Date: Sun, 30 Dec 2001 09:38:56 +0800 From: Raymond <[EMAIL PROTECTED]> Subject: Re: [LIB] Security
At 04:37 PM 29/12/2001 -0800, you wrote: >Date: Sat, 29 Dec 2001 16:35:01 -0800 (PST) >From: David Chien <[EMAIL PROTECTED]> >Subject: Re: [LIB] Security > >In any case, a good firewall like ZoneAlarm on the highest security settng Watch the freeware version though ... > + >the latest windows patches + webwasher to prevent popup windows, cookies, >webbugs, and more + the use of a non-IE webbroser and non-Outlook mail client >(my recommend is Netscape 4.79 with Java turned off & Javascript in Mail and >News turned off LYNX AND PINE!!!!! > + a good virus scanner (eg. McAfee) with the latest updates and >finally, www.pgpi.com's PGP Disk will help keep your PC secured from outside >hackers, safe from most silly Outlook/IE bbased attacks, and all of your >private data encrypted away from prying eyes. Don't count on PGPDisk against a major corporation, a government or a particuarly tech-savvy and highly resourced group. There are ways of extracting the passphrase or passphrase hash based on analysis of the pagefile if your implementation of PGPDisk doesn't guard against that or if your OS doesn't allow pagelocking (I don't think 9x does), it also doesn't guard against unencrypted data being written to pagefile whilst you're viewing it (and hence being extractable either off the pagefile or by analysis of residual magnetism on the hard drive which tends to survive up to 3 rewrites and possibly longer). If you've got information that such groups would regard as being valuable enough to take a crack at you'd need to get a little more paranoid (I'm talking clearing swapfiles and running cryptographically secure disk wipes after every viewing of encrypted data). Oh ya, and all this is no good if your passphrase itself is insecure. >I laugh as other poor IE/Outlook users keep getting hacked/viruses/exploited >with my Netscape-based, secured Libretto. Now hey, IE is secure if you turn everything off as you've done with NS ... at least as secure as NS (and before you say anything, I use Netscape/Mozilla at work and Netscape/IE at home ;-) Outlook Distress I dare say hasn't got an awful lot going for it though, I stick to Eudora and Pine for my email (at least Eudora does the HTML emails correctly without running ActiveX junk ... doesn't guard against an embedded con/con or similar though) ... - Raymond --- /~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\ | | "Does fuzzy logic tickle?" | | ___ | "My HDD has no reverse. How do I backup?" | | /__/ +-------------------------------------------| | / \ a y b o t | [EMAIL PROTECTED] | | | HTTP://www.raybot.net | | ICQ: 31756092 | Need help? Visit #Windows98 on DALNet! | \~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~/ ************************************************************** http://libretto.basiclink.com - Libretto mailing list http://libretto.basiclink.com/archive - Archives http://www.picante.com/~gtaylor/portable/faq.html - FAQ -------TO UNSUBSCRIBE------- Reply to any of the list messages. The reply mail should be addressed to: [EMAIL PROTECTED] - Then replace any text on the message's subject line: cmd:unsubscribe --------TO UNSUBSCRIBE DIGEST------ Do above but with this on subject line: cmd:unsubscribe digest **************************************************************
