Linked by Alcibiades on Wed 4th Jan 2006 18:04 UTC
Windows Like a lot of people who have worked in the business, I find myself in conversations about computer security with people who are having problems or know people who have problems. I wrote this to save me from explaining the same thing over and over again to different people, and to save them the trouble of having to make notes as we talked. It was meant to be something you could give to a 'naive user' and have them be able to read and follow it more or less unaided, and while not being a complete guide, at least be something that made them more secure than before they got it.
Permalink for comment 81770
To read all comments associated with this story, please click here.
Great article!
by Anonymous! on Wed 4th Jan 2006 20:33 UTC
Anonymous!
Member since:
2005-11-11

This article is concise and the proposed measures are pretty effective against most typical attacks on windows.

Rule 4: Keep as much personal information as possible off the machine, on paper.

I fully agree.

Never have your browser remember passwords or logon information.

I'm not so sure about it - OK, I wouldn't trust MS IE at all. It's also a good strategy to avoid entering important passwords too often. Revealing the master password to a (remotely working) keylogger doesn't automatically mean that you reveal all your stored passwords to the attacker in the same step - but it could just mean this, it depends on the overall vulnerability of your system and the software you use...

Btw, there's a good reason not to enter important passwords directly into your browser if you use JavaScript. The broken same origin policy of JavaScript allows many remote keylogging attacks by definition. You not only have to trust the website you're visiting, but also all included (even remote) JavaScript ads. These vulnerabilities are known for a long time but the vendors don't bother to fix them because they consider them as a feature.

As one simply cannot win the battle by using windows on the long term, you can't be sure that you never get compromised by some kind of keylogger or some other malicous software. Just think about it and the consequences... which lets me clearly favour Plan B ;)

Edited 2006-01-04 20:52

Reply Score: 2