The Bare Minimum You Should Do to Protect Your Family's Data
blog.mozilla.org
blog.mozilla.org
This is really a strange document...
Just a few examples:
"Don’t open emails, texts, ]...] from anyone you don’t know, don’t recognize, or weren’t expecting" <- sorry, that's not how email works. I want to get emails from strangers that care about what I do.
"Don’t use unsecure Wi-Fi networks" Largely outdated due to HTTPS and completely impractical. Everyone uses the Wifi at starbucks.
"Even better, get a VPN (virtual private network) — but, just like with antivirus software, don’t use a free VPN." How should an average user know if the VPN is a scam? (More than half of VPN providers are scam and there's little reason to believe that payed providers are always better.)
"Use tough passwords and change them frequently." Changing passwords frequently is considered deprecated advice. The single most important rule about passwords is to use unique passwords. Which they don't say at all...
I could go on...
Update: Mozilla deleted the post after criticism, see https://twitter.com/asadotzler/status/1068961020540899329
Many people click the links at the bottom of a news article, open every email they get and click their contents with abandon and generally ignore they privacy and security on the web. That does not mean that that behavior should go unchallenged or that we should dismiss basic personal security with the old phrase, "Everyone is doing it."
I would call it an "appeal to practicality"
I mean, sure, you and I carry mobile plans with tethering capabilities; my iphone/verizon combo is nearly always better than your average free or included with purchase wifi network. But I also have a device that was like a grand up front and the service is north of $100/month. It's a totally reasonable and practical solution for me, sure, but for someone who doesn't work in tech, or for someone who has kids, etc, etc... for a lot of people, spending that much on connectivity is not particularly practical.
(you can get cheaper tethering setups, of course; those that I've tried have been worse in the areas where I've tried them; it has been more than a year since I tried, so the 'verizon is the best if you don't care about price' statement may be out of date, and of course, different areas have different coverage. YMMV, of course. My main point is just that if you want tethering that is consistently better than free wifi... that's going to cost you an amount of money that might be impractical for most people.)
I mean, sure, you could still just not use data... my computer would be more secure if I left it off. But it would also be a lot less useful.
https://medium.com/@perplamps/super-basic-security-advice-f9...
If anyone finds any problems or disagrees with any of my suggestions, let me know and I'll update it!
For example, some web browsers (Google Chrome and Apple Safari) offer to create randomized passwords.
Installing more proprietary software with unrestricted access seems like a huge step backwards. https://en.wikipedia.org/wiki/Magic_Lantern_%28software%29#A...
Whenever I help clean up someone’s Windows computer, I treat any antivirus product other than Windows Defender as malware and get rid of it.
I have the feeling that security software is often the most insecure one, because of bad design choices and lack of quality engineering.
> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. More likely, they hurt security significantly; for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors, but in general their developers do not follow standard security practices. (Microsoft, on the other hand, is generally competent.)
In the linked Project Zero issue tracker, all 3 of these "reputable sources" have exploits in their anti-virus software.
[1]: https://robert.ocallahan.org/2017/01/disable-your-antivirus-...
I mean,even just reading vulnerability bulletins and CVE descriptions should familiarize you with explotability and complexity of attack,they exist to help remediators prioritize more insecure vulns.
Quick example: 'ls' has an easily exploitable code execution vuln. On a shared terminal server,this vuln translates to severe loss of security. On a firewall,this is nothing more than a house keeping item with no real loss of security as there are no threats that can run 'ls'.
Would you want your electric company to use these products knowing that another country will attack with 0 frequency until war is declared?
I highly recommend looking these things up on your own but the goal of Information security is to reduce the risk that vulnerabilities will be exploited to where a breach of your security goals occurs(i.e.:CIA triad,confidentiality,integrity and availability mostly). It's not to make your system impregnable to all conceivable attacks.
My electric company should have well resourced nation state actors as part of their threat model. They should not only remediate known vulns,they should also employ EDR solutions that perform ML and behavioral detections/preventions. They should be part of their industry ISAC for threat intel sharing (which includes 0days) as well as have a comprehensive threat hunting and incident response program. Your average consumer,howevet has different types of data and attackers to worry about.
A banking trojan cleaning out your account,ransomware demanding payment for your family pictures, an ex installing RATs to monitor what you do are what consumers are threatened with.
Being attackable is not insecurity Right now you're attackable by an endless list of threats. Your local gang,serial killers,crazy people who shoot up schools,terrorists,etc... But your security is measured by a number of factors including where you live,what you're doing and specific attacker's cost-benefit analysis of attacking you.
A simpler example: apache2 has a RCE but known exploits require PIE disabled for an exploit to work. You have one apache server in a segregated vlan that is facing your admin vlan with PIE enabled. In contrast you have an IIS server with DOS vuln facing the internet. The IIS server is more insecure because there is a significantly higher likelihood of a security compromise(availability) against it and the org will face reputational and revenue(?) Impact.
