The OFFICIAL Unofficial Achewood Message Board
Trivial Pursuits => Science & Nature => Topic started by: Nabubrush on March 24, 2004, 02:58:09 am
-
So, here's the deal. Me and the sweetie got the old DSL setup at home just recently. It's the first time I've ever had that at home - I've only had dial up. You people know hella more than I do about computers and stuff of that nature, so what's up with the whole firewall thing? What do I need? In answering, if you act like I don't know a damn thing about computers, you can't go far wrong.
-
I don't know poop about firewalls either. But my broadband provider has given all the subscribers access to firewall and antivirus programs for free and they seem to work pretty well. I guess giving that away en masse is cheaper than dealing with the spammers and data miners and spyware and all that crap that is floating around. They gave us e-trust anti-virus and e-trust EZ Firewall. So to piggyback on the above question in a way, could some of you branier people tell me if running this stuff is a waste of time?
-
A good firewall is a good solution if you're sloppy on the internet, or if you're hosting a web site. Here's the secret nobody wants to reveal: If you're a careful surfer, you don't need a firewall.
Being a careful surfer:
- Don't give out your email address. Period. Set up a catch-all webmail account somewhere that's not related to an email address you download to your computer.
- Don't open unknown attachments. Don't read spam, even in the preview pane of your browser. If you don't know the address, or if the subject looks even a little bit skunky, skip it. If it's from somebody real, they'll email you again. If it looks too good to be true, it is.
- Block ads and popups with a good browser (http://www.mozilla.org/projects/firefox/) or plugin.
- Run an antivirus check daily, with "quarantine" and "alert" settings enabled. Update it at LEAST weekly, and especially when you hear news of a new virus making the rounds.
- Disable print and file sharing on your computer (google for instructions). These are two of the biggest security gaps in all of Windows, and I wouldn't trust either in any operating system without very specific permissions.
This is not to say that a firewall is worthless. If you aren't any of the above, you should install a good free firewall - reviews abound on the internet, and I like reading grc.com (http://grc.com/) for internet and Windows security news.
-
I want to think we use etrust AV at work and it seems to work okay. Paid firewalls are better and I know a lot of people who pirate stuff like BlackIce and Sygate Personal Firewall Pro but the free version of Zone Alarm is fine for most people.
-
A good firewall is a good solution if you're sloppy on the internet, or if you're hosting a web site. Here's the secret nobody wants to reveal: If you're a careful surfer, you don't need a firewall.
I won't 2nd that. There are several programs out there that just do port scans to try and get in. A decent router should stop it but I wouldn't rely on it. Plus the new witty worm can infect computers without the user doing anything (http://www.washingtonpost.com/wp-dyn/articles/A15760-2004Mar22.html). Clones will be on the way soon and you can be they'll be more advanced.
- Don't open unknown attachments. Don't read spam, even in the preview pane of your browser. If you don't know the address, or if the subject looks even a little bit skunky, skip it. If it's from somebody real, they'll email you again. If it looks too good to be true, it is.
Can anybody on the planet justify why the preview pane even exists? Using it is practically suicide yet it's on by default and most are ignorant of its dangers.
Also, depending on your client you can right click a message and view its source without actually opening it. This way you can skim the code for things like "Vi-ag-ra" or "hey, I'm on the Achewood board" without the danger of opening the message or running any associated scripts/attachments.
- Run an antivirus check daily, with "quarantine" and "alert" settings enabled. Update it at LEAST weekly, and especially when you hear news of a new virus making the rounds.
- Disable print and file sharing on your computer (google for instructions). These are two of the biggest security gaps in all of Windows, and I wouldn't trust either in any operating system without very specific permissions.
Agreed.
-
Cort, I haven't used a firewall in a couple years, and even with the missus on the PC a couple hours a day, I haven't had any incident. Let it be noted that I've been educating her - it started with how to get less spam, and Lesson Number One was "Drop all your old email addresses, and find a new one."
That said, is there a copy of that article somewhere which requires less than the forfeiture of all my Intellectual Property and Potential Offspring to view? How about you PM it to me?
Edit: Also, I don't know of a client other than Outlook Express (often bashed, but a fairly good client and much more secure than regular Outlook) that will allow one to view the source of a message without first opening it.
Also also, I've got a feature in Thunderbird (http://www.mozilla.org/projects/thunderbird/) (doesn't seem to be an extension) which allows me to view all messages as plain text, simple HTML, or original HTML - either of the first options disables any remote files (such as scripts or web bugs) and most, if not all, formatting. This is a good way to use the preview pane. I don't have to open a new message window to read a message, and it's safe in either case. I do wish I had some mappable keyboard shortcuts, though... *grimace*
-
It is true that you can get by perfectly happily without a firewall. But the moment you install one, you will get a note saying that an unknown IP has tried to access yours. This is not good. And happens many, many, many times an hour.
Various machines out there are trying various ip's, and yours will come up now and then. Maybe nothing comes of it, but it is best to be safe.
Just get ZoneAlarm and install it. It takes you through everything, is very easy to use, and will stop anything getting access to your machine.
Best of all, unlike BlackIce who are in bed with Microsoft, you can tell ZA not to let Windows access the internet if you like. This allows you to stop various programs talking to home.
It's also free (the free version that is).
