Showing 1–15 of 17 posts

Passwords used by the Conficker worm

Published: January 15, 2009 Reading time: 1 min

It’s not possible to emphasise enough the importance of using sensible passwords on your network. Not just on the areas of your network that you don’t want your users to traipse through, but also on the default network shares that are present on installations of commonly used operating systems. The Windows versions Conficker targeted — NT, 2000, XP, and 2003 — are all end of life and no longer receive security updates. The lesson still applies to any machine with open shares today. ...

Continue Reading

5 tips to help keep your passwords secret

Published: January 14, 2009 Reading time: 2 min

Treat passwords with as much care as the information they protect. For how to make them strong — and why a manager should generate them — see Passwords. These tips are about keeping secrets secret day to day. 1. Never provide your password over e-mail Phishing messages pretend to be a bank, a shop, or a social network and ask you to “confirm” your login. Legitimate services do not need your password by email. Learn how to spot phishing. ...

Continue Reading

10 tips for safe instant messaging

Published: January 13, 2009 Reading time: 3 min

Communicating by using an instant messaging (IM) program has some of the same security and privacy risks as e-mail, but there are a few dangers that are unique to IM. The original 2009 version of this guide was written for desktop IM clients like AIM and MSN Messenger. The same principles apply to modern apps — WhatsApp, Telegram, Signal, Discord, Slack, and iMessage. 1. Never open files or links from strangers Never open pictures, download files, or click links in messages from people you don’t know. If they come from someone you do know, confirm with the sender that the message (and its attachments) is trustworthy. If it’s not, close the conversation. ...

Continue Reading

11 tips for social networking safety

Published: January 13, 2009 Reading time: 4 min

Social networking Web sites like Facebook, Instagram, X (Twitter), LinkedIn, TikTok, and Threads are services people can use to connect with others to share information like photos, videos, and personal messages. As the popularity of these social sites grows, so do the risks of using them. Hackers, spammers, virus writers, identity thieves, and other criminals follow the traffic. Read these tips to help protect yourself when you use social networks. ...

Continue Reading

TFC

Published: January 13, 2009 Reading time: 2 min

TFC (Temp File Cleaner) was a small utility that cleared out temp folders for all user accounts — temp, browser caches, Java, and system temp directories — across every profile on a Windows machine. It showed the amount removed for each location and required a reboot afterward. The original 2009 version of this page recommended TFC for routine maintenance. TFC is no longer maintained and is not suitable for Windows 8.1, 10, or 11. On modern systems it can destabilize things by force-stopping Explorer and other running apps. ...

Continue Reading

Passwords

Published: January 13, 2009 Reading time: 3 min

Strong passwords still matter, but the way we handle them has changed since this post first ran in 2009. The default today is simple: let a password manager create a unique random password for every site, turn on two-factor authentication (2FA) wherever it is offered, and use a passkey when a service supports one. What actually makes a password strong Attackers guess and crack passwords with dictionaries, leaked lists, and raw computing power. Strength comes from: ...

Continue Reading

How to Choose a Firewall

Published: January 13, 2009 Reading time: 2 min

Three basic types of firewalls are available for you to choose from: Software firewalls (built into your OS) Hardware routers Wireless routers To determine which type of firewall is best for you, answer these questions: How many computers will use the firewall? What operating system do you use? (Windows, macOS, or Linux.) That’s it. You are now ready to think about what type of firewall you want to use. There are several options, each with its own pros and cons. ...

Continue Reading

Check for Windows Updates

Published: January 13, 2009 Reading time: 4 min

Three steps to keep Windows fast, stable, and secure. The original 2009 version of this guide recommended FileHippo Update Checker (later renamed AppManager) and the Secunia Online Scanner. Both are gone — FileHippo retired its updater, and Secunia’s consumer tools shut down years ago. Here is what still works. 1. Patch Windows and Microsoft products Turn on automatic updates and verify nothing is pending. Reboot when prompted — pending restarts leave patches half-applied. ...

Continue Reading

Checklist: Protecting your business, your employees and your customers

Published: January 13, 2009 Reading time: 2 min

The original 2009 version of this checklist recommended Symantec Brightmail and the Symantec State of Spam site. Brightmail is now part of Broadcom’s enterprise portfolio and is not a practical choice for home users. The do/don’t advice below is still sound. Do Unsubscribe from legitimate mailings that you no longer want to receive. When signing up to receive mail, verify what additional items you are opting into at the same time. De-select items you do not want to receive. Be selective about the Web sites where you register your email address. Avoid publishing your email address on the Internet. Consider alternate options — for example, use a separate address when signing up for mailing lists, get multiple addresses for multiple purposes, or look into disposable address services. Using directions provided by your mail administrators, report missed spam if you have an option to do so. Delete all spam. Avoid clicking on suspicious links in email or IM messages as these may be links to spoofed websites. We suggest typing web addresses directly in to the browser rather than relying upon links within your messages. Always be sure that your operating system is up-to-date with the latest updates, and employ a comprehensive security suite. For organizations, use a reputable e-mail security gateway (Microsoft Defender for Office 365, Google Workspace spam filtering, or a dedicated provider such as Proofpoint or Mimecast) to filter spam before it reaches inboxes. Keep up to date on recent spam trends — the Anti-Phishing Working Group publishes quarterly reports on phishing and spam activity. Do not Open unknown email attachments. These attachments could infect your computer. Reply to spam. Typically the sender’s email address is forged, and replying may only result in more spam. Fill out forms in messages that ask for personal or financial information or passwords. A reputable company is unlikely to ask for your personal details via email. When in doubt, contact the company in question via an independent, trusted mechanism, such as a verified telephone number, or a known Internet address that you type into a new browser window (do not click or cut and paste from a link in the message). Buy products or services from spam messages. Open spam messages. Forward any virus warnings that you receive through email. These are often hoaxes.