The whole point I want youbto get is that real (in)security is context aware.
vul·ner·a·bil·i·ty noun the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally.
This is security101. Risk is measured by multiplying vulnerability by threat.
Maybe an analogy might help. You are vulnerable to bullets. But your security with respect to your bullet vulnerability is measured by multiplying it against active threats that might shoot you with bullets. So,your security decreases when in a warzone as opposed to lying in bed at your suburban house due to reduction of threat.
On the other hand, I'm not sure I'd trust a typical end user to protect themself otherwise. Are they going to secure their OS profile? Avoid malware?
As a techie you might have nation state actors employing sophisticated attacks or corpirations spying on users. But the most immediate threat to consumers are things like phishing attacks,ransomware and banking trojans.
Connecting to unsecured WiFi is mostly not a problem. Most websites and applocations encrypt traffic and the security of the channel does not matter.
Plus, the recommendation to installl shady antivirus software throws the motivation of this article into doubt.
1. In terms of “strong passwords” it’s better to use the words “paraphrase” which if they get past 4 words are almost always stronger than traditional “passwords” humans actually use. It’s a nitpick, but using the better term leads to better results in my experience. “Do I need a new password? No, you need a new passphrase”
2. In terms of rolling credentials frequently and on some time period, NIST specifically recommends against that now.
The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$5, ...
> Even better, use a password manager like Lastpass.
They really should have lead with this.
Password managers have become a nearly non-negotiable necessity. Telling people just use a password manager is becoming kind of like telling developers just use source control 15 years ago. You just won't know how important they are (or the true cost/benefit) until you start using one yourself.
Source control was very, very standard 15 years ago. 15 years ago I would have run, not walked, from a job if they didn't use source control.
There was no git, we used CVS, which was almost old enough to vote at that time.
For commercial shops, perhaps. But back then the bar for using source control was much, much higher, so for many small projects, people didn't bother. There wasn't anything as simple as `git init`.
There were a few public CVS and SVN servers that were appropriate for open source projects, but for anything personal or commercial, you had to use a local, single-user repo or set up your own server. (Back then, the only viable DVCS systems were commercial.)
That was like 5 minutes of work, though. Maybe an hour or two if you hadn't done it before. It's absurdly easy to set up and use SVN. CVS was easy to set up, but a nightmare to use.
> you had to use a local, single-user repo or set up your own server.
That's the opposite of having no source control, that's having source control.
I’m not arguing with that, only pointing out that it wasn’t ubiquitous.
The privacy policy for the firefox extension is also fairly clean.
> You may use our Services only as permitted in these Terms, and you consent to our Privacy Policy at https://www.logmeininc.com/legal/privacy, which is incorporated by reference.
pp:
> When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example, schedules, attendee info, etc.), or from the Service infrastructure itself, (for example, duration of session, use of webcams, connection information, etc.) We may also collect usage and log data about how the services are accessed and used, including information about the device you are using the Services on, IP addresses, location information, language settings, what operating system you are using, unique device identifiers and other diagnostic data to help us support the Services.
> Third Party Data: We may receive information about you from other sources, including publicly available databases or third parties from whom we have purchased data, and combine this data with information we already have about you. We may also receive information from other affiliated companies that are a part of our corporate group. This helps us to update, expand and analyze our records, identify new prospects for marketing, and provide products and services that may be of interest to you.
> Location Information: We collect your location-based information for the purpose of providing and supporting the service and for fraud prevention and security monitoring. If you wish to opt-out of the collection and use of your collection information, you may do so by turning it off on your device settings.
> Device Information: When you use our Services, we automatically collect information on the type of device you use, operating system version, and the device identifier (or "UDID").
and
> Some specific examples of how we use the information:
> * Conduct research and analysis
> * Display content based upon your interests
> * Market services of our third-party business partners
and
> 4. Information Sharing
> ... We may share your personal information with (a) third party service providers; (b) business partners; (c) affiliated companies within our corporate structure and (d) as needed for legal purposes.
and
> Examples of how we may share information with service providers include:
> * Sending marketing communications
there's more
https://twitter.com/asadotzler/status/1068961020540899329?s=...
But here's the original article:
https://web.archive.org/web/20181130081659/https://blog.mozi...
Do people still really install anti-virus? Isn't it just another vector for attack since they themeselves use exploits to manipulate the OS?
Linux for desktop, pixel or iOS for phone. Signal for communication, fastmail or Gmail on g suite for email.
Minimize installed apps on phone Run JavaScript blocker on Firefox if you're using an Android (and on your desktop).
My default is 20 characters of alphanum, or 16 of "graph" (though I drop look alike characters; 32 chars if I'm entering payment details).
One has to hope they have a small limit on retries. They definitely carry commercially sensitive data and do payment processing.
What worries me is they used js to catch my attempt to use 20 chars, so they're not operating completely naively -- all I can think was it was a misinterpretation and s/most/least.
This is not so great advice, especially as a "bare minimum." What setting would a user really want to change here?