Zone Alarm (http://www.zonealarm.com)
I haven't had anti virus software installed full time. Ever. I install it when I want to check a file, but I have never succumbed to a virus, or trojan, because I know how not too. The same however cannot be said of port attacks, since you have no control over them.
You may get by without any trouble Choop, but it won't, and can't last indefinitely. The laws of inevitablity say so.
-
Cort, I haven't used a firewall in a couple years, and even with the missus on the PC a couple hours a day, I haven't had any incident. Let it be noted that I've been educating her - it started with how to get less spam, and Lesson Number One was "Drop all your old email addresses, and find a new one."
That said, is there a copy of that article somewhere which requires less than the forfeiture of all my Intellectual Property and Potential Offspring to view? How about you PM it to me?
Edit: Also, I don't know of a client other than Outlook Express (often bashed, but a fairly good client and much more secure than regular Outlook) that will allow one to view the source of a message without first opening it.
Sorry, I forget people who don't live around here don't use the Post as the default news source. Plus until recently they only required a username, gender, and ZIP code. Try this (http://zdnet.com.com/2100-1105-5177292.html).
I'd love to use Thunderbird but it work work with my hotmail account (which I use as my "fake" e-mail for things like message board registration). And even OE is more secure than actually using the web interface (http://zdnet.com.com/2100-1105_2-5178155.html).
I agree with what slink said. Although my computer is never off so I'm more vulnerable.
Oh, and make sure to disable Windows Messenger. Most firewalls will protect you but you should be sure.
-
So, here's the deal. Me and the sweetie got the old DSL setup at home just recently. It's the first time I've ever had that at home - I've only had dial up. You people know hella more than I do about computers and stuff of that nature, so what's up with the whole firewall thing? What do I need? In answering, if you act like I don't know a damn thing about computers, you can't go far wrong.
Home, Personal, Software based firewall:
www.zonelabs.com, download and install the FREE zonealarm. you can buy the other versions later, if you want, but the Free Version is about all you should need unless you get wicked fancy down the line.
this program will work, and it's free, and they do updates when they find problems (supposedly). why do i mention that? becuase there have been stinks about other companies NOT doing updates to their app when flaws were found, vis. Black Ice Defender a couple of three years ago.
Now, Black ICe, Mcafee, Norton, they may have great products, but, i've either heard bad things about them, or i've gotten confused by their programs (i'm a professional. i've always felt that if a company's program is confusing _me_, then i'm going to have a hard time recomending it to my customers), or they cost money.
black ice- a couple of three years ago or so, there 'twas a HUGE stink about flaws that they denied (a la Real Netowkrs saying "spyware? huh?") existed and may or may not have ever fixed. current version may be fine, but i say let 'em go out of business if they're going to lie to their customers.
McAfee- haven't tried their product. supposedly they are the bastard responsible for taking Signal 9's PC Conseal off the market (best. personal. windows. firewall. ever. (imho...)) by BUYING them and "incorporating" their product into McAfee's. well, i don't think so, but anyways. i found the interface horrid and confusing and had to rely on my trust for McAfee knowing what's best so i caulked the hole in the cd and dumped it in the rubbish.
Norton's product- inernet something something. usually get's bundled with a copy of NAV. it's ok, but it seems less functional as a firewall than zonealarm, and it costs like 50-60 bucks.
ok, some of the above products, norton, come with other poducts, like AV software, popup blockers, etc, and it might seem a good idea to get them for the other stuff. i wouldn't recommend it. stick with zonealarm. as a software firewall.
another thing-
installing a firewall on yor pc does NOT IN ANY WAY SHAPE OR FORM protect you. the default settings are just that, default. if you install it and just start clicking, you may or may not be opening up holes, etc.
you really need to understand what it is you are doing, and how to do it.
now, you said "if you act like I don't know a damn thing about computers, you can't go far wrong". ok, fair enough. and honestly, you shouldn't HAVE TO understand firewalling to put your _Personal_ Computer on the internet, but that's a different rant.
now, when you go online, your connection get's assigned an IP address. this is _similar_ to a mailing address. except that the address is for a big apartment building, with tons of different apartment numbers. those are Ports. for instance, if i send you a letter to you at 1234 North Street, Somewhereville, NY, 55555, the letter will get to your BUILDING (ip address / pc), but it won't get to your mailbox. So, i have to address it to Apt 12987, or the specific PORT number on your PC, like port 10876.
why the ports? well, because you might open up email and 6 browser windows and icq and who knows what else, all at the same time. so when the data gets back from all those servers to your PC, your PC needs to know which program gets what data. hence port numbers.
now, in the "good old days" you really needed to know port numbers, etc.
but with Zone Alarm, and several of the others, instead of dealing (mostly...) with Port numbers, it deals with which APPLICATION you want to be able to listen to the internet.
so, when you open Zone Alarm up, and run it, and THEN open your email program, Zone Alarm will ask "hey, do you want this to listen to the internet?" rather than pop up and say "hey, do you want to allow outgoing port 110 connections to bind to temp port 11,832?".
but, and this is why i said "you really need to understand what it is you are doing, and how to do it." if you tell zone alarm or black ice or any of them, "hey let me be wide open, or let this program be connectable from anywhere, etc" it WILL DO JUST THAT!
now, depending on what version of windows you are running, running zone alarm is going to offer you a TON of confusing questions (do i have to allow "services an control app" internet access?). just remember, if you don't check "remember this answer" on the pop up box, the next time you reboot, it will ask you again. so, if you don't know, tell it no.
also, you can go into the zonealarm and check the list of things you have allowed and disallowed, and make changes.
um, i hope this helps.