Continue Reading

Cleanup Windows Hard Disk

Published: January 13, 2009 Reading time: 5 min

Freeing up disk space keeps Windows responsive and gives updates room to install. The original 2009 version of this guide recommended Auslogics BoostSpeed and CCleaner for the job. Today you rarely need either — Windows 10 and 11 ship with cleanup tools that are safer than third-party “boosters” and registry cleaners. Here is the modern workflow. Why cleanup Over time Windows accumulates files you can safely remove: Temporary files from apps and the system Browser caches and downloaded program files Windows Update leftovers, WinSxS component-store bloat, and orphaned installer patches The Recycle Bin Delivery Optimization cache and old restore points Apps and games you no longer use Tip: On modern browsers the cache is capped and self-managing, so the biggest wins are usually Windows Update leftovers (especially WinSxS and the Installer folder), the Downloads folder, and unused applications — not the browser cache. ...

Continue Reading

Firewall

Published: January 13, 2009 Reading time: 3 min

A firewall is an application which controls network traffic to and from a computer, permitting or denying communications based on a security policy. A personal firewall differs from a conventional firewall in terms of scale. Personal firewalls are typically designed for use by end-users. As a result, a personal firewall will usually protect only the computer on which it is installed. Many personal firewalls are able to control network traffic by prompting the user each time a connection is attempted and adapting security policy accordingly. Personal firewalls may also provide some level of intrusion detection, allowing the software to terminate or block connectivity where it suspects an intrusion is being attempted. ...

Continue Reading

How to handle suspicious e-mail

Published: January 13, 2009 Reading time: 4 min

There are good reasons to be suspicious of e-mail. Some e-mail messages might be phishing scams, some might carry viruses. Images in spam e-mail might turn out to be pornographic, or to include Web beacons, which can be adapted to secretly send a message back to the sender. Follow these guidelines to help protect yourself when suspicious mail shows up in your Inbox. 1. Do not respond — and don’t open junk mail If an e-mail looks suspicious, don’t risk your personal information by responding to it. Delete junk e-mail messages without opening them. Sometimes even opening spam can alert spammers or put an unprotected computer at risk. Don’t reply to e-mail unless you’re certain that the message comes from a legitimate source. This includes not responding to messages that offer an option to “Remove me from your list.” Do not “unsubscribe” unless the mail is from a known or trusted sender. Use the junk mail tools in your e-mail program. Gmail, Outlook, Yahoo, and most providers let you mark messages as spam or phishing, which trains their filters and blocks the sender. 2. Approach links with caution Links in phishing e-mail messages often take you to phony sites that encourage you to transmit personal or financial information to con artists. Avoid clicking a link in an e-mail message unless you are sure of the real target address, or URL. ...

Continue Reading

How to recognize phishing e-mails or links

Published: January 13, 2009 Reading time: 3 min

A few clues can help you spot fraudulent e-mail messages or links within them. What does a phishing e-mail look like? Phishing e-mail messages are designed to steal your identity. They ask for personal data, or direct you to Web sites or phone numbers to call where they ask you to provide personal data. Phishing e-mail messages take a number of forms: They might appear to come from your bank or financial institution, a company you regularly do business with, such as Microsoft, or from your social networking site. They might appear to be from someone you know. Spear phishing is a targeted form of phishing in which an e-mail message might look like it comes from your employer, or from a colleague who might send an e-mail message to everyone in the company, such as the head of human resources or IT. They might ask you to make a phone call. Phone phishing (vishing) scams direct you to call a customer support phone number. A person or an audio response unit waits to take your account number, personal identification number, password, or other valuable personal data. They might include official-looking logos and other identifying information taken directly from legitimate Web sites, and they might include convincing details about your personal information that scammers found on your social networking pages. They might include links to spoofed Web sites where you are asked to enter personal information. To make these messages look even more legitimate, scam artists may place a link that appears to go to the legitimate Web site, but actually takes you to a phony scam site or a pop-up window that looks exactly like the official site. ...

Continue Reading

Phishing

Published: January 13, 2009 Reading time: 2 min

Phishing (pronounced “fishing”) is a type of online identity theft. It uses e-mail, text messages, and fraudulent Web sites that are designed to steal your personal data or information such as credit card numbers, passwords, account data, or other information. Con artists might send millions of fraudulent messages with links to fraudulent Web sites that appear to come from Web sites you trust, like your bank or credit card company, and request that you provide personal information. Criminals can use this information for many different types of fraud, such as to steal money from your account, to open new accounts in your name, or to obtain official documents using your identity. ...

Continue Reading

Sandbox

Published: January 13, 2009 Reading time: 2 min

In computer security, a sandbox is a security mechanism for separating running programs. It is often used to execute untested code, or untrusted programs from unverified third-parties, suppliers and untrusted users. I recommend Sandboxie for daily use on Windows — the open-source fork maintained by the Sandboxie-Plus community after the original project was discontinued. The sandbox typically provides a tightly-controlled set of resources for guest programs to run in, such as scratch space on disk and memory. Network access, the ability to inspect the host system or read from input devices are usually disallowed or heavily restricted. In this sense, sandboxes are a specific example of virtualization. ...

Continue Reading