The only advice should perhaps be the last sentence "Consider using plug-ins like Privacy Badger or HTTPS Everywhere to block tracking or keep your activity safer from snoops." And then explain what they do.
Do not change passwords frequently. Do not use short passwords and try to compensate by using special characters and nonsensical word obfuscation, instead use long passphrases, the longer the better.
What is bigger threat and attack vector, McAfee, Symantec or modding forums for 10 year old?
For me installing AV is silly I don't download and run random crap from internet that friend from school also installed. But If I would have kids having installed AV and updated is quite good idea. I also wonder all time how my non technical close ones break their computers, I don't know what they are clicking but I do not get unusable windows 10 every 3 months. My gf is not technical but she almost never install anything on her laptop and it works fine, so for this one I am quite happy.
For example: third party cookies are never needed on 99% of the sites you visit.
This is a futile advice, no sane person is ever going to follow it. You can memorize a tough password or two but change them and memorize the new ones frequently... nope.
> Tweak your home assistants.
Don't use home assistants unless you are a kind of person who really doesn't mind broadcasting their whole life as a reality show without even being informed when you're on air. I can't imagine a reasonable privacy-caring person who would.
- ISPs - Routers - Ad Blockers - OS - Data storage / backups - Facebook or not ? - ios v android ...
I also don't use the ISP router / wifi.
I feel like those two things are good steps towards protecting my family. They give me some piece of mind at least.
I've only had to disconnect once or twice to unsubscribe from spam lists, but I doubt my family would even bother.
I am running it on a old Pi B (the old one with an RCA jack). No issues. if I was sending to family across the country, I'd probably add remote access of some sort for myself.
I feel like someone actually doing that right would be a big deal but haven't heard anything special about the market leaders.
I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them.
Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.
Some people would say, "Don't murder people, then!" but folks sometimes prefer, "How dare they catch you, what a violation of your privacy!"
The punchline: the series of rapes and murders that was used to institutionalize mass DNA collection turned out to have been done by a cop who didn't have DNA taken.
Of course, if you go down this line of reasoning, you need to weigh the probability of this versus the probability of dying to an undiagnosed/late-diagnosed genetic condition.
https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrim...
And if GINA was repealed, (and it wouldn't be, it was passed the House 420-3 a and passed the Senate 95-0), the insurance companies aren't going to beat around the bush and try to hack 23andMe, they'd just demand DNA samples directly as a requirement of being insured.
> they'd just demand DNA samples directly as a requirement of being insured.
Unless GINA was repealed, but that remained illegal.
Will this make it impossible to find your lost iPhone?
Obligatory xkcd telling you to not do this: https://xkcd.com/936/
They recommend a minimum of six words though.
(also good stuff here: https://security.stackexchange.com/questions/151165/is-rando...)
It seems the consensus is to use 5-6 words, and following the xkcd trick of 4 may not be enough.
It assumes that the attacker has complete knowledge of the password generation method. This is good security practice and provides you with a worst case boundary. In reality, though, an attacker seldomly has that advantage. Before an attacker spends x hours/days/weeks to crack pure word-based passwords, they will spend time to crack "passw0rd". If you remove the advantage of password generation method knowledge, all numbers in this article are very different. The reader should know about that!
It assumes that whoever is storing the password may do so badly. It even states "assume the site stores our credentials in the weakest possible way". Which is a dangerous assumption since the weakest possible way would be plaintext and then the whole article would be moot. So, obviously we exclude plaintext. The article goes with simple, single md5 hashes instead. While some kind of worst case, it's pretty unrealistic nowadays that someone makes an effort not to store passwords in plaintext and then fails so miserably in googling how to do so. This worst case is probably chosen to have easier and more impressive cracking numbers. The reader should be aware of this.
It assumes that the attacker obtains the password database. Again, good security practice and a worst case scenario. But still not exactly 100% realistic. If you argue with this assumption, the reader should be aware of that.
In essence, this article proves that the "3 word method" is not secure enough when absolutely everyone uses this exact same method (with knowledge of the exact same words) with a service who incompetently stores passwords and got its password database stolen.
While that is true, the advice it gives "Don't use words in passwords. Ever." is just another example of great oversimplification that is harmful in the end.
Instead of bashing methods for being not secure enough (whatever that means), we should provide users with practical methods to come up with usable passwords that are reasonably secure for the service in question.
My extended family and remote friends actually got upset when I dropped Facebook. They asked why I didn't want to be part of their lives, asked why I was choosing not to talk to them anymore... All while texting me on phones that allow instantaneous communication of any type of election media imaginable, more so that Facebook allows.
Moral of the story: Facebook and other social media makes most people socially lazy with continuous use. If you don't believe me, go try to meet someone under the age of 30 "out in the wild", at a bar or venue. Bars used to be easiest places to meet anyone at, just walk in, sit at the front, and start chatting. I'm not talking about people who are on their phones ignoring the outside world; even people just chilling and having a beer just don't know how to talk to someone outside of their social media platforms.