Sunday, September 30, 2012


IT'S TIME TO GO THROUGH THE COMPUTER SECURITY CHECKLIST




I know I had them off to one side of the blog, but they got lost in the transition when Blogger changed formats, so it's a good time to drill them into your head again before I forget.

BRIAN'S COMPUTER SECURITY TIPS
  • Unless needed for an online game or special program, uninstall JAVA
  • If you want to keep JAVA (and all of it's risks) keep up with the updates
  • Update Adobe Flash (very important) and Reader as updates become available
  • Always update from the vendors website. Adobe and Java have update links on their homepages
  • BUY an anti-virus product. You'll have a better chance of blocking something with one you paid for vs. a free anti-virus product.
  • I recommend Norton Internet Security, Norton 360, and Trendmicro Titanium
  • When Microsoft sends updates down to your PC - INSTALL THEM.
  • If you use Microsoft Outlook (not Outlook Express), close the preview/reading pane
  • If you don't have Malwarebytes on your PC, download it from a reliable source and install it. I use downloads at cnet.com
  • If you do have Malwarebytes installed, update and run a quick scan at least twice a month, and a full scan every other month.
  • Don't upgrade from pop-up windows telling you an upgrade is available and to "Click here"  to install it. I'm repeating myself, but it's worthwhile - upgrade from the vendor website.
  • When doing a search with GOOGLE, and if you have either of the Norton/Symantec products I mentioned above, pay attention to the colored squares that appear after each search link.


You may never have noticed it before, but they should be there. If you hover the mouse over the colored square a little box like the one in the picture pops up. The rule of thumb is: GREEN = They've gone to that link, and checked the links on that site and it's safe. ORANGE = They've gone to that link, and checked out the links on that site and they found the website okay, but, some of the links were questionable (avoid ORANGE). Last but not least, RED = STAY AWAY!!

  • If you do get infected, turn off your computer and call for help. Leave it off until someone arrives.
  • Keep backups. Some Trojans that have come out this year are very destructive and corrupt photo, music, document, PDF, and other files.
  • Use an online backup for your photos and music. I use Carbonite.
  • Even if you are just a "Home User", password protect your login account.
  • If you have children or teens and everyone uses the same PC, make their account profiles "Limited", so they can't install anything.
  • Don't give them your password because you're too lazy to get off the Lazy Boy and log into the PC to download a game or other program they just bought.
  • Don't use a word for password. Use phrases, sentences, etc. [Example: itrainsinspainbutmostlyintheplains
  • Use alpha/numeric swaps. i or L = 1; o = 0; s = $. [Example, using the phrase above: itrainsinspainbutmostlyintheplains becomes - 1tra1n$1n$pa1nbutm0$t1y1nthep1a1n$
  • Don't use the same password for every site you go to. Buy a notepad and write them down, or if using the Norton product, take advantage of their password "Vault" [ed. - I do both. I write them in a notepad and also use the Norton password vault.]
  • If you setup your wireless router yourself, change the SSID from it's default (netgear, d-link, cisco, etc.) so a casual neighborhood hacker won't know what you're using.
  • Avoid using your last name for an SSID choice [Example: TheAndersons] use a pets name, or maybe your favorite movie title.
  • Change the default wireless router administrator login [and write all of this down, including your wireless key]
I've offered enough suggestions this time around [probably too much and you're seeing white spots in your eyes] to help you remain as secure as possible. Surf the web cautiously, and be safe -

'Nuff Said
Brian

Saturday, September 29, 2012



ADOBE, ADOBE, ADOBE, AGAIN

BUT AT LEAST IT'S NOT JAVA THIS TIME

Adobe has a certificate problem; why should you care? and what is a certificate? I'll tackle the last one first. A certificate a like working for a top secret company and you're working in the highest level, so you're issued a security card that grants you access to the top floor. When the elevator door opens on that floor and you walk out of it, everyone assumes you have the highest level of security, after all - how else could you get there?

Software companies (along with vendors and computer mfg. to a lesser extent) have certificates of their own so when you get a request to update (for example) Adobe Flash, your computer trusts that request; you see the request and choose "Yes", "No", or "Later". So if I've been able to describe this in a manner we can all follow, I'm sure you realize that if the certificate was malicious in any way your computer could get a virus, trojan, or more.

