- Joined
- May 18, 2008
- Messages
- 600
Computer security 101
First, there is no such thing as a perfectly secure computer. You can follow all of these recommendations and still have your computer's security compromised. There are even more in-depth ways to guard yourself against vulnerabilities on the internet, and there are as many solutions to this problem as there are computers on the internet. This is not a comprehensive guide. However, I do feel that it covers most of the bases and gives you a good starting point for understanding how to properly protect yourself against most of the common computer security problems people have.
Let me make a few things clear:
Software Vulnerabilities/Worms
Almost all of the software that runs on computers today can accept or initiate connections to the internet. Most of the time, we don't even know they are doing so. However, poorly written code on your computer combined with malicious intent on the part of people on the internet results in exploited software vulerabilities and internet worms. These programs attack computers on the internet, taking advantages of the software flaws to gain access. They then copy themselves to other vulnerable computers wherever they can.
Software vulnerabilities are constantly being discovered and patched. It is important to keep your system up to date by installing the latest patches from the people who make the software you run.
A firewall can also help, by blocking incoming and outgoing connections to the internet. Although many firewall software packages exist for various operating systems, the most effective for the typical user's home network is to use a properly configured and up-to-date router. Routers block most incoming connections, unless you specifically open ports. Thus, you should be careful to always keep your router's firmware up to date (thereby avoiding most software vulnerabilities in the router itself) and by being very careful about opening ports, which allow people on the internet to access programs on your local network.
Weak Passwords
Many systems on the internet use a login/password combination to protect data. This is all fine and good, but most people pick poor passwords. A password should not:
A good password doesn't need to just be one word, it may be a phrase, complete with spaces and punctuation. This type of password is very difficult to break.
Trojans/Spyware/Malicious Software
This type of security flaw relies on your ability to install software on your own machine. You may browse to a seedy site and that site installs software on your computer, or perhaps you download a malicious file or open a malicious email attachment. Most modern operating systems warn you when you are about to do something that installs software on your computer, but these warnings are not always clear, and are often dismissed too quickly.
Although virus and spyware scanners can help here, no scanner is 100% effective against all possible malicious software threats. The best way to protect yourself is to be very careful about the sites you browse on the internet, and be extra careful when installing software. If you don't trust the source of the software, don't install it. Make sure you get your software from reputable sources.
Phishing/Social Engineering/Trust Vulnerabilities
This type of security issue is perhaps the most difficult to protect against with software. This type of vulnerability deals directly with tricking the user. By appearing as some trustworthy or authoritative source, malicious internet users get us to do their work for them. We gladly hand over our important information and passwords. Many people fall for this because they don't know any better. Here are some things to watch out for:
Believe nothing you recieve via email. No authority, website, bank, etc will ever ask for your account information via email. Generally they will also threaten you with account closure, etc, in a ploy to get you to act without thinking.
Do not trust that the sender of an email is who they say they are. It is quite simple to send an email from any address.
Never click links in email messages. A common attack is to send an official looking email from some company (eBay/PayPal is common as of this writing) with a link for you to click in order to verify your account information. However, the link does not go to the company, instead, it directs you to the scammer's site, which looks exactly like the company's home page. When you input your login details, the scammer has you.
It is also common to use instant messaging software to attempt a similar attack. The same rules as for email apply here. No one will ever ask for your account information via instant message. They will threaten you. It will look vaguely official. Ignore them. Don't click links people send you via instant message, and don't install programs people send you via these systems either.
Major Database Compromises
Even if your computer is totally secure, and you know everything there is to know about computer security, you still may fall victim to this type of attack. Here, the malicious user steals your information from another computer system, such as a corporate database for an internet retailer.
The best way to protect yourself here is to guard your personal information. If some company wants to know your name, mailing address, phone number, etc, and they are forcing you to provide it even though the service they are providing doesn't require it - make something up. Come up with a 'false internet' identity, complete with a name, address, telephone number, zip code, etc. Save it somewhere on your computer, and provide that info instead.
Sometimes you need to put your real information into a database. You should still do everything in your power to protect that data. For instance, if a retailer has an option to save your credit card information, decline. If you are only ordering once, try to find an option to not create a profile on the site. The less your information is stored, the better.
Conclusion
I hope this short guide has given you some of the basic tools you need to understand common threats on the internet today. The security threats that we face on the internet are changing rapidly, so keep your education fresh and up to date to be aware of the latest threats and how to respond to them.
The security of your personal information and your personal computer is your responsibility. Take it seriously!
First, there is no such thing as a perfectly secure computer. You can follow all of these recommendations and still have your computer's security compromised. There are even more in-depth ways to guard yourself against vulnerabilities on the internet, and there are as many solutions to this problem as there are computers on the internet. This is not a comprehensive guide. However, I do feel that it covers most of the bases and gives you a good starting point for understanding how to properly protect yourself against most of the common computer security problems people have.
Let me make a few things clear:
- The only secure computer is one that no one has access to, ever. Anyone who tells you otherwise is ignorant, a liar, and/or they are selling something. If you want perfect security, lock your machine in a safe and sink it to the bottom of the ocean. You can be reasonably certain at this point that it is secure.