-
Well, I'll be home in a week and I'll try that. We'll see if we have the internet back - we've had nothing but problems with Qwest, so who knows.
-
Sometimes I wish ZA had the option to let you fiddle with the ports individually. Like when I changed the ports eMule uses I couldn't get ZA to let it through until I deleted it from the list then totally re-authorized it. Had ZA just let me see the port options I could've just switched 4662 to 5555 or whatever by myself.
Otherwise I found that ZA is actually set up really well for the average user "out of the box"
-
Amen to ZoneAlarm, for all the aforementioned reasons.
That is all.
-
Sometimes I wish ZA had the option to let you fiddle with the ports individually. Like when I changed the ports eMule uses I couldn't get ZA to let it through until I deleted it from the list then totally re-authorized it. Had ZA just let me see the port options I could've just switched 4662 to 5555 or whatever by myself.
Otherwise I found that ZA is actually set up really well for the average user "out of the box"
i don't know if "pro" version allows anything different, but i definitely agree with you. given that they're binding the app to the ports and tracking it, it would seem to be "trivial" to me (i am not a programmer, hence it most likely would not be "trivial") to add another option in the applications menu wherein you can fiddle with the app-specific settings.
on the flip side, I have a "test" for computer related things. i call it "would i try to get this to work for my mom?". if the answer is no, then i usually don't suggest that solution to people who don't want to call me often. if the answer is yes, then i, um, suggest it to people.
CortJstr, if you ever come across a copy of Signal 9's PC Conseal, i'd recommend it to you. it's learning curve is astronomical compared to the point and click of ZA, but it's entirely customizable with a text editor. on the flip side, it got bought out by McAfee 3-4 years ago or so, and i'm not really sure how well it would operate with the differences in win2k & Xp's network stacks as opposed to nt4/win9x. i think i remember it running ok on win2k, but can' be sure.
-
I would highly recommend against using either Windows XP's built-in firewall OR McAfee Firewall - they cause more trouble than they solve.
The best thing to do is to have your Cable/DSL modem go straight into a hardware firewall and then into a network switch.
The entire solution costs about $250, but it's well worth it.
-
There are several programs out there that just do port scans to try and get in. A decent router should stop it but I wouldn't rely on it.
Interesting. I've got three PC's sitting behind a Netgear MR814 (http://www.netgear.com/products/details/MR814.php?view=hm) at home. I've questioned the real need to go behind a software firewall as well.
Am I hiding behind the equivalent of a candy-filled toy* here? Do I really need to 'double-bag' my home junk?
*credit to FJ for that phraseology
i was going to yammer on about hardware based firewalling up there, but then my hand cramped and i realized the audience [that exists in my head] had "fallen asleep" a la the passenger next to guy in Airplane.
ok, first off it's sort of a misnomer to call a NAT box a firewall. in it's strictest sense, unless you are logging you aren't firewalling. in the loose sense of trying to keep the "fire" on the other side, NAT boxes are.
NAT is great, and when used correcty, it is wicked hard to counter. but, if you ask for it, it will let you do anything dumb you want to.
Asherdan, if i find your public IP, and you are behind NAT, and running an un-secured OS like XP with no patches, or linux with all kinds of random unneded services bound, it is no longer Trivial for me to "do bad things to you". without NAT or firewalling of some sort, "all your boxen are belong to us".
with NAT, however, unless there's a specific exploit for the Firmware your router is running, and unless you have horribly misconfigured your router (such as setting your PC as the "DMZ" point), it is quite difficult (read that as: i'm sure there's a way to, but i don't know of any specific way) to exploit your NAT.
However, if you were to run an application that OPENS a NAt'd connection trhough your router, well, then all bets are off.
the same, however, goes for say running Zone Alarm and clicking "ok" to all the "are you sure" pop-ups. if an app get's on your system, and you run it and tell your "system" that it is a "good thing", and that app is compromised (read- virus, trojan, malware, etc) then all bets are off.
this is why, even though i'm behind a Nat'd mess right now, i'm running zonealarm. because, if my NAV software misses an update, or i do something stoopid like open an unknown attachment, etc, the NAT box is going to let the outgoing connections go, because that's what it's _supposed_ to do.
With ZA, though, if i have a rampant app on my system, it _should_ be detected by me, because ZA is going to keep asking me if i want to let "new-random-app.exe" have access to the net.
So, by using both HArdware NAT, and Software Rulesets (ZA in this case) i can be somehwat prudently sure that i'm somehwat secure.
Throw in AV software that i update religiously (set to autoupdate, and updated everytime i turn the PC on in the morning), and Malware Detection Tools (such as Spybots Search and Destroy & ADAware) that i update and scan with, and you have a _reasonably_ secure Personal Computer.
If it's not Personal, though, all i've said is a bunch of BS.
Anyways, the key with "security" is how prudent do you want to be, because in the end, there's _always_ going to be away for your system to be compromised (worst case, search and seizure warrant...).
