Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, May 29, 2012

Review: PacSafe CitySafe 400 GII Hobo Bag


Stated specifications:

Dimensions: 14.6" W x 13" H x 6.7" D (37 x 33 x 17 cm)

Volume: 884.8 in3 (14.5 L)

Weight: 1 lb 4.5 oz (580 g)

Strap length max: 33.1 in (84 cm)

Strap length min: 19.7 in (50 cm)

This is my fifth security travel bag and third from PacSafe, the other two being the CitySafe 200 shoulder bag and the StashSafe 200 waist pack. I wanted a cross-body bag and for it to be cavernously large for carrying my usual assortment of travel items like my notepad, camera, mini tripod, monocular/binoculars, water bottle, folding umbrella, and pareo plus air travel comfort items such as lumbar and neck pillows in addition to my small travel survival kit that fits into a waist pack like the PacSafe StashSafe 200 or Mountainsmith Nitro waist pack or about half of a gallon zip bag with the top half folded down. Because some museums and stores require large bags to be checked, I also bought a Baggallini Everything Bagg to easily take my wallet items, camera, and cell phone with me. It all fits!

Designed to foil pickpockets, slash-and-run, and slash-to-dump thieves, PacSafe anti-theft travel bags feature security closures as well as cut-proof straps and panels.

This particular hobo bag, which I got with a standard water-repellent jet black exterior and celadon interior (it's supposed to be lemon yellow) that makes it easier to see items inside, has an outside back pocket with a zipper at the bottom edge to allow the extended handle of wheeled luggage to slip through; there is an interior band to stabilize the bag.

The generous pockets at either end of the bag have cord locks to make the openings smaller so contents won't slip out and are more than large enough for a 1 liter bottle. The pocket that would be out of sight at the rear when it's carried as a shoulder bag has a D-ring inside at the top and at the bottom to secure items using my own utility carabiners or other fasteners to thwart pickpockets.

The padded strap, that has wires inside to prevent slash-and-run theft, may be detached at one end to secure the bag temporarily to a fixed object to foil a bag snatcher. The snap hook has a locking collar as an additional deterrent. The other end has a snap hook to secure the zipper pull of the bag's main compartment to stop a pickpocket from opening it.

The strap may be snapped up to make it shorter to convert the bag into a shoulder bag or left long to use the bag as a hip-length cross-body bag.

Because I tend to heavily load my travel bag and because the wires of the unpadded CitySafe 200 strap dug into my shoulder painfully, I went ahead and attached a removable Timbuk2 Gripster strap pad over the CitySafe 400 GII's too thin-looking shoulder pad without even first trying it by itself. YMMV.

Inside the main compartment is a variety of pockets. Along the front wall, that is the inside wall of the front of the bag, there is a zippered pocket, 7" W x 14.5" L, with a press hook fastener to hold anything like a key ring.

Below the zipper of that pocket is a line of:

1. A split key ring to which I attached a mini key ring LED to help me see what's inside the bag.

2. A pocket, 4.5" W x 5.25" L.

3. A pocket, 3.25" W x 5.25" L.

4. A pocket, 4.25" W x 5.25" L, labeled "RFIDsafe" to hold passport and credit cards containing RFID chips to prevent identity theft.

5. A fat pen pocket, 0.75" W x 5.25" L.

6. A fatter pen pocket, 1.25" W x 5.25" L, that will hold a standard highlighter if inserted cap down.

Those preferring the pockets could be closed can put their own self-adhesive Velcro coins or strips available from stores selling sewing notions.

Along the interior rear wall, there is one large pocket, 10" W x 15" L, that the enclosed literature says will hold a 13" laptop and an iPad or similar tablet. I found it holds my 15" laptop snugly. There's a strap that snaps over the top of the opening to ensure it doesn't slip out.

The bag's front, back, side, and bottom panels are all lined with eXomesh to prevent thieves from slashing the bag to let the contents fall out. The included literature has a diagram of the eXomesh rising to just under the top edge of the side pockets. On the front and rear panels, I can feel the top edge of the eXomesh about five inches up from the bottom, about three inches lower than in the side panels. I appreciate this sensible weight-saving design since gravity prevents items from falling up.

