CIS 105 week 3 discussion

profilechales31
cis105_week3eactivity.pdf

Search ZDNet

US EditionUS Edition TopicsTopics Log InLog In

MUST READ:MUST READ: BlackBerry acquires Secusmart, ups voice security anteBlackBerry acquires Secusmart, ups voice security ante

Topic: Security Follow via:

Follow Follow @kenhess@kenhess

10 security best practice guidelines for consumers Summary: Consumers need to proceed with extra caution to avoid scams, viruses, social engineering attempts, privacy-leaking apps, and malicious software of every flavor. These guidelines will keep you on the straight and narrow.

By Ken Hess for C onsumerization: BYOD | March 5, 2013 -- 22:55 GMT (14:55 PST)

Yesterday's "10 security best practice guidelines for businesses" outlined some good advice for businesses to avoid security problems by implementing some industry standard hardw are, softw are, and common sense. Now it's time for you, as a user — corporate or otherw ise — to take your share of the responsibility for security on any device that you use or have control over. Just because a device (computer, mobile phone, tablet) is ow ned by the company you w ork for doesn't relieve you of your responsibility for security for that device. Negligence is never a good excuse. And after you read these 10 guidelines, you'll never be able to claim ignorance again.

Educate yourself on these 10 security best practice guidelines for consumers (you) so that you can keep your data private and your job secure. These 10 guidelines are in no particular order.

1. Always use antivirus software on your personal devices: There are several free ones and multiple subscription services to keep your computer virus free. Dow nload and use them. Don't turn them off because you think it makes your computer run slow . Leave them on and stay protected. Upgrade your device if you think the antivirus program slow s it dow n.

2. Always use a device firewall: A personal or operating system firew all is an excellent line of defense against malicious softw are that attempts to connect out to its home server. You'll receive a w arning w hen an attempt is made, and you can optionally block the communication. Blocking the communication w on't remove the infection, but it w ill render it mostly harmless, especially if it is one of the many "logger" infections that grabs your data as you type it into w ebsites or client softw are.

3. Keep your operating systems and software up to date: Yes, it's a pain to update your apps and operating systems up to date because doing so often requires a reboot. Your device w ill react slow ly w hile the device updates, but it's for your ow n good. Take a tea break, w atch an old episode of The IT Crow d or take a w alk until your updates have finished.

4. Never download pirated or cracked software: This type of softw are almost alw ays includes some type of malw are. Plus, it's illegal to steal softw are, so there's that aspect of it. If you're using a corporate computer and you dow nload pirated softw are onto it, you're jeopardizing your job because your company can get into big trouble for harboring pirated softw are.

5. Don't click on popup windows that tell you that your computer is infected with a virus: Antivirus softw are doesn't w ork that w ay. Those popups install malw are onto your computer, w ith your permission. Sometimes it's a scam that requires you to pay money to have the softw are removed by the softw are originator. Don't fall for it. Don't pay them to remove it if you've done it. Look up online how to remove the malw are yourself.

6. Be careful with email attachments: Not all email attachments are harmful, but unless you're expecting an attachment from someone you know , don't dow nload or open it until you're sure it's OK to do so. If it's from someone you don't know , delete the email or identify it as spam. Do not dow nload or open the attachment.

7. Don't use public wi-fi hotspots without using a VPN (secure) connection: This is alw ays true if you're a corporate user. Do not connect to a public w i-fi unless you do so through a VPN. A VPN w ill encrypt your communications to and from the internet so that anyone w ho might be eavesdropping can't steal your information.

8. Use passwords on everything and be sure that they're strong passwords: Do not use the same passw ord for everything. Do not use easy-to- guess passw ords. Use strong passw ords that are at least eight characters in length and include capitals, numbers, and alternate characters. Passw ord protect everything: Devices, email, VPN, anything that you don't w ant shared w ith others. Be paranoid and change your passw ords often.

9. Beware of what kind of information you share on social media sites: Everyone loves Facebook (not me) and you probably place photos on it, have conversations on it, play games on it and attach all kinds of other apps to it. And by doing so, you put your privacy at risk. There are companies that scan these sites and collect data on you. They collect data on you from public records sites, social media sites and from sites that deliver malicious payloads to your devices. Keep private information private. Never use social media sites at w ork. Doing so can compromise your company's data or defame their reputation.

10. Review your online accounts and credit report: You should review your bank accounts, auction accounts, and mobile phone accounts for signs of fraud or charges that you didn't make. There are companies that send text messages out to scam you into responding and then charge you for doing so. Don't fall for it. You should also check your credit report annually to combat any fraudulent additions. Entries are too easy to put onto your credit report and very hard to take off. W atch yours carefully and take steps to remove errors as soon as possible.

I could potentially offer up another 10 of these consumer guidelines, but no one w ants to read 20 things, so I'll save them for another post.