-
Well, I'll be home in a week and I'll try that. We'll see if we have the internet back - we've had nothing but problems with Qwest, so who knows.
you have dsl, your modem, is it an internal modem (a card that was inserted into the computer) or an external modem?
if external, is it USB, or Network-based (network- the cord plug would look like an extra wide phone cord plug, usb- the cord would look nothing like a phone cord plug.)?
-
I would highly recommend against using either Windows XP's built-in firewall OR McAfee Firewall - they cause more trouble than they solve.
The best thing to do is to have your Cable/DSL modem go straight into a hardware firewall and then into a network switch.
The entire solution costs about $250, but it's well worth it.
i'm curisous as to where you get the $250 approximation? are you including the price of a network-based cable/dsl modem?
i've never been a fan of "walmart el-cheapo" stuff, but the "Netwok Everywhere" "brand" at walmart herebouts is simply rebranded Linksys with less support. a Nat lan to lan router with 4 port hub or switch (can't remember) is ~~ $50 or so.
have them in use at a couple of places, and they are definitely not bad as a SOHO device.
i completely agree, though, that having a network-based modem and a router is generally better solution, especially from a troubleshooting standpoint or making changes to the pc down the line, etc.
-
i'm curisous as to where you get the $250 approximation? are you including the price of a network-based cable/dsl modem?
No. People usually either rent them month-to-month or buy them upfront - so I'm not including the hardware that they've already purchased in my estimation.
Figure about $50 for a decent 4-port switch, and about $200 for a decent hardware firewall (sometimes you can get a combo firewall/router/switch but I recommend against it).
You could probably get the firewall cheaper, but again, I wouldn't recommend it.
-
If you want to check out your own PC to see if you have open ports or vulnerabilities, check out http://grc.com (and click on "Shields Up!").
You can do all kinds of useful scans and probing from that site, and at least will know if you have ports that are open.
-
There are several programs out there that just do port scans to try and get in. A decent router should stop it but I wouldn't rely on it.
Interesting. I've got three PC's sitting behind a Netgear MR814 (http://www.netgear.com/products/details/MR814.php?view=hm) at home. I've questioned the real need to go behind a software firewall as well.
Am I hiding behind the equivalent of a candy-filled toy* here? Do I really need to 'double-bag' my home junk?
*credit to FJ for that phraseology
Run Shields Up! as Jough recommended. If you get a perfect score (total stealth) then you're probably okay. Unless you also game online or use any P2P software. Because to use them you have to tell your router to open certain ports no matter what comes through.
A software firewall like ZoneAlarm sets up a 2nd line that makes sure that only the programs you specified can talk and/or listen on those ports. This way eMule can accept traffic on port 4662 but some random virus/worm probing your computer on 4662 will be stopped by ZA.
Oh, and totally run Ad-Aware and Spybot S&D at least monthy. More if you do high risk stuff (like P2P).
-
OK.
Erm, lots of activity here.
BlackIce, as I mentioned above, got in bed with Microsoft. So you can't assume that you can block certain things that MS don't want you to. Which sucks!
As for port tweakage, Zone Alarm pro does let you. The new versions of Pro are actually very good, and I find preferable to hardware firewalls, which by their very nature suck. I was having various problems with freeing up individual ports for certain purposes and found the new version of Pro let me do so, with, well I won't say ease for most people.
Oh, and as for Outlook, since I don't know if this was addressed... It's dangerous too. I don't know how well they fixed problems with it, since well, it's MS, but the preview pane and the lack of real options allow it to selfrun macros through HTML emails. This is not good.
I stuck with Eudora, since it allowed text only email (all you should need, though I'm a utilitarian geek), for years, until switching to Thunderbird recently.
More info may be needed on the Outlook issues, since I knew of this problem a year or so ago, and have just laughed at the idea of using it ever since. And this is Express I am talking about at any rate.
-
Oh, and for the love of god, no matter what e-mail client you use, disable the "preview" pane. It pretty much just lets scripts run on your computer just by "previewing" the message.
-
It pretty much just lets scripts run on your computer just by "previewing" the message.
And regardless, it's ugly as hell and totally anti-good-UI-practice!
Apparently it was the use of Outlook and the preview pane that caused Valve to let keyloggers at their system and thus free up the possibility of cracking.
But still, the issue with Outlook wasn't fixed like this. It could essentially, at one point at least, have macro scripts run in stealth.
-
I don't believe Thunderbird's preview pane ("Message pane") allows any scripting to process. By all means, though, only open it when you're focused on a message you believe to be safe to read. And activate the Junk filters, and train them (by marking any junk or virus-looking mail as junk).
-
I don't believe Thunderbird's preview pane ("Message pane") allows any scripting to process.
Indeed, as far as I am aware, it is safe. And it would certainly be an anomaly* on the part of the Moz Foundation to leave such a glaring and obvious error present in their software, particularly when designed from the groundup so recently.
*This of course, does not apply to the slackwristed, assmonkeys at Microsoft.
-
Moz Foundation
hehehehe.
-
Moz Foundation
hehehehe.
Yeah, don't you just love the mental image of Morrissey coding away furiously for the safety of our computers?
