05 July 2013

Google Chrome / Chromium

Google Chrome / Chromium Portable

Chrome has made a strong showing.  While initially fast it can also become a resource hog.  Partially driven by the popularity of Android and the synchronization options in Google services.  Some reports have Chrome at a 45% market share of all browsers.

Chrome also shares the two main values as Firefox over IE, flexibility and a large selection of extensions.

Flexibility
Chrome is a casual browser that I use and I have not yet personally looked at any of the 'about:' menu options.

Extensions
For me Chrome does not have comparable versions of  all the extensions that I like and use in Firefox.  One of the reasons Firefox continue to be my primary browser as mentioned in the previous post.  However Chrome does have a version or comparable version of extensions for all your primary security and privacy extensions.
ScriptNo
AdBlock
Netcraft AntiPhishing
Ghostery
Collusion


If you do not like the heavy hand of big brother Google, you can alternately run Chromium, or like I do Chromium Portable.
Chromium is the original open-source project on which Google Chrome is based.  It has all the same base browser functionality but does not have all the integrated Google services.
If you are familiar with "portable apps" there is also a custom Chromium Portable available for use.  I personally prefer the portable apps when I can find them.  The concept behind portable apps is that they are "self-contained" and do not use the typical Windows installer and does not write to the registry.  This allows for the application to be stored on a usb drive and easily used on more than one system.  For example if you travel and want to carry your favorite apps without losing your preferred settings etc.  Or simply if you do not want to clutter your Windows OS with a ton of installation data.  I highly recommend giving Chromium Portable a spin around the block.


Alternately if you are looking for that Chrome feel with pre-built security in mind check out the custom version from Comodo, Comodo Dragon


Google Chrome / Chromium Portable

04 July 2013

Mozilla Firefox

Mozilla Firefox

While Firefox has lost a lot of its luster for me it is still my primary browser.  I have been using Firefox since the early 0.x days when it was still called Phoenix.  The original lore and draw was that it was based on open standards, was lite weight, and very fast.  Since then and partially due to the general change in web technologies and their implementation Firefox has joined the ranks of bloated, slow, hoggish browsers.  I've been looking something better but today it seems to be an issue of which is the least bad rather than which is the best.

Firefox has two exceptional values, flexibility and a vast selection of extensions.

Flexibility
While I have not personally delved to far into the flexibility arena, I do occasionally utilize customizations via the 'about:' menus.  Mozilla 'about:' is an entire set of subjects unto itself and will not be covered her.  Just know that it exists and query it in your favorite search engine.  You might find some options you like.

Extensions
Much like the do not track lists available in IE, there are many privacy extensions for Firefox from cookie management to script restriction, to do not track, to data obfuscation.
Some of my favorites include
NoScript
AdBlock
Netcraft AntiPhishing
Ghostery
Collusion


Alternately if you are looking for that Firefox feel with pre-built security in mind check out the custom version from Comodo, Comodo IceDragon


Mozilla Firefox

IE

Okay this one is a break from the focused objective.
Ideally I will only discuss tools that are free and replace the usually inferior native tools in Windows.  Sure, sure, I already mentioned Microsoft Security Essentials, but that is not technically native, it is a separate download.

But it is time to talk about Browsers, and honestly I have to include IE in the discussion.  Despite its reputation IE has come a long way and the last couple of versions have actually been climbing the secure browser rankings.  The biggest single flaw in IE is still ActiveX.

While IE is not my personal browser of choice there are some services that just run better on it.  This is and will hopefully continue to change with the broader adoption of HTML5.

As the OS gets more secure and as more OSes gain larger market share and as more services turn to web based models more attacks are targeting the browsers.  The average user probably does more on their device from a browser than any other application.  Thus browser security is paramount.

While IE is lacking in the add-on department there are some options to consider.

Tracking Protection - Currently there are 11 options from 7 different companies.  Review which one fits your needs best and start regaining some of your privacy.

InPrivate Browsing - This effectively disables local logging of internet activity.  Keep in mind any other logs by your ISP, the remote web server, search engine, etc. are still collected and stored remotely.  If you want to flush your cache after a session start by using InPrivate Browsing.

ActiveX Filtering - Enable this one.  Read up on some of the additional options for ActiveX under Internet Options.  The extra prompts may save you from some malware.

Smart Screen Filter - This one is manual and has to be initiated by the user (you) for each page you want to check.   Play around with it.  Run it on sites you have not visited before.

Here is another blog with a round up of security settings for the big 3 browsers.

Remember a browser is just another tool.  It is how you use it that makes it safe or unsafe.
These things are designed to work out of the box, and most people never scratch the surface of their browser options.





