Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Saturday, December 4, 2010

Electronic Pickpockets

This is some pretty scary stuff.

Many new credit cards carry an RFID chip for 'fast pay/swipe pay'.

RFID stands for Radio-frequency identification. RFID is a technology that uses communication via electromagnetic waves to exchange data between a terminal and an electronic tag attached to an object, for the purpose of identification and tracking.

Here is a video showing a technique of stealing your information with out you even knowing it. Sadly this has been known for quite a while and not publicized much. I have seen many security related articles on this but I guess the public is just now being made more aware of it. And I think that is good. Be careful out there folks.

Saturday, August 21, 2010

Some simple privacy and security tips

Besides my many previous tips on keeping your Browsers(and plug-ins like Flash), Operating Systems, Anti-Virus/Anti-Spyware, and other productivity applications here are some other things you can do to help keep yourself even more secure and less likely to be ‘compromised’. Please read my previous articles on security and follow those tips first. The things here are some ways to ‘clear/delete’ temporary files that may contain sensitive information or possible a trojan/virus that is just ‘waiting’ to launch from a temporary location.

First

Every time I close my internet browser(s) (IE, Firefox, Opera etc.) I run CCleaner. Actually I run a ‘batch file’ that runs CCleaner and clears my network cache settings too. You can, and I recommend you do, simply run CCleaner every time you shut your browser.  If you would like to use/create my batch file simply copy the information between the ‘start’ and ‘end’ into a text file and rename it with a .bat extension. Example copy the file into notepad and save the file with a name of clean.txt. Then rename the file clean.bat.

For XP

Start:

"C:\Program Files\CCleaner\CCleaner.exe" /AUTO
arp -d
nbtstat -R
ipconfig /flushdns
nbtstat -RR
ipconfig /registerdns

Finish

for Window 7

Start:

"C:\Program Files (x86)\CCleaner\CCleaner.exe" /AUTO

arp -d
nbtstat -R
ipconfig /flushdns
nbtstat -RR
ipconfig /registerdns

Finish

Second

Some third-party programs can temporarily store unencrypted (plain-text) passwords or other sensitive information in memory. Because of the Windows virtual memory architecture, this information can be present in the paging file.

Although clearing the paging file is not a suitable substitute for physical security of a computer, you might want to do this to increase the security of data on a computer while Windows is not running.

   1. Start Registry Editor (Regedt32.exe).
   2. Change the data value of the ClearPageFileAtShutdown value in the following registry key to a value of 1:
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management
      If the value does not exist, add the following value:
      Value Name: ClearPageFileAtShutdown
      Value Type: REG_DWORD
      Value: 1

This change does not take effect until you restart the computer.

Hope this helps some of you.

Sunday, March 28, 2010

Managing Passwords – Using KeePass

In the digital age remembering your usernames and passwords can be very difficult. You need a password for the Windows network logon, your e-mail account, your homepage's FTP password, online passwords (like website member account), etc. etc. etc. The list is endless. Also, you should use different passwords for each account. Because if you use only one password everywhere and someone gets this password you have a problem... A serious problem. The thief would have access to ALL your e-mail accounts, banking, mortgage, homepage, etc.

Here is a list of what I have to manage.
My corporate accounts: 64, my logmein accounts: 22,Personal Internet sites and services: 38, my internet email accounts(gmail, hotmail, yahoo): 14,personal banking/credit: 9.
That is a total of 147! And there are probably some I can't remember!
As you can see having to manage these could be a nightmare without some kind of password management system.

To that end I use KeePass.
KeePass is a free open source password manager, which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file. So you only have to remember one single master password or select the key file to unlock the whole database. The databases are encrypted using the best and most secure encryption algorithms currently known (AES and Twofish). I also use KeePass to store my non-digital passwords such as 'PINs' for banking and credit cards. Because the database is digital and can be exported it can be copied to many locations for back up purposes - such as USB drives, CDROMs, place in a save deposit box and/or to an Internet storage solution.

http://keepass.info/features.html

There are versions for Windows, Linux, OSX and portable devices such as Blackberrys, iPhones and Windows Mobile (PPC).

There are also 'Portable Versions' that can be installed on a USB drive with your Key database for use on other non-secure machines.
[Just a note when backing up and/or exporting your database make sure you backup/copy your 'key file' too if you created one, otherwise you will not be able to open your database!!]
I keep my KeePass database synchronized to my 'SkyDrive' incase I need it and as a good backup.

Here is a good video how to:

Here is another pretty good video on how to setup and use KeePass. It is a little 'slow' and it is covering the portable version but the instruction is right on.

Friday, February 12, 2010

Get Un-Buzzed!

Since Google ‘foisted’ Buzz on us Gmail users I have been very concerned about how it works and how privacy seems to be highly compromised. I made a few posts/buzz replies about how to turn off or disable buzz. But apparently buzz ‘sticks around’ unless certain deliberate steps are taken to actively remove ANY sharing of information whether you wanted to or not with people you approve and even those you don’t!

I do like a great deal about Google apps – Gmail, Docs and Calendar and I have made a few posts on using them for increasing productivity. I have also made it known that I do not want to share every bit of my life with Google too (see part about toolbar).

My fears spring from my natural high degree of paranoia and usual vigilance when it comes to privacy and security. Seems my concerns about Buzz were warranted. There are numerous articles of people – many very tech savvy, who have had information shared that even they did not know they were exposing. Sometimes to people that could pose a real eminent threat.
I have recommended that people turn off Buzz but I guess that was not enough. Here are the steps you should take to turn off this feature.

Turning Buzz off
If you don't want to use Buzz, and I think you shouldn’t, you can disable it. To completely remove all of your participation in Buzz, follow all of these steps AND FOLLOW THEM IN THIS ORDER(or it will not be disabled completely!!):
  1. Delete your Google profile. Here's how.
  2. Block all of the people following you. Here's how.
  3. Turn off Buzz at the bottom of Gmail. Here's how.
Read more about Disabling Buzz.

Given the populist sentiment about the way it launched Buzz, by merging it with Gmail, resulting in a million-and-one privacy kerfluffles, Google's now thinking about going beyond the tweaks it made the other day by cutting the cord between Buzz and Gmail entirely. Or maybe just changing the way it is ‘linked’ to your accounts and contacts.

I make a deliberate effort to try and keep my privacy secure and I think all people should. Especially in the ‘information age’ we currently live in.
I am experimenting with further steps to make sure my information is even more secure. I will post updates as I can.

As always though, remember that the World Wide Web is exactly that – World Wide! If you post anything or have it ‘hosted/stored’ (Gmail, Yahoo, Hotmail, Facebook, LinkedIn, Digg, Myspace etc.) your information is then in ‘someone else's hands’ literally and figuratively. Your privacy and control of that information is subject to someone besides you. So think wisely what you post, comment on, or email by way of ‘public’ networks.

Be safe all,
Peace.