</tangent>
-
CortJstr, if you ever come across a copy of Signal 9's PC Conseal, i'd recommend it to you. it's learning curve is astronomical compared to the point and click of ZA, but it's entirely customizable with a text editor. on the flip side, it got bought out by McAfee 3-4 years ago or so, and i'm not really sure how well it would operate with the differences in win2k & Xp's network stacks as opposed to nt4/win9x. i think i remember it running ok on win2k, but can' be sure.
I'd heard that PC Conceal was a god among firewalls but that MacAfee claimed they aquired it to integrate into and improve their own product. But in reality they just wanted the competition gone because the code bases were so different integration was impossible.
This was in Eric Szulczewski's column, the same place the Sygate firewall was recommended and a source of techological and political blatherings that would make James Lileks plead for mercy.
-
Well, I'll be home in a week and I'll try that. We'll see if we have the internet back - we've had nothing but problems with Qwest, so who knows.
you have dsl, your modem, is it an internal modem (a card that was inserted into the computer) or an external modem?
if external, is it USB, or Network-based (network- the cord plug would look like an extra wide phone cord plug, usb- the cord would look nothing like a phone cord plug.)?
Well, I haven't actually seen it because I've been at work, but it's definitely external, and I'm 95% sure it's network-based.
Also, you people may know too much, because this is mostly way above my head. I'm hoping at the end of this someone will boil this down to a simple, three-step procedure for me.
-
0) Step 0 is stuff you should've been doing on dial-up anyway: have a virus scanner and update it frequently, use Windows Update (and Office Update, if you have MS Office), don't use the preview pane in e-mail programs, don't use IE if you can help it, and don't open strange attachments or lick people with open wounds.
1) This depends on if you have a router and if so, what brand.
2) Download the free version of ZoneAlarm (http://www.zonelabs.com) and install it.
3) Go to www.grc.com and click "Shields Up!" on all ports. The test should come back green and happy. If not come back here for further advice.
-
Green boards on all tests, according to those folks it's stealthy around here.
Inviso High Five!
::smack::
w00t!
-
I'm happy to report that this OLD machine with the EZ Firewall supplied free by my Cable Company is also all green and happy. Which makes me all green and happy.
-
I'd heard that PC Conceal was a god among firewalls but that MacAfee claimed they aquired it to integrate into and improve their own product. But in reality they just wanted the competition gone because the code bases were so different integration was impossible.
they probably couldn't figure out how to use it...
and to add my "me too":
- outlook & outlook express are horrid security nightmares. that said, i've run outlook/outlook express for a long time. keeping up to date with AV updates, OS updates, and application updates plus disabling preview pane AND running something like zone alarm that's going to yell if something goes rampant AND generally being able to "keep an eye" on my system has allowed me to not (to my knowledge.... and that's nightmare inducing in and of itself) get infected/compromised. And the fact that i have to list those caveats is the best reason i can think of NOT to use Outlook or OE. Eudora is gem. not sure about Mozilla stuff, last time i screwed around with that "stuff" was Netscape 4 on a mac. *shudder*. Webmail systems (as much as i hate hotmail) are great in certain circumstances.
- if you are running a MS Windows OS, do your windows updates religiously.
- if you are on the internet, budget $50/yr for Antivirus Software. (and to drift further... how "hide under the bed and whimper" frightening is the idea of MS "integrating" AV in future OS releases???? agree with whoever said "XP's firewall is horrid", it's better not to use anything than to falsely _rely_ on it to do anything to protect you. )
- thunderbird's preview pane. i have no experience with thunderbird. i should, but that's a long story. it very well might be "safe", but given that it runs on top of an unsecured OS, and the fact that i personally don't like preview panes, and that to me preview pane screams "the application will now be doing things without you telling it to, so sit back and relax, we know best", i'd still be and would be and will be leery of it. dependent upon how it interprets html, etc, or any scripting language or non-text only content i just am not sure what the app is going to allow to be passed onto the OS, which again has many flaws.
- i highly recommend the combination of lavasoftusa.com's AdAware and Spybots Search and Destroy, not just for the anti-spyware detection, but for the anti-malware detection. I've had AV software go "wonky" and not detect klez variants, etc, and the anti-malware combo detect it and remove it. it's free, it's a great additional piece of mind.
- P2P apps etc, and being "safe" by using a firewall. whenever you are running somone else's App, you have to trust that they know what they are doing AND that they have your best interests at heart. witness Kazaa, with embedded spyware. ok, so you use Kazaa Lite, no spyware. but, who are these people, and what does their application REALLY do? At some point paranoia will stop you from being able to use your computer, which is counterproductive to using your computer safely.
but, it's important to never say "oh, i'm doing X, Y, and Z, there's NO WAY that i'm infected, compromised, etc." there's always a possibility that some new problem has occured, and if your system is acting wonky, pay attention to it.
-
- if you are on the internet, budget $50/yr for Antivirus Software. (and to drift further... how "hide under the bed and whimper" frightening is the idea of MS "integrating" AV in future OS releases???? agree with whoever said "XP's firewall is horrid", it's better not to use anything than to falsely _rely_ on it to do anything to protect you. )
$50/yr?!
Supposedly the firewall will actually somewhat functional in this summer's SP.
