TER General Board

IT Security Professional - some advice from a fellow hobbist on how to keep it on the DLregular_smile
liploss 30 Reviews 1355 reads
posted


Hi everyone,

I thought it would be helpful to provide some suggestions to providers and my fellow hobbists.  My career is in IT security so I do work with Fortune 500 companies, government, etc on IT security issues.  This includes busting employees for surfing provider sites, sexual harassment, etc.

Here are some of my suggestions for the gentlemen:

1.  Assume everything on your work computer, network, phone, and email is being tracked.  Therefore, do NOT use your work computer, email, blackberry, iphone, etc for anything.  I know that is probably obvious, but you'd be surprised at what I've found in the past.  Especially on those super convenient smart phones...

2.  Isolate any / all hardware from everyone.  If you can afford your own laptop, pre paid cell or sim card, etc do it.  I have a friend that lost 1/2 of everything in a divorce because of his cell logs...

3.  Use Private Browsing settings on something like the Firefox browser or change IE settings to automatically delete everything after you close the session.  Note: this is essential if you have a significant other or kids that share your computer.

4.  Use gmail, yahoo, or whatever email service.  Do not sync those emails to your outlook, mac, iphone, etc.  Keep those emails those servers and not on your desktop / laptop.

5.  Use strong (hard for people to guess) passwords all the time.  Even when you walk away from your computer for 10 min.  Last thing you want is to forget to 'close' what you were last doing.

For those of you who are like me, and want to keep it on the way DL, here is my situation and what I use:

I have friends and family that hang out in my house and 'want to check something on the web' on my macbook.  I can't throw the laptop out the window and pretend everything is cool...So I use Parallels (or VMWare) to run seperate operating systems complete with strong passwords, hard drive encryption, account access controls, etc.  I only operate this virtual instance (within computer) when I need to 'do my thing.'  Otherwise everyone sees / uses the 'normal' default operating system (the one that comes on first).  

For the providers, I'm not sure there is much you gals can do to keep 'the business' hidden outside of what was written above.  Unfortunately, you ladies take more risk than us guys...Also, I'm not familiar with how providers operate and what tech is used, but feel free to PM me if there is something specific you need to ask.

Happy and safe journeys...

I hope it's OK to post this here rather than PM.

Depending on where I am, I have to use a proxy server to connect to some sites. I have lost a couple of gmail accounts lately and I'm wondering if it's because of that. I switched to yahoo and I have to captcha authenticate almost every email I send when connected via the proxy. And I can only use yahoo classic because regular yahoo mail uses too much javascript.

My email content is never explicit and I avoid DHS buzz words. I started asking correspondents not to include graphic images. Despite that, gmail has clobbered two accounts.

Any comments or advice on proxy servers and services?

Thanks.


-- Modified on 7/23/2010 2:06:45 AM

Hi, I just added to my original post with some comments on proxies.  In your situation, I think it was google that nuked your account.  Keep in mind all your emails are stored and monitored by gmail, yahoo, etc.  So they can nuke your account if they think there is cause such as kiddie porn (I am not accusing you of that evil activity).

Curious...interesting post, is there any value to using a proxy server, especially for the providers?  I see services offering proxy hosting for as little as $100/yr.

bounce emails from proxy servers and/or secure email servers. so there may be lost opportunity costs that outweigh the direct costs involved.

spooky_one212 reads

use thumb drives to keep your data safe. Do not rely on the thumb drives built-in security unless you do your research. Use something like truecrypt. It won't save you from LE, but should help avoid unintended exposure.

As suggested. Strong password that are not real words. DO NOT use anniversary or birth dates, etc!

As for VM ware on laptop. Nifty idea but maybe beyond the scope of the average provider or client. I'm pretty sure (google it) you can buy a thumb drive with an operating system pre-loaded. It's simpler and keeps everything off the laptop as well.

Good physical security trumps electronic every time.

I do all hobbying using an opera browser which is installed on a three strike destructive hardware encrypted thumb drive. I save any hobby related files on this as well. (Actually I have two and I mirror them).

The opera browser is set to save any temporary files in a directory on the thumb drive, but I still delete all private data at the end of each session.

I also use a bit level "shredder" on all of the free space on my computers and automatically on anything deleted.

Nothing is perfect and absolute these days, but unless they turn my stuff over to some very sophisticated folks they're not getting anything....