Overall, I'm exceptionally pleased with this bag. Purchased in January for travel to cities known for pickpockets and purse snatchers and slashers such as Barcelona, I've expanded its use to ordinary weekend getaways and other domestic travel.

Highly recommended.


Saturday, July 2, 2011

Grommets


I've been thinking about my soft-sided travel pack which has an easy-access zipper to the main compartment that can't be locked.

Since there might be times I need to check the bag during a domestic flight, foreign train stations usually won't allow baggage in their baggage-hold rooms if they can't be locked, and considering those Pacsafe wire nets are so darn heavy and might even lead a thief to believe there's something inside worth stealing, I've been thinking about putting grommets into my bag in a place convenient to insert a lock through them and the zipper pull.

Wal-Mart's sewing notions section has a Prym Creative eyelet kit for US$2.97 that should work, part #14015, the bar code on the back is #72879 25061. Maybe I'll put more in to lock the zippers on the outside pockets while I'm at it.

The discouraging thing is that suitcase locks are meant only to keep bags from opening accidentally during transit which could also be accomplished by safety pins or cable ties. While locks will also keep an honest person honest by discouraging crimes of opportunity, anyone determined to get into a bag won't be deterred.


Thursday, May 5, 2011

National Day of Prayer


This year's theme is Psalms 91:2 "I will say of the Lord, He is my refuge and my fortress: my God; in him will I trust."

What keeps going through my mind is:

"If my people, which are called by my name, shall humble themselves, and pray, and seek my face, and turn from their wicked ways; then will I hear from heaven, and will forgive their sin, and will heal their land." (2 Chronicles 7:14)

Fortunately, we can pray whatever our hearts desire and if it is His will, He will grant it:

1 John 5:
14. And this is the confidence that we have in him, that, if we ask any thing according to his will, he heareth us:
15. And if we know that he hear us, whatsoever we ask, we know that we have the petitions that we desired of him.

Because of the disasters all over the world as well as in the U.S., my prayer this year is for the healing of our land, air, and waters. I pray also for liberty and justice for all people, everywhere.

And, yes, of course, that "I will say of the Lord, He is my refuge and my fortress: my God; in him will I trust."


Matthew 18:19. Again I say unto you, That if two of you shall agree on earth as touching any thing that they shall ask, it shall be done for them of my Father which is in heaven.


Thursday, November 11, 2010

For Veterans on Veterans Day


To all veterans of the armed forces of the United States of America -

Thank you so very much for your service to our country! I treasure the freedom that you fought and bled for, for each one of us Americans. I am often appalled at how women are treated in too many other countries and thank God for letting me be born here with people like you who believe in protecting us and preserving our freedom.

My prayers are with you.


Thursday, October 28, 2010

Some Thoughts About Hiking


Several weeks ago, a friend went on a six-mile hike that turned into a nine-mile hike. When I asked if she went alone, she replied no, she had gone with a guy. She never hikes alone because if you fall, you might not be found soon enough.

True. However, there are easy to moderate trails where I can't imagine anyone falling that are popular enough that someone in distress would soon receive help.

Setting aside the different degrees of hiking difficulty, here are additional considerations:

1. Do you have a hiking staff or trekking poles that can support your weight to help you rescue yourself? Can your companion(s) carry you out or make a travois to drag you out?

2. Does anyone in your party have a cell phone and the number to call for a rescue team, usually the sheriff's department?

3. Can your or your companion's smart phone provide a GPS fix so the rescue team can be told your location? If not, do you hike with a GPS receiver? If your electronic devices fail or if you don't carry any, is your companion skilled enough with a map and compass to give coordinates for a search unit to begin looking for you?

4. If your companion goes for help, does s/he know the way there and back? Is anyone carrying a pen or pencil and paper, preferably waterproof, to give your coordinates to the rescue unit?

