Earlier quoted context omitted.
On the backup question, this is one reason why I have a set of backups that are physically disconnected and not automated.
I have a backup NAS that's normally powered off, but it's scheduled to turn on, perform backup, shut down. It doesn't wake on LAN and there should be no way of knowing it exists outside of checking DHCP static addresses reservations - and now that I mention it, maybe I should remove it from there too. This minimises the size of the window, and network-snoopable information, required to compromise this set of backups.
Ask HN: How do you trust that your personal machine is not compromised?
61–70 of 469 posts
Re: Ask HN: How do you trust that your personal machine is not compromised?
#62Re: Ask HN: How do you trust that your personal machine is not compromised?
#63Re: Ask HN: How do you trust that your personal machine is not compromised?
#64Here's a short, fairly practical guide that you might find helpful: https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-... . It is aimed mostly at small businesses, but I find a lot of the guidance to be pretty relevant to my personal IT. My even shorter (and incomplete) summary of the document would be: configure your router and firewall; remove default passwords and crapware from your devices; use a lock s…
Do you lock your computer every time you leave your desk? And do you always check for keylogger thumbdrives and such?
Check for keylogger thumbdrives: I use a laptop so it would be immediately obvious. But now that you say it I haven't checked the charger USB-outlet on the back of my cabled keyboard.
[1]: it has happened I have failed. Once a year or something.
[2]: I sometimes try to allow myself to go downstairs in my own house to fetch a cup coffe without locking when I am alone, but I find it so stressful in practice I always lock it. I don't need to know but it is a good habit. I'm otherwise normal :-)
Re: Ask HN: How do you trust that your personal machine is not compromised?
#65Noone has drained my crypto from my wallets yet. So either my personal machine is not compromised, or they think the amount of crypto in the wallets is too low. Jokes on them though, cause I am moving my crypto to a hardware wallet eventually
If the U.S. has backdoors on every PC, they're not going to bother draining the wallets of "small fish"; they need to keep these things secret so they can go after terrorists
Re: Ask HN: How do you trust that your personal machine is not compromised?
#66Re: Ask HN: How do you trust that your personal machine is not compromised?
#67Earlier quoted context omitted.
On the backup question, this is one reason why I have a set of backups that are physically disconnected and not automated.
I have a backup NAS that's normally powered off, but it's scheduled to turn on, perform backup, shut down. It doesn't wake on LAN and there should be no way of knowing it exists outside of checking DHCP static addresses reservations - and now that I mention it, maybe I should remove it from there too. This minimises the size of the window, and network-snoopable information, required to compromise this set of backups.
I don't think it would help against situations where your primary system is being encrypted for a while, and thus your backups eventually get overwritten with bad stuff.
Re: Ask HN: How do you trust that your personal machine is not compromised?
#68Earlier quoted context omitted.
"which providers I trust: * Software: Google, Microsoft" I trust that Google and Microsoft won't hack into my bank account and steal money, even though they could, but otherwise I assume they collect anything they want and can.
I assume they profile me, but I don't assume they steal my files.
Re: Ask HN: How do you trust that your personal machine is not compromised?
#69Re: Ask HN: How do you trust that your personal machine is not compromised?
#70Here's a short, fairly practical guide that you might find helpful: https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-... . It is aimed mostly at small businesses, but I find a lot of the guidance to be pretty relevant to my personal IT. My even shorter (and incomplete) summary of the document would be: configure your router and firewall; remove default passwords and crapware from your devices; use a lock s…
> enable anti-malware if your OS has it . . . Would be interested in hearing other things Given the most common network activity is web browsing, it seems like enabling protections in the browser is becoming mandatory for the security-conscious. For me this amounts to enabling NoScript and uBlock[edit: [0]] plugins in Firefox, desktop and mobile versions, and disabling or locking down various "features". An additiona…
I also made an app and extensions to help me use multiple browsers, one per site. (Browsr Router)