Live data from Hacker News

The Bare Minimum You Should Do to Protect Your Family's Data

blog.mozilla.org

81–90 of 119 posts

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#81
post #25
post #21

Earlier quoted context omitted.

As soon as you are on the same collision domain as an adversary I think the risk of being attacked and exploited increases drastically. Many do it, but it's not a very safe thing to connect to untrusted Wifi.

Can you explain further? Are you saying SSL doesn’t provide the security a normal person thinks, there is more unencrypted traffic outbound than a normal person thinks, or that the unencrypted headers of the otherwise encrypted traffic are more valuable to a hacker than a person might think?

An adversary doesn't have to decrypt the traffic, they just reroute to their own TLS site to trick users. Or they do broadcasts like LLMNR to grab things and there are some WPAD attacks. Firewall on many computers might also allow things through, to perform relay or direct password bruteforce attacks. There are so many attacks that are possible, decrypting traffic really isn't so interesting.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#82

OK, ... so what would the Hacker News Guide to Online Family Security look like? - ISPs - Routers - Ad Blockers - OS - Data storage / backups - Facebook or not ? - ios v android ...

I have PiHole running on our home network blocking ads, phisihing domains, etc.

I also don't use the ISP router / wifi.

I feel like those two things are good steps towards protecting my family. They give me some piece of mind at least.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#83
post #28

More than half of that I wouldn't advice or would have serious caveats about the advice given... This is really a strange document... Just a few examples: "Don’t open emails, texts, ]...] from anyone you don’t know, don’t recognize, or weren’t expecting" "Don’t use unsecure Wi-Fi networks" Largely outdated due to HTTPS and completely impractical. Everyone uses the Wifi at starbucks. "Even better, get a VPN (virtual p…

I think it was well intentioned, and given the size of their audience/reach, I hope they revise it and provide a new version with solid advice. I think the general population could really do with more modern understandings of security like using very long passwords, a basic understanding of using 2FA/MFA methods, and obscuring their identity by using temporary/throwaway emails and phone numbers.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#84
post #82

OK, ... so what would the Hacker News Guide to Online Family Security look like? - ISPs - Routers - Ad Blockers - OS - Data storage / backups - Facebook or not ? - ios v android ...

I have PiHole running on our home network blocking ads, phisihing domains, etc. I also don't use the ISP router / wifi. I feel like those two things are good steps towards protecting my family. They give me some piece of mind at least.

Have you run into any issues that required tweaking of the PiHole set-up? I'm running PiHole + a hand-rolled VPN on Digital Ocean but I'm looking to put together little PiHole boxes for my family who live across the country. It needs to pretty much be perfect out of the box or they'll unplug it.

I've only had to disconnect once or twice to unsubscribe from spam lists, but I doubt my family would even bother.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#85

Earlier quoted context omitted.

I agree. The section on "Use tough passwords and change them frequently", except for the final suggestion to use a password manager, felt like antiquated password advice.

As long as the password manager is trusted. Some are run by a single person nobody's heard of. I met a woman in Vegas who ran one and who couldn't believe that people trusted it so much.

And then there are ones like LastPass that people on HN seem to recommend even though their TOS basically says they spy on all your browser behavior and sell it to 3rd parties

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#86
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

When will LastPass stop being recommended? It says right in their TOS they collect all your browser behavior and sell it to 3rd parties. Why should I trust them?

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#87
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

When will LastPass stop being recommended? It says right in their TOS they collect all your browser behavior and sell it to 3rd parties. Why should I trust them?

Huh? I just went through LogMeIn's privacy policy (which covers all of their services) and it says nothing of the sort.

The privacy policy for the firefox extension is also fairly clean.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#88
post #28

More than half of that I wouldn't advice or would have serious caveats about the advice given... This is really a strange document... Just a few examples: "Don’t open emails, texts, ]...] from anyone you don’t know, don’t recognize, or weren’t expecting" "Don’t use unsecure Wi-Fi networks" Largely outdated due to HTTPS and completely impractical. Everyone uses the Wifi at starbucks. "Even better, get a VPN (virtual p…

I ended up writing my own take on bare minimum security practices for less-technical people as a sort of response to the Mozilla article:

https://medium.com/@perplamps/super-basic-security-advice-f9...

If anyone finds any problems or disagrees with any of my suggestions, let me know and I'll update it!

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#89
post #59
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

No, the best practice is to use a password manager with randomly generated passwords.

True, but there's still a few you have to memorize. Your PC's password and your password manager's password at least.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#90
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

When will LastPass stop being recommended? It says right in their TOS they collect all your browser behavior and sell it to 3rd parties. Why should I trust them?

Can you highlight where in the TOS they say this? I’ve used LastPass for several years and this would be concerning if true. I didn’t seen any such language in their ToS: https://www.logmeininc.com/legal/terms-and-conditions
Post reply on HN