- thunderbird's preview pane. i have no experience with thunderbird. i should, but that's a long story. it very well might be "safe", but given that it runs on top of an unsecured OS, and the fact that i personally don't like preview panes
90% of the security of Thunderbird/Firefox is because they don't support ActiveX. Granted that's what a lot of malware relies on but there are still enough other sneaky tactics out there that I say No Preview Panes Period is a good rule.
- P2P apps etc, and being "safe" by using a firewall.... witness Kazaa, with embedded spyware. ok, so you use Kazaa Lite, no spyware. but, who are these people, and what does their application REALLY do?
Safe here is just a relative term. Running a decent P2P client like bitTorrent or eMule with PeerGuardian, Ad-Aware, SB S&D, an AV, and ZA isn't totally safe but it's the safest you can be. It's like wearing pads and headgear while wrestling. You're doing something inherently dangerous but taking all reasonable steps to lower the risk level.
-
Personally, I've always been fond of You Are the Woman (That I've Always Dreamed Of...), although Just Remember I Love You is pretty OK too.
-
$50/yr?!
well, i pimp the hell out of NAV, Mcafee pissed me off in 97/98 or so with it's near impossibleness to update, but i'm sure it works i just hate it. i'd assume it's about the same price as nav. f-prot, i liked, but haven't used in a long while. the other ones, i dunno, i just don't trust 'em. avg free is better than nothing, i guess.
what do you use and what do you recommend?
Supposedly the firewall will actually somewhat functional in this summer's SP.
i'm assuming this is one of those comments that in real life i would raise my eyebrow to and you would chuckle.
Safe here is just a relative term. Running a decent P2P client like bitTorrent or eMule with PeerGuardian, Ad-Aware, SB S&D, an AV, and ZA isn't totally safe but it's the safest you can be. It's like wearing pads and headgear while wrestling. You're doing something inherently dangerous but taking all reasonable steps to lower the risk level.
amen.
-
Supposedly the firewall will actually somewhat functional in this summer's SP.
You trust what they say is functional?
Eeek!
If I don't trust BlackIce for their partnering with MS, I'm sure as hell not oging to trust MS themselves.
Plus, I still haven't dared try XP again. It was too scary for my utilitarian sensibilities.
As far as server I run Apache, so IIS can go fuck itself, and as for the whole media player fiasco of late - who hasn't switched to Media Player Classic, found at sourceforge.net?
-
well, i pimp the hell out of NAV, Mcafee pissed me off in 97/98 or so with it's near impossibleness to update
...
what do you use and what do you recommend?
I left McAfee for the same reason. I use Norton simply as the default alternate. But I'm confused because the main program costs like $50 but subscriptions are only like $10 last time I checked.
Supposedly the firewall will actually somewhat functional in this summer's SP.
Read "somewhat functional" as "not actively destructive." Having the current wall on actually hinders your connection and stops P2P's from connecting. I've heard from a couple sources that the Service Pack 2 version isn't a good (or even adequate) firewall but it also doesn't actively screw up your connections.
who hasn't switched to Media Player Classic, found at sourceforge.net?
This confused me. All versions of windows come with Media Player 6.4 still hidden (run "mplayer2" sans quotes) so how is Media Player Classic different?
Yesterday I decided to try out BSPlayer (http://www.bsplayer.com/) based on this (http://www.411mania.com/black/columns/article.php?black_id=186) recommendation but I haven't had a chance to install it yet.
-
This confused me. All versions of windows come with Media Player 6.4 still hidden (run "mplayer2" sans quotes) so how is Media Player Classic different?
Well. Newer version of Media Player suck nastily (anything post 6), so they are best avoided. And Media Player 6 has negatives.
Media Player Classic is faster, more stable and less hassle than mplayer2. It isn't embedded in Windows which always helps!
It supports playlists and has many options not available in your normal player.
Take a look here (http://sourceforge.net/projects/guliverkli/)
The other thing I was going to address, is a warning about Norton.
Don't let it try to fix a hard drive. If you ever have a bad sector show up in Norton, do not let it do anything about it! I have watched both Mac and PC Hard Drives destroyed because of Norton fuck*ng about with them, in various versions of Norton. This is the sole reason I have never used Norton.
I know you can run only AntiVirus, but I don't trust a company who have killed so many HD's around me!
And of course for DVD's NVDVD (easily cracked) kicks everything elses ass.
-
I left McAfee for the same reason. I use Norton simply as the default alternate. But I'm confused because the main program costs like $50 but subscriptions are only like $10 last time I checked.
hmmm. the last couple of re-subscribes customers have tried have been approx 30bucks. regardless, though, my statement "i recomend budgeting $50/yr for AV if you are on the internet" is a budget. if you can find NAV for 15bucks, grab it, ya? often times staying a release behind can be far cheaper.
and, resubscribe online, great for a version or two, but after awhile nav2k1 just doesn't cut it, ya know waddimean? i'm not a big fan of the online AV subscribes, because i've seen people get sooo pissed after they've formatted and not had tth cd. YMMV obviously and all that.
who hasn't switched to Media Player Classic, found at sourceforge.net?
me. i use an old winamp.
-
me. i use an old winamp.
I am talking for divx purposes here.
I use Winamp for audio, unless mixing in which case I use the old version of DJS that allows individual apps assignable to whatever soundcard I wish.
