dispatchrabbi / half-day-security-guide

Got half a day and nothing to do? Level up your electronic privacy!
MIT License
3 stars 0 forks source link

Feedback from Bernie #51

Open dispatchrabbi opened 3 years ago

dispatchrabbi commented 3 years ago

Summary of the feedback up top, the whole email is included below.

IoT:

Routers:

VPN:

Browsers:

Webcams:

EULAs:


Bernie's feedback in whole:

Harold,

I think this is well written and well thought out. I agree with all the recommendations I saw, especially the ones about smart (IoT) devices. I'm frankly terrified by the potential abuse of them. Dana lectures about this; IoT devices are a stalker's best friend. Most people don't secure them and even if they do, IoT security is pretty lacking (to be generous). I got a really nice fancy IoT thermostat (essentially free from PSE &G), but I'm kind of reluctant to install it.

I'd add a few things to this paper:

In the section on routers: Many/most people get their routers from their ISP if they have a broadband connection (e.g. you and I get ours from Comcast). They come pre-configured to work out of the box and usually have a pre-assigned SSID and password (which you need to get started).

You should change these settings to your own SSID (often they have a startup that facilitates this for you) and password. You should also change the administrator login/password and the admin password should be different from your wifi password.

Some routers allow multiple SSID's and some come pre-configured with 'public' ones. Comcast does this. Your router will also have an Xfinity wifi SSID unless you turn it off. This is how Comcast (or Verizon or RCN or Cablevision or whoever) can make the claim they have a gazillion 'public' access points. They do - and your house is one of them! Usually these require an ISP account (such as with Comcast), but often you can get into another ISP's network (e.g. Spectrum) using your Comcast credentials (they often turn off the credentials requirement during disasters). They share somewhat. Which is nice for us users, but a foreign entity is now inside your private network device. When I'm out and about I can often access Xfinity wifi in stores on my phone. No need to manually log in; iphone does it all and I've got free wifi access without the store's knowledge.

Not as big a deal where we live, but in high density populations (e.g. high rise apartment building) bigger exposure.

On VPN's: everything they said is good, but I think if you value privacy and anonymity, they're worthwhile. HTTPS encrypts traffic on the wire, but doesn't hide endpoint info; a VPN makes you look like you're in LA or London or Paris (which can be useful for some things, amusing for others. Like getting Amazon prices in Euros). I use one on my main computer almost continually.

On Browsers: They're correct about Chrome, but don't mention Edge, which comes standard with every Win 10 PC. It's essentially the Microsoft version of Chrome. Really. Full of tracking, too.

If you want higher security and no #$%^ ads or tracking, the browser of choice now is Brave. I often use Brave with my VPN turned on and - voila! - no ads, no tracking. If I go to a commercial website, I don't suddenly see ads from them in my email sidebar. Bonus: it's faster.

On Webcams: This used to be commonly publicized, but in the Zoom/Covid era seems not. Get a privacy cover for your webcam and cover it when you're not using it. Late model laptops often have one built in, most external webcams have some sort of cover. You can buy stick on sliding ones for older devices for a few $ online. Worth it.

On EULA's; They don't mention this, and it might freak people out, but the terms of service for most everything these days, the End User License Agreement, pretty much gives every vendor the right to look at all the bits that go through their apps in any way (sometimes more). So Google can read all Gmail messages, for instance. And they really do. It's bots, but they're still doing it. Virtually all free email systems do this as well as many other apps. It's all fodder for big data analysis for advertising. Or propaganda. In some cases, you can opt out of some areas (like sharing your data with their partners), but they don't make it easy and often an update will reset this. There really isn't much more you can do, especially given lax US law in this area (EU is a bit better. Asia mostly worse.)

If you want the convenience and utility of these apps (of course you do!) you're pretty much stuck. But better to be aware even if you tolerate it.

Enjoyed reading this. Always appreciate having my opinions and prejudices independently confirmed. :-)

Bernie

cajunluke commented 3 years ago

Routers:

sgtm; we should add those things

VPN:

I agree that what we've got is good

Browsers:

I'd rather not even mention Brave, the whole organization seems sus. We should mention that Edge is now Credge and has similar issues to Chrome.

Webcams:

We should also mention opaque tape :)

EULAs:

sgtm

cajunluke commented 3 years ago

@dispatchrabbi did we ever implement these suggestions?