Get new articles by email:

Oblivious Investor offers a free newsletter providing tips on low-maintenance investing, tax planning, and retirement planning.

Join over 24,000 email subscribers:

Articles are published every Monday. You can unsubscribe at any time.

Financial Planning Roundup: Help Wanted (Technical Editor)

I find myself coming back to the FBI’s cybercrime stats over and over, because they’re just mind-blowing. Over the last decade (2015-2025), annual losses to cybercrime for people age 60+ grew by an annualized rate of 39%.

For comparison, NVIDIA’s annual revenue also grew by 39% annualized from 2015-2025. And over that time NVIDIA went from being a company most people hadn’t heard of to being the largest or second largest company in the world. (It’s a tight race with Apple at the moment.)

So it’s safe to say that cybercrime is a growth industry in the US right now. (It has been growing rapidly with victims under age 60 as well, just not as rapidly.)

I’ve been writing about the topic here on the blog this year, corresponding with readers, and discussing the topic with clients. (I also picked up a few cybersecurity-related certifications along the way, so that I could speak and write about it more intelligently.)

And after learning more about it and discussing it with so many people, I’m pretty firmly convinced that cybersecurity should be considered another core area of personal finance — no different from insurance planning, for instance. To spend decades working, saving, and investing, only to then leave the proverbial doors wide open to would-be thieves makes no sense. (And, just like with dangerous gaps in insurance coverage, most people with dangerous cybersecurity gaps aren’t doing it intentionally.)

Within the personal finance realm though, most of what you’ll see written about cybersecurity and fraud prevention is essentially a) telling the reader to freeze their credit and b) descriptions of types of scams. To be clear, it is a good idea to freeze your credit. And it is valuable to be aware of the common types of scams. But the reality is that “don’t fall for scams” is not a sufficient cybersecurity policy. A policy that relies on always getting it right, every time, your whole life, is simply not good enough.

To that end, I’ve been working on a book (current working title: A CPA’s Guide to Cybersecurity: How to (Hopefully) Not Get Hacked or Lose Your Financial Accounts to Fraud).

It’s not finished yet, but it’s getting closer and closer. It’s at the stage where I could use the assistance of somebody who works in cybersecurity, who could serve as technical editor. If that’s something you’d be open to doing, please get in touch.

Update: thank you to everybody who got in touch! I have found multiple people to provide their expertise as technical editors.

Other Recommended Reading

Thanks for reading!

SpaceX, Mega-IPOs, and Efficient Markets

A reader writes, asking

“With Spacex’s recent IPO and other upcoming IPOs and the changes that the index fund providers are making, would it be more advantageous right now (until at least things calm down a bit) to mix my own choice of domestic/international funds versus going with a ‘pre-mixed’ blend fund like VT, target date, or something like AOA?”

It’s always the case that if you have a prediction that you think is better than the market’s collective prediction — and you turn out to be right — then doing something other than a boring market-weighted index fund would have given you better results. The challenge of course is somehow managing, on your own, to know better than the market’s collective knowledge.

My prior article, “Why Stock Prices Are Still Volatile in an Efficient Market,” is applicable here. Here’s the relevant part, edited for brevity:

The idea of an efficient stock market isn’t that the stock market can predict the future. Nobody knows what is ultimately going to happen with any given stock.

That is, the market price for a stock doesn’t mean that this is where the price will stay; it’s simply the consensus best estimate, given the information that is currently available.

By way of analogy, imagine that I’m hosting a raffle, in which the winner gets $100. I’m going to sell exactly 100 tickets to the raffle. How much is each ticket worth?

Each ticket is worth $1, because each ticket has a 1% chance of winning $100.

Of course, the reality is that, of the 100 tickets, 99 of them will turn out to be completely worthless, and one lucky ticket will turn out to be worth $100. But we don’t know in advance which ticket will be the lucky one, so until the raffle actually happens, each ticket is worth $1.

The point of the efficient market concept isn’t that an efficient market would successfully predict which raffle ticket will be the winning ticket. Rather, the point is that an efficient market would successfully price each ticket at $1 prior to the raffle.

With regard to SpaceX’s market price, it’s a similar concept. Everybody knows that the current price is not the ultimate “right” price. But the challenge is that there’s a pretty good chance the company will turn out to never be profitable and thus the shares will ultimately be worthless or nearly so. And then there’s also a small chance that it will someday be wildly profitable, possibly even the most profitable company in the world. So the current market price is the market’s attempt to probability-weight those two potential outcomes (as well as potential outcomes in between).

And of course nobody really knows the percentage probabilities of any of those outcomes, nor does anybody have a good way of calculating how profitable the company would be in the best scenarios. So there’s a lot of guesswork going on here. But:

  1. “A lot of guesswork going on here” is something that is true for a lot of stocks, a lot of the time, and
  2. It is, at least, the collective guesswork of the market, which is probably better than my own guesswork anyway.

