drduh / macOS-Security-and-Privacy-Guide

Guide to securing and improving privacy on macOS
https://drduh.github.io/macOS-Security-and-Privacy-Guide/
MIT License
21.19k stars 1.45k forks source link

Miscellaneous nov.2 #70

Closed TraderStf closed 8 years ago

TraderStf commented 8 years ago

Hi DrDuh,

Up to you to evaluate and see what to do with these sites, remarks, questions or explanations collected from....., some are above my ItQ 👀

Sorry for my usual mess.

Thank you,



https://letsencrypt.org https://github.com/okTurtles/dnschain

http://thehackernews.com/2015/10/nsa-crack-encryption.html

http://www.cisco.com/web/about/security/intelligence/nextgen_crypto.html


FOR FASTER VPN


VPN for privacy... but VPN are always starting after other programs which might already have accessed internet...


Paranoia Who is behind these testing websites. Nice places to collect data, browser fingerprints... especially when you are testing your 'uncompleted/unsafe' configuration.

whoer, browserleaks, ipleak and similar, why so many 'secret/domain-by-proxy...' whois?


We use Google Public DNS server, which we consider unproblematic. It is not only the biggest public server with over 130 billion requests per day and works fast, but also does not store personally identifiable information nor IP-addresses permanently and all temporary logs are deleted after 48 hours at the latest. (from a VPN provider... don't remember)

Though Google DNS Resolvers are censuring several kinds of sites and are among companies providing data to bigbro...


2FA Don't forget to have a 'backup', e.g. like printed code for Google Authenticator, in case your phone is down.

TraderStf commented 8 years ago

https://www.verisignlabs.com/orscan/ Are Open Resolvers bad? Generally, yes.

TraderStf commented 8 years ago

Concerning VPN and IP4-IP6 leakage. http://blog.cyberghostvpn.com/dns-ipv6-leak-cyberghost-not-affected/

TraderStf commented 8 years ago

Beginner’s Guide to Open Source Intrusion Detection Tools https://www.alienvault.com/resource-center/white-papers/beginners-guide-to-open-source-intrusion-detection-tools

drduh commented 8 years ago

Thanks for the usual tips and guides. I will add these in over time as incremental changes, as I work through more thoroughly reading and reviewing them.

Re: ignoring proxy settings for localhost, the default seems reasonable.

Re: disabling IPv6, I am not an expert in the matter, so I would rather trust the defaults.