Live data from Hacker News

The Bare Minimum You Should Do to Protect Your Family's Data

blog.mozilla.org

101–110 of 119 posts

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#101
post #30
post #14

"Use antivirus protection. Buy and download antivirus software from a reputable source such as McAfee, Norton, or Symantec. Beware of free antivirus software, as it can contain malware. The iOS operating system has antivirus software built in..." Do people still really install anti-virus? Isn't it just another vector for attack since they themeselves use exploits to manipulate the OS? Linux for desktop, pixel or iOS…

Not only do people install it, I see it required in corporate IT all the time. As in, they even set a VPN policy that checks your anti-virus definitions for currency and will refuse to connect if the definitions aren't current or if anti-virus is not installed. These same corporate IT who force 90 day password changes, and nonsense like 5pEAzhawh$ instead of fivepizzassoundsgoodbutdontforgetthebeer because no matter…

I was on a site the other day, which I won't share publicly, that required "NO MORE than 6 characters, including precisely 1 number and 1 capital" (paraphrase, my emphasis) ... I definitely WTF-ed at that.

My default is 20 characters of alphanum, or 16 of "graph" (though I drop look alike characters; 32 chars if I'm entering payment details).

One has to hope they have a small limit on retries. They definitely carry commercially sensitive data and do payment processing.

What worries me is they used js to catch my attempt to use 20 chars, so they're not operating completely naively -- all I can think was it was a misinterpretation and s/most/least.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#102
post #51
post #34

Earlier quoted context omitted.

Vulnerability is not lack of security. You need a threat actor exploiting the weakness for it to become actual insecurity.

That's... not what vulnerability means. vul·ner·a·bil·i·ty noun the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally.

I did not define vulnerability,I only explained security.

This is security101. Risk is measured by multiplying vulnerability by threat.

Maybe an analogy might help. You are vulnerable to bullets. But your security with respect to your bullet vulnerability is measured by multiplying it against active threats that might shoot you with bullets. So,your security decreases when in a warzone as opposed to lying in bed at your suburban house due to reduction of threat.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#103
post #48
post #34

Earlier quoted context omitted.

Vulnerability is not lack of security. You need a threat actor exploiting the weakness for it to become actual insecurity.

Insecurity is having a vulnerability. Whether a threat actor exploited it and what results you can detect are part of a useless variant of Schrödingers cat that everyone prefers you focus on to sell useless software.

Are you redefinig the field of information security? Please read some basic material on information risk and security.

I mean,even just reading vulnerability bulletins and CVE descriptions should familiarize you with explotability and complexity of attack,they exist to help remediators prioritize more insecure vulns.

Quick example: 'ls' has an easily exploitable code execution vuln. On a shared terminal server,this vuln translates to severe loss of security. On a firewall,this is nothing more than a house keeping item with no real loss of security as there are no threats that can run 'ls'.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#104
post #102
post #51

Earlier quoted context omitted.

That's... not what vulnerability means. vul·ner·a·bil·i·ty noun the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally.

I did not define vulnerability,I only explained security. This is security101. Risk is measured by multiplying vulnerability by threat. Maybe an analogy might help. You are vulnerable to bullets. But your security with respect to your bullet vulnerability is measured by multiplying it against active threats that might shoot you with bullets. So,your security decreases when in a warzone as opposed to lying in bed at y…

[deleted]

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#105
post #103
post #48

Earlier quoted context omitted.

Insecurity is having a vulnerability. Whether a threat actor exploited it and what results you can detect are part of a useless variant of Schrödingers cat that everyone prefers you focus on to sell useless software.

Are you redefinig the field of information security? Please read some basic material on information risk and security. I mean,even just reading vulnerability bulletins and CVE descriptions should familiarize you with explotability and complexity of attack,they exist to help remediators prioritize more insecure vulns. Quick example: 'ls' has an easily exploitable code execution vuln. On a shared terminal server,this v…

You are moving the goal posts. The issue I take is with "threat actor". If a threat actor wasn't detected you have no idea if they exist. Only windows crapware tries to make the warped perception that what it doesn't know doesn't exist and priority obviously goes to where exploits provably exist. But insecurity is being attackable not being aware you are attackable (and certainly not knowing you are attackable but seeing no frequency of attacks).

Would you want your electric company to use these products knowing that another country will attack with 0 frequency until war is declared?

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#107

It was removed: https://twitter.com/asadotzler/status/1068961020540899329?s=... But here's the original article: https://web.archive.org/web/20181130081659/https://blog.mozi...

Also on Archive.today: https://archive.is/7SYNe

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#109
post #105
post #103

Earlier quoted context omitted.

Are you redefinig the field of information security? Please read some basic material on information risk and security. I mean,even just reading vulnerability bulletins and CVE descriptions should familiarize you with explotability and complexity of attack,they exist to help remediators prioritize more insecure vulns. Quick example: 'ls' has an easily exploitable code execution vuln. On a shared terminal server,this v…

You are moving the goal posts. The issue I take is with "threat actor". If a threat actor wasn't detected you have no idea if they exist. Only windows crapware tries to make the warped perception that what it doesn't know doesn't exist and priority obviously goes to where exploits provably exist. But insecurity is being attackable not being aware you are attackable (and certainly not knowing you are attackable but se…

Look,the concept is not subjective. I didn't say a threat actor,I said threat.

I highly recommend looking these things up on your own but the goal of Information security is to reduce the risk that vulnerabilities will be exploited to where a breach of your security goals occurs(i.e.:CIA triad,confidentiality,integrity and availability mostly). It's not to make your system impregnable to all conceivable attacks.

My electric company should have well resourced nation state actors as part of their threat model. They should not only remediate known vulns,they should also employ EDR solutions that perform ML and behavioral detections/preventions. They should be part of their industry ISAC for threat intel sharing (which includes 0days) as well as have a comprehensive threat hunting and incident response program. Your average consumer,howevet has different types of data and attackers to worry about.

A banking trojan cleaning out your account,ransomware demanding payment for your family pictures, an ex installing RATs to monitor what you do are what consumers are threatened with.

Being attackable is not insecurity Right now you're attackable by an endless list of threats. Your local gang,serial killers,crazy people who shoot up schools,terrorists,etc... But your security is measured by a number of factors including where you live,what you're doing and specific attacker's cost-benefit analysis of attacking you.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#110
post #82

Earlier quoted context omitted.

I have PiHole running on our home network blocking ads, phisihing domains, etc. I also don't use the ISP router / wifi. I feel like those two things are good steps towards protecting my family. They give me some piece of mind at least.

Have you run into any issues that required tweaking of the PiHole set-up? I'm running PiHole + a hand-rolled VPN on Digital Ocean but I'm looking to put together little PiHole boxes for my family who live across the country. It needs to pretty much be perfect out of the box or they'll unplug it. I've only had to disconnect once or twice to unsubscribe from spam lists, but I doubt my family would even bother.

The only thing that almost annoys me is that Google ads are blocked on the redirect, but not display. So sometimes I click them and have to go back and click the organic result. I could probably tweak it.

I am running it on a old Pi B (the old one with an RCA jack). No issues. if I was sending to family across the country, I'd probably add remote access of some sort for myself.

Post reply on HN