Thursday, October 11, 2012

Configure Internet Explorer...

Internet Explorer offers four different zones to help you classify security level depending on how well you know or trust the site: Trusted, Restricted, Internet and Intranet or Local.

Classifying the sites you visit and configuring your Internet Explorer security settings for each zone can help to ensure you can safely surf the Web without fear of malicious ActiveX or Java applets.

Click on Tools on the menu bar at the top of Internet ExplorerClick on Internet Options from the Tools drop-down menuWhen Internet Options opens up, click on the Security tabInternet Explorer begins by categorizing sites into either Internet, Local Intranet, Trusted Site or Restricted Site zones. You can specify the security settings for each zone. Select the zone you wish to configure.You can use the Default Level button to select from the pre-defined security settings Microsoft set up in Internet Explorer. See Tips for details of each setting.MEDIUM is most appropriate for the majority of Internet surfing. It has safeguards against malicious code, but is not so restrictive as to prohibit you from viewing most web sites.You can also click on the Custom Level button and alter individual settings, starting with one of the Default levels as a baseline and then changing specific settings.LOW -Minimal safeguards and warning prompts are provided -Most content is downloadable and run without prompts -All active content can run -Appropriate for sites that you absolutely trust MEDIUM-LOW -Same as Medium without prompts -Most content will be run without prompts -Unsigned ActiveX controls will not be downloaded -Appropriate for sites on your local network (Intranet) MEDIUM -Safe browsing and still functional -Prompts before downloading potentially unsafe content -Unsigned ActiveX controls will not be downloaded -Appropriate for most Internet sites HIGH -The safest way to browse, but also the least functional -Less secure features are disabled -Appropriate for sites that might have harmful content if(zSbL

View the original article here

Tuesday, October 9, 2012

HomePlug Powerline Net Sec

There used to be two basic options for setting up a network in your home. You could either string Ethernet cables all over the place or you could invest in a wireless access point or wireless router and go wireless. Over the last few years a third option has emerged and started to catch on.

Enter: the HomePlug Powerline network. Powerline networks use your home's electrical wiring to carry network traffic at speeds that rival traditional wired network technologies. Powerline networks are super simple to implement thanks to the HomePlug Powerline Alliance who has done their best to make Powerline network products interoperable and easy for consumers to install.

The basic Powerline network consists of at least two Powerline network devices which look like little bricks that plug into your home's power outlets. Each Powerline network adapter has an Ethernet port to connect network devices to.

Say you have a computer in your basement and your Internet router is on the third floor of your house. Instead of running a network cable up to the third floor, all you would need to do is take a Powerline network adapter, plug it in near your computer in the basement, connect the cord to your computer and to the powerline adapter, and follow the same process with another Powerline adapter, plugging it into your router and a power outlet near you router. Boom. You're done!

If you want to add more devices in other rooms to the network, you just need to buy more Powerline network adapters. Some versions of the homeplug standard support of to 64 adapters. I don't think I even have half that many power outlets in my home.

So what's the catch? Well, Powerline networks get a little trickier when you move out of the realm of the single family home. This is where the security issues begin.

The HomePlug standard has security features such as encryption built in but because their main goals seem to be ease of use and interoperability, most HomePlug devices have the same network name "HomePlugAV" or something similar. This makes it easy for people to 'plug and play' devices from different companies who are part of the same HomePlug standard. Since they have the same network name they will all talk to each other without any user intervention.

The main issue with all Powerline network devices having the same out-of-the-box default network name is when you live in an apartment, dorm, or other situation where the electrical wiring is shared. If two or more different apartments start using Powerline networking products with the same network name then they are essentially sharing their network with each other which could lead to all manner of security and privacy issues.

How do you implement the security features of HomePlug Powerline Networks to create a more private network?

Change your Powerline network name

Most HomePlug Powerline network devices have a 'group' or 'security' button that will allow you to change your network's name. Usually this involves holding the security button down for s specified period of time to clear the default name and generate a new random network name.

Once the new network name is established, all the other powerline network devices must be given the new name so they can communicate with each other. Again, this is done by pressing the security button on one of the Powerline network devices for a certain number of seconds and then going to the other Powerline network devices and pressing their security button while the unit with the new network name is in 'broadcast new network name' mode.

Even though the HomePlug Standard is used by several manufacturers such as DLink, Netgear, Cisco, and others, the time you hold down the security button to accomplish creating and joining a network may be slightly different depending on the manufacturer of the HomePlug network devices you are using. Check your specific Powerline network device maker's website for details on how to create and join a network.

Use Powerline HomePlug scanning / configuration software to detect rogue devices

Some HomePlug Powerline network device makers have a software program that can detect what devices are present on your network and can configure them as well (provided you have the device passwords that are printed on each device).