- Software alone cannot protect you. I don't care how often you scan for viruses, how many spyware programs you have, if you're running ten thousand firewalls, there is no perfect software solution to computer security. These things alone will not protect you if you are not properly educated.
- I/We can't help you if you get hacked. Please don't send me a message about needing help because someone hacked you. Contact the company that runs the service where your account was stolen, or in the case of your own personal computer, either use google to help you fix it, or prepare to format and reinstall.
Software Vulnerabilities/Worms
Almost all of the software that runs on computers today can accept or initiate connections to the internet. Most of the time, we don't even know they are doing so. However, poorly written code on your computer combined with malicious intent on the part of people on the internet results in exploited software vulerabilities and internet worms. These programs attack computers on the internet, taking advantages of the software flaws to gain access. They then copy themselves to other vulnerable computers wherever they can.
Software vulnerabilities are constantly being discovered and patched. It is important to keep your system up to date by installing the latest patches from the people who make the software you run.
A firewall can also help, by blocking incoming and outgoing connections to the internet. Although many firewall software packages exist for various operating systems, the most effective for the typical user's home network is to use a properly configured and up-to-date router. Routers block most incoming connections, unless you specifically open ports. Thus, you should be careful to always keep your router's firmware up to date (thereby avoiding most software vulnerabilities in the router itself) and by being very careful about opening ports, which allow people on the internet to access programs on your local network.
Weak Passwords
Many systems on the internet use a login/password combination to protect data. This is all fine and good, but most people pick poor passwords. A password should not:
- Be a word in the dictionary. A popular attack against a password system is to try every word in the dictionary. This cuts down on the number of things that have to be tried, and is surprisingly effective.
- Consist entirely of letters. Using numbers, spaces, symbols, etc, increases the number of things that must be tried before the password can be guessed.
- Be the same everywhere. Using the same password everywhere means that if someone guesses (or swindles you out of/steals the user data from) your password in one place, they have access to all of your accounts.
- Need to be written down. Don't ever write a password down. If you can't remember it, its a bad password.
A good password doesn't need to just be one word, it may be a phrase, complete with spaces and punctuation. This type of password is very difficult to break.
Trojans/Spyware/Malicious Software
This type of security flaw relies on your ability to install software on your own machine. You may browse to a seedy site and that site installs software on your computer, or perhaps you download a malicious file or open a malicious email attachment. Most modern operating systems warn you when you are about to do something that installs software on your computer, but these warnings are not always clear, and are often dismissed too quickly.
Although virus and spyware scanners can help here, no scanner is 100% effective against all possible malicious software threats. The best way to protect yourself is to be very careful about the sites you browse on the internet, and be extra careful when installing software. If you don't trust the source of the software, don't install it. Make sure you get your software from reputable sources.
Phishing/Social Engineering/Trust Vulnerabilities
This type of security issue is perhaps the most difficult to protect against with software. This type of vulnerability deals directly with tricking the user. By appearing as some trustworthy or authoritative source, malicious internet users get us to do their work for them. We gladly hand over our important information and passwords. Many people fall for this because they don't know any better. Here are some things to watch out for:
Believe nothing you recieve via email. No authority, website, bank, etc will ever ask for your account information via email. Generally they will also threaten you with account closure, etc, in a ploy to get you to act without thinking.
Do not trust that the sender of an email is who they say they are. It is quite simple to send an email from any address.
Never click links in email messages. A common attack is to send an official looking email from some company (eBay/PayPal is common as of this writing) with a link for you to click in order to verify your account information. However, the link does not go to the company, instead, it directs you to the scammer's site, which looks exactly like the company's home page. When you input your login details, the scammer has you.
It is also common to use instant messaging software to attempt a similar attack. The same rules as for email apply here. No one will ever ask for your account information via instant message. They will threaten you. It will look vaguely official. Ignore them. Don't click links people send you via instant message, and don't install programs people send you via these systems either.
Major Database Compromises
Even if your computer is totally secure, and you know everything there is to know about computer security, you still may fall victim to this type of attack. Here, the malicious user steals your information from another computer system, such as a corporate database for an internet retailer.
The best way to protect yourself here is to guard your personal information. If some company wants to know your name, mailing address, phone number, etc, and they are forcing you to provide it even though the service they are providing doesn't require it - make something up. Come up with a 'false internet' identity, complete with a name, address, telephone number, zip code, etc. Save it somewhere on your computer, and provide that info instead.
Sometimes you need to put your real information into a database. You should still do everything in your power to protect that data. For instance, if a retailer has an option to save your credit card information, decline. If you are only ordering once, try to find an option to not create a profile on the site. The less your information is stored, the better.
Conclusion
I hope this short guide has given you some of the basic tools you need to understand common threats on the internet today. The security threats that we face on the internet are changing rapidly, so keep your education fresh and up to date to be aware of the latest threats and how to respond to them.
The security of your personal information and your personal computer is your responsibility. Take it seriously!
Last edited:




