Internet Security & Privacy - What You Can Do To Protect Yourself

in #technology7 years ago

Internet Security & Privacy.png

Passphrases

I'm going to touch on this only briefly since I did a full twenty to twenty five minute podcast on this subject. As mentioned before, make sure to use a password manager such as Lastpass. Lastpass does have a free version that has a ton of functionality. I used to pay for Lastpass premium but recently stopped since the benefits of using premium were not being used enough.

Grab some dice and a word list such as the one from the EFF. Roll the dice to get five numbers and write those numbers down. Then replete for as many words as you want your passphrase to be long. I would suggest using at least six, this will make the chances of cracking so low that even if the attacker can guess 1 trillion times per second it will still take them 3,505. Keep this in mind, since using just one less word results in your attacker being able to guess your passphrase in only 165 days!

The passphrase you get from your dice should only be used for Lastpass. The more places you have it used the better the chance you have of getting fished. This is when someone makes a fake site that looks just like the site you want to go to. They then can steal your password and kick you back to the real site.

Why use dice to pick your passphrase? Something called entropy:

Entropy is a measure of the uncertainty or randomness of a system. The concept is a difficult one to grasp fully and is confusing, even to experts. Strictly speaking, any given passphrase has an entropy of zero because it is already chosen. It is the method you use to randomly select your passphrase that has entropy. Entropy tells how hard it will be to guess the passphrase itself even if an attacker knows the method you used to select your passphrase. A passphrase is more secure if it is selected using a method that has more entropy.

Entropy is measured in bits. The outcome of a single coin toss -- "heads or tails" -- has one bit of entropy. - Arnold G. Reinhold

I've been asked before if it's ok to use a site like rempe.us/diceware instead of trying to find dice that you may or may not have. For normal everyday use this should be fine but keep in mind that no computer connected to the internet is 100% safe and you should assume it's been compromised. One thing you can do is to download the site and run it offline in order to ensure no one is snooping. I'd even go as far as creating a bootable USB drive running Linux that is fresh and has never been online to run the downloaded files.

Remember, convenience is the killer of security and privacy.

Useful Extensions

HTTPS_Everywhere_logo.png

HTTPS Everywhere

HTTPS Everywhere is a Firefox, Chrome, and Opera extension that encrypts your communications with many major websites, making your browsing more secure.

Many sites offer encypted web traffic but they may default to unencrypted HTTP, or have links that go back to the unencrypted version of their site.

HTTPS Everywhere is an open-source extension that fix this problem by rewriting your requests to the encrypted version of the site your visiting.This of course only works if the site offers an encrypted version, but getting a site encrypted is more and more common with each passing year.

By defaulting to an encrypted version of a site you greatly increase your security and privacy on said site. When encrypted sniffing and eavesdropping on your web traffic is much more difficult. So much more that an attacker would have to spend more time to break the encryption than the value they would get from your information.

Privacy Badger

Privacy Badger is a browser add-on that stops advertisers and other third-party trackers from secretly tracking where you go and what pages you look at on the web. If an advertiser seems to be tracking you across multiple websites without your permission, Privacy Badger automatically blocks that advertiser from loading any more content in your browser. To the advertiser, it's like you suddenly disappeared.

When you view a webpage, that page will often be made up of content from many different sources.

Privacy Badger keeps track of all of this. If as you browse the web, the same source seems to be tracking your browser across different websites, then Privacy Badger springs into action, telling your browser not to load any more content from that source. And when your browser stops loading content from a source, that source can no longer track you.

Privacy Badger keeps note of the "third party" domains that embed images, scripts and advertising in the pages you visit.

In some cases a third-party domain provides some important aspect of a page's functionality, such as embedded maps, images, or stylesheets. In those cases Privacy Badger will allow connections to the third party but will screen out its tracking cookies and referrers.

Decentraleyes

logo.png
Decentraleyes is a local Content Delivery Network (CDN) Emulator.

The aim of this add-on is to cut-out the middleman by providing lightning speed delivery of local (bundled) files to improve online privacy.

a lot of websites make you load vital files through large third-party services

There are a couple of reasons why web developers are tempted to do this. It lowers upkeep costs (as these services do not cost the host any money), and it speeds up the web in the sense that if you store a specific version of a file once, you will only contact that central content delivery service to see if the file your browser already has, is identical to the one that's being served.

Since these companies are now deeply woven into the fabric of the web, cutting them off actually breaks a significant percentage of all websites.

That is where Decentraleyes comes in!

It comes bundled with a fair amount of commonly used files that you would need to get from these 3rd party providers, and serves them locally on your machine.

Whenever a site tries to fetch them from a delivery network this extension grabs the version that you have stored on your computer saving you bandwidth and protecting your privacy.

Decentraleyes complements regular content blockers such as Privacy Badger we previously mentioned.

Use a VPN

A VPN allow you to connect to a another server and encrypt your data from your home to their server. This will stop your ISP from spying on you and collecting data. Keep in mind that the company you use for the VPN can spy on you and collect data. So make sure to do your research and find a good company.

