What can ordinary users do to protect themselves other than patching?
What can ordinary users do to protect themselves other than patching?
So this was far more reaching than Windows.
To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you.
However, on reading this article my first thoughts are if this method evades detection by not having a listening port that a network scan or locally using ss/netstat can detect then perhaps you would still be able to benefit from egress filtering (only allowing outbound connections to things you need and blocking the rest). On a router most connections are through the router (FORWARD table) as opposed to directly locally originated and outbound (OUTPUT table).
If NSO does it, so could the intelligence agencies of dozens of countries. Looks like a hopeless situation, where a small percentage of population have access to anyone’s data (but not conversely).
This is posing a threat to the democratic society.
There ought to be a way to make a secure device.
But again, maintaining an offline life could be very tricky given that the society as a whole is moving everything online. For example, if you earn salaries like me, there is no way to avoid a bank account and a mobile number.
Well, you can - you just need to live a mostly offline live with few, highly hardened devices and enter you passwords under a blanket. Edward Snowden does manage, after all. But you'll have to skip on a lot of enjoyment - new software, games, even Netflix - forget it.
The real question is, is it worth to you to live such a live. Probably not.
Wipe and reinstall often, rotate passwords at same time, also teaches good backups.
ad blocker by default and always up to date system.
Use VMs or other machines for dubious websites and wipe those often (like a raspberry?)
Careful what you execute on your machine
Then if you're really paranoid:
Some external firewall running suricata for alerting
Logging to an external system so you can review things in case of issues.
I had an idea that thin clients were going to be big - and I stupidly pitched ideas for cloud based software to Adobe, Newtek, and Autodesk.
Never gunna do that again.
Anonymous guides I read mostly recommend Tor, anonymous sim card and purchasing electronics with cash. But I don't think it's going to render any state player's work impossible. I mean if they are really onto you.
On the other side, three char agencies cannot waste resources on every individual, so the best way is to stay out of the radar.
(NAT , in general, = how the multiple devices at your home all share a single public IP address from your ISP)
This article mainly addresses servers / public facing services (which do not make use of nat)