Actually when I travel, the laptop has *no proprietary information* on it. only proggies. I use the same type of thumb drives for proprietary information when I travel....

Thumb/usb drives rock!  I would recommend it to everyone that can work/travel/chill solo.  

Unfortunately, it didn't really work for me because I like to make appointments and surf while at the office too.  It was difficult to explain why I couldn't pull up the email they just sent me b/c I was using a usb drive...

If only I could get rid of the pesky people that come by my office...

Funny story, we caught an employee hacking our corporate systems and when we sent physical security to hold him he ran off toward the cafeteria.

He put all his usb drives in a microwave to fry all the data.  We couldn't get any of the data back.

I give him points for creativity...but they still peppersprayed and beat his ass...before they sent local LE to lock him up.

HalfHour82 reads

The only one of it's kind! Like the cool spy stuff that M made for Bond, James Bond, regular folks have never heard of it. Real black ops stuff. Snunkworks.

I really get a belly laugh out of your tech talk, GTM. I'm not tryin' to be a butthead, but come on now.

You mirror flash drives? for real? do you mean you duplicate the data on them or you actually mirror them. What kind of controller do you use?

WTF is a bit level "shredder" ???

...and "PROGGIES"???? as in applications? Seriously, where did these terms come from? ROFL!

bit level shredding or randomizing software is all over the place. It randomizes at the bit level in any area of the HD you designate.

It can be set to automatically "shred" anything you trash, and to keep space marked "Free" randomized as well so that your "deleted" files cannot be recovered  

a cheap and easy example is File Shredder Pro but there are many more (and better) packages out there.

AES 256bit hardware encrypted thumb drives are all over the place as well. Those that self destruct their encrpytion chip are another thing. IN that class see for example the Ironkey Military Strength flashdrives

Lastly it is easy to write a driver to configure two USB ports as a raid array.  Many teen agers are up to it.

HalfHour74 reads

But you are good at it, yes? :) BTW, very evasive answers! The baloney doesn't cover it. And two reply posts to my one comment? ... really got under your skin on that one. My bad. Like I said, my PURPOSE was not to be jerky to you. I appreciate your presence on the board.

That being said, you have no idea what I do for a living, nor what I know. Let's put it this way: I come in contact with a lot of big tech talkers. Most don't know half of what a typical script kiddie knows, but they sure do love 'usin' da big woids' to impress the average folk. Sometimes, they even make up their own words and phrases! I love it! LMAO!

to someone who I honestly took as being technologically ignorant. The answers I offered under the OP are not the least esoteric. Anyone following the thread may do a search on the topics and judge the merits for themselves.

Not knowing what we do for a living cuts both ways, my friend. That little piece of real estate up on Rt 32 is running a number of tasks for my little group even as we speak.

Now - I'm not going to joust with you. Waste of time.

HalfHour56 reads


Jousting is pointless, and it's not intended on my part.

Socialness and helpfulness to others is what we are all here for. We can all contribute what we want and each can judge. Good way to approach it.

Be safe & have fun!

actually I very much appreciate someone who can banter or disagree, but does not get their ego all up in it, and at the end of the day, can be reasonable lol

Not too much of that going on here lately.

Kudos

GTM

spooky_one93 reads

I posted from my mobile so I didn't get explicit...

The really high-end thumb drives are better, but many respected thumb drives are very insecure.

As always, use technology to help. These things are like locking your car doors. They only discourage the lazy thief. Use good physical security procedures and practices first.


See:
http://www.zdnet.co.uk/news/security-threats/2010/01/04/kingston-flash-drives-suffer-password-flaw-39963327/

http://www.zdnet.com/blog/hardware/encryption-busted-on-nist-certified-kingston-sandisk-and-verbatim-usb-flash-drives/6655

http://communities.sandisk.com/sandisk/board/message?board.id=u3&thread.id=5334

I keep on my hobbying activities on a personal laptop....No one else will ever use it.  When at my office I use dial up with this laptop [ I know...I'm probably the last person in America to use dial up...but I consider it safer].  At home I use our wireless , which is of course far superior to dial up.  My office also has wireless , but it is connected to our server.  Again , no one will ever touch my hobby laptop, Am I safe to use my office wireless that is connected to our server?

if that's what you are asking - ie using your work office wireless for hobby purposes.