Get the ZDNet Security new sletter now

CommentsComments 77 VotesVotes 22 more +more +

co nve rte d by W e b2P DFC o nve rt.co m

T alkback

Log in or register to join the discussion

password advice IMO needs updatingpassword advice IMO needs updating

"Use strong passw ords that are at least eight characters in length""Use strong passw ords that are at least eight characters in length"

I'd go for 10, 12, or even more. Eight w as sufficient some time ago, but I don't think that's really the case anymore. I'm pretty sure eight can beI'd go for 10, 12, or even more. Eight w as sufficient some time ago, but I don't think that's really the case anymore. I'm pretty sure eight can be brute forced.brute forced.

Follow Follow @kenhess@kenhess C ontactC ontact DisclosureDisclosure

I w ill give you this one bonus guideline: Use discretion w hen answ ering questions via phone calls from reader service cards that you've filled out or "contests" that you've entered. Many of these contests that you see in malls or online are scams to grab your personal information. The people on the phone are very nice and clever about the w ay they ask questions of you. They ask deeper and deeper personal questions because people love to talk about themselves. Doing so puts you at risk of identity theft.

Have you been the victim of some type of fraud or security compromise? Do you have any other guidelines you'd like to share? Talk back and let me know.

Related stories

'One fraud event a w eek': survey finds internal data breaches all too pervasive

Google opens up more about FBI requests for personal info

Java zero-day malw are 'w as signed w ith certificates stolen from security vendor'

Bew are! Anonymous has become the Hello Kitty of hacktivism

Topics: Security, Malware, Mobility

About About Ken HessKen Hess Kenneth 'Ken' Hess is a full-time W indow s and Linux system administrator w ith 20 years of experience w ith Mac, Linux, UNIX, andKenneth 'Ken' Hess is a full-time W indow s and Linux system administrator w ith 20 years of experience w ith Mac, Linux, UNIX, and W indow s systems in large multi-data center environments.W indow s systems in large multi-data center environments.

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

77 commentscomments

co nve rte d by W e b2P DFC o nve rt.co m

Ideally - go as long as possible, w here allow ed. Use pass phrases. The length of the passw ord is really your best protection. And yes, absolutely,Ideally - go as long as possible, w here allow ed. Use pass phrases. The length of the passw ord is really your best protection. And yes, absolutely, throw numbers, mixed case, and symbols into the mix.throw numbers, mixed case, and symbols into the mix.

And as if getting people to use good passw ords w asn't bad enough, w hat REALLY annoys me to no end is how many places actually make itAnd as if getting people to use good passw ords w asn't bad enough, w hat REALLY annoys me to no end is how many places actually make it impossible to use a good passw ord. I recently had a w ebsite refuse to accept a passw ord change because I used symbols. It w as pretty crazy.impossible to use a good passw ord. I recently had a w ebsite refuse to accept a passw ord change because I used symbols. It w as pretty crazy.

CobraA1CobraA1 6 Ma rch, 2013 00:126 Ma rch, 2013 00:12

Reply Reply 22 VotesVotes

Definitely agreeDefinitely agree

W hat also gets w eird is w hen they say "use symbols, but only use these specific symbols". W hat also gets w eird is w hen they say "use symbols, but only use these specific symbols". They just changed the company processing my oldThey just changed the company processing my old student loans, so I had to register on the new site. student loans, so I had to register on the new site. The passw ord requirements w ere 8-12 characters, at least 1 number...and then you hadThe passw ord requirements w ere 8-12 characters, at least 1 number...and then you had to have a symbol, but only certain symbols w ere allow ed. to have a symbol, but only certain symbols w ere allow ed. IIRC, they w ould allow "@" & ",", but didn't allow "#".IIRC, they w ould allow "@" & ",", but didn't allow "#".

[email protected]@... 6 Ma rch, 2013 12:046 Ma rch, 2013 12:04

Reply Reply VoteVote

Well,...Well,...

I don't set passw ord guidelines in apps or devices. I suggest "at least 8" w ith 8 being the bottom of the food chain for length. If I had said 10,I don't set passw ord guidelines in apps or devices. I suggest "at least 8" w ith 8 being the bottom of the food chain for length. If I had said 10, someone else w ould have had a problem w ith that.someone else w ould have had a problem w ith that.

khesskhess 6 Ma rch, 2013 13:296 Ma rch, 2013 13:29

Reply Reply VoteVote

@ZDnet: Please review VPNs@ZDnet: Please review VPNs

Please review free and low -cost VPNs suitable for personal use on laptops running W indow s 7 or 8. Please review free and low -cost VPNs suitable for personal use on laptops running W indow s 7 or 8. I w ould be very interested in such an articleI w ould be very interested in such an article and I imagine many others w ould be as w ell.and I imagine many others w ould be as w ell.

[email protected]@... 6 Ma rch, 2013 16:466 Ma rch, 2013 16:46

Reply Reply VoteVote

Thanks,...Thanks,...

