Live data from Hacker News

The Bare Minimum You Should Do to Protect Your Family's Data

blog.mozilla.org

21–30 of 119 posts

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#21

I expected better from Mozilla. Connecting to unsecured WiFi is mostly not a problem. Most websites and applocations encrypt traffic and the security of the channel does not matter. Plus, the recommendation to installl shady antivirus software throws the motivation of this article into doubt.

As soon as you are on the same collision domain as an adversary I think the risk of being attacked and exploited increases drastically. Many do it, but it's not a very safe thing to connect to untrusted Wifi.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#22
> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.”

The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$5, ...

> Even better, use a password manager like Lastpass.

They really should have lead with this.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#23
post #8

"Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec." Installing more proprietary software with unrestricted access seems like a huge step backwards. https://en.wikipedia.org/wiki/Magic_Lantern_%28software%29#A...

Previously, from a former Mozilla developer [1]:

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. More likely, they hurt security significantly; for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors, but in general their developers do not follow standard security practices. (Microsoft, on the other hand, is generally competent.)

In the linked Project Zero issue tracker, all 3 of these "reputable sources" have exploits in their anti-virus software.

[1]: https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#24

I expected better from Mozilla. Connecting to unsecured WiFi is mostly not a problem. Most websites and applocations encrypt traffic and the security of the channel does not matter. Plus, the recommendation to installl shady antivirus software throws the motivation of this article into doubt.

> Most websites and applocations encrypt traffic

DNS requests, connections' IP addresses and HTTP's Host header are still in plaintext; in short, lots of metadata goes out the window on wireless Layer-Ones.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#25
post #21

I expected better from Mozilla. Connecting to unsecured WiFi is mostly not a problem. Most websites and applocations encrypt traffic and the security of the channel does not matter. Plus, the recommendation to installl shady antivirus software throws the motivation of this article into doubt.

As soon as you are on the same collision domain as an adversary I think the risk of being attacked and exploited increases drastically. Many do it, but it's not a very safe thing to connect to untrusted Wifi.

Can you explain further? Are you saying SSL doesn’t provide the security a normal person thinks, there is more unencrypted traffic outbound than a normal person thinks, or that the unencrypted headers of the otherwise encrypted traffic are more valuable to a hacker than a person might think?

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#26
post #20

Earlier quoted context omitted.

I agree. The section on "Use tough passwords and change them frequently", except for the final suggestion to use a password manager, felt like antiquated password advice.

What do you use instead of a password manager?

I think you misunderstood the sentence. OP is saying TA's password advice (except for "use a password manager") is antiquated.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#27
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

https://xkcd.com/936/

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#28
More than half of that I wouldn't advice or would have serious caveats about the advice given...

This is really a strange document...

Just a few examples:

"Don’t open emails, texts, ]...] from anyone you don’t know, don’t recognize, or weren’t expecting" "Don’t use unsecure Wi-Fi networks" Largely outdated due to HTTPS and completely impractical. Everyone uses the Wifi at starbucks.

"Even better, get a VPN (virtual private network) — but, just like with antivirus software, don’t use a free VPN." How should an average user know if the VPN is a scam? (More than half of VPN providers are scam and there's little reason to believe that payed providers are always better.)

"Use tough passwords and change them frequently." Changing passwords frequently is considered deprecated advice. The single most important rule about passwords is to use unique passwords. Which they don't say at all...

I could go on...

Update: Mozilla deleted the post after criticism, see https://twitter.com/asadotzler/status/1068961020540899329

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#29
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

Yes, they clearly didn't consult (and/or use) security researchers' most recent recommendations about passwords.

Password managers have become a nearly non-negotiable necessity. Telling people just use a password manager is becoming kind of like telling developers just use source control 15 years ago. You just won't know how important they are (or the true cost/benefit) until you start using one yourself.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#30
post #14

"Use antivirus protection. Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec. Beware of free antivirus software, as it can contain malware. The iOS operating system has antivirus software built in..." Do people still really install anti-virus? Isn't it just another vector for attack since they themeselves use exploits to manipulate the OS? Linux for desktop, pixel or iOS…

Not only do people install it, I see it required in corporate IT all the time. As in, they even set a VPN policy that checks your anti-virus definitions for currency and will refuse to connect if the definitions aren't current or if anti-virus is not installed. These same corporate IT who force 90 day password changes, and nonsense like 5pEAzhawh$ instead of fivepizzassoundsgoodbutdontforgetthebeer because no matter what longer is better.
Post reply on HN