{"id":73,"date":"2015-01-21T17:37:45","date_gmt":"2015-01-21T17:37:45","guid":{"rendered":"https:\/\/cms.digitalbes.com\/?p=73"},"modified":"2015-01-21T17:37:45","modified_gmt":"2015-01-21T17:37:45","slug":"security-advice-count-computer-internet","status":"publish","type":"post","link":"https:\/\/cms.digitalbes.com\/?p=73","title":{"rendered":"Security Advice You Can Count on when it come to your computer and the internet"},"content":{"rendered":"<p>I couldn\u2019t put my finger on what was nagging at me the last few months. When I finally sorted it out, it was the realization that most computer security advice is an absolute waste of time \u2014 and most of what isn\u2019t is barely useful.<br \/>Even I\u2019m guilty. Statements I\u2019ve spouted in the past, like using long and complex passwords or hardening your computer system, don\u2019t really deliver much value. Disable weak password hashes? That was good advice 15 years ago. Use an up-to-date antivirus program? If that worked, we would have solved the problem decades ago.<br \/>When I look at the data of how people and computers are compromised, those previous recommendations didn\u2019t effectively address the attack vectors that make malicious hackers so successful. Instead of giving you dozens to hundreds of truly ineffective recommendations, I\u2019m going to give you a few basic defenses that really work.<br \/>Forget every past computer security advice you\u2019ve ever read \u2014 even from me. This is the real deal. Everything else is wasted cycles.<\/p>\n<p>Bank robbers rob banks because that\u2019s where the money is. Malicious hackers and malware concentrate on exploiting the most popular programs because those are the ones most likely to be on the computers they want to compromise.<br \/>If you look at how most computers are compromised, it\u2019s through unpatched software. Usually, the exploited unpatched software is the popular software used by everyone. Today, client-side, Oracle Java leads the pack, followed by Adobe Flash and Acrobat Reader. Server-side it\u2019s unpatched admin or remote access tools. The most popular programs change over time. What doesn\u2019t change is that those programs are the ones most often exploited.<br \/>You\u2019re going to get far more bang for your buck by patching the most commonly exploited programs and doing that perfectly than patching almost all of your programs with less rigor (which is the case in most organizations). If you can\u2019t patch or mitigate the most exploited programs, the rest of your efforts aren\u2019t worth much.<\/p>\n<p>Social engineering is a fancy name for a con, accomplished over the phone, via email, or on the Web, where the con artist manages to extract some vital piece of information or convince the victim to install malware. The only way to guard against social engineering is to keep your user training up to date to combat the most prevalent threats, which most companies fail to do.<br \/>Test your employees, and if you can successfully socially engineer them, do a better job at education. If you have an excellent user education program and employees still fail the test, redouble your efforts.<br \/>Make sure your user education material tells people they\u2019re more likely to be exploited by trusted websites than strange or new websites. Tell users not to be tricked into installing new programs. Let them know that popular, free software, is often full of unwanted programs and malware<\/p>\n<p>Although the security of 2FA (two-factor authentication) is often oversold, its effectiveness often depends on which risks you think you\u2019re mitigating. For example, 2FA can\u2019t stop most of today\u2019s APTs (advanced persistent threats) once they have full control of your PC \u2014 but 2FA is great at preventing phishing attacks (which often precede the ultimate compromise).<br \/>If you can be strict enough to allow only 2FA when users log on to company resources, then there\u2019s no logon name and password combination to steal. When the fake phishing email arrives asking for the user\u2019s logon credentials \u2014 sorry, bad guy, you\u2019re out of luck. This works well only if you use 2FA everywhere on the corporate network, and you don\u2019t need a logon name and password for some websites.<\/p>\n<p>After phishing, the most common way hackers obtain your password is from other systems and sites. Many users have been successfully phished for their Facebook or Twitter logon and the attackers use the same password for the user\u2019s corporate logon. It works all the time.<br \/>Make sure your corporate passwords never match any password you use off the corporate network \u2014 and don\u2019t use the same passwords on multiple websites. Even on the corporate network, local admin and service\/daemon accounts should never share passwords on different systems \u2014 it allows a credential theft attacker to leverage a single compromise into a network-wide compromise in minutes. Not sharing local passwords is one of the best measures you can take to slow down attackers and minimize the damage.<\/p>\n<p>Malicious hackers always escalate their privileges to obtain the highest security credentials in the network. Once they have those, it\u2019s game over. Want to frustrate a hacker? Don\u2019t have any permanent members of any elevated group, and monitor and alert on unexpected member additions. There are ways around this defense, but most hackers are stymied when their go-to methodologies fail. Frustrate a hacker today!<\/p>\n<p>If you\u2019re collecting a bazillion events a day, you\u2019re doing it wrong. Instead, focus on defining only events that indicate maliciousness, and only alert on those. Everything else is trying to find needles in a haystack. If you want to know what events to monitor, email me.<\/p>\n<p>Today\u2019s attackers gain a regular user\u2019s credentials, then begin moving around the network accessing servers and sites the user\u2019s logon credentials can access. Or they are using memory-only resident software that\u2019s really hard to detect. But no matter what they use, bad guys move around networks in illegitimate ways. Use a network flow analysis tool, define what is normal, and alert on the abnormal.<\/p>\n<p>If everyone used a whitelisting application control program it would make everyone\u2019s life easier. Whitelisting programs can prevent previously undefined programs from executing. That\u2019s a terrific way to stop previously unknown malware. But even if you can\u2019t use it in enforcement mode, turn on your application control program in audit-only mode. Then you can alert on and respond to new suspicious programs without interrupting normal operations.