Financial Planning Roundup: “Ultraprocessed Content”

This week I encountered an article (from March) by Cal Newport (author of Deep Work) on the topic of smartphones, social media, and their effect on attention spans and mental health. The very short summary is that we have enough research on the topic at this point to be able to confidently say, “it’s bad for you.”

Newport writes, “We should consider taking as strong a stance against ultraprocessed content as we already do against ultraprocessed food. Which is to say: Most people should avoid these diversions most of the time. In the same way that you’re unlikely to eat Twinkies as a regular snack or still believe that Pop-Tarts provide a balanced breakfast, stop consuming ultraprocessed content. ”

For anybody for whom that link does not work or for anybody interested in reading further, here’s one of the papers he references, which I found worth reading:

Other Recommended Reading

Thanks for reading!

What Happens if My Password Manager Gets Hacked?

Password manager providers are naturally attractive targets for hackers. So a critical question to ask is: what happens if an attacker manages to access the servers of the company that provides your password manager software? And the answer to that question will depend on both your own practices as well as the policies and practices of the password manager provider.

Here it’s worth backing up a step and looking at historical security breaches in general. For instance, there have been many cases in which some company (e.g., an insurance company, a credit bureau, a hospital system, or a large retailer) gets hacked, and the attacker is ultimately able to access customer/patient information, such as contact info and Social Security numbers.

But wouldn’t that data have been encrypted on the company’s servers? In other words, even if the attacker was able to download the data, why weren’t they stuck with unusable encrypted data? Sadly, in some cases, the answer is that no, the data in fact was not encrypted on the company’s servers. But even in many cases in which the data was encrypted, the attacker was ultimately able to decrypt the data. Generally, that’s not because the attacker was able to defeat the encryption. (Modern best-practice encryption is quite secure.) Rather, the explanation is a simpler one: the attacker was able to access the decryption keys.

In most cases, when a company is storing encrypted data, they also need to be able to decrypt that data themselves, so that they can use the data when needed. So the decryption keys must be accessible in some way by systems (and sometimes people) at the company. And that is where the security often fails. In the major data breaches that you’ve heard about, what has generally been the case is that the decryption keys were stored in some way that was itself insecure, or the attackers were able to access an application that has access to the keys. The details vary, but the result is typically that the attacker is able to download the encrypted data and access the decryption keys, thereby allowing them to simply decrypt the data.

Now back to our discussion of password manager software specifically. The details vary by provider, but many password managers (including Bitwarden or 1Password) use what is known as zero-knowledge architecture. The idea of zero-knowledge architecture is that the password manager provider itself never has your master password, the key necessary to decrypt your data, or a decrypted version of your usernames, passwords, etc. Your encrypted vault is stored on their servers, and when the vault needs to be decrypted (in order for you to access saved information) that decryption happens entirely on your device. Your device uses your master password to derive the decryption key and then uses that decryption key to decrypt the requested data. To reiterate: with zero-knowledge architecture, the password manager provider never has your master password, the decryption key, or a decrypted version of your vault.

What this means is that, if your password manager is using zero-knowledge architecture with strong encryption practices, and you are using a strong master password, then even if an attacker were able to breach the password manager’s servers and download your encrypted vault, they would almost certainly not be able to decrypt the information. There’s a fundamental difference here between this sort of setup and a setup in which the company is saving not only your encrypted data but also the means to decrypt that data.

Of course, it would still be preferable for your password manager provider not to be hacked at any point. And if you ever learn that your password manager provider has suffered a breach involving customer vaults, you should promptly change the passwords of your most important accounts, and then change the remaining passwords as soon as practical. But if you and your password manager are both following best practices, you don’t need to worry that a data breach would mean that an attacker would immediately have access to all of your passwords.

There are also options for offline password managers. For instance, KeePassXC is a dedicated offline password manager. Alternatively, Bitwarden can be self-hosted on your own server. In these cases, your vault would not be stored on the vendor’s servers and thus would not be accessible at all if the vendor’s servers were breached. One downside is that syncing your passwords across devices or sharing with other family members becomes something you must set up and manage yourself. Also, now you would be fully responsible for security (including backups and other security-related policies). Whether that’s a good thing or a bad thing depends on your skills and how much time you want to spend on the endeavor.

Finally, on the topic of password manager breaches, we have to talk about LastPass. In 2022, LastPass was the subject of a major breach. In addition to being breached, it became clear that they were not following certain other best practices. For one, they were not encrypting the URLs of the websites for which users were saving usernames and passwords. That made it easier for the attacker to pick specific vaults to target for brute-force decryption attacks. (Specifically, the attacker appears to have gone after vaults that had cryptocurrency assets.) Secondly, the vaults of LastPass users with older accounts were not as securely encrypted as they should have been. In 2018, LastPass had upgraded its default for new users, but older users were still on older encryption policies unless they explicitly adjusted the setting themselves. That made it easier for the attacker to effectively use brute-force attacks on customer vaults. (Weaker encryption settings meant that the attacker could make many more password guesses per second against those vaults.) We know that some people did have money stolen as a result. Finally, LastPass customers were not informed that their encrypted vaults had been accessed until months after it had occurred. A more timely notification could have allowed customers to update all of their passwords promptly and avoid any actual losses. For the above reasons, many experts in the field simply no longer feel comfortable using or recommending LastPass. Regardless, the event illustrates the importance of a password manager provider following best practices.

