On 05/01/2013 05:29 PM, I.P. Freely wrote:
> I do not go near unvetted websites like that; it's foolish even with
> serious firewalls. Visiting it on a corporate or, especially, government
> computer could get an employee fired; it's a blatant court martial
> offense in my last carer.
>
> Be careful out there.
That's reasonable advice. In my own case I'm a lot less concerned about
nasty websites because I run Linux - which is not the target of choice
of most hackers.
However here are my non-expert tips on lowering risk while visiting sites.
1. Keep your browser up to date with the latest security patches.
2. Keep your browser plugins similarly up to date. The biggest security
holes in the past have been the java plugin and the flash plugin. If
you use those, and just about everyone uses flash, make sure you've got
the latest.
3. Always run a virus checker and, if possible, configure it to scan
everything that you can download from the Internet before allowing it to
be saved. That includes email attachments and files saved by the
browser. If you don't have an automatic scan then use a manual scan.
I admit I don't do that on files that I'm very sure about, but I will do
it on anything that I'm not 100% sure of.
If you use Yahoo mail, and probably a lot other mail services, they will
scan anything you try to download before they even send it to you.
4. Check that the URL matches the description in a link.
If there's a mismatch, you've found a problem. Example:
"Please go to your <Yahoo Account> and sign in."
You put your cursor over the link that says "Yahoo Account" and the
browser shows the actual link (usually in the status bar at the bottom
of the screen) to be "
kissmytuchas.com" in Romania.
Or it might have some twisted name that looks right unless you look more
carefully, like "
yahou.com" or "
yahhoo.com" or "
yahoo.ru"
I also have two levels of firewall. I have a wifi router that blocks
anything coming in that I didn't request. A "request" means that you
clicked something in your email client or browser, or something else,
that opened a connection to a server and a "response" came back. An
unrequested connection is initiated from outside that you never requested.
The other level is a software firewall in my Windows computers. I use
Zonealarm for that but the latest builtin Windows firewalls are said to
be pretty good. The software firewall has the great virtue of blocking
outgoing requests that you didn't authorize. If you install software
like this you will be shocked at the number of programs running on your
computer that exchange information with unknown computers on the
Internet without ever saying a word to you.
I once bought a scanner and installed the driver for it. My firewall
then told me that a program named "bm.exe" wanted to send out
information on the net, should I let it? I looked up "bm.exe" on the
net and found out it was a program that sent all of my browser bookmarks
to "Bookmark Central", a company that apparently sold information about
who has what bookmarks in their browser. Needless to say I rooted that
piece of bm out of my computer.
Alan