Anything but Winamp just doesn't cut it for typical music use, but it just doesn't do for movie files for me. Not even the newer plugins and versions that support video. Too clunky for video.
-
I just installed the BSPlayer and it's dandy. Support for lots of formats, comes with 5 dandy full-mod skins and damned near every fuction allows you to customize two shortcut keys (and "out of the box" almost all the keys are the Winamp defaults). There's a dandy desktop mode in addition to full screen, about 700 video output options, and image capture in two sizes (full or WhatUSee).
The only three complaints I have are there's no FF or rewind buttons in the GUI (although changed the shortcuts to right/left works nicely), there's only one FF speed, and the seek bar is bit touchy.
Only the whole it shames everything else I've used.
-
Sorry to bump a thread from 2004,
but damn, this bears repeating
---------> everyone running Windows should install zone alarm. <----------
here's a review of zone alarm:
http://download.cnet.com/ZoneAlarm-Free-Firewall/3000-10435_4-10039884.html
I'm cocky, so I always assumed that since I know what the hell I'm doing, I can be fine with a NAT router (aka "firewall")
I've got years of experience doing tech support for Windows, Macintosh, Unix, Dos...
but no dice. Even I need zone alarm.
One thing to consider is that any computer on your local network is a potential threat to you. So if a friend comes over and borrows your internet with their laptop, malware on their laptop could potentially hack into your computer. It's possible to configure some cheap routers such that all the computers on your network are firewalled from each other, but this is too technical for most people, and you wouldn't want to do this anyway in many situations because it would render useless, for example, your ethernet-connected printer.
and anyway, every friggin week, literally, Microsoft is releasing a patch for some security vulnerability that could let someone take over your computer remotely...
and besides... we install so much damn software on our computers these days that it's hard to say for sure that we can trust all the sources of all this software. The other day I installed the 10 most popular video players on my computer, trying to get a stubborn DVD to play... Can I say with absolute certainty that all of these programs are made by trusted people who didn't slip up and on purpose or on accident let some malware get into their product? No...
As for anti-virus programs... forget about them... Sure, run spybot. It's free, and to be FAIR you should even donate a little bit to them if you use them, but come on... there is no need to pay for commercial anti-virus software. The companies that sell anti-virus software can not be trusted, and some of their products even qualify as malware / spyware.
This article explains more clearly than anything why no one should patronize the anti-virus companies:
http://www.wired.com/politics/security/commentary/securitymatters/2005/11/69601
Long story short, I was browsing my router logs for no particular reason, and I noticed that MY computer, not my roommates, but MY computer, while I was sitting there running no programs, had made a call to some IP using a pretty odd looking port number.
So I look up that port, and it's not referenced in the wikipedia list of ports... okay... so I do a reverse DNS lookup on the IP, and it's some friggin' cable or DSL modem in some other state.. I'm like... damn... I know I have no reason to talk to someone on a comcast connection... any kinda servers that any mainstream software products are talking to would probably be behind something a little more high end than that, right? Maybe?
So I am a little concerned so I download and install zonealarm, something I've never done before, and upon the first reboot, it tells me that this and that program want to talk to the internet.. Well I told zone alarm to block literally half these programs, because they were programs that I use once in a while, but I don't want them using my internet bandwidth all the time like that, however small amount they may use, and more importantly, I don't want them sucking my CPU on boot. If they think there's no internet connection, maybe they'll calm the fuck down every time I boot up. The next time I want to check for an update to those programs, then I'll enabled them in zone alarm. Or I'll download the update manually.
so anyway, zone alarm next proceeds to tell me that vservice.exe wants to talk to the internet. I wasn't able to figure out from a few minutes of fumbling with Google if my particular copy of vservice.exe is malware or is some idiotic part of the windows OS, or both, but in any case, I disabled it in zone alarm and pulled it out of the windows/system32 folder as well. Spybot doesn't think it's malware, but hey, I'm skeptical of anti-virus software to start with. I know that if anti-virus says that something is malware, then it probably is, but just because anti-virus software doesn't know about a program (yet) doesn't mean it's not malware.
Certainly, aspiring to a reasonable level of security in an operating system like Windows is kind of a lot to ask anyway.. what with the task manager displaying nothing but cryptic names of processes to you... how the fuck would you know what is going on by looking at that unless you're a programmer, right... I know I don't know what the fuck any of those processes do. Something as simple as alerting me when a new process rears it's head, or when an executable responsible for a process suddenly changes size... the windows OS certainly doesn't do that.
cloud computing is absolutely the only way that people will be able to have secure computers.
cloud computing with a thin client or something like that.
Kind of like the old Minitel green screen terminals they had in France all the way back to 1982... from wikipedia:
"From its early days, users could make online purchases, make train reservations, check stock prices, search the telephone directory, and chat in a similar way to that now made possible by the Internet
Millions of terminals were handed out free to telephone subscribers, resulting in a high penetration rate among businesses and the public. In exchange for the terminal, the possessors of Minitel would not be given free "white page" printed directories (alphabetical list of residents and firms), but only the yellow pages (classified commercial listings, with advertisements); the white pages were accessible for free on Minitel, and they could be searched by a reasonably intelligent search engine; much faster than flipping through a paper directory."