If you only have two powerline network devices in your home and the software detects more than two, then you know that your network is mixing with a neighbors and that you should create your own private network by following the instructions above.


View the original article here

Monday, October 8, 2012

Right Of Privacy

Citizens of the United States are afforded a number of rights. These rights have evolved and developed over the centuries and have been added to the permanent record in the form of amendments to the Constitution of the United States.

As it stands right now, there are a total of 27 amendments. A couple of them cancel each other out like the 21st amendment which repeals the 18th amendment prohibition on the manufacture, sale or transportation of alcoholic beverages.

Most United States citizens are probably not aware of what is written in those amendments. They may have memorized it long enough to pass a high school government or civics class, but that data has long since been purged to make room for more important things. Many Americans are probably unaware that it was not legal for the United States government to collect income taxes until they passed the 16th amendment or that a person could be President indefinitely until the two term limit was imposed by the 20th amendment.

Not casting stones, I myself could not tell you what most of them are. Most people are familiar with “taking the fifth” which implies using one’s 5th amendment right to not “be compelled in any criminal case to be a witness against himself”. Amendments such as the 1st amendment right that essentially defines the separation of church and state, the 2nd amendment right to bear arms, or the 4th amendment protecting you from unlawful search and seizure of your property are fairly common knowledge and are mentioned frequently in the media in support of various causes.

Having read through the amendments on the Findlaw.com web site though, I can’t find any amendment that explicitly protects a United States citizen’s right of privacy. The 14th amendment is often cited as the amendment which protects what Justice Louis Brandeis called the “right to be left alone”, but upon reading it, it appears that a fair amount of interpretation has to be allowed for in order to come to the conclusion that it inherently protects our privacy. The 1st, 4th and 5th amendments are also occasionally referred to in discussions of a right of privacy.

Of course, the 10th amendment explicitly grants authority to the individual states for any power not delegated to the United States Congress or prohibited explicitly in the Constitution of the United States. So, there may very well be provisions protecting privacy in state constitutions or state laws. There are also a number of statutes and regulations at both the federal and state levels which are based at least in part on the inferred right of privacy.

Unfortunately, privacy, and the protection of sensitive or personal information, seems to be legislated on an industry by industry basis. The Privacy Act of 1974 prevents the unauthorized disclosure of personal information held by the federal government. The Fair Credit Reporting Act protects information gathered by credit reporting agencies. The Children’s Online Privacy Protection Act grants parents authority over what information about their children (age 13 and under) can be collected by web sites.

As it relates to securing computer networks or data, the Sarbanes-Oxley Act, HIPAA and GLBA all contain at least some guarantee of an individual’s right not to have their personal or confidential information exposed. These regulations mandate that companies take steps to ensure their customer’s data is secure and impose fines and penalties on companies that fail to do so.

California’s SB-1386 places a responsibility on companies operating in that state to inform customers when their data has been exposed or compromised in any way. If it weren’t for that California law, the recent debacle at ChoicePoint might never have been disclosed.


View the original article here

Saturday, October 6, 2012

Reset Passwords

There are tools available to help you track and remember your many passwords. However, you have to get into your computer to begin with in order to use them. Windows XP allows you to add a password hint which you can use to trigger your memory if you forget the password, but what do you do if the hint doesn’t help? Are you locked out of your computer forever?

In most cases, the answer is “no”. You can reset the password by using an account with Administrator privileges. If you are the only one using your computer, you might think that you are just out of luck, but don’t give up just yet.


View the original article here

Friday, October 5, 2012

Google+ Security

You've heard all the hype about Google+. You may have even dived in, gotten yourself an account, and started building your "circles" of friends, but have you taken the time to see what kind of privacy and security features that Google has baked into Google+?

Facebook, Google+'s main competitor, has adapted its privacy and security settings over time, based on its user's concerns and other factors. Facebook has achieved a fairly robust system of opt-in, opt-out, group, and friend-based security and privacy measures that are still evolving today.

It's ultimately up to the Google+ developers as to whether they want to follow Facebook's lead or go in a completely different direction with regards to security and privacy features.

The jury is still out on whether or not Google+ has done a good job implementing its privacy and security features. We all remember Google's first major foray into the world of social networking, also known as Google Buzz. Buzz's initial privacy settings left a lot to be desired and a class action lawsuit was filed as a result. Has Google learned it's lesson? We'll have to wait and see.

Here are some tips on how you can use Google+'s currently offered security and privacy options to make your Google+ experience a safe one.

To begin, click on the gear icon in the top-right corner of your Google+ home page.

1. Restrict the visibility of your Google+ circles to increase your privacy

Unless you want everyone in the world to be able to see who your friends are, you'll probably want to limit access to this information.