5. How will you protect yourself from dying of hypothermia/hyperthermia while waiting for help that might be many hours away? Do you have insulation from the cold and protection from the sun among your personal attire and emergency sheltering gear? Do you have a fire-making kit?

6. How will you prevent yourself from dying of dehydration while waiting for help that might be days away? Did you take more water than you expected you'd need or do you have the means to collect and purify water your companion might find in the area for you before s/he goes for help?

7. If your hiking companion is the one who gets injured, are you able to do the same things that you're counting on if you were injured?

It's this last point that bothers me. Too many times, I've found that women depend on men to bail them out of trouble to the extent they're virtually helpless. What if it's the man who gets injured?

After all, I once skied with a man who hit a tree. Another man got bucked off a horse and was knocked out for about an hour.

What if a companion hiker doesn't know where they are or how to get help back to the injured party? If it's a less popular trail, it won't be like in town where you can stop at a gas station to ask for directions.

This isn't a matter of one person being more able than another solely because of sex as if it's a matter of physical strength. It's a matter of knowledge and there's no good reason for anyone of either sex not to know or be able to figure out where they are and how to get back.

This isn't about my friend hiking with a guy, either, since I know she's gone hiking with women. The same thing goes for two women hiking together, two men, or a larger group, mixed sex or not. It isn't about her at all. This post contains some thoughts about hiking that arose after my exchange with her.

My point is that more than one person needs to know how to use a map and compass. Leaving the responsibility to a single person just isn't the smart thing to do.

If you hike or want to start, please take a navigation class or teach yourself how to use a map and compass from resources online or books from the public library and PRACTICE.

If you're not interested in hiking but know someone who hikes, please challenge her or him to ensure they know how to use a map and compass and encourage them to learn if they don't.

It's a basic skill for hiking and someone's life may depend on it.


Thursday, October 21, 2010

Cue Evil Laughter


All this preparedness stuff got me thinking about camping. This means I have to inventory my camping gear because a lot of things were stolen from my car when I was in San Ysidro, CA.

One of the items stolen was a BearVault. Although I'm not currently in bear country, a bear-resistant canister also protects food from being stolen by small creatures such as raccoons that are quite adept at accessing food campers thought they had secured.

Not only do I have to decide whether or not to replace the BearVault now or wait until later, I also need to decide whether to buy another BearVault or get a canister made by a different company.

Reading customer reviews, I was struck by a series of thoughts:

Considering that bears can break into cars but not into canisters approved by the Sierra Interagency Black Bear Group (SIBBG)...

Considering that BearVaults are made of super-strong polycarbonate, the same stuff used to make bullet-proof glass...

Considering that some campers were able to open their BearVaults to store food inside but missed meals because they weren't able to re-open them to get their food out...

Considering that I may have removed the label on the lid that has instructions on how to open the BearVault (I can't recall)...

Considering that San Ysidro, being a border town, has a majority Hispanic population and the thief might not have been able to read English if I left the label on (considering some restaurants there had menus only in Spanish and many business signs were in Spanish)...

Considering I had nothing worth more than US$20 stored in my BearVault (a coffee mug gift for a friend wrapped in a couple of shawls for cushioning)...

The thief likely expended great effort over a period of time to open my BearVault for very little reward, if it was ever opened at all!

Cue evil laughter.

I'm getting a kick from the thought of buying another see-through BearVault, putting a $20 bill in it, and Super gluing the lid shut just for the joy of knowing another thief will be aggravated by not knowing how to get the money out.

Except bear canisters are too expensive to buy just for the heck of it, I'd rather spend the $20 myself, and when the time comes, I've decided to try the Model 812 by Garcia Machine that can be opened, obviously, with a simple tool such as a coin.

Still, it's good to laugh at the idea.


Friday, August 6, 2010

D*@%! Spammers


Some low-down, no-good, dirty, slimy, frickin spammer(s) stole one of my domain names and an associated email address to forge email headers to escape detection and being shut down as they've done to so many other netizens.

As a result, I'm busy with damage control and what can be done to protect my other domain names.

