How about running the browser in a sandbox that resets all changes on exit? I've actually set up Firefox (hardened) + Sandboxie on Win7 but exactly how good is this setup?
How about running the browser in a sandbox that resets all changes on exit? I've actually set up Firefox (hardened) + Sandboxie on Win7 but exactly how good is this setup?
a) disable flash
b) disable java
c) disable any plugins really.
d) use chrome (at least)
e) do not allow downloading of any file. Instead use chrome's plugin to open any word/etc files in google docs.
f) Use a chromebook. Chromebooks can't really execute programs like windows machines can, so it's fairly safe. And worst case is you expose a sandbox machine with no private data other than caches, that can be set to be cleared on sleep or whatever. Bonus security points:
- if a chromebook is hijacked, it will only be hijacked until a reboot during which time the chromebook does a sanity check ensuring the OS is exactly intact. If it is not it just reinstalls the OS from ROM. Basically no long-term compromised machines.
- The only time chrome's sandbox was ever completely bypassed allowing arbitrary code execution was using a combination of multiple chrome exploits (now closed) and a windows data execution prevention bug. That can't happen on linux (and the chrome team works to further solidify that sandbox). Pretty much almost impossible. And if it is quickly patched and vuala.
g) browse in private browsing mode only
h) When visiting links (like facebook) manually type in the url to ensure nothing is spoofed.
I think you will be fairly safe. However... I doubt most people will go that far.
So to avoid leaking any private data to third parties, I should send all my private data to a third party using a proprietary protocol?
Also, I 'd recommend using noscript, with no plugins. Don't bother opening word files, get them to send it to you in plain text. Or run around with usb drives (no one ever said it would be easy).
embarrasing to admit, but I've always wanted to believe one could at least trust plugins like Adblock Plus or Ghostery to protect ones mind and privacy a little.. now, reading Hacker News almost every day, I'm getting paranoid. is it a vulnerability to even use them?
Addons is more generic term, it includes extensions, plugins and themes.
Let's say you trust Chrome, you can't trust AdBlock just because you trust Chrome. The install on the Chrome store could get compromised, somehow.
In this specific case though, you also have to weigh the risk of an attack being delivered from an ad. What's more likely? One of the thousands of ads you view a day launches an attack, or installing a Chrome extension does? Which would be more damaging?
Security is not an exact science. It's all about weighing options and making informed decisions.
If an attacker can gain access to your network (splicing a network cable somewhere, long term hacks against wifi keys, etc) then they can run DNS or arp poisoning, and redirect all of your traffic through a transparent proxy that can strip off HTTPS and log all cookies and form submission.
Many people will then type in 'www.facebook.com' into the address bar, and will see facebook as normal (minus the padlock, which most people wouldn't notice is missing).
So: don't just type in 'www.facebook.com' ALWAYS type in 'https://www.facebook.com manually, or make a habbit of checking the padlock on every page view (perhaps there is a chrome addon for this?)
EDIT: and if you're being spoofed by a government or syndicate who has the ability to sign global certificates, then there is probably not much you can do.
I'm interested to know how google's cloud is going to implement my updated video card drivers.
Yeah. Technology to hack someone is getting better by the minute.
eg, here's the DoD global phone book (in case I want to email somebody). Server requires CAC token from the client, but the client's browser doesn't trust the server!
https://dod411.chamb.disa.mil/
I don't even know what to call this level of broken, Chomsky-esque?
I've used approximately zero DoD computers since 2005 that had the SSL CA chain misconfigured for use on DoD websites. It's really not that hard, even my Linux box here works fine.
In my humble experience, installing DoD roots is a journey: there are at least a few dozen and they are constantly being retired and superseded. Meanwhile, to get the DoD root certs, one has to trust A) DNS B) whomever is in charge of access control to the cert servers. Clearly, access control is a major problem for the DoD, that's the whole problem to begin with.
But like I said, it works on my home computer too. Google for DISA InstallRoot (or try going here and running through the steps http://iase.disa.mil/pki-pke/getting_started/index.html)
It is true that they go through the intermediate CAs fairly quickly, but the actual root is still at CA-2 from what I can tell.
DNS security is certainly a concern, but not the kind of concern that leads to SSL warning popups unless there's something else screwy going on. But then maybe Chrome is seeing screwy stuff that MSIE doesn't know to check for...
However this is a policy which is not computer-enforced, which means of course that it's fairly useless in practice.
See, for example, https://www.authentic8.com
Chrome OS is probably the only commercial platform that is designed with this era of threats in mind. It's at least a generation ahead of everybody else. They're actually building their own embedded controller (controls the fans, battery etc.) to go along with their open source firmware so they can worry less about bad guys in the supply chain.
The problem with this sort of approach is that it is slow on most office machines. A lot of companies are still running XP desktops with 1GB RAM.