Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, November 12, 2013

Thieves steal 113 smartphones every minute -- Is yours next?

A Windows 8 Phone
The ZoneAlarm Security Blog has some great tips for safe computing. A recent post deals with smartphone theft. Many people have no password to their smartphone. If you lose or even just temporarily misplaced your smartphone, anyone can do business "in your name" as well as gather up contact information and much, much more.

Adding a strong password (not just a simple PIN) to use the phone may be a slight inconvenience while using it, but it protects your data. This is crucial if you do any online [shudder] financial transactions with your smartphone.

Protection tips also apply to tablets and similar portable computing devices.

Saturday, November 09, 2013

Fun games foster security awareness

Phishing Scams - avoid the bait
The U.S. government has a great site to learn more about being smart and safe online. It's called OnGuard Online. The site includes some simple online games that let you check your "smarts" about safe computing.

You may learn something new or maybe just reinforce good habits. Either way, visit the site.

Below are links to some interactive video quizzes:

Saturday, August 15, 2009

IE8 more secure than Firefox

A report on Browser Security testing by NSS Labs shows that Internet Explorer 8 security is far better than Firefox, catching 81 percent of "live threats" vs. only 54 percent caught by Firefox 3, which came in second place.

The tests include rating the browser's protection against malicious software using socially engineering and phishing attacks.

The lab tested the most recent versions of Microsoft's IE8, Mozilla Firefox, Apple Safari, Google Chrome, and Opera. Opera caught a mere 2 percent of the threats.

Friday, May 01, 2009

Adobe Reader, Acrobat security issues -- again!

In respect to the latest in a series of security vulnerabilities with Adobe Reader and Adobe Flash, Adobe says, "We are in the process of fixing the issue, and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009."

"SANS NewsBites" newsletter editors comment that users of Adobe Reader and Acrobat may want to consider less-exploited alternatives. Adobe Reader keeps bloating in size and Acrobat seems way over-priced, so perhaps it is time to start looking elsewhere.

Friday, April 03, 2009

Beware Antivirus 2009

Beware of fake antivirus software. And beware of a pop-up notice that you have a virus or "might have" a virus (unless the pop-up notice comes from software you already own).

A type of software that tricks you into installing it, then demands payment "or else" is called ransomware. And it's spreading.

One nasty piece of ransomeware seems to be a legitimate program called Antivirus2009. But after you install the software, it encrypts several document types. Then when you try to open one of the encrypted files, it pops up an alert and offers to sell you FileFix Pro 2009, which it says can decrypt the file.

So you get duped into downloading the fix. But it decrypts only one document. After that, it demands that you pay $50 to buy the software to decrypt the rest of your files (that the Antivirus 2009 encrypted).

Beware of "something for nothing". Be paranoid. Check out reviews of software at trusted sites before you download and install any.

Wednesday, April 01, 2009

Protect your personal information

A PC World test found that some search sites had random details about co-workers' and acquaintances' college roommates and boyfriends from the 1980s, political donations, shopping preferences and musical tastes.

Social networking sites give a false sense of security and if left "open" to all can result in a lot of personal information being harvested (sometimes called "scraped") by criminals.

A recent Symantec study showed that 91% of Phishing attempts are now aimed at social networking sites (the top two are My Space and Facebook). Why? The personal data is there for easy pickings. Plus, people who join social networking sites tend to feel more "free" in their personal comments.

Another disturbing tidbit ... 23% of people succumb (are tricked by) social engineering attemps via Phishing emails. At a recent Information Security conference, a speaker admitted that he had been a victim too. His daughter had joined Facebook, soon had 300 "friends" (right!) and then her got an email from "his daughter" with a link to something neat "she" wanted him to check out. He did. His computer got attacked. The problem? Too trusting. Bad assumptions.

People get tempted to take risky actions when using social networking sites. Human nature plus the very essence of a social networking site make using it risky.

How much is your identity worth? Is is humany possible to not be a social networking lemming? Just say, "No" to joining social networking sites. You'll live to rejoice in that decision.

Thursday, March 26, 2009

IE8 is gr8

I installed the newly released IE 8 and am already liking the enhancements.
  • Web Accelerators looks like something I'll use a lot, for example:http://www.microsoft.com/windows/internet-explorer/videos.aspx?mname=accelerators
  • Automatic Crash Recovery (tab closes, not all of IE).
  • Web Slices.
  • Faster page display.
  • Better pro-active built-in security (domain highlighting, SmartScreen filter -- sites ID'd with Spyware or PII collection get a pop-up warning [I assume it uses a database, so frequent updating is hopefully provided].
  • InPrivate browsing, easier data deletion/cleanup.
  • Compatibility mode for pages coded for older browsers (with compatibility updates pulled from MS as available).
  • Love the grouped, suggested URLs as you start typing in the address bar.
  • Oooo ... a "Read mail" toolbar icon automatically opened my Thunderbird email.

Next I'll have to see if FireFox 3.5 will match or beat that. As of now, IE8 is my preferred browser experience.