03 July 2013

Anti-Malware

Anti-Malware, yeah it sucks, yeah it is easily evaded, yeah it is needed.

Say what you want about anti-malware but it is a component of defense in depth, and it does help the average user.  The question is less about should you run anti-malware and more about which one.

I'm going to high light 3 applications however there are many more out there.

Microsoft Security Essentials
Microsoft actually surprised me with Security Essentials when it was released.  It does not have the most options but at the same time that is not all bad for the average user.  I have been running Security Essentials for about 3 years and it has served me well.   I am also a wee bit paranoid about what I download and use several browser plugins.  Security Essentials is pretty much on or off.

  • It does not appear to use too much for resources.  
  • It also has a setting for max allowed CPU utilization.   
  • It has the usual custom and scheduled scan options.
  • It has the option to right-click and scan an individual file.
  • It ties in nicely with the Windows Security Center / Action Center.



Sourcefire Immunet
Admittedly I have not used Immunet for a substantial and dedicated period of time.  However I do like the company and it is based on the open-source ClamAV.  While Immunet is specific to Windows, ClamAV can run on most any OS.  For those folks that run multiple OSes this might give you more of a common feel across your devices.  Immunet is also fairly simplistic in the options available, though I would say it is a bit more flexible than Security Essentials.  Instead of a single on/off switch, Immunet has an on/off for various sub-components of its features.


AVG
AVG used to be the king of free anti-malware.  While I liked AVG it was a bit noisy and became annoying with all the various pop-ups.  AVG does offer the the most flexibility and configuration options.  It is typically favored by the more experienced users.

Just a small sampling of options.  Find one that you like and make it work for you.


02 July 2013

Secunia PSI

Secunia PSI

So the question is do I lead or follow with Secunia PSI?
As this is partially a ramp-up to DefCon ending on a security note would be appropriate.  However security is important and should not be left to wait, so grab this puppy and run it.

Personally I prefer the 2.x interface more than the 3.x interface.  With that said the interface in 3.0 has been tweaked since it's initial release mostly compensating for the aspects I did not like.  The addition of the list view is very welcomed.  As was the option to select between auto-update and notification only.

In theory the 2.x version is completely usable and will keep you just as updated as 3.x.  I have not attempted to run 2.x on Windows 8, mileage may vary.

Download and install is the typical double-click process, no surprises there.  Last I ran the installer the application was still pleasantly unbundled and did not contain any extra garbage, tool-bars, etc.

So why should you care and run Secunia PSI?
You are running Windows right? Enough said.  No seriously while Microsoft is making strides towards better security it is still a huge target.  As are many of the big name applications that run on Windows.

Secunia PSI will not secure or protect the OS or the applications themselves.  It will however alert you to the presence of a known vulnerable version of software and provide a link to the patch if one is available.  There is an option to allow Secunia PSI to automatically download and install patches.  Point being there is a distinction between having an up-to-date version of software and securely configuring said software.  Secunia PSI does not examine the specific configuration of the software, only that it is up-to-date.  For most of you average Windows users this is huge and Secunia PSI is incredibly valuable.  Even for seasoned users the task of ensuring your patch process each month is greatly simplified.

Secunia PSI will make you aware of exactly how much stuff is on your PC, and what most be updated.  Listen to it well.  Use it to eradicate the unnecessary bloat ware shipped with your new PC.  Use it to keep the high target apps up-to-date in near real time, Java, Adobe Flash, to name a few.

Every Windows user should take advantage of this wonderful and free app.

Secunia PSI

30 Days of Tools

So the gratitude diary was a fail.
Positive Comments May was a fail.  Or success as i really didn't say anything, depending on which side of the fence you are on.
A tune a day in June went well.
(All posted via other services.)

For July, to get back into more of a tech vibe and to force myself to blog more often I will be commenting on a tool a day.

Enjoy.

09 May 2013

Meaning of Life

So there i was sitting at the local DC Groups meeting with the rest of the DC214 kids and the same question crosses my mind.  What the hell am i doing?!  Yet another year, another project restart, another memory of another project never completed.  Then off in the corner i hear Rengade say to RedSand "dude your root kit talk is what made me realize i'm stupid and to get off my ass."  Yep, thanks Renegade that is about how i feel at this very moment, Shooting Blanks and all.

So what is to be done?  Buck up kiddo and pull on your big boy pants.  It is time to make shit happen.
1.) update this damn blog on  reasonable basis
2.) finish that network project
3.) do another talk for DC214

So.... With that i plan to return bearing topics of useful data and or opinionated banter.  Until then... keep hacking my friend.