Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, September 25, 2009

How email service providers tag spam

As a former technical support representative for two big Internet Service Providers (ISPs) in the United States, I have come to understand how their mail servers work in reducing spam. Of course, the one I would like to discuss is just the basic manner of recognizing spam. Providers may have other means of identifying spam.

First: For definition, we will work on "spam" as unsolicited email--be it business, advocacy or commercial email. I will not talk about IM spam or SMS spam or gaming spam. I will discuss spamming in emails.

Spam identification is the key to spam reduction, so ISPs actually focus on that aspect. As soon as they determine that an email is spam, what they do with that spam is just a matter of creativity on the email address owner or the email service provider.

There are two key strategies in spam identification: Keyword monitoring and Spam tagging.

Keyword monitoring is (of course) monitoring key words in the email's subject line. Based on the ISP's pre-studied list of words that are most likely to contain spam, ISPs control the distribution of messages that have these words. Instead of going to the recipients' Inbox, they go to the Junk or Bulk mail folder.

This means that if you send email with words such as "tits" or "dicks" in your email, this will probably be sent to the Spam folder of the recipient if the email server has that approach in spam detection.

While this seems logical, the downside of this is not supported by certain groups as this same rule may be applied to the words such as "breasts" or "penis" which may be required in medical professions. Useful emails may be forwarded to the spam folder without knowledge of the recipient (obviously) even though they intend to receive it.

Spam tagging refers to the use of the "Report Spam" or "This is spam" feature of your email service provider to report that the email you are reading is actually a spam. Most of the email service providers have this feature, but the level of effect of the feature varies.

With this feature, what happens usually is that the email you use is transferred to your Spam folder. What you may not know, however, is that what you actually do is not just tag the email as spam, but tag the sender as a spammer.

This indicates that if a certain number of users tag that email sender as a spammer, the email server of the recipient will automatically tag it as spam, resulting to the future emails of that sender to be forwarded to the Spam folder, even for other receivers.

Spam identification focus on two parts of the communication model: the message (Email subject line)b and the sender (Email sender / address), with the channel (email service provider) processing also the setting of rules in spam identification.

The implication of these technologies is simply discretionary use of spam identification. Spam costs a lot of money for organizations as they have to deal with wasted resources (bandwidth) and time (for deleting spam), not to mention privacy and other security issues, so proper identification of spam is really useful. On other hand, be careful with tagging an email as "spam" if you are in an organization where the sender is sending relevant information that only you do not appreciate receiving. You may be costing the inconvenience not just to the sender but to the other recipients.

Resolution for recipients who have discovered they have received an email but it is in the Spam folder when it is actually not spam:
  1. Use the "Unmark as spam" or similar feature
  2. Add the recipient's email address to your address book. This adds a rule to your email that the sender is a valid contact.

Friday, July 17, 2009

Understanding Patches

Cyber Security Tip ST04-006

When vendors become aware of vulnerabilities in their products, they often
issue patches to fix the problem. Make sure to apply relevant patches to
your computer as soon as possible so that your system is protected.

What are patches?

Similar to the way fabric patches are used to repair holes in clothing,
software patches repair holes in software programs. Patches are updates that
fix a particular problem or vulnerability within a program. Sometimes,
instead of just releasing a patch, vendors will release an upgraded version
of their software, although they may refer to the upgrade as a patch.

How do you find out what patches you need to install?

When patches are available, vendors usually put them on their websites for
users to download. It is important to install a patch as soon as possible to
protect your computer from attackers who would take advantage of the
vulnerability. Attackers may target vulnerabilities for months or even years
after patches are available. Some software will automatically check for
updates, and many vendors offer users the option to receive automatic
notification of updates through a mailing list. If these automatic options
are available, we recommend that you take advantage of them. If they are not
available, check your vendors' websites periodically for updates.

Make sure that you only download software or patches from websites that you
trust. Do not trust a link in an email message—attackers have used email
messages to direct users to malicious websites where users install viruses
disguised as patches. Also, beware of email messages that claim that they
have attached the patch to the message—these attachments are often viruses
(see Using Caution with Email Attachments for more information).
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Author: Mindi McDowell
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed
to increase awareness.

