Live data from Hacker News

Comparing how security experts and non-experts stay safe online

googleonlinesecurity.blogspot.com

41–50 of 122 posts

Re: Comparing how security experts and non-experts stay safe online

#42
Not entirely surprising the experts ranked "install software updates" #1, but it didn't even make the non-experts' top 5.

We, as an industry, still have a long way to go in making it easy and safe for consumers to keep their software up to date. Have you ever tried to explain to someone (outside the industry) which "click to install the latest version" messages are important to obey, and which are malicious?

Re: Comparing how security experts and non-experts stay safe online

#43

But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...

Are the security experts are target more likely to attract those who might want to compromise them for bragging rights?

Re: Comparing how security experts and non-experts stay safe online

#44
post #4

The thing that software security people do that most normal people don't do is: browsing and accessing email in a virtual machine, not their actual machine.

Non-developers probably do everything that would be valuable to an attacker in the browser and/or via email. (Heck, what else do people do on a computer?)

Re: Comparing how security experts and non-experts stay safe online

#45
post #4

The thing that software security people do that most normal people don't do is: browsing and accessing email in a virtual machine, not their actual machine.

Just to be clear, do you browse and read email in a virtual-machine or is this statement referring to the behaviours of security researchers more generally?

If so, have you ever forgot to use the virtual machine and instead browsed or read email on your host operating system? If so, what did you do?

Furthmore, is it possible to break out of the hypervisor and into the host operating system?

Re: Comparing how security experts and non-experts stay safe online

#46

Do security experts place less emphasis on virus scans because they do their browsing on OS for which virus scanning is less important? EDIT This question is partly motivated by wondering if a Linux browsing user should be running a virus scanner?

IME: No, it's because they know virus scanners are ineffective. Security experts on windows also don't run virus scanners.

Re: Comparing how security experts and non-experts stay safe online

#47

One bit of advice that should be up there is to run an ad blocker and a flash blocker (not so relevant anymore now that FF started blocking by default). I know, I know, websites depend on ads for revenue. But ads are also a great way to deliver exploits, in addition to all the personal tracking ad networks do. Our number one priority is to protect ourselves, not to protect website revenue.

For the lazy:

https://addons.mozilla.org/en-us/firefox/addon/ublock/

https://www.ghostery.com/en/

https://cs.nyu.edu/trackmenot/

https://addons.mozilla.org/en-us/firefox/addon/self-destruct...

https://noscript.net/

Anything I missed?

Re: Comparing how security experts and non-experts stay safe online

#48

But are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...

It depends on what your definition of safety is. The perspective of this paper probably relates to compromised accounts and information leaks, not adware infections.

Re: Comparing how security experts and non-experts stay safe online

#49
[Non-experts] mistakenly worry that software updates are a security risk.

I think this betrays a lack of thought about the risks to non-experts. Tons of malware masquerades as legitimate updates, and non-experts don't always have the knowledge to distinguish legitimate updates from malicious ones. Therefore, to non-experts software updates are a security risk.

Edit: And this is why Chrome's policy of updating automatically and completely silently is the right thing to do, and everyone else (Adobe, Oracle, Microsoft, looking at you) is doing it wrong.

Re: Comparing how security experts and non-experts stay safe online

#50
post #17

I am personally concerned with the "patch, patch, patch" message. Stated that way, I completely agree with it. However, for many it is just "update, update, update." I'm all for getting the latest security patches. Or any security patches, really. I'm growing tired of getting the latest possibly risky feature from a product because it is the only way I can get a security patch.

Just yesterday, Windows Update automatically installed a driver for my GTX 970. It broke OpenGL and I had to go to Nvidia's website to get their standard driver and reinstall it.

And since Windows 10 breaks the ability to block specific updates, I'll probably have to keep the installer around and reinstall it every damn time that Windows Update decides that the driver MS is distributing is better than the one from nvidia.com.

I'm a techy and I completely understand why users ignore updates. Either it's invisible and the user doesn't know it happened, or it breaks something with no obvious way to revert, or it arbitrarily changes things that were fine how they were. So their perception ends up being "every time it updates, things get worse."

Post reply on HN