<\/p>\n<p>Lastly, learn how badness breaks into your network and put less focus on names. The name of the malware program on an exploited computer isn\u2019t nearly as useful as how it got in (through unpatched software, social engineering, and so on). Learn those modalities and focus on mitigating those types of threats; then you have a real computer security defense plan in the works.<br \/>After every major public hacking attack I read article after article offering absolutely useless advice. Those writers aren\u2019t thought leaders. They are parroting the unoriginal, unsupported dogma they\u2019ve read. They haven\u2019t spent years looking at the data and interacting with hacked customer after hacked customer. I have. This advice is the real deal. Follow it, and you\u2019ll be better off than anyone else.<br \/>Orinally writen by Roger A. Grimes<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I couldn\u2019t put my finger on what was nagging at me the last few months. When I finally sorted it out, it was the realization that most computer security advice is an absolute waste of time \u2014 and most of what isn\u2019t is barely useful.Even I\u2019m guilty. Statements I\u2019ve spouted in the past, like using [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-73","post","type-post","status-publish","format-standard","hentry","category-tech-news"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cms.digitalbes.com\/?p=73\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog\" \/>\n<meta property=\"og:description\" content=\"I couldn\u2019t put my finger on what was nagging at me the last few months. When I finally sorted it out, it was the realization that most computer security advice is an absolute waste of time \u2014 and most of what isn\u2019t is barely useful.Even I\u2019m guilty. Statements I\u2019ve spouted in the past, like using [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cms.digitalbes.com\/?p=73\" \/>\n<meta property=\"og:site_name\" content=\"Digitalbes Limited Premium Blog\" \/>\n<meta property=\"article:published_time\" content=\"2015-01-21T17:37:45+00:00\" \/>\n<meta name=\"author\" content=\"dbl\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"dbl\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73\"},\"author\":{\"name\":\"dbl\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"headline\":\"Security Advice You Can Count on when it come to your computer and the internet\",\"datePublished\":\"2015-01-21T17:37:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73\"},\"wordCount\":1157,\"commentCount\":0,\"articleSection\":[\"Tech News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73\",\"name\":\"Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\"},\"datePublished\":\"2015-01-21T17:37:45+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/?p=73#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cms.digitalbes.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Advice You Can Count on when it come to your computer and the internet\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#website\",\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/\",\"name\":\"Digitalbes Limited Premium Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cms.digitalbes.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cms.digitalbes.com\\\/#\\\/schema\\\/person\\\/501f983dd73df2b3abf7b41c11a10904\",\"name\":\"dbl\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g\",\"caption\":\"dbl\"},\"sameAs\":[\"https:\\\/\\\/cms.digitalbes.com\"],\"url\":\"https:\\\/\\\/cms.digitalbes.com\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cms.digitalbes.com\/?p=73","og_locale":"en_US","og_type":"article","og_title":"Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog","og_description":"I couldn\u2019t put my finger on what was nagging at me the last few months. When I finally sorted it out, it was the realization that most computer security advice is an absolute waste of time \u2014 and most of what isn\u2019t is barely useful.Even I\u2019m guilty. Statements I\u2019ve spouted in the past, like using [&hellip;]","og_url":"https:\/\/cms.digitalbes.com\/?p=73","og_site_name":"Digitalbes Limited Premium Blog","article_published_time":"2015-01-21T17:37:45+00:00","author":"dbl","twitter_card":"summary_large_image","twitter_misc":{"Written by":"dbl","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cms.digitalbes.com\/?p=73#article","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/?p=73"},"author":{"name":"dbl","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"headline":"Security Advice You Can Count on when it come to your computer and the internet","datePublished":"2015-01-21T17:37:45+00:00","mainEntityOfPage":{"@id":"https:\/\/cms.digitalbes.com\/?p=73"},"wordCount":1157,"commentCount":0,"articleSection":["Tech News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cms.digitalbes.com\/?p=73#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cms.digitalbes.com\/?p=73","url":"https:\/\/cms.digitalbes.com\/?p=73","name":"Security Advice You Can Count on when it come to your computer and the internet - Digitalbes Limited Premium Blog","isPartOf":{"@id":"https:\/\/cms.digitalbes.com\/#website"},"datePublished":"2015-01-21T17:37:45+00:00","author":{"@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904"},"breadcrumb":{"@id":"https:\/\/cms.digitalbes.com\/?p=73#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cms.digitalbes.com\/?p=73"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/cms.digitalbes.com\/?p=73#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cms.digitalbes.com\/"},{"@type":"ListItem","position":2,"name":"Security Advice You Can Count on when it come to your computer and the internet"}]},{"@type":"WebSite","@id":"https:\/\/cms.digitalbes.com\/#website","url":"https:\/\/cms.digitalbes.com\/","name":"Digitalbes Limited Premium Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cms.digitalbes.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cms.digitalbes.com\/#\/schema\/person\/501f983dd73df2b3abf7b41c11a10904","name":"dbl","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32bb84d38230af21f8f3323e55011359ebae16aa5c7b6554ae4fbbdc77b32582?s=96&d=mm&r=g","caption":"dbl"},"sameAs":["https:\/\/cms.digitalbes.com"],"url":"https:\/\/cms.digitalbes.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/73","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=73"}],"version-history":[{"count":0,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=\/wp\/v2\/posts\/73\/revisions"}],"wp:attachment":[{"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=73"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=73"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms.digitalbes.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=73"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}