Originally Published at: http//www.us-cert.gov/cas/tips/ST04-006.html

Wednesday, July 1, 2009

Understanding Anti-Virus Software

Cyber Security Tip ST04-005


Anti-virus software can identify and block many viruses before they can
infect your computer. Once you install anti-virus software, it is important
to keep it up to date.

What does anti-virus software do?

Although details may vary between packages, anti-virus software scans files
or your computer's memory for certain patterns that may indicate an
infection. The patterns it looks for are based on the signatures, or
definitions, of known viruses. Virus authors are continually releasing new
and updated viruses, so it is important that you have the latest definitions
installed on your computer.

Once you have installed an anti-virus package, you should scan your entire
computer periodically.
* Automatic scans - Depending what software you choose, you may be able to
configure it to automatically scan specific files or directories and
prompt you at set intervals to perform complete scans.
* Manual scans - It is also a good idea to manually scan files you receive
from an outside source before opening them. This includes

* saving and scanning email attachments or web downloads rather than
selecting the option to open them directly from the source
* scanning media, including CDs and DVDs, for viruses before opening any
of the files

What happens if the software finds a virus?

Each package has its own method of response when it locates a virus, and the
response may differ according to whether the software locates the virus
during an automatic or a manual scan. Sometimes the software will produce a
dialog box alerting you that it has found a virus and asking whether you
want it to "clean" the file (to remove the virus). In other cases, the
software may attempt to remove the virus without asking you first. When you
select an anti-virus package, familiarize yourself with its features so you
know what to expect.

Which software should you use?

There are many vendors who produce anti-virus software, and deciding which
one to choose can be confusing. All anti-virus software performs the same
function, so your decision may be driven by recommendations, particular
features, availability, or price.

Installing any anti-virus software, regardless of which package you choose,
increases your level of protection. Be careful, though, of email messages
claiming to include anti-virus software. These messages, supposedly from
your ISP's technical support department, contain an attachment that claims
to be anti-virus software. However, the attachment itself is in fact a
virus, so you could become infected by opening it (see Using Caution with
Email Attachments
for more information).

How do you get the current virus information?

This process may differ depending what product you choose, so find out what
your anti-virus software requires. Many anti-virus packages include an
option to automatically receive updated virus definitions. Because new
information is added frequently, it is a good idea to take advantage of this
option. Resist believing email chain letters that claim that a well-known
anti-virus vendor has recently detected the "worst virus in history" that
will destroy your computer's hard drive. These emails are usually hoaxes
(see Identifying Hoaxes and Urban Legends for more information). You can
confirm virus information through your anti-virus vendor or through
resources offered by other anti-virus vendors.

While installing anti-virus software is one of the easiest and most
effective ways to protect your computer, it has its limitations. Because it
relies on signatures, anti-virus software can only detect viruses that have
signatures installed on your computer, so it is important to keep these
signatures up to date. You will still be susceptible to viruses that
circulate before the anti-virus vendors add their signatures, so continue to
take other safety precautions as well.
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed to
increase awareness.

Terms of use

http//www.us-cert.gov/legal.html

This document can also be found at

http//www.us-cert.gov/cas/tips/ST04-005.html

Friday, June 26, 2009

Spam, Phishing, and Malicious Code Related to Recent Celebrity Deaths

US-CERT is aware of public reports of an increased number of spam
campaigns, phishing attacks, and malicious code targeting the recent
deaths of Michael Jackson and Farrah Fawcett. These email messages may
attempt to gain user information through phishing attacks or by
recording email addresses if the user replies to the message.
Additionally, email messages may contain malicious code or may contain
a link to a seemingly legitimate website containing malicious code.