Fortunately, the last few years have seen the acceptance of the Sender Policy Framework (SPF) record to help authenticate legitimate email. Had I known about and used it in time, it might have saved me from jumping through hoops getting up to speed this week trying to protect my domain from being blacklisted.

So far, I've set up and published SPF TXT records for my DNS to authenticate my outgoing email with the help of the SPF Setup Wizard. One thing I don't like about the wizard is that it doesn't give the option of -all which means the email is to be treated as spam if it doesn't match the passing criteria, although changing the softfail ~all to the hardfail -all is easy enough by manually editing it.

For the domain names that I'm not using for email, my SPF record is simply:

v=spf1 -all

because any and all email from those domains should be considered forgeries by spammers. Should I decide to use one for email later, it's easy enough to modify the record and republish it through my DNS.

I'm also transferring my domain name registration to another registrar, that I've been using since 1999, because it offers free privacy protection.

(I'd provide a link, except I can't find one for only domain registrations and the current website is all about packages. Using the same company for both domain name registration and web hosting is a really bad idea because you could lose both in one fell swoop. For an idea of how bad a situation can be, read some of the complaints at NoDaddy.)

Some registrars charge for the privacy service and my former registrar of the forged domain name doesn't offer it at all. I'm sure that's how the spammers got it because the email addy that I've seen in spam had to have been harvested from the public Whois listing since I use it exclusively as my contact email address for domain name registration and web hosting.

Just to make sure, I've also changed my contact email address on my website from a simple disguise that some might now be able to decrypt to an image that can't be read by computers. Visitors won't be able to click a mailto link anymore, but I don't get enough emails through my website to warrant my setting up an email form.

Maybe the slight inconvenience of having to read, manually call up their email client and enter my addy will discourage the weirdoes from emailing me like the guy who complained about my dissing pencils on one of my pen pages. (Please see the last paragraph for what I wrote about using a pencil and remember that I didn't make the rules; I was merely reporting them for my visitors' convenience.)

My next step is to set up a webpage to let any recipients of spam purporting to be from me know that I did NOT have anything to do with it. I've already created the page, but must wait for the registration transfer to be completed before I can set it up with my web host.

GRrrrrr...



Luke 6:28b ...pray for them which despitefully use you.


Friday, July 23, 2010

Wal-Mart to Put Radio Tags on Clothes


"Wal-Mart Stores Inc. plans to roll out sophisticated electronic ID tags to track individual pairs of jeans and underwear, the first step in a system that advocates say better controls inventory but some critics say raises privacy concerns."

For the rest of the article, please see the Wall Street Journal.

I remember there being a huge squawk several years ago because of privacy concerns when Wal-Mart embedded e-tags into other, non-clothing, soft goods.

These sound better because they're removable, if they're removed at the checkout counter.

If Wal-Mart refuses to remove them before we leave the store, I think shoppers should remove them at their cars and toss them into Wal-Mart trash cans to avoid taking them home.

A keychain knife or multitool such as the 2.25 inches long (closed) Classic model of Swiss Army Knife and Leatherman Micra, Squirt, or Style include a pair of scissors that might be ideal for this purpose.

The Classic SAK is available in several colors and designs from Amazon from US$9.50 and in red at Wal-Mart (US$9.97). The Leatherman keychain multitools which have more tools and, as a result, weigh more than the Classic SAK, start at about US$21.

Definitely get an RFID-blocking wallet if you have a driver's license, credit cards, or other personal information with RFID chips attached to protect yourself from snoops and the bad guys.


Wednesday, July 21, 2010

Wonderful Seatbelt Ad


Thanks to my dear friend, Roxie, I've just seen the "wear your seat belt" ad the UK started doing in January. From the news articles I've read about it, it's being hailed across the world as a beautiful commercial and is so popular, it's gone viral and has its own fan page on Facebook.

If you're behind the curve and haven't watched it yet, here's the link.


Friday, July 2, 2010

Her First Solo Road Trip


This week, there was a three-day visit with a friend from high school I haven't seen in eight years because of the distance between us.

