Date: Sun, 30 Dec 2001 09:38:56 +0800
From: Raymond <[EMAIL PROTECTED]>
Subject: Re: [LIB] Security

At 04:37 PM 29/12/2001 -0800, you wrote:
>Date: Sat, 29 Dec 2001 16:35:01 -0800 (PST)
>From: David Chien <[EMAIL PROTECTED]>
>Subject: Re: [LIB] Security
>
>In any case, a good firewall like ZoneAlarm on the highest security settng

Watch the freeware version though ...


> +
>the latest windows patches + webwasher to prevent popup windows, cookies,
>webbugs, and more + the use of a non-IE webbroser and non-Outlook mail client
>(my recommend is Netscape 4.79 with Java turned off & Javascript in Mail and
>News turned off

LYNX AND PINE!!!!!


> + a good virus scanner (eg. McAfee) with the latest updates and
>finally, www.pgpi.com's PGP Disk will help keep your PC secured from outside
>hackers, safe from most silly Outlook/IE bbased attacks, and all of your
>private data encrypted away from prying eyes.

Don't count on PGPDisk against a major corporation, a government or a particuarly 
tech-savvy and highly resourced group. There are ways of extracting the passphrase or 
passphrase hash based on analysis of the pagefile if your implementation of PGPDisk 
doesn't guard against that or if your OS doesn't allow pagelocking (I don't think 9x 
does), it also doesn't guard against unencrypted data being written to pagefile whilst 
you're viewing it (and hence being extractable either off the pagefile or by analysis 
of residual magnetism on the hard drive which tends to survive up to 3 rewrites and 
possibly longer). If you've got information that such groups would regard as being 
valuable enough to take a crack at you'd need to get a little more paranoid (I'm 
talking clearing swapfiles and running cryptographically secure disk wipes after every 
viewing of encrypted data). Oh ya, and all this is no good if your passphrase itself 
is insecure.


>I laugh as other poor IE/Outlook users keep getting hacked/viruses/exploited
>with my Netscape-based, secured Libretto.

Now hey, IE is secure if you turn everything off as you've done with NS ... at least 
as secure as NS (and before you say anything, I use Netscape/Mozilla at work and 
Netscape/IE at home ;-)
Outlook Distress I dare say hasn't got an awful lot going for it though, I stick to 
Eudora and Pine for my email (at least Eudora does the HTML emails correctly without 
running ActiveX junk ... doesn't guard against an embedded con/con or similar though) 
...


- Raymond

---


/~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\
|                 | "Does fuzzy logic tickle?"                |
|   ___           | "My HDD has no reverse. How do I backup?" | 
|  /__/           +-------------------------------------------|
| /  \ a y b o t  |          [EMAIL PROTECTED]             |
|                 |          HTTP://www.raybot.net            |
| ICQ: 31756092   |   Need help? Visit #Windows98 on DALNet!  |
\~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~/




**************************************************************
http://libretto.basiclink.com - Libretto mailing list
http://libretto.basiclink.com/archive - Archives
http://www.picante.com/~gtaylor/portable/faq.html - FAQ
                 -------TO UNSUBSCRIBE-------
Reply to any of the list messages. The reply mail should be
addressed to: [EMAIL PROTECTED] - Then replace any text
on the message's subject line: cmd:unsubscribe
              --------TO UNSUBSCRIBE DIGEST------
Do above but with this on subject line: cmd:unsubscribe digest
**************************************************************

Reply via email to