US-CERT would like to remind users to remain cautious when receiving
unsolicited email. Users are encouraged to take the following measures
to protect themselves from these types of attacks:
* Do not follow unsolicited web links received in email messages.
* Install and maintain up-to-date antivirus software.
* Refer to the Recognizing and Avoiding Email Scams (pdf) document
for more information on avoiding email scams.
* Refer to the Avoiding Social Engineering and Phishing Attacks
document for more information on social engineering attacks.

Relevant URLs:

http://www.us-cert.gov/cas/tips/ST04-014.html

http://www.us-cert.gov/reading_room/emailscams_0905.pdf

Originally posted at:

http://www.us-cert.gov/current/index.html#spam_campaigns_based_on_recent

Friday, June 5, 2009

Good Security Habits

Cyber Security Tip ST04-003

There are some simple habits you can adopt that, if performed consistently,
may dramatically reduce the chances that the information on your computer
will be lost or corrupted.

How can you minimize the access other people have to your information?

You may be able to easily identify people who could, legitimately or not,
gain physical access to your computer—family members, roommates, co-workers,
members of a cleaning crew, and maybe others. Identifying the people who
could gain remote access to your computer becomes much more difficult. As
long as you have a computer and connect it to a network, you are vulnerable
to someone or something else accessing or corrupting your information;
however, you can develop habits that make it more difficult.
* Lock your computer when you are away from it. Even if you only step away
from your computer for a few minutes, it's enough time for someone else
to destroy or corrupt your information. Locking your computer prevents
another person from being able to simply sit down at your computer and
access all of your information.
* Disconnect your computer from the Internet when you aren't using it. The
development of technologies such as DSL and cable modems have made it
possible for users to be online all the time, but this convenience comes
with risks. The likelihood that attackers or viruses scanning the
network for available computers will target your computer becomes much
higher if your computer is always connected. Depending on what method
you use to connect to the Internet, disconnecting may mean disabling a
wireless connection, turning off your computer or modem, or
disconnecting cables. When you are connected, make sure that you have a
firewall enabled (see Understanding Firewalls for more information).
* Evaluate your security settings. Most software, including browsers and
email programs, offers a variety of features that you can tailor to meet
your needs and requirements. Enabling certain features to increase
convenience or functionality may leave you more vulnerable to being
attacked. It is important to examine the settings, particularly the
security settings, and select options that meet your needs without
putting you at increased risk. If you install a patch or a new version
of the software, or if you hear of something that might affect your
settings, reevaluate your settings to make sure they are still
appropriate (see Understanding Patches, Safeguarding Your Data, and
Evaluating Your Web Browser's Security Settings for more information).

What other steps can you take?

Sometimes the threats to your information aren't from other people but from
natural or technological causes. Although there is no way to control or
prevent these problems, you can prepare for them and try to minimize the
damage.
* Protect your computer against power surges and brief outages. Aside from
providing outlets to plug in your computer and all of its peripherals,
some power strips protect your computer against power surges. Many power
strips now advertise compensation if they do not effectively protect
your computer. Power strips alone will not protect you from power
outages, but there are products that do offer an uninterruptible power
supply when there are power surges or outages. During a lightning storm
or construction work that increases the odds of power surges, consider
shutting your computer down and unplugging it from all power sources.
* Back up all of your data. Whether or not you take steps to protect
yourself, there will always be a possibility that something will happen
to destroy your data. You have probably already experienced this at
least once— losing one or more files due to an accident, a virus or
worm, a natural event, or a problem with your equipment. Regularly
backing up your data on a CD or network reduces the stress and other
negative consequences that result from losing important information (see
Real-World Warnings Keep You Safe Online for more information).
Determining how often to back up your data is a personal decision. If
you are constantly adding or changing data, you may find weekly backups
to be the best alternative; if your content rarely changes, you may
decide that your backups do not need to be as frequent. You don't need
to back up software that you own on CD-ROM or DVD-ROM—you can reinstall
the software from the original media if necessary.
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have
identified this topic as one of the top tips for home users.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed
to increase awareness.