As a former flight attendant who married a pilot, my friend is, undoubtedly, an experienced traveler by air. She enjoys getting lodging through Priceline saying that's how she gambles.

Isn't she smart? She never loses money that way plus saves money by getting nicer rooms for less.

What makes this trip especially exciting is that it's her first solo road trip because her husband didn't want to drive from Texas to Nebraska and back with all the stops she planned along the way.

Among our sharing, reminiscing, and verbal battling caused by her pushing me to live my life as she sees fit (Yes, she lost points for that!), we discussed her preparations and the rest of her itinerary only changing her whistle for an extra Fox 40 Micro I happened to have because it's much louder and her keychain flashlight for one that's brighter that was leftover from a bunch I got to give out for Christmas.

(Isn't it interesting that I just happened to have them? Isn't God good?)

I also gave her a next generation 2-AA Mini Maglite LED flashlight because it has the SOS feature along with an accessory pack with a red lens so her night vision won't be impaired should she have to check a map at night.

Since I know many women who want to travel but won't go by themselves, I applaud her for not allowing her husband to deter her from pursuing her dreams.


Wednesday, December 30, 2009

Laptop Cable Lock


Boy, do I feel dumb.

Have you ever not seen something right in front of you simply because you weren't paying attention?

That's what happened to me.

I bought my current laptop online from Dell early in 2008 and kicked myself for not ensuring that it had a security port after not being able to find one on the back or right side like it was on two previous laptops. Most laptops have it and, since my last laptop was made by Dell and had a security port, I expected the feature to be standard on the series. Sure, I could have returned the laptop and gotten another, but I liked the other features too much which is why I selected it in the first place.

So, for close to two years, I haven't taken my laptop to the public library because I couldn't figure out how to secure it and didn't want to have to carry it with me every second.

However, on Christmas Day, probably due to the atypical blizzard that shut down mid-Oklahoma through the top half of Texas, I found myself contemplating the ports on my laptop where I discovered one on the LEFT side that I didn't remember having seen before.

"Wait a minute. That looks like..."

I got my cable lock, fit it into the hole, and it locked down tight. Sure enough, the left side is where Dell put the security port for this laptop. Boy, do I feel dumb for not noticing it before!

If you didn't know there's a way to secure your laptop, examine the back and BOTH sides for a little rectangular hole that doesn't seem to have a purpose (photo below). Then, visit a store that sells computer accessories or search online for "laptop cable lock" for the type of lock you prefer. There are combination locks, keyed locks, locks with short cables, locks with long cables, locks with expandable or retractable cables, locks with motion detectors, and locks that will link more than one device together provided each device has a security port.

Because my last laptop was stolen from the locked trunk of my car in broad daylight, I recommend getting a cable lock and figuring out how to secure your laptop to a part of your car as an additional theft deterrent. While your home owner's or renter's insurance policy may cover the theft of your laptop, the loss of the data you have on it will be what devastates you unless you're really good about keeping a current backup. Even then, losing personal data puts you at risk of identity theft.

Better safe than sorry.



Thursday, July 2, 2009

What I Wish I Said


It's been 100 degrees hot for several days and when the temperature was in the low 90s on Tuesday afternoon, it felt cool enough for me to drive with the windows down.

So, there I was starting to back out of a parking space when a 30-ish man approached from I-don't-know-where and bent down to talk to me through the passenger window.

"Could you give me a ride to the store on the corner? It sure is hot," he said.

"Sorry," I said, "I'm not going that way." Then, I backed out and drove off in the opposite direction.

What I wish I said is, "What makes you think I'm dumb enough to give a ride to a complete stranger, a hitchhiker who wants to go only two blocks when it's cool enough that I'm not running the a/c?"


Thursday, March 6, 2008

What's Your Internet Safety Score?


Before I get to the tests, there are four more downloads I got since my last post.