Adobe had a certificate compromised and they will issue a new on one October 4th. Until then, if you should get an update request from Adobe please do what I've always asked you to do: close it, go to Adobe's website, scroll down the main page and you'll find links to upgrade Reader, Flash, and other Adobe products.

PC WORLD has an article related to this which you can read HERE. Until then, surf safely my friends -

'Nuff Said,
Brian








WHY DO PEOPLE MAKE VIRUSES, TROJANS, AND WORMS?

[THE LINK TO THE PAPER WORKS NOW]




I get this question asked of me quite frequently and I suppose I've been pretty close in my summation after reading a white paper by Tom Kellermann, VP of Cyber Security for Trendmicro. Obviously quite a bit of  time and studying various trends went into the paper which I encourage you to read via download on their website or HERE (click on link and another window should bring the PDF into view).

Wednesday, September 26, 2012




MONEY TALKS

[I'VE NEVER HEARD IT THOUGH]




Nonetheless it does. From Computer Worlds website comes a story about Google patching 24 bugs in it's browser "Chrome", and paying $29K to bug "Bounty Hunters". Chrome Ver.22 became available to the public yesterday. Microsoft and other companies are paying high bounties as well. To read the full article go HERE.

STAYING AWAKE AT NIGHT?

It's no wonder. Between Microsoft, Adobe, JAVA "Zero-Day" exploits, your bank website not being available and much, much more, comes another one of those "He was looking for one thing on the website and stumbled into....." stories, also via Computer World. Apparently a Danish student was looking for some research material and suddenly, before he eyes, were about 100,000 user names and passwords from other research associates working for NASA, and APPLE (to name just 2). [ed. - pace a few times across floor tonight for me while you're at it].

SPEAKING OF WINDOWS 8

I'm not, but someone, somewhere in the world is....
Intel's CEO said that Windows 8 bug's will "Sting" consumers. Hmmm, I.E.9 came out in March of 2011, still has issues, including the BIG one last week, and yet Microsoft is pushing out I.E.10. Meanwhile, Windows 7, which after more years than Microsoft cares to count, finally restored some confidence with consumers and businesses alike after the terrible "VISTA" affair, yet, pushing out 8 they are. The article about what Intel's CEO said is HERE.

FBI SCAM

Locally, we've seen a somewhat moderate increase in a virus/trojan which displays a full screen FBI warning page. Yeah, it's not real (unless you're doing something real bad, but then why would they warn you before they come crashing through your door, right?), and successful removal varies, depending on what other things have been downloaded without your knowledge. I've worked on several that all seemed to come in via JAVA, and if you've been reading this or the other blogs you know I've been without JAVA for over 2 months and haven't run into anything I couldn't do before. Perhaps you could try this experiment? Benefit - you're not going to worry about new security holes in JAVA. The worse that can happen? You find out there is something you need it for and re-install it!

(Hopefully)
'Nuff Said,
Brian


SAMSUNG PATCHES REMOTE WIPE HOLE ON IT'S GALAXY S III



According to an article on PC Worlds website, the security hole mentioned earlier today has been patched and Samsung is urging Galaxy S III users to run an update ASAP. No other models were mentioned regarding the fix and you can read the article HERE.


WHY SHOULD I BE SURPRISED?

ANOTHER ZERO-DAY EXPLOIT IN JAVA HAS BEEN DISCOVERED


Reporting on ComputerWorld's website, a researcher has discovered another zero-day exploit in JAVA. This one is in versions 5, 6, and 7. Whether you are a MAC or Windows user, your both wide open for something to slip in and bite you in your wallet. They verified the bug was present even in the last JAVA update which came just last week. Read the all the gruesome details in the Article HERE.

ARE YOU A SAMSUNG SMARTPHONE USER?

According to an article on PC Magazine's website you should stay off the Internet until a bug is fixed. This security flaw could potentially allow someone from the Internet to reset your phone [ed. - oh what fun that wouldn't be]. Read that news HERE.

Monday, September 24, 2012



WHY DO PEOPLE MAKE VIRUSES, TROJANS, AND WORMS?







I get this question asked of me quite frequently and I suppose I've been pretty close in my summation after reading a white paper by Tom Kellermann, VP of Cyber Security for Trendmicro. Obviously quite a bit of  time and studying various trends went into the paper which I encourage you to read via download on their website or HERE (right-click and select download, left-click should bring it into view).