If you are talking about a home office, and are concerned about someone spying on your activities by sniffing your wireless packets, that depends on whether you are using encrpytion and at what level. If you are using robust encryption and a key that is not obvious (and a router password that is not easily guessable) you're good.

and of course anyone who uses wireless at home should be using MAC address filtering to prevent unauthorized access....

if you are concerned about being spied upon by someone with whom you share your home wireless network that's a bit different...

If they are technically savvy and intend to spy on you they can see your traffic..... in real time.

There are ways that they could intercept and store your traffic for later examination etc as well but again someone would have to intend to spy on you, be technically proficient, acquire a bit of hardware etc - or hire a very PC literate PI to do it for them lol....

spooky_one46 reads

It is unspoken but required... anyone can monitor your wireless connection if the encryption isn't turned on. The old WEP is a joke. The new WPA isn't much better, but will keep out the casual snoopers.

Hi,

I would recommend proxy services in your situation.  While your company has no legal right to take and search your personal laptop (unless you are doing something very illegal), they can still see the web traffic to/from your laptop.

Couple of other things to consider:

1.  Kiddie porn (I don't approve of this activity at all) - If a coworker even mentions that someone at work is viewing or distributing this content, the company security will detain you and all your equipment until LE shows up (I was the one that coordinated this for a company).  

2.  Company security monitoring - If you work at a smaller company, usually IT security budgets are limited and don't include monitoring controls, so you may be able to use their wireless without monitoring (proceed at your own risk)

HalfHour65 reads

blah blah blah broadband blah blah VPN blah blah blah big fuckin word blah blah

:D

also, if you are using Firefox, disable caching to disk, and set it to cache web pages to memory, this way cached pages cannot be recovered, works in Windows and Mac versions of Firefox.

browser.cache.disk.enable - set to false

On a Mac set "Use secure virtual memory" on, in the System Preferences->Security->General tab.

In addition to the agreed-on (use a thumb drive with TrueCrypt, never ever use your employer's network): search using Ixquick; run CCleaner set to Wipe Free Space regularly on your machine.

Not long ago, the Sarasota (FL) County Sheriff (presumably) engaged in illegal activity.  He took his work laptop home and used CCleaner.  The authorities never could recover the many files he erased that were presumed evidence. They could only get him for not turning in the laptop.

I would be interested in any actual evidence that TrueCrypt with a very strong password (I use a long line of poetry in a langauge other than English)can be broken by anyone short of NSA.

shudaknownbetter113 reads

I'm not an expert & it doesn't apply to my situation since I'm retired, but I strongly agree that using your personal equipment on an employer's network is too risky.  It might be costly but one alternative is a USB plug in network card, can be used anywhere.  
skb

Hi everyone,

There were a couple of common questions about proxies so I thought I'd answer them here...

A simple way to explain how a proxy works is to imagine that there are 2 cups and a straw going from one to the other.

One cup is your computer or gmail server (I said simple example, so all you IT experts please don't flame me on this).  

The other cup is a provider's computer or email.

Imagine the water in your cup is the email you want to send to the provider, the other cup.

A proxy will just hide and encrypt the straw so that others can't really see the water (email) move between cups.

However, notice I did not say if your company or a 3rd party can see the water (email) in each cup.  Companies have IT security so that your 'cup' is made of glass and they can see/track everything you do.

Therefore, proxies are good for some situations.  But if you are using your work computer at a Fortune 500 or tech savy company, stop immediately and use something else.

Some companies even track how much time you spend on the Internet. So even if you are reading news articles on CNN.COM they know how much time you spend doing it.
So if your job does not require a lot of Internet usage, be careful!!

Be self employed and avoid all the corporate crap

When your done with laptop, they not worth much 6 yrs old...I have a nice barrel burn for it !

spooky_one109 reads

You can anonymize (not much of a word, I know) using Firefox add-ons such as Scroogle or GoogleSharing. They route your searches over various proxies.

For those with mobile devices that can use a wireless connection:

First, many wireless devices, such as the NIC in your laptop are set to automatically connect to some network names when they see them. Ones with the same default names that come with (for example) a LinkSys wireless network router. Disable these settings in your network interface card. Otherwise, someone can set their laptop to run in adhoc mode using these common wireless network names and connect to your laptop anonymously and cruise your entire laptop.

Second, most of these are not secured. Maybe not a big deal as long as your not "logged on".

Register Now!