Yes that's right... I'll bet the first minitel terminals didn't get fuck*ng viruses and pop-ups pushed at them every time you went to look up a fuck*ng phone number.
that was my rant for today.
thanks
-
Zone alarm? are you fuck*ng serious? just rely on your router to block ports and don't click on and pop-ups that say your computer is infected with a virus.
-
blocking ports is inadequate security. It's necessary to intelligently analyze both incoming and outgoing packets, regardless of what port it's on, to determine if you really want that data coming into, or leaving your computer. Zone alarm assists in doing this by helping you know which program is sending and receiving which data.
As the article I linked to about the Sony rootkit demonstrates, "not clicking on popups" is an inadequate precaution, because there are innumerable other ways in which malware can install it's self on your computer. In the case of the sony rootkit, merely inserting an audio CD into your computer was enough to infect it with spyware. Zone alarm wouldn't prevent your computer from being infected with the sony rootkit, and neither would any of the commercially available anti-virus products, but at least if some rootkit starts keyboard sniffing your passwords or dumping your hard drive to a remote location, there is a reasonable possibility that zone alarm will alert you to this fact.
Point being, detecting that your computer has become compromised is much more effective and reliable than preventing it from becoming compromised in the first place.
Further, there are all sorts of levels of compromise that zone alarm helps with - everything from out and out malware that's using your computer in a DOS attack to more subtle things, like some random process that's innocent enough but totally useless and you forgot you ever installed and you never even knew it used your internet connection and CPU time to check for updates every 10 minutes or every time you boot up.
Zone alarm is just one useful tool. If you install it, regardless of how savvy a user you are, there's a good chance you will find some program running on your computer talking to the internet that you aren't comfortable with.
-
Fanta, your advice is garbage. I installed zone alarm and now my computer flips its shit when I try to play Alien Swarm. It thinks Alien Swarm is trying to steal my credit card information or give me AIDS. Even when I turn it on "game mode" or "off" it thinks it knows better than me. ZA can eat a dong. >:(
-
First off no one with a username of Fanta could possible be giving anything but the most refreshing of advice.
But yeah I dunno maybe Zone Alarm is garbage but if Zone Alarm doesn't work for you then find some other firewall software that does. My advice about the utility and necessity of an intelligent firewall is pretty good advice I think.
I had an issue with Zone Alarm whereby it popped up a message asking me if I wanted to allow or block some program... and since I was in the middle of typing, whatever key I hit automatically hit one of the buttons in the allow/block dialogue.
So I initiated a chat with Zone Alarm tech support to bitch about that, and the guy was like 'yeah we know about that' and I was like 'then why don't you fix it?' and so he said he'd send it to the programmers.
I wouldn't be surprised if there is better firewall software out there.
-
I used ZA on my old Win XP laptop. Then I got tired of bad laptops and got a mac.
I dunno if it's just cause he came onto me, but this dude is like a pro troll. I mean, I don't bother with that crap much anymore, but seriously, I don't think there is better firewall software than ZA, when it comes to Windows. I really don't care though, all I do is not enter my CC info on Windows, and if my info ever got stolen, I would just cancel it all. Ya know what, I don't even care if anyone steals my identity, the only things my identity has gotten so far is a handful of chicks breaking up with me so they can date or marry skinny lanky guys. Go head, motherfuckers take it. It's your problem now.
-
I used ZA on my old Win XP laptop. Then I got tired of bad laptops and got a mac.
I dunno if it's just cause he came onto me, but this dude is like a pro troll. I mean, I don't bother with that crap much anymore, but seriously, I don't think there is better firewall software than ZA, when it comes to Windows. I really don't care though, all I do is not enter my CC info on Windows, and if my info ever got stolen, I would just cancel it all. Ya know what, I don't even care if anyone steals my identity, the only things my identity has gotten so far is a handful of chicks breaking up with me so they can date or marry skinny lanky guys. Go head, motherfuckers take it. It's your problem now.
I think you should turn the tables and become an identity thief yourself. Proactive and all that.
Maybe you could start by stealing Fanta's identity. He'll just come up with a new one.
-
agreed Mac OS un*x is a much better OS than Windows... hell Mac OS from the 80's is better that Windows XP.
I'm not trying to troll anyone, I'm just trying to share some good advice re: zone alarm.
re: stealing your identity... I dunno if you are joking or not **#** G0d. If not, then, I dunno, to each their own, but someone hacking into your computer is not to be taken lightly. Beyond stealing your identity, access to your computer can be used to gain access to the computers of your friends, can be used to assist in all manner of attack on someone, from simple identity theft to coordinating a burglary / kidnapping, to dox dropping your docs or those of a friend. Your computer is an awesome tool for criminals. By leaving your computer open, you're basically aiding and abetting terrorists, child abusers of the worst sort, ID thieves, etc. I think that the argument that there are millions of other open computers is a poor excuse for leaving yours open. A computer is like a loaded gun, and should be treated as such.
Credit cards... the policies of credit card companies make credit card crime somewhat lucrative. The credit card companies are willing to tolerate the losses from this crime because the profits from increased ease of use of credit cards more than offsets the losses... for the credit card companies... society as a whole comes out on the loosing end, however, because all of the money gained by the criminal elements results in a more robust criminal industry which harms all of us, not just the credit card industry.
-
Word.
-
sugar walls, muh' fuckuh.