This document can also be found at

http://www.us-cert.gov/cas/tips/ST04-003.html

Thursday, May 21, 2009

Choosing and Protecting Passwords

Cyber Security Tip ST04-002

Introduction

Passwords are a common form of authentication and are often the only barrier
between a user and your personal information. There are several programs
attackers can use to help guess or "crack" passwords, but by choosing good
passwords and keeping them confidential, you can make it more difficult for
an unauthorized person to access your information.

Why do you need a password?

Think about the number of personal identification numbers (PINs), passwords,
or passphrases you use every day: getting money from the ATM or using your
debit card in a store, logging on to your computer or email, signing in to
an online bank account or shopping cart...the list seems to just keep
getting longer. Keeping track of all of the number, letter, and word
combinations may be frustrating at times, and maybe you've wondered if all
of the fuss is worth it. After all, what attacker cares about your personal
email account, right? Or why would someone bother with your practically
empty bank account when there are others with much more money? Often, an
attack is not specifically about your account but about using the access to
your information to launch a larger attack. And while having someone gain
access to your personal email might not seem like much more than an
inconvenience and threat to your privacy, think of the implications of an
attacker gaining access to your social security number or your medical
records.

One of the best ways to protect information or physical property is to
ensure that only authorized people have access to it. Verifying that someone
is the person they claim to be is the next step, and this authentication
process is even more important, and more difficult, in the cyber world.
Passwords are the most common means of authentication, but if you don't
choose good passwords or keep them confidential, they're almost as
ineffective as not having any password at all. Many systems and services
have been successfully broken into due to the use of insecure and inadequate
passwords, and some viruses and worms have exploited systems by guessing
weak passwords.

How do you choose a good password?

Most people use passwords that are based on personal information and are
easy to remember. However, that also makes it easier for an attacker to
guess or "crack" them. Consider a four-digit PIN number. Is yours a
combination of the month, day, or year of your birthday? Or the last four
digits of your social security number? Or your address or phone number?
Think about how easily it is to find this information out about somebody.
What about your email password—is it a word that can be found in the
dictionary? If so, it may be susceptible to "dictionary" attacks, which
attempt to guess passwords based on words in the dictionary.

Although intentionally misspelling a word ("daytt" instead of "date") may
offer some protection against dictionary attacks, an even better method is
to rely on a series of words and use memory techniques, or mnemonics, to
help you remember how to decode it. For example, instead of the password
"hoops," use "IlTpbb" for "[I] [l]ike [T]o [p]lay [b]asket[b]all." Using
both lowercase and capital letters adds another layer of obscurity. Your
best defense, though, is to use a combination of numbers, special
characters, and both lowercase and capital letters. Change the same example
we used above to "Il!2pBb." and see how much more complicated it has become
just by adding numbers and special characters.

Longer passwords are more secure than shorter ones because there are more
characters to guess, so consider using passphrases when you can. For
example, "This passwd is 4 my email!" would be a strong password because it
has many characters and includes lowercase and capital letters, numbers, and
special characters. You may need to try different variations of a
passphrase—many applications limit the length of passwords, and some do not
accept spaces. Avoid common phrases, famous quotations, and song lyrics.

Don't assume that now that you've developed a strong password you should use
it for every system or program you log into. If an attacker does guess it,
he would have access to all of your accounts. You should use these
techniques to develop unique passwords for each of your accounts.

Here is a review of tactics to use when choosing a password:
* Don't use passwords that are based on personal information that can be
easily accessed or guessed.
* Don't use words that can be found in any dictionary of any language.
* Develop a mnemonic for remembering complex passwords.
* Use both lowercase and capital letters.
* Use a combination of letters, numbers, and special characters.
* Use passphrases when you can.
* Use different passwords on different systems.

How can you protect your password?

Now that you've chosen a password that's difficult to guess, you have to
make sure not to leave it someplace for people to find. Writing it down and
leaving it in your desk, next to your computer, or, worse, taped to your
computer, is just making it easy for someone who has physical access to your
office. Don't tell anyone your passwords, and watch for attackers trying to
trick you through phone calls or email messages requesting that you reveal
your passwords (see Avoiding Social Engineering and Phishing Attacks for
more information).

