two-step verification on the email account. One correction there: a text telling you someone has signed in is not two-step verification.

If a website emails you your actual password, change that password on every other account where you used it, starting with your email account. Change the reused password when a site emails it to you is for the moment you click “forgot password” and the site sends back the password you chose. A site that can do that has kept it in a form it can read back; a site that stores passwords properly keeps only a scrambled, one-way version, which is why those sites ask you to reset instead. It does not mean you were hacked. One person says that anyone who gets into the site’s systems could read every password stored there, and that attackers then try those same passwords on other sites; that second part is the risk to you, and it only bites if you used that password somewhere else. The UK’s National Cyber Security Centre says that if you have used the same password across different accounts, criminals only need one to reach all of them, and that someone with access to your email can reset your other account passwords. So the email account comes first, then your bank, card and shopping accounts, then the rest, each given something you use nowhere else. A small variation may not count as a different password: one person says a pattern, such as the same base with a site’s initials, is better than one password everywhere but can still be guessed. The US Federal Trade Commission advises turning on two-step sign-in when an account offers it, and the page says to do it for your email and bank. If you used that password only on the site that emailed it, nothing else needs changing: change it there, to something you use nowhere else. One person warns that email is not a secure way to send a password, however the site stores it, so the copy in your inbox is one more place it sits. The page’s safety line: if you see a charge, a login or a message you do not recognise on any account, do not use a number or link from an email or text about it; call your bank or card company on the number printed on your card, in the US or the UK. If the email held a reset link or a temporary password you must change, that is the normal way to recover an account and not this problem; if an email with a password arrived that you did not ask for, it may be a scam rather than a careless site; and if an account has already been taken over, the page does not cover recovering it.

Turn on every alert. Turn on every alert says the best defence against both card fraud and the subscription you forgot is a free setting: notifications for every transaction, with the threshold as low as your bank allows. Not amounts over fifty. Every one. The counterintuitive part is why: an unexplained charge of a dollar or two is frequently a test of whether a stolen card number is still live before anything larger is tried, and any sensible-sounding threshold sits above it. The page’s own block at the top: if credit is a trap for you, skip its credit-card paragraphs, because the move that does the most is the free setting on any account you already have.

Who this is not for. The freeze page says if you live outside the US, the freeze as described does not exist in most of Canada and it does not know your country’s rules; and if the fraud you fear is on a card you already hold, the freeze is not the tool, the issuer is. The breach page says if what worries you is a partner reading your email, that is about the relationship rather than the password, and it does not carry that; and if someone is already using your exposed details against you, the police and the platform are the places.

Answered from the real, shared experience of thousands of people. Shared experience, not professional advice.

Heavy moment? Call or text 988 — or we’re here.

a quiet placeSit for a minuteA meadow, a river, and nothing you have to do. The field is always open — and the wind on this page already knows the way.

Close