PIALogo2x.png

I currently use Private Internet Access. They say they don't keep logs and some news in the past shows me that they are holding up to their word. At some point in the past, the US government asked for the log files of the users to look for data they needed. PIA could not give them anything since they don't keep logs. This is good for privacy. Even if bad people use it, there are many more good people using it and their data does not need to be collected.

For maximum privacy make sure the VPN you choose does not keep logs, allows you to pay with Bitcoin, only asks for an email address (use a temporary address for added privacy), have openVPN connections, and is not United States corporation.

That all being said, using a VPN will not make you anonymous. But it will give you a better privacy. A VPN is not a tool for illegal activities and don't rely on a "no log" policy because companies can lie.

Web Browsers

The Tor Browser gives you the most privacy over every other browser. It does slow down your speeds slightly due to how it works to provide you with said privacy. However, if you really want to cut down on the amount of spying (both corporate or state sponsored) than the Tor browser is your best best.

Firefox is a great second choice browser for privacy and security. It is fast, reliable, open source and respects your privacy. There is a bit of work that needs to be done to make it the most privacy and security buff that it can be.

5b818044.png

Finally there is the Brave browser. Brave is open source and automatically blocks ads and trackers. This browser is based on chromium, the open source version of what Google turns into Chrome.

Email

Proton Mail is a very user friendly and privacy focused email service. They have free and paid versions, accept bitcoin as payment for their paid plans, allows you to use your own domain, and has encryption built in and automatically enabled.

You can send an encrypted email to anyone on the web and they can view it with a key you supply them. If you don't encrypt the email they can see it as with any email. The nice thing about Proton Mail is that every message in your account is automatically encrypted and only you are able to view the messages. The company does not even know what your messages say.

Other email providers include, Disroot and Tutanota. Both of these have free accounts and have encryption built-in.

Privacy Respecting Search Engines

Searx

Searx is an open source search engine that searches other search engines. This site takes your search and aggregates the results if finds from many of the webs search engines. Including Google, Yahoo, Bing, ect. This all happens without storing information on you and what you are looking for. Also there are no ads!

StartPage

StartPage gives you Google search results, with complete privacy protection.

adad4e5c.png

Duck Duck Go

The search engine that doesn't track you. Some of DuckDuckGo's code is free software hosted at GitHub, but the core is proprietary. This is by far the most popular of the security and privacy focused search engines.

Thanks for reading!

If you found what I do informational and would like to buy me a cup of coffee (yes, I love coffee, yum), check out my Patreon page at patreon.com/jrswab.
Rather donate in Bitcoin? -> 1FjdUJXtQ2VuyQfN2iLMe2vWgtJ6fwa36X

speaker-wireless.png Listen to the podcast version

Sort:  

Hi
I'm hoping you might have info on a slightly different aspect of security.

I'm finding my CPU being used at almost 100%, making it impossible for me to surf (at times). I think this is someone using my pc for mining.

I don't use Adblock, so was wondering, do you know of any firewall that can block them?

Does it stay pegged at 100% when you turn off the internet?

Thanks for responding so quickly. Actually, I use a program for freeing Ram and it tries but cannot. I have 1gb Ram and 2gb in pagefile. It reports I have, in total 2gb (the way it does its' arithmetic puzzles me). When it takes me minutes to open a steemit page, or my emails fail to get sent because the connection is too slow, I see availability is down to about 400mb.

Here is something else very strange. I kill Firefox. Fine, it is either immediately gone or posts me a box saying it crashed and do I want to report it! Thae strange part? When I see the memory is still very low I go to windows Task Manager and I see that in Processes wondow, Firefox is still running.

When I use the firewall to block the internet, I can see the outside is constantly trying to contact my pc, for a minute maybe. Then it flashes on and off until it gives up. Once that stage is reached, I unblock and can use Firefox (after killing it in Processes and re-starting). I'm then ok for 20 to 30 minutes.

For yi: I am using XP (one that was cleaned by a hacker, getting rid of reporting and other dangerous utilities), plus I need to keep my Word97 for my writing, so I don't want to go to SP3 or to Win 7 or newer. After all, I only use my pc for writing my stories and being on Steemit.

If there is no other way, I'll get myself an old HD of about 100gb, install Win7 (light) and use it only for going on the web. It will be a nuisance having to swop OS every day, but I'll take your advice.

The other answer might be to use Tor. Have not tried it with Steemit....

Try running AVG and CCleaner to see if that helps at all. Instead of putting windows on another hard drive I would suggest to use 'Ubuntu Mate' instead. Then use that for browsing the web and posting to steem. It won't run Word97 but there are alternatives that work just fine. (Libre Office has a great history)

Congratulations! This post has been upvoted from the communal account, @minnowsupport, by jrswab from the Minnow Support Project. It's a witness project run by aggroed, ausbitbank, teamsteem, theprophet0, someguy123, neoxian, followbtcnews/crimsonclad, and netuoso. The goal is to help Steemit grow by supporting Minnows and creating a social network. Please find us in the Peace, Abundance, and Liberty Network (PALnet) Discord Channel. It's a completely public and open space to all members of the Steemit community who voluntarily choose to be there.

Coin Marketplace

STEEM 0.29
TRX 0.12
JST 0.032
BTC 63156.26
ETH 3071.73
USDT 1.00
SBD 3.86