If your internet service provider (ISP) offers choices of authentication
systems, look for ones that use Kerberos, challenge/response, or public key
encryption rather than simple passwords (see Understanding ISPs and
Supplementing Passwords for more information). Consider challenging service
providers that only use passwords to adopt more secure methods.

Also, many programs offer the option of "remembering" your password, but
these programs have varying degrees of security protecting that information.
Some programs, such as email clients, store the information in clear text in
a file on your computer. This means that anyone with access to your computer
can discover all of your passwords and can gain access to your information.
For this reason, always remember to log out when you are using a public
computer (at the library, an internet cafe, or even a shared computer at
your office). Other programs, such as Apple's Keychain and Palm's Secure
Desktop, use strong encryption to protect the information. These types of
programs may be viable options for managing your passwords if you find you
have too many to remember.

There's no guarantee that these techniques will prevent an attacker from
learning your password, but they will make it more difficult.
________________________________________________________________

Authors: Mindi McDowell, Jason Rafail, Shawn Hernan
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Source: http://www.us-cert.gov/cas/tips/ST04-002.html

Wednesday, May 6, 2009

Why is Cyber Security a Problem?

Re-published from US-CERT Cyber Security Tip ST04-001
========================================================================

You've heard the news stories about credit card numbers being stolen
and email viruses spreading. Maybe you've even been a victim yourself.
One of the best defenses is understanding the risks, what some of the
basic terms mean, and what you can do to protect yourself against
them.

What is cyber security?

It seems that everything relies on computers and the Internet now --
communication (email, cellphones), entertainment (digital cable,
mp3s), transportation (car engine systems, airplane navigation),
shopping (online stores, credit cards), medicine (equipment, medical
records), and the list goes on. How much of your daily life relies on
computers? How much of your personal information is stored either on
your own computer or on someone else's system?

Cyber security involves protecting that information by preventing,
detecting, and responding to attacks.

What are the risks?

There are many risks, some more serious than others. Among these
dangers are viruses erasing your entire system, someone breaking into
your system and altering files, someone using your computer to attack
others, or someone stealing your credit card information and making
unauthorized purchases. Unfortunately, there's no 100% guarantee that
even with the best precautions some of these things won't happen to
you, but there are steps you can take to minimize the chances.

What can you do?

The first step in protecting yourself is to recognize the risks and
become familiar with some of the terminology associated with them.
Hacker, attacker, or intruder - These terms are applied to the people
who seek to exploit weaknesses in software and computer systems
for their own gain. Although their intentions are sometimes fairly
benign and motivated solely by curiosity, their actions are
typically in violation of the intended use of the systems they are
exploiting. The results can range from mere mischief (creating a
virus with no intentionally negative impact) to malicious activity
(stealing or altering information).
Malicious code - This category includes code such as viruses,
worms, and Trojan horses. Although some people use these terms
interchangeably, they have unique characteristics.

* Viruses - This type of malicious code requires you to actually do
something before it infects your computer. This action could be
opening an email attachment or going to a particular web page.
* Worms - Worms propagate without user intervention. They typically
start by exploiting a software vulnerability (a flaw that allows
the software's intended security policy to be violated), then once
the victim computer has been infected the worm will attempt to
find and infect other computers. Similar to viruses, worms can
propagate via email, web sites, or network-based software. The
automated self-propagation of worms distinguishes them from
viruses.
* Trojan horses - A Trojan horse program is software that claims to
be one thing while in fact doing something different behind the
scenes. For example, a program that claims it will speed up your
computer may actually be sending confidential information to a
remote intruder.

This series of information security tips will give you more
information about how to recognize and protect yourself from attacks.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________
Produced 2004 by US-CERT, a government organization.

Terms of use

<http://www.us-cert.gov/legal.html>

This document can also be found at

<http://www.us-cert.gov/cas/tips/ST04-001.html>

Monday, May 4, 2009

Home security myths

This is a post from PC Doctor, a blog which I follow. I hope you find it informative and useful.