Wednesday, January 28, 2009

Be paranoid!

Be very wary of emails you did not expect to get and of any web pages they may link to. Just because an email or web page looks nice or is interesting or you are just plain curious is no reason to start clicking away.

A case in point is the recent malware that pretends to be about President Obama (or for you Irish folks, O'Bama). The Microsoft Malware Protection Center (MMPC) blog has more about this Waledac Trojan, including pictures of an email and the malicious web page.

Remember, it's perfectly OK to be paranoid -- the bad guys really out to get you!

Saturday, December 20, 2008

Infected web pages increase

During 2008, the rate at which the number of web pages infected with malicious software (malware) increased rose from one every 14 seconds to one ever 4.5 seconds. [See "Forecast: Security Threats for 2009"]

So what can you do?

  • Don't "assume" a web site is safe to visit.
  • Don't "assume" a link in an email is safe to click on.
  • Don't "assume" an email from a friend was really sent by them.
  • Use anti-phishing software, antivirus software, and anti-spam software.
  • Keep all your computer programs updated. If there is a security patch available for any of your programs, install the patch.
  • Use a program like Secunia's free Personal Software Inspector to check for program updates.
  • Use a program like Driver Detective to check for updates to program driver files.

Firefox less secure?

Firefox has often been touted as fundamentally "more secure" than Internet Explorer. If you have been led to believe that, you need to look at some cold, hard facts:
  • From March to September 2005 (yes, even as early as 2005), FireFox had 40 vulnerabilities to IE's 10. [ZDNet article]
  • From April through September 2005, the number of published Firefox exploits was 11 compared to IE's 6.
  • The most recent FireFox-related security problem is that some Russian criminals are using it to add malicious software as a "Plug-In". The malware detects when you connect to any of over 100 banks and then steals your account name and password, sending them to the criminals. [read the SC Magazine article]
  • In terms of vulnerability numbers reported in March 2008, Opera had the most, followed by Safari, FireFox, then Internet Explorer.

The biggest problem with malware is not the browser, it's the person using the browser. People are either too trusting of links and unknown sites or just think they will never get attacked.

Friday, November 28, 2008

Beware nasty Mebroot trojan

Beware of malware called Sinowal (also as Mebroot) captures bank and similar data. A gang of Internet criminals have been using this and even morphing the malware to temporarily fool antivirus software.

Windows Secrets contributing editor Woody Leonhard likens Mebroot to "a parasitic operating system that runs inside Windows". [Disclaimer: I subscribe to the paid version of "Windows Secrets" newsletter. Prior to that subscribed for years to the paid version of Fred Langa's "LangaList" newsletter, which is now integrated into Brian Livingston's "Windows Secrets" newsletter. I highly recommend Windows Secrets anyone concerned about or interested in PCs.]

Leonhard says that his experience is that a lot of systems get infected with Mebroot (Sinowal) because the owners did not keep up with Adobe Reader, Adobe Flash, or Apple Quicktime security patches. You can manually check for such patches, set the apps to automatically check for updates, or (even better), install the free Secunia Personal Software Inspector (PSI) and scan for programs that need updating.

In October 2008 Brian Krebs, Washington Post, alerted readers to the "virtual heist" going on. Mebroot infects the Master Boot Record (MBR) of your PC and sends personal data to its "owners". Krebs says that the criminals have stolen over half a million credit and debit card account in the past few years.

While Symantec lists the malware's risk as low, if your data gets stolen, it won't be a little thing to you. Here are some actions Symantec and I recommend to reduce your risk of malware infections:

  • Use a firewall
  • Enforce complex passwords for all users of your computer
  • Use the lowest level access privileges.
  • Never use an Administrator-level login account as your normal one. Always login as a lower level account and then "Runas" or login as the Administrator level only as needed. Vista security is a big advance in making this type security easier. Yes, you get pop-ups to login as Administrator, but that's much better than manually running a "runas" command and you don't need to know the runas command line syntax.
  • Disable Auto-play
  • Turn off "File Sharing"
  • Turn off and remove unnecessary system services
  • Always keep your programs patched (You can use the free Secunia PSI to monitor patch status)
  • Don't open email attachments unless you were expecting them. Contact the sender separately (not by a "Reply") and see if they really did send you that email and attachment.
  • Turn off Bluetooth via Windows Control Panel if you are not using it.
  • If you really need to use Bluetooth, make sure every Bluetooth device's visibility is set to "Hidden".

Wednesday, November 26, 2008

Secunia PSI now in final form

Secunia Personal Software Inspector (PSI) is now officially out of beta and at version 1.0 (well, OK ... version 1.0.0.1). I have used versions prior to 1.0 and found them excellent. I'll be downloading, installing, and running PSI 1.0 today. I encourage you to do the same. This free software checks your programs for any updates.

While Microsoft Update (or the lesser Windows Update) does a great job, they naturally only deal with Microsoft products. Your computer has tons more programs, each of which may need a security patch, bug fix, or enhancement. Why check them all manually? Let PSI check for you. Try it; you'll like it.

