Here's a #cososec New Year's resolution in three parts:
1. Enable 2FA on every account that supports it. Use a software token (Authy, Google Authenticator) or a hardware token (YubiKey, Only Key) instead of SMS or email 2FA, if possible.
Check your accounts for 2FA support:
https://twofactorauth.org/
2. Use a password manager and generate unique, complex passwords for all accounts. I recommend https://bitwarden.com and I use 64 or 128-character passwords wherever possible.
1/2
pedantry...
hardware keys support supplying TOTP (2FA)...but I assume you mean U2F...which virtually nothing supports...Google does, but not in all circumstances
Marshy hopes 2020 is the year of U2F
we chose to keep it gray!
3. Log in to your mobile phone carrier account and enable a an account PIN or passcode. The PIN must them be supplied for any future account changes. This will make SIM-swap attacks against you more difficult.
(Incidentally, this is one of the reasons you really don't want to use SMS as your 2FA method, unless you have no other option.)
https://www.wired.com/story/sim-swap-attack-defend-phone/
2/2