====================

I keep coming across loads of home security myths on forums an din blog posts on the web. Most of these myths start out as good intentions but spread widely to become damaging urban myths.

Here are a few for you:

  • Hiding the SSID on your WiFi router makes you safer - it doesn't, and the same goes for MAC ID filtering and switching off DHCP
  • Writing down a password is bad - depends who you are trying to keep out!
  • A really long password is better than one that is 8 to 10 characters long - not usually.
  • You should run more than one antivirus/firewall software - that'll cause more problems than it solves.
  • Trust your security software - no piece of software can replace common sense!
  • Most PC problems are the result of malware/hacker - no, most problems are down to the user!
  • Most data loss is down to hacker/malware - again, no
  • If you see HTTPS in the address bar of a browser, you are safe - there's a lot more to it than that.
======================
Source: http://www.pcdoctor-guide.com/wordpress/?p=5017

Monday, April 27, 2009

Swine Flu Phishing Attacks and Email Scams

Original release date: April 27, 2009 at 3:04 pm
Last revised: April 27, 2009 at 3:04 pm


US-CERT is aware of public reports of email scams circulating related
to the Swine Flu. The attacks arrive via an unsolicited email message
typically containing a subject line related to the Swine Flu. These
email messages may contain a link or an attachment. If users click on
this link or open the attachment, they may be directed to a phishing
website or exposed to malicious code.

US-CERT encourages users to take the following measures to protect
themselves:
* Do not follow unsolicited web links or attachments in email
messages.
* Maintain up-to-date antivirus software.
* Refer to the Recognizing and Avoiding Email Scams (pdf) document
for more information on avoiding email scams.
* Refer to the Avoiding Social Engineering and Phishing Attacks
document for more information on social engineering attacks.

US-CERT will provide additional details as they become available.

Relevant Url(s):
<http://www.us-cert.gov/cas/tips/ST04-014.html>

<http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/>

<http://www.us-cert.gov/reading_room/emailscams_0905.pdf>

====
This entry is available at
http://www.us-cert.gov/current/index.html#swine_flu_phishing_attacks_and

Sunday, April 26, 2009

Staying Safe on Social Network Sites

Re-Published from United States Computer Emergency Readiness Team
______________________________
Cyber Security Tip ST06-003

The popularity of social networking sites continues to increase, especially among teenagers and young adults. The nature of these sites introduces security risks, so you should take certain precautions.

What are social networking sites?

Social networking sites, sometimes referred to as "friend-of-a-friend" sites, build upon the concept of traditional social networks where you are connected to new people through people you already know. The purpose of some networking sites may be purely social, allowing users to establish friendships or romantic relationships, while others may focus on establishing business connections.

Although the features of social networking sites differ, they all allow you to provide information about yourself and offer some type of communication mechanism (forums, chat rooms, email, instant messenger) that enables you to connect with other users. On some sites, you can browse for people based on certain criteria, while other sites require that you be "introduced" to new people through a connection you share. Many of the sites have communities or subgroups that may be based on a particular interest.

What security implications do these sites present?

Social networking sites rely on connections and communication, so they encourage you to provide a certain amount of personal information. When deciding how much information to reveal, people may not exercise the same amount of caution as they would when meeting someone in person because

* the internet provides a sense of anonymity
* the lack of physical interaction provides a false sense of security
* they tailor the information for their friends to read, forgetting that
others may see it
* they want to offer insights to impress potential friends or associates

While the majority of people using these sites do not pose a threat, malicious people may be drawn to them because of the accessibility and amount of personal information that's available. The more information malicious people have about you, the easier it is for them to take advantage of you. Predators may form relationships online and then convince unsuspecting individuals to meet them in person. That could lead to a dangerous situation. The personal information can also be used to conduct a social engineering attack (see Avoiding Social Engineering and Phishing Attacks for more information). Using information that you provide about your location, hobbies, interests, and friends, a malicious person could impersonate a trusted friend or convince you that they have the authority to access other personal or financial data.

