Advise me on my Computer Security Set-Up?

Status
Not open for further replies.
Originally Posted By: ToyotaNSaturn
Never, ever, ever use IE.


Can you explain that to my company? The only thing we can use to go online is IE.

I am now using a router based on the info from this forum. Nice to have so many knowledgeable people here.
 
I like it too, since some things like Hotmail and my office applications display better. I tend to switch back and forth. Firefox tends to be my Google, search for info, pay bills, go to forums browser (spell check).
 
In a perfect world, maybe we wouldn't need all that protection running.

I've installed and run spybotSD in multiple computers. SAS has never found anything in those systems. So, I don't see it as worthless. It is free and has a good immunization that isn't a resource hog. Always pair it up with spyblaster.

Any AV program is a must these days. Sorry, not everyone has a hardware firewall, linux...... and most enjoy downloading every possible email, music, video, picture, visiting questionable websites........ The typical user doesn't have common sense.

If you're a Network Admin and don't believe in protection, then I wouldn't hire you. It is up to you to assume the user is a fool, since most are. No wonder why so many companies have issues and poor security! Too much reliance on '1' method.

Many programs do not waste resources on a decently powered PC. My 512mb P3-1400mhz Via'd(chip/graphics/sound) has no problem running with an AV program, firewall, and antispy in the background. No speed issues here.

My recommendation for everyone:
Any AV program. Avast, AVG, and Antivir are 3 FREE to use.
Any antispy program. AVG has it built in the free 8.0 now.
Enabled firewall, whether Vista/XP or Comodo, zonealarm.....
Everyone forgets Opendns. I find that a simple mistype leading to a questionable website can hose a system. Opendns is so easy to use.
All available updates, especially if running anything from MS. Regular automated/manual scans/updates/habits with the software you choose is also a must.

Any user can hose any browser. I have no issues with IE. Stick with the latest one with all updates. Is Firefox, without noscript, any better? Doubt it! And, as any user base with a program, like an alternative browser, grows larger, more will attack it.

The other week, I found an interesting virus on a PC that none of the major AV programs detected. Even after submitting it, only 3 of 30 would pick it up now. Its a scary world. Protect yourself, update, and scan regularly. Competitor scans should also be considered, regardless of what your front line protection is.
http://www.security-ops.eu.tt/
 
I know I had some infection problems (computer related) and the method described in PC World worked for me. They recommended buying one of the anti-spyware products. The person who wrote the article was using CounterSpy, so for the last year that is what I used. It found things none of the free anti-spyware programs found. They also recommended Trend Micro's House Call, the free online scan. I had success with that in the past finding things that AdAware, etc. never found. They also recommended switching the primary anti-spyware program from time to time. Counterspy was no longer finding anything, so now I am using Spyware Doctor. Sure enough, it found something Counterspy did not find. The main point is to use two or three programs since each one may pick-up on things the other missed. You get what you pay for. I am very pleased and feel more at ease. I had problems with credit cards being stolen. Never found out how it happened, so I am more proactive with security.
 
The problem with Internet Explorer is ActiveX. Firefox doesn't support ActiveX, there's a big plus for Firefox's security right there.

Firefox is open source. It is being constantly developed and refined, thousands of eyes are constantly scanning it's code and any time a bug or vulnerability is found, it is quickly patched.

With Internet Explorer, the vulnerability is in the wild for WEEKS, sometimes MONTHS at a time until MS finally releases a patch/fix.

When you have software where the source code is free and readily accessible, how much motivation do you think there is to make sure that the software is as vulnerability-free as possible?

My first line of defence is to educate my users on the LAN's and WAN's I manage. I can also block sites and file types at the router level. Beyond that, all the machines have good antivirus protection and some basic level of spyware protection.

Spybot is a great product, I agree. And it's immunize feature is a way to prevent "accidental" browsing/infections on roadwarrior clients which you don't always have hands-on access to.

Software firewalls are a resource hog and do nothing but tell you that you've been infected with something and it's trying to get out, or that somebody was probing your computer for a port that should have been closed to begin with. If you are behind any cheap consumer-grade router, the latter is not applicable, which simply leaves the former... Which begs the question, if you have software trying to get out, and it's malicious, shouldn't your antivirus and/or antispyware software have picked it up then to begin with? So then what is the point of the software "Firewall" in this instance?
 
Here's a plug for Sandboxie and reminder of one of the biggest attack vectors. Yesterday, I downloaded a song on Limewire. I did it sandboxed. Voilla, Avira Antivir stops it - it's a trojan downloader. Antivir kept going nuts - had to turn it off. So I scanned the "song" at virustotal - almost every vendor detected it as a nasty trojan downloader (which downloads all kinds of stuff - keyloggers etc.)

Deleted the sandbox - GONE. Zip, zilch, nodda.

If you want 100% isolation from malware, I highly recommend it.
 
Status
Not open for further replies.
Back
Top Bottom