On my stolen laptop, I had WinPatrol by BillP Studios because it uses a heuristics approach for checking system changes instead of comparing against a list that must be updated and downloaded periodically as do the other security software I mentioned in "The Bad, the Great, and the Tedious." After I downloaded it for this laptop, I decided to add SiteAdvisor by McAfee, available for IE and Firefox, because it isn't expedient to read the Privacy Policy for every website I visit and the nefarious websites don't come right out and say, "This site distributes adware and/or spyware." I also downloaded Opera because it's now free, is the first of only two browsers to pass the Acid2 test, and because the bad guys are paying more attention to how they might exploit Firefox. The other browser that passes the Acid2 test is the new Safari for Windows by Apple which I also downloaded to try out.

Now for the tests.

SiteAdvisor's website has two tests of eight questions each to gauge yourself in regards to spam and spyware.

"Are you spam savvy? Can you tell which sites will respect your personal information? Can you tell which ones might sell or rent your e-mail address to spammy third parties? Take our Spam Quiz and find out. Can you spot the spammy Web sites?"

How did you do?

My score: "YOU GOT 8 OF 8 QUESTIONS CORRECT Rating: Safety Guru."

Whoo-hoo! Thank God for the teachers who taught me how to read, although I hate plowing through those Privacy Policy statements!

"They say it's hard to judge a book by its cover. We'd argue that it's even harder to judge the safety of a Web site by its looks. Think you can sniff out which sites are adware & spyware free? Take our spyware quiz and see."

Did you score higher than, lower than, or the same as on the spam quiz?

My score: "YOU GOT 6 OF 8 QUESTIONS CORRECT Rating: Tightrope Walker."

I'm not concerned about one of my wrong answers because I don't use file-sharing sites, but the other wrong answer was for lyrics sites and I have used a few of them on occasion. Now, with SiteAdvisor, I'll know which sites to avoid when I google to verify song lyrics.

How safe is your PC? Here are some tests for you to run on your computer to see if the nasties can get in and if they can send your data out or enslave your PC without your knowledge:

On the Gibson Research Corp. websute:

ShieldsUP!

LeakTest.

On the PC Flank website:

A quick test for now until you have time to do the rest.

A leak test

A stealth test

A browser test

A Trojans test

An advanced port scanner test and,

An exploits test.

There are also tests from other sites.

Some observations:

My ZoneAlarm Free passes GRC's LeakTest, but fails PC Flank's Leaktest which exposes a particular vulnerability. I used Firefox and didn't even have to open Internet Explorer as instructed by the PC Flank leak test. My laptop failed repeatedly until I figured out how to make it pass.

One important thing to note is that the little PC Flank window ALWAYS reports that the test failed, even when it doesn't, so be sure to check your results on the webpage. The last little window has a link to it, also. When your PC passes the test, you won't see your IP address, the date and time you did the test, or the text you typed. (I can't help wondering: If they're so good at making tests, why didn't they make their little window display the right test results? Harumph!)

How to disable this vulnerability and pass PC Flank's Leaktest if all else fails:

1. Set your firewall to request permission each time IEXPLORE.EXE is used.

In ZoneAlarm Free under Program Control, this is listed as Internet Explorer. Under Access and Server, click and select Ask so that question marks appear in all four columns. When you use IE (or OE or Outlook), ZA will pop up a window for you to select Allow or Deny. Do NOT check the box for "Remember this setting" or your PC will be able to leak your data EVEN WHEN YOU'RE NOT USING IE (or OE or Outlook)!

To pass the leak test, do not allow IE to access the Internet. (In ZA, click Deny when the pop-up first asks for permission. Whatever you answer the second time, doesn't matter. Your data's already leaked out if you failed the test.)

2. Do NOT use IE unless you absolutely have to for those websites that don't display decently with other browsers such as Firefox or Opera or Safari because your computer WILL be vulnerable during those times.

Comments on the other tests:

I haven't done all of the other tests listed because Atelier Web, Breakout #1 and 2, Copycat, DNS Tester, Firehole, and Thermite set off the Avast! alarm while I was downloading them, which was neat to hear, and I want to verify that Avast! was giving false positives, that the programs are virus- and trojan-free, before I run them. While a couple of websites recommend them for testing, upon hearing the alarm, I decided to check them out further because I've known of safe files in the past that were perverted by the bad guys after they became popular to take advantage of their safe reputation in order to slip malicious code onto people's systems. Other tests simply wouldn't work.

