Can someone do this if you DO NOT use a public library? If I stay away from libraries and unsecure wireless networks, can they still get into my hotmail?
That depends on how tight your computer's security is and how much of a target you are on one hand, and how good your personal security conduct is on the other. Let me explain.
If you run a computer with any Windows version on it which is connected to the Internet, a sufficiently knowledgeable and determined person can get in 100% of the time. If you have no firewall/virus scanner even a bot/virus/worm/trojan/whatever can get into Windows, so buy one if you don't have one. As for hackers hacking into your PC, all Microsoft software is notoriously vulnerable to human attacks (Windows XP has somewhere near 200000 reported and fixed security holes to date); the question is here if you present enough of a target for them, i.e., are you (inter)nationally well known, or do you have geeky enemies, etc. etc.. If you are running for vice president like Mrs. Palin was, you can bet someone will try to hack into your accounts; if you are not quite so well known, no one will bother, probably. If you are paranoid or important enough to care, you can switch to Linux, BSD or Solaris (I use the first, though for other reasons). Those work well, though you will have to learn how to use them, and of course, if you do not keep everything completely up to date, you are still vulnerable to human hackers; on the other hand, note that viruses do not exist for these OSes.
This basically boils down to: buy a firewall & virus scanner, and keep it up to date, if you haven't done so already.
The second thing is, you need to take good personal security measures; if you do not, your passwords can easily be cracked.
First, never use your e-mail password or your computer password (your PC is password protected, isn't it?) for any other service. For example, if you used the same password for your e-mail,
public or private, for this board, and Rich was not the nice person we knew him to be, he could look up your password and log into your account straightaway. If you did do that, for this or any other service, take this cue, and change you e-mail account's password
immediately.
Secondly, make sure your passwords are not trivial. Combinations of dictionary words are easily crackable; special programs exist for this purpose, even if you spell them backwards or use multiple dictionary words. For the same reason, do not use anything personal, such as place or date of birth, wife's maiden name, first name, children's names, father's place of birth, or any such things; social engineering can get those really easily, and you expose your account to any malevolent person (not necessarily hackers).
Thirdly, a good, strong, password is eight (8) or more characters long and exists of both numbers and letters; a good one would be, for example, 1Maas99tricht2, which is a jumbled up date and place, i.e., the Treaty of Maastricht, signed in 1992; another one would be 4Dan9iel0, which is a jumbled up version of Daniel's name and his Messian prophecy of the 70 year-weeks. Of course, you could also go for 4YerUk396, but that might be harder to remember.
Lastly, it is better to have a strong password which you need to write down and lock away, than a weak one which you can remember; hackers are almost never burglars, and a simple safe will deter them. On the other hand, make sure never,
never, never, to write down the account name or the purpose of the password on the same page; burglars can become hackers, if you furnish them with the appropriate means.
Security is never as simple as it seems.