Additionally, because of the popularity of these sites, attackers may use them to distribute malicious code. Sites that offer applications developed by third parties are particularly susceptible. Attackers may be able to create customized applications that appear to be innocent while infecting your computer without your knowledge.

How can you protect yourself?

* Limit the amount of personal information you post - Do not post information that would make you vulnerable, such as your address or information about your schedule or routine. If your connections post information about you, make sure the combined information is not more than you would be comfortable with strangers knowing. Also be considerate when posting information, including photos, about your connections.
* Remember that the internet is a public resource - Only post information you are comfortable with anyone seeing. This includes information and photos in your profile and in blogs and other forums. Also, once you post information online, you can't retract it. Even if you remove the information from a site, saved or cached versions may still exist on other people's machines (see Guidelines for Publishing Information Online for more information).
* Be wary of strangers - The internet makes it easy for people to
misrepresent their identities and motives (see Using Instant Messaging and Chat Rooms Safely for more information). Consider limiting the people who are allowed to contact you on these sites. If you interact with people you do not know, be cautious about the amount of information you reveal or agreeing to meet them in person.
* Be skeptical - Don't believe everything you read online. People may post false or misleading information about various topics, including their own identities. This is not necessarily done with malicious intent; it could be unintentional, an exaggeration, or a joke. Take appropriate precautions, though, and try to verify the authenticity of any information before taking any action.
* Evaluate your settings - Take advantage of a site's privacy settings. The default settings for some sites may allow anyone to see your profile. You can customize your settings to restrict access to only certain people. However, there is a risk that even this private information could be exposed, so don't post anything that you wouldn't want the public to see. Also, be cautious when deciding which applications to enable, and check your settings to see what information the applications will be able to access.
* Use strong passwords - Protect your account with passwords that cannot easily be guessed (see Choosing and Protecting Passwords for more information). If your password is compromised, someone else may be able to access your account and pretend to be you.
* Check privacy policies - Some sites may share information such as email addresses or user preferences with other companies. This may lead to an increase in spam (see Reducing Spam for more information). Also, try to locate the policy for handling referrals to make sure that you do not unintentionally sign your friends up for spam. Some sites will continue to send email messages to anyone you refer until they join.
* Use and maintain anti-virus software - Anti-virus software recognizes most known viruses and protects your computer against them, so you may be able to detect and remove the virus before it can do any damage (see Understanding Anti-Virus Software for more information). Because attackers are continually writing new viruses, it is important to keep your definitions up to date.

Children are especially susceptible to the threats that social networking sites present. Although many of these sites have age restrictions, children may misrepresent their ages so that they can join. By teaching children about internet safety, being aware of their online habits, and guiding them
to appropriate sites, parents can make sure that the children become safe and responsible users (see Keeping Children Safe Online for more information).
_________________________________________________________________

Author: Mindi McDowell
_________________________________________________________________

Produced 2006 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed to increase awareness.
____________________________________

While this article is from a US government agency, I believe that the tips here are practical and necessary for everyone's peace of mind when using social networking sites.

Friday, April 17, 2009

To save or not to save: Passwords and your laptop

Should you save your passwords in your browser if you log in to websites using your laptop?

I would recommend that you use the password saving option of your browser if you:
  • are careful of websites where you go to
  • are careful of software that you download or install
  • are the only one using your laptop or you are mindful of people who use your laptop
  • clear your browsing history appropriately.
I do not recommend saving your password in a browser if you:
  • are not careful of websites where you go to (i.e., you go to websites which are prone to malicious software, such as porn sites)
  • are not careful of software that you download and install (you might actually be downloading a virus, a Trojan, or a worm).
  • too many people use your laptop and you do not consider how they use your laptop (security-wise)
  • do not clear your browsing history at all.
Security is everybody's concern. The first level of security should start with the user. And forget about hackers. When you consider security, consider virus, rogue virus, spyware, and data loss.