The cpil.exe has left some PCs with something that keeps trying to start IE. Some people clear it up by simply rebooting. Some have had to download and install a HIPS program to stop it. Since I'm waiting to see if my system is affected and what I'll have to do to clean it up if it is, please don't run it. I figured it's okay for me to run because, if I should have to rebuild my system if it leaves trash behind that can't be cleaned up otherwise - the worst case scenario, it won't bother me so much since I don't have any personal files on it, yet. But if someone else has to do it, who has personal files, that may not be backed-up, and who wasn't expecting to spend time cleaning up after the test much less doing a system rebuild, well, let's just say that I don't want to get put on anybody's bad list. Of course, since you now are warned about it, go ahead and run the test if you want. Just don't blame me if it keeps trying to start IE and you have to clean up after it to make it stop.

Ghost, when I allowed IE to access the Internet, proved once again, that we shouldn't be using IE. In all fairness, though, bad people have always looked for ways to break into anything containing value and there's no reason to expect them not to continue. Remember, people didn't use to have to lock their house doors and could leave their cars unlocked with keys in the ignition and now there are security systems for both homes and autos in addition to our having to use the regular locks. Computer crimes are just another venue for the bad guys.

Jumper acted like it wasn't working, giving an error because my laptop wouldn't let it create a file on my C drive named jumperleaktest_dll.dll, but it then proceeded to hijack my IE home page to change it to http://www.google.fr, a harmless change that demonstrates that a bad guy could make something worse happen, even though IE was never open during the test. Scotty, my faithful little watchdog from WinPatrol, caught it and warned me so I could stop it.

The TooLeaky test was passed because I told ZoneAlarm to Deny it the first time. After that, when I had ZA Allow it, it was passed because it couldn't run scripts, ActiveX controls, or plug-ins due to my setting them to Prompt which I denied when action was requested. I never did let them run during repeat tests, either.

(In IE version 6, see Tools -> Internet Options -> Security tab -> Internet -> Custom level. Under "ActiveX controls and plug-ins," set "Download signed ActiveX controls," "Run ActiveX controls and plug-ins," and "Script ActiveX controls marked safe for scripting" to Prompt. Set the others in that section to Disable.

Next, directly below, is a Download section. Set the three listed there to Disable. Be sure to remember doing this so you can change it back when you want to download files or fonts you want, except you won't be using IE as much after reading this post and conducting the tests, right?

Anyway, after that, there's another heading for "Scripting." Set the three there to Prompt. You may be tempted to set "Active scripting" to Enable because you're likely to be prompted a lot as I am; it's your PC, your choice, and your risk if you want to Enable it. Click OK to save changes.

While you're at it, you may as well go over to the Advanced tab and ensure that the box for Java is clear. Click OK to save changes. You can always go back to check the Java box if you need it.)

WallBreaker consists of four tests. The first and third tests are especially sneaky in that they got around ZA which didn't ask for permission for IE.

Remember, it's not just what gets into your computer from the outside that can mangle your hard drive, it's also what goes out that can hurt you and others.


1 Peter 5:9. Be sober, be vigilant; because your adversary the devil, as a roaring lion, walketh about, seeking whom he may devour.


Friday, February 29, 2008

The Bad, the Great, and the Tedious


Taking me three times as long as I should have to find the half-dozen items on my list because the store is rearranged, I find myself in the electronics department next to the laptops looking at accessories.

"What's the difference between a notebook and a laptop?" a male customer asks a saleswoman.

A few questions later, she falters at his asking about wireless.

"May I answer that?" I ask. At their response, I continue, "All new laptops should come with wireless by now. What you need to watch for is which standard they're using."

"Which standard?" he asks.

