Live data from Hacker News

The Bare Minimum You Should Do to Protect Your Family's Data

blog.mozilla.org

91–100 of 119 posts

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#91
post #70

Earlier quoted context omitted.

> Source control was very, very standard 15 years ago. For commercial shops, perhaps. But back then the bar for using source control was much, much higher, so for many small projects, people didn't bother. There wasn't anything as simple as `git init`. There were a few public CVS and SVN servers that were appropriate for open source projects, but for anything personal or commercial, you had to use a local, single-use…

Sourceforge is almost 20 years old now, and offered version control free of charge. For a while it was almost as dominant in the free software world as github is now. The FreeBSD CVS archive is 25 years old. Version control was absolutely mainstream back then.

> Version control was absolutely mainstream back then.

I’m not arguing with that, only pointing out that it wasn’t ubiquitous.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#92
post #23
post #8

"Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec." Installing more proprietary software with unrestricted access seems like a huge step backwards. https://en.wikipedia.org/wiki/Magic_Lantern_%28software%29#A...

Previously, from a former Mozilla developer [1]: > At best, there is negligible evidence that major non-MS AV products give a net improvement in security. More likely, they hurt security significantly; for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors, but in general their developers do not follow standard security practi…

BTW, why would Microsoft even need to release an antivirus if they can patch the bugs in the OS the viriuses exploit as soon as they get discovered instead of just adding them to the virus database?

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#93
post #15
post #8

"Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec." Installing more proprietary software with unrestricted access seems like a huge step backwards. https://en.wikipedia.org/wiki/Magic_Lantern_%28software%29#A...

That’s a somewhat minor issue compared to the fact that the major anti-virus products appear to be effectively adware with a dubiously secure scanning engine built in. Whenever I help clean up someone’s Windows computer, I treat any antivirus product other than Windows Defender as malware and get rid of it.

As for resident antiviruses I would generally agree (even for purely logical reasons - that means adding another 3-rd party to the 100% trusted list, you grant their app godlike access to your computer and everything on it and let it talk freely and secretly to their vendor), nevertheless a live-cd version of something like Dr.Web can be of great use in such cases, Windows Defender a well as other antiviruses ran under an infected system can often be futile against viruses infesting it. Perhaps open-source ClamAV can do the job too but I'm not sure.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#94
post #28

More than half of that I wouldn't advice or would have serious caveats about the advice given... This is really a strange document... Just a few examples: "Don’t open emails, texts, ]...] from anyone you don’t know, don’t recognize, or weren’t expecting" "Don’t use unsecure Wi-Fi networks" Largely outdated due to HTTPS and completely impractical. Everyone uses the Wifi at starbucks. "Even better, get a VPN (virtual p…

Whenever something is critiqued and/or taken down it makes me feel curious like might be really worth a closer look. Fortunately we have the Internet Wayback Machine: https://web.archive.org/web/20181201131617/https://blog.mozi...

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#95
> Use tough passwords and change them frequently.

This is a futile advice, no sane person is ever going to follow it. You can memorize a tough password or two but change them and memorize the new ones frequently... nope.

> Tweak your home assistants.

Don't use home assistants unless you are a kind of person who really doesn't mind broadcasting their whole life as a reality show without even being informed when you're on air. I can't imagine a reasonable privacy-caring person who would.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#97
post #35
post #8

"Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec." Installing more proprietary software with unrestricted access seems like a huge step backwards. https://en.wikipedia.org/wiki/Magic_Lantern_%28software%29#A...

Windows itseld is a proprietary software. MS Defender does an ok job but for most malware that target consumers,those av softwares are not a negative. As a techie you might have nation state actors employing sophisticated attacks or corpirations spying on users. But the most immediate threat to consumers are things like phishing attacks,ransomware and banking trojans.

[deleted]

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#98
post #90

Earlier quoted context omitted.

When will LastPass stop being recommended? It says right in their TOS they collect all your browser behavior and sell it to 3rd parties. Why should I trust them?

Can you highlight where in the TOS they say this? I’ve used LastPass for several years and this would be concerning if true. I didn’t seen any such language in their ToS: https://www.logmeininc.com/legal/terms-and-conditions

tos:

> You may use our Services only as permitted in these Terms, and you consent to our Privacy Policy at https://www.logmeininc.com/legal/privacy, which is incorporated by reference.

pp:

> When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example, schedules, attendee info, etc.), or from the Service infrastructure itself, (for example, duration of session, use of webcams, connection information, etc.) We may also collect usage and log data about how the services are accessed and used, including information about the device you are using the Services on, IP addresses, location information, language settings, what operating system you are using, unique device identifiers and other diagnostic data to help us support the Services.

> Third Party Data: We may receive information about you from other sources, including publicly available databases or third parties from whom we have purchased data, and combine this data with information we already have about you. We may also receive information from other affiliated companies that are a part of our corporate group. This helps us to update, expand and analyze our records, identify new prospects for marketing, and provide products and services that may be of interest to you.

> Location Information: We collect your location-based information for the purpose of providing and supporting the service and for fraud prevention and security monitoring. If you wish to opt-out of the collection and use of your collection information, you may do so by turning it off on your device settings.

> Device Information: When you use our Services, we automatically collect information on the type of device you use, operating system version, and the device identifier (or "UDID").

and

> Some specific examples of how we use the information:

> * Conduct research and analysis

> * Display content based upon your interests

> * Market services of our third-party business partners

and

> 4. Information Sharing

> ... We may share your personal information with (a) third party service providers; (b) business partners; (c) affiliated companies within our corporate structure and (d) as needed for legal purposes.

and

> Examples of how we may share information with service providers include:

> * Sending marketing communications

there's more

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#99
post #87

Earlier quoted context omitted.

When will LastPass stop being recommended? It says right in their TOS they collect all your browser behavior and sell it to 3rd parties. Why should I trust them?

Huh? I just went through LogMeIn's privacy policy (which covers all of their services) and it says nothing of the sort. The privacy policy for the firefox extension is also fairly clean.

see other reply

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#100
post #23

Earlier quoted context omitted.

Previously, from a former Mozilla developer [1]: > At best, there is negligible evidence that major non-MS AV products give a net improvement in security. More likely, they hurt security significantly; for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors, but in general their developers do not follow standard security practi…

BTW, why would Microsoft even need to release an antivirus if they can patch the bugs in the OS the viriuses exploit as soon as they get discovered instead of just adding them to the virus database?

Viruses don't always exploit bugs. Most cryptolockers generally just trick people into executing them, for example.
Post reply on HN