What Comes After Financial Independence?

Among people who read personal finance books, many save a high percentage of their income through most of their careers. One thing that eventually happens for some such people is that they reach a point at which they realize they have not only saved "enough," they have saved "more than enough." Their desired standard of living in retirement is well secured, and it’s likely that a major part of the portfolio is eventually going to be left to loved ones and/or charity. And that realization raises a whole list of new questions and concerns.

This book’s goal is to help you answer those questions.

More than Enough: A Brief Guide to the Questions That Arise After Realizing You Have More Than You Need

Topics Covered in the Book:
  • Impactful charitable giving
  • Talking with your kids or other heirs
  • Qualified charitable distributions
  • Deduction bunching
  • Donor-advised funds
  • Trusts
  • Click here to see the full list.

Financial Planning Roundup: Social Security Trust Fund Projected Depletion Moves Closer

The Trustees of the Social Security and Medicare trust funds released their annual report this month. The big headline finding: “The Old-Age and Survivors Insurance (OASI) Trust Fund will be able to pay 100 percent of total scheduled benefits until the fourth quarter of 2032, one quarter earlier than projected last year. At that time, the fund’s reserves will become depleted and continuing program income will be sufficient to pay 78 percent of total scheduled benefits.”

Other Recommended Reading

Thanks for reading!

Asset Allocation with a Very Low Spending Rate from the Portfolio

A reader writes in, asking:

“What is your view on owning TIPS ladder (Bogleheads preferred) or short term TIPS fund when the majority of expenses are covered by pension and/or social security which are COLA adjusted.

One view I read is from Charles Ellis, who views all sources of stable retirement income (pension, social security) as bond like assets, essentially an indirect TIPS ladder.”

On the “should Social Security or a pension be treated as a bond” topic, my answer is that, no, they aren’t bonds. They are clearly fixed-income. But they are not bonds. (For a more full explanation, please see Social Security: It is an Asset, But Not a Bond.)

The case in which Social Security or an inflation-adjusted pension entirely covers spending needs is just a subset of the broader category of cases in which the household is spending at a very low rate from the portfolio in retirement. That is, for this purpose, we can lump together all cases in which a household is spending anywhere from zero to roughly 2% of the portfolio per year.

In cases like that, there is a huge range of asset allocations that would be reasonable. The household does not need high returns, so they can use a very conservative allocation. On the other hand, the volatility of an aggressive portfolio would not put their well-being at risk either, so an aggressive allocation would also be acceptable. Or anywhere in between.

In other words, at this point, it becomes entirely a matter of preferences. The retirement spending goal has been entirely satisfied. So now the question becomes:

  • Should we use an aggressive allocation, in order to increase the expected bequest to heirs?
  • Or should we use a conservative allocation, in order to not have to experience as much volatility?

Either answer is acceptable.

And because a very broad range of allocation (from highly aggressive to highly conservative) is reasonable, all the various sub-topics within the asset allocation topic become even less important.

Should this household own a ladder of individual TIPS? Sure, if that appeals to them. Or not.

Should they own a short-term TIPS fund? Again, sure, if that sounds good to them.

They could use a single LifeStrategy fund or iShares Core Allocation ETF.

Or they could use a “VT + TIPS” portfolio like I do. Or they could use a three-fund portfolio, with the bond fund being any of several different bond funds (short-term TIPS, intermediate-term TIPS, short-term nominal Treasuries, intermediate-term nominal Treasuries, a total bond fund, etc.). Or they could use any of 1,000 other more complicated portfolios, if one such portfolio appeals to them for a particular reason.

In general, when creating or assessing a portfolio, we want to be sure of five things:

  1. The portfolio is diversified (no huge allocation to a single stock).
  2. The portfolio’s risk level is appropriate for the household’s circumstances.
  3. The portfolio is simple enough to manage.
  4. The portfolio does not include anything with unreasonably high costs.
  5. The portfolio is reasonably tax-efficient.

For any given household, there are going to be many potential options that satisfy all five requirements. There is no perfect portfolio, but there are countless perfectly fine portfolios.

And specifically for a retiree household with a very low spending rate, requirement #2 on the list becomes less of a limiting factor than it often might be, so now there is an even broader range of acceptable portfolios.

Disclaimer: By using this site, you explicitly agree to its Terms of Use and agree not to hold Simple Subjects, LLC or any of its members liable in any way for damages arising from decisions you make based on the information made available on this site. The information on this site is for informational and entertainment purposes only and does not constitute financial advice.

Copyright 2026 Simple Subjects, LLC - All rights reserved. To be clear: This means that, aside from small quotations, the material on this site may not be republished elsewhere without my express permission. Terms of Use and Privacy Policy

My Social Security calculator: Open Social Security