I w ill do exactly that. See? Some of us read and listen. That's a great idea for an article. In the meantime, check out Banana VPN. I have usedI w ill do exactly that. See? Some of us read and listen. That's a great idea for an article. In the meantime, check out Banana VPN. I have used it and it's very good. http://w w w .banana-vpn.com/ It isn't all that cheap but it's so good that it might be w orth it. I've used it on my computerit and it's very good. http://w w w .banana-vpn.com/ It isn't all that cheap but it's so good that it might be w orth it. I've used it on my computer and my iPad.and my iPad.

khesskhess 6 Ma rch, 2013 16:566 Ma rch, 2013 16:56

Reply Reply VoteVote

application whitelistingapplication whitelisting

W hat are your thoughts on Application W hitelisting? And its potential to replace AV (especially on corporate machines)W hat are your thoughts on Application W hitelisting? And its potential to replace AV (especially on corporate machines)

david_fentondavid_fenton 7 Ma rch, 2013 18:577 Ma rch, 2013 18:57

Reply Reply VoteVote

co nve rte d by W e b2P DFC o nve rt.co m

WhitelistingWhitelisting

It's a good practice but I don't think it's a replacement for AV.It's a good practice but I don't think it's a replacement for AV.

khesskhess 7 Ma rch, 2013 22:137 Ma rch, 2013 22:13

Reply Reply VoteVote

Related S tories

BlackBerry acquires Secusmart, ups voice security ante

Internet of things big security w orry, says HP

Firefox adds anti-malw are file reputation service

The Apple backdoor that w asn't

T he best of ZDNet, delivered

ZDNet NewslettersZDNet Newsletters Get the best of ZDNet delivered straight to your inboxGet the best of ZDNet delivered straight to your inbox

Enter your email address

ZDNet Must Read News Alerts - US:ZDNet Must Read News Alerts - US: Major news is breaking. Are you ready? This newsletter has only the most important tech news nothing else. Major news is breaking. Are you ready? This newsletter has only the most important tech news nothing else.

Facebook Activity

Subscribe Now

Next Gen Firewalls barracuda.com/Firewall

Protect Your Business & Simplify. VPN, Web Filter, Anti-Virus & More.

Bitdefender Official Site Read Magic Quadrant Idm

co nve rte d by W e b2P DFC o nve rt.co m

White Papers, Webcasts, & Resources

Powerful Data Protection For Y our Virtual, Physical or Cloud Environment Dell AppAssure unifies backup, replication and recovery for your virtual, physical or cloud environment in one softw are solution. Test drive a complimentary trial of AppAssure today for a robust and simple data protection solution.

On-demand Webcast - ZDNet's 201 4 Cloud Priorities Research Presentation In case you missed it live, catch the on-demand presentation of ZDNet's latest cloud computing research. Bill Detw iler, Managing Editor of Tech Pro Research, unveils trends, use-cases, and attitudes driving cloud in business today.

Effective S ecurity in a BY OD Environment: Arming Y our Organization Against the Unknown Check out this w hite paper to learn how to secure your data and assets from malw are and theft - w ithout impeding flexibility.

Featured ArticlesFeatured Articles

WalmartLabs acquires e-commerce discovery community LuvocracyWalmartLabs acquires e-commerce discovery community Luvocracy

Avast Free Antivirus 2014Avast Free Antivirus 2014

LG G3 review: A superb flagship smartphone with a great displayLG G3 review: A superb flagship smartphone with a great display

In IBM and Apple's wake, has Android lost its enterprise chance?In IBM and Apple's wake, has Android lost its enterprise chance?

Around ZDNetAround ZDNet

TopicsTopics

Broadband Speed TestBroadband Speed Test

Events CalendarEvents Calendar

Meet the TeamMeet the Team

About ZDNetAbout ZDNet

Site MapSite Map

ServicesServices

Log InLog In | | Join ZDNetJoin ZDNet

MembershipMembership

New slettersNew sletters

RSS FeedsRSS Feeds

ZDNet MobileZDNet Mobile

Site AssistanceSite Assistance

© 2014 CBS Interactive. All rights reserved. © 2014 CBS Interactive. All rights reserved. Privacy PolicyPrivacy Policy | | CookiesCookies | | Ad ChoiceAd Choice | | AdvertiseAdvertise | | Terms of UseTerms of Use | | Mobile User AgreementMobile User Agreement

Visit other CBS Interactive sitesVisit other CBS Interactive sites Select Site

Sign Up Create an account or Log In to see what your friends are doing.

Samsung and Google provide more details on Knox contribution to Android L | ZDNet One person recommends this.

Huawei sees smartphone shipments rise to 34 million, narrowly misses first-half targets | ZDNet One person recommends this.

OS X 10.10 Yosemite preview: Welcome to infinite connectivity and seamless productivity | ZDNet One person recommends this.

Facebook social plugin

co nve rte d by W e b2P DFC o nve rt.co m