Sunday, September 17, 2006

Top 5 Tips to NOT Get Hacked Online

Update: WashingtonPost blogger Brian Krebs agrees with me on #1. "My advice: If you or someone you care about is in the habit of cruising the Web with IE, now would be a very good time to get acquainted with another browser that doesn't use IE's rendering engine, such as Firefox or Opera." Porn websites are exploiting IE 6 0-day vulnerabilities.

“Oh my God, I’m never doing anything on-line again!,”
is a common reaction to one of my web application hacking presentations. Recently I’ve been demonstrating how easily the average website or user can be hacked. No doubt scaring audiences has a certain mass appeal and gets people to pay attention to why the right security practices are of vital importance. People frequently ask if I still bank or shop online (of course I do), or how they can protect themselves when they do. For those who are not experts in computer security, here are my top 5 tips to a safer online experience (in addition to having firewalls, anti-virus, and patching diligently).

1) Switch your web browsers to Firefox, Mozilla, Safari, or anything else besides Internet Explorer
This is probably the single most important thing you can do to protect yourself online. I’ve mentioned before that I’m a fan of staying secure by staying out of the line of fire. Internet Explorer is well known for being in the crosshairs of viruses, spyware, and adware. I know I know, Microsoft is releasing the highly anticipated version 7, supposedly a security light-year ahead of everything else. A web browser so revolutionary it’s being pushed as a mandatory upgrade! Talk about an attractive target for malicious hackers. In my view it’s best to use an alternate product and remain out of the fray. If a website REALLY does need IE and you REALLY need to use the website, make sure the website is legit, then it’s reasonably safe to fire up IE.

2) Add more security to your web browser
No matter what browser you choose, the Web is a hostile place and they all need a little help to defend themselves. NoScript (Firefox extension), Netcraft Anti-Phishing Toolbar, E-Bay Toolbar, and Google Toolbar are great products that do just that. These add-ons help identify phishing websites, prevent your computer from being hacked, and passwords from falling into the wrong hands. Most people will only need the first two add-ons, but if you are an E-Bay buyer, using theirs is essential is well.

3) Don’t click on links in email, almost ever
Whenever possible try NOT to click on any links in email, especially since links are themselves are dangerous and phishing emails are difficult to spot. An ounce of paranoia is worth a pound of patches. If I’m unsure if an email is real, one thing I do is manually type the domain name into the web browser location bar. This way I know I’m on the real website. If Wells Fargo were to ask to verify my account information by “clicking here”, instead I type in then proceed to login. If Wells Fargo, or whatever the organization your doing business with, really wanted to verify the account information they would have asked at that point. Some email links are safer to click on than others. Like those sent in response to an action (account registration, password reset, order confirmation, etc) you might have performed on the website within the last several minutes.

4) Defend your Web Mail!
Hundred of millions of people use Web Mail, which in many ways email is more important to keep secure than your bank account. Many people have important online accounts tied to a single Web Mail address. If anyone gained access to your email account, all accounts associated to could be compromised as well. The best thing you can do is use unguessable passwords, change them ever six months or so, and don’t use that password anywhere else. Bonus points for deleting emails with any sensitive information.

5) Use a single credit card for online purchases
In light of recent events, chances are the CC #’s we use online are going to be stolen at some point. For that reason it’s best to try and limit any potential damage. Using a single credit card with just enough of a limit to conduct your online transactions makes it easier to monitor statements for any strange charges. Plus, any fraud is isolated to that one card. Also, refrain from using a debit card online since they don’t carry the consumer legal protections as credit cards.

Normally this is the part where the experts start talking about SSL and tells you to check for the lock symbol. In my experience just about every legit website accepting credit cards is now SSL-enabled. So the better advice is to make sure your actually on the legit website you think you are on. Otherwise SSL isn’t going to matter much anyway.


Jeremiah Grossman said...

Feedback from Jim Bonds:

Greetings, Jeremiah

I was reading over the above listed article and though I might interject a bit of information regarding a couple of points you made. While all were excellent advice I think you may be mistaken on the Check Card point about it not being insured. I have been informed by more then one banking service and also ads on TV that MasterCard and Visa both now insure the check cards they provide. I know at one time this was not the case and may still not be covered by any of the others, but if this is in fact the case then it would be a very nice bit of information to share with your readers.

Secondly, on the topic of clicking URL links in mail, I have found that a program called Mailwasher Pro. " There is still a freeware version although no longer supported is still floating around the Net somewhere, and works just as well as for its purpose" The program is simply something you should not be without if you get large amounts of mail. It allows you to download a configurable amount of each email to determine if you want all of it or none at all, but the reason for mentioning it is the fact that it downloads the files in text format only and if the user has just a mild understanding of URL's then it is quickly evident when they are phishing links because it shows the entire thing with the normally hidden part perfectly visible.

Again I must say how good it is to see someone placing the commonsense information so that people will read it, I have been preaching the part about keeping a second limited and only for online use account to friends for years now, thankfully most have listened, and since about 3 years ago when the one that did not listen got nailed, the rest came around to my viewpoint quickly and without question after that ;-) .

Anyway, I do hope that you will get this through the channels as at a minimum the information about the Check Cards needs added.
Take care, and safe surfing!

Anonymous said...


I found another blog containing similar information. The post title is:
Buying And Selling Online - Computer Security

These are very useful for people who use the internet to purchase, not just for fun:)