To really stay on top of patches, I also use Driver Detective (not free, but very worth having).

Tuesday, November 11, 2008

Patch Adobe Reader, Acrobat!

If you use Adobe Reader 8.12 or earlier or Adobe Acrobat 8.12 or earlier, update them now! Adobe has released security updates to critical vulnerabilities.

Better yet, for Adobe Reader, upgrade to the version 9 -- it's free.

Both programs come configured to automatically check for updates, but some people turn that off. Leave the auto-check on -- protect yourself.

Monday, June 16, 2008

Firefox 3 leaps ahead

While not revolutionary or even truly evolutionary, version 3 of the Mozilla Firefox web browser looks very good. Some of its new features may even get me to use it as my default, which is now Microsoft Internet Explorer 7. Some of the new features I look forward to most relate to security and ease of use:

  • Site ownership. The "Passport Officer" lets you know who really owns a web site. This helps reduce accidental visiting of malicious sites.
  • Malware protection. A "Reported attack site!" message box with a red background pops up when the site you asked to visit is on a list of malware sites. Firefox blocks access and you must select the "Ignore" link if you really want to visit that URL. I also like that the link is small, in the lower right corner, and not a normal button. The two buttons are "Get me out of here" and "Why was this site blocked". This is a good security precaution.
  • Page zoom now zooms both text and images.
  • Multiple text select. You can now use the Control key to select and copy multiple blocks of text on a web page.

Features I an unsure about until I try them extensively include the new "keyhole" shaped navigation control. IE7 font rendering is better than FF2, so I am also curious about how well the font rendering in FF3 will work.

Features I already like in Firefox 2 include spell-checking in Web text areas, including Blogger, and the wide range of add-ons for blogging, editing, and web development.

I do wish Firefox would support the "standard" MSIE hot keys for such things as create a hyperlink (Ctrl+K), as using Firefox in Blogger is less useful than IE at this point (except for Spell-check).

It would help if at least Firefox and Mozilla had consistent hot keys. For example, Thunderbird uses Ctrl+L to insert a hyperlink. It doesn't match MSIE, but the Ctrl+L is easy to remember (L for "link"). But Ctrl+L in Firefox accesses its "Location Bar" (what IE calls the address bar. Bummer.

Friday, February 01, 2008

Firefox 3 to better indicate "safe" site

For many people, the "padlock" symbol showing in their browser status bar means "safe" or "secure". Actually, it only means that someone has bought a certificate and is using SSL (Secure Sockets Layer) -- encryption.

Since it's possible for criminals to buy a certificate and use SSL, the padlock is no guarantee that you won't get duped or have your identity stolen. What's important is to know that the site is really what it seems and to know who really owns it -- identity.

Firefox developers are now working on a different way to indicate the potential safety (or not) of a site by concentrating on identity, not SSL. In the process, Firefox looks like it will abandon the padlock symbol as an indicator of safety. This should appear in Firefox 3.0 when it comes out.

Friday, December 28, 2007

Scammers target eBay names

Anti-scammer tips:

  • Use a different name on eBay than on your webmail. Scammers target an email name on gmail, hotmail, and similar online webmail apps.
  • If it sounds too good to be true, it's not true.

- Based on a blurb in the December 28th SANS emailed newsletter (not online yet). You can subscribe to get security "NewsBites" by email.

Software Patch Inspector

Secunia's Personal Software Inspector (PSI) is now in Release Candidate 1 (RC-1).

Of ZD Net's top 10 free security utilities you should be using, they say, "Number one is the Secunia Personal Software Inspector, quite possibly the most useful and important free application you can have running on your Windows machine."
http://content.zdnet.com/2346-12691_22-95490-1.html

The latest update features an improved look plus easier use by novices, yet advanced options can be turned on.

You can even track the results of your patching. Run, don't walk, and get Secunia's PSI now!

Wednesday, October 24, 2007

Non-Microsoft security updates

Several security updates came out recently for products other than Microsoft ones, although a couple apply only if you are using Internet Explorer version 7. If you have the following software, make sure you get the patches:

  • Adobe Acrobat 8
  • Adobe Reader 8.1.1
  • Apple Quicktime 7.2
  • Mozilla Firefox 2.0.0.8

Saturday, October 20, 2007

Malicious emails contain fake Youtube link

US-CERT says that new variations of the Storm Worm have been appearing in email messages as fake YouTube video links.

The emails arrive with headers such as, "LOL, that is too cool..."

The email claims to be a video of you that has been discovered. The message contains a fake link to youtube.com. The link acually sends you to a malicious website that downloads and runs malware.

Thursday, September 27, 2007

Adobe Reader vulnerable

Adobe Reader has a serious vulnerability that could be exploited by a maliciously created PDF. The flaw could be exploited to take control of computers. So far, Adobe has no patch for it

Until this vulnerability is patched, do not open a PDF file you get unless it's from a trusted source and you were expecting the file.

If the source is trusted but the file unexpected, contact the sender before opening the PDF.