"Yes, the draft 802.11n is 80% approved and will be official maybe late this year, surely sometime next year. With such a high percentage of approval, some companies are making compliant products already. If the computer you want doesn't use the 802.11n standard, you should wait, if you can, to buy it when it does because it's so close."

An older saleswoman joins us, then goes and checks their routers. "Here's one," she calls over to us. He and I go over to her while the first saleswoman leaves.

"Yes," I point to the box. "See this? This is the standard you want. Make sure your laptop and router match." I point to another router. "See this box? It uses an older standard. If you get the 802.11n on your laptop, it'll work because it's backwards compatible, but it won't be as fast. As long as you're buying new equipment, you may as well get the latest technology."

"How do you know about this stuff?" he asks. "I took some classes to learn about computers, but they didn't teach anything about this."

"I used to be a programmer; different system, but the principles are the same. If two sides don't use the same standard, they can't communicate or don't communicate as well as they could."

"Oh, no wonder! Say, can you tell me how people are able to steal other people's data when they're using wireless?"

The saleswoman leaves.

"Essentially, it's radio like your cordless and cell phones, just a different frequency, and the sniffers tune in. That's why you'll need to get a VPN, a Virtual Private Network, if you'll be doing anything sensitive like using passwords and doing online shopping or banking. A VPN makes a tunnel for your data to go through so sniffers can't see it. You'll have to google to find one. If you just surf and read, don't worry about it because you won't be submitting any personally sensitive information."

"Thanks a lot! I learned a lot and I think you gave me more help than the salespeople would have."

"It's possible. I just ordered my fourth laptop and I've always known more than the salespeople."

"Fourth laptop?" His eyes are big.

"The first hardly counts because it didn't have the hard drive I wanted. The salesman lied about the size and I had it about two months while going through him, his manager, and up to the district manager before they accepted it back. My third got stolen last July while I was in California and the fourth is to replace it."

It's Monday evening and my new laptop arrives the next morning, more than a week earlier than Dell said to expect it, only five days after I ordered it. Wow! How great is that? Not only did it arrive a lot faster than my last one, it doesn't have all the pre-loaded trial software crap I had to delete off the other. Much better!

I'm ready to go online with it before the new CD from my ISP arrives, so I decide to set up the connection myself since I have my username, password, and the ISP's phone number on my eight-year-old laptop.

First, download and install a firewall from ZoneAlarm to keep the hackers out. Check.

Next, the ShieldsUP! test at the Gibson Research Corp. to ensure the firewall didn't leave any open ports for the hackers to sneak through. Check.

Firefox because it's safer than Internet Explorer. Check.

SpywareBlaster to prevent malware from getting into those little hidden places in the first place, probably why Ad-Aware and Spybot-S&D never found anything after I ran it on my old laptop. Check.

Ad-Aware. Ad-Aware. Ad-Aware. Ad-Aware. In four tries, I can't get more than half a meg of the free version to download. Hmm, it hasn't found any adware, spyware, or other malware since the first time I ran it on my old laptop, so maybe I'll be okay without it for awhile.

Spybot-S&D to catch and kill malware if it gets past SpywareBlaster and its own defensive measures. While it overlaps a lot of what Ad-Aware covers, it also covers what Ad-Aware misses, and vice versa. That's why it's best to have two good antispyware programs. Check.

Avast! antivirus software to handle viruses, trojans, and worms. Check.

System updates - there are 41 of them. (No, I didn't get Vista.) The estimated download time at 49 Kpbs is over seven hours. How tedious. I think about going to the library to use their high-speed connection, but rather stay here watching "Monk," "Without A Trace," and "Law & Order" on TNT and USA. I fall asleep and nap during a couple of episodes of "Walker, Texas Ranger." Check. Finally.

I guess maybe I'll start working on my (ugh) income tax return tomorrow during the "N.C.I.S." marathon on USA.

Or maybe not.


[Note: SUPERAntispyware is another good antispyware program but since it's weak on defensive measures, takes about an hour and a half to run, has a bit of nagware, and doesn't uninstall cleanly, it's best reserved for cleaning up spyware and malware that other antispyware programs can't eradicate.]