To restrict who can see your friends and circles:

Click the "Profile and Privacy" link from the "Google+ Accounts" page:

Click the "Edit Network Visibility" button from the "Sharing" section of the page..

Uncheck the box for "Show People In" if you don't want anyone, including those in your circles, to be able to see who your friends are. Your other option is to leave the box checked, and choose whether you want your friends to be able to see who is in your circles, or you can allow the whole world to see this information. The current default is to allow everyone in the world to see who are in your circles.

If you want to be extra private you can prevent the fact that you have been added to other people's circles by unchecking the box that says "Show people who have added you to circles" at the bottom of the "Edit Network Visibility" pop-up box.

2. Remove global access to the parts of your personal profile that you don't want to share with the world

Identity thieves love personal details such as where you went to school, where you have worked, etc. These details are a gold mine for them. If you make these tidbits of information available for the whole world to see, you are just asking for them to use them to steal your identity. It's best to restrict access to most of these details, allowing only your friends the ability to see this information.

Anytime you see a globe icon next to something in Google+ it means that you are sharing that item with the world and not just with those within your circles.

To restrict certain parts of your profile to only be visible to people within your circles:

Click the "Profile and Privacy" link from the "Google+ Accounts" page.

Click the "Edit visibility on profile" link under the "Google Profiles" section of the page.

On the page that opens, click each item in your profile to modify its visibility settings. Click the drop-down box and change the items that you don't want revealed to the world.

Click the "Done Editing" button in the red bar near the top of the screen when you are finished modifying your profile visibility.

If you don't want your information made available to search engines, you should uncheck the "Help others find my profile in search results" box from the "Search visibility" section at the bottom of the page.

3. Restrict visibility of individual posts in your Google+ stream

Google+ allows you to restrict visibility of individual posts (i.e. status updates, photos, videos, links, etc...). When you're posting something in your Google+ stream on your homepage, look at the box underneath the text box you are typing your post into. You should see a blue box with the name of your default circle (i.e. Friends). This indicates the people that your post is about to be shared with. You can remove visibility for the post by clicking the "X" icon inside the blue box. You can also add or remove an individual's or circle's ability to see the post.

As Google+ evolves, it will undoubtedly feature additional privacy and security options. You should check the "Profile and Privacy" section of your Google+ account every month or so to make sure that you haven't been opted-in to something you would have rather been opted-out of.


View the original article here

Wednesday, October 3, 2012

Phishing Protection

Phishing attacks have become more sophisticated and users need simple steps they can use to protect themselves from becoming victims of phishing scams. Follow these 5 steps to avoid being a victim and protect yourself from phishing scams. Be Skeptical: It is better to err on the side of caution. Unless you are 100% sure that a particular message is legitimate, assume it is not. You should never supply your username, password, account number or any other personal or confidential information via email and you should not reply directly to the email in question. Ed Skoudis says “If the user really suspects that an e-mail is legit, they should: 1) close their e-mail client, 2) close ALL browser windows, 3) open a brand new browser, 4) surf to the e-commerce company's site as they normally would. If there's anything wrong with their account, there will be a message at the site when they log in. We need people to close their mail readers and browsers first, just in case an attacker sent a malicious script or pulled another fast one to direct the user to a different site.” Use The Old-Fashioned Way: An even safer means of verifying if an email regarding your account is legitimate or not is to simply delete the email and pick up the phone. Rather than risking that you may somehow be emailing the attacker or mis-directed to the attacker’s replica web site, just call customer service and explain what the email stated to verify if there is truly a problem with your account or if this is simply a phishing scam. Do Your Homework: When your bank statements or account details arrive, whether in print or through electronic means, analyze them closely. Make sure there are no transactions that you can’t account for and that all of the decimals are in the right spots. If you find any problems contact the company or financial institution in question immediately to notify them. Let Your Web Browser Warn You: The latest generation web browsers, such as Internet Explorer 7 and Firefox 2.0 come with built in phishing protection. These browsers will analyze web sites and compare them against known or suspected phishing sites and warn you if the site you are visiting may be malicious or illegitimate. Report Suspicious Activity: If you receive emails that are part of a phishing scam or even seem suspicious you should report them. Douglas Schweitzer says "Report suspicious e-mails to your ISP and be sure to also report them to the Federal Trade Commission (FTC) at www.ftc.gov".

View the original article here

Tuesday, October 2, 2012

Windows Vista Backup

If you choose Backup Files, Vista will walk you through choosing a destination to backup to (again- this is typically an external USB hard drive or a CD / DVD recorder), and then choosing the drives, folders, or files that you want to include in your backup.

Note: If you have already configured Backup Files, clicking on the Backup Files button will instantly initiate a backup. To modify the configuration, you instead need to click on the Change Settings link below the Backup Files button.


View the original article here