Securing your computer

(2000-may-22 a brand new page, a muddled mess so far. I'll impose organization later.)

PGP is about securing your communications, and to a certain extent your files by encryption. Privacy is about hiding your life and activities from those who have no business knowing about it. Security is about securing your computer, especially your Net connected computer from snooping and malicious meddling.. They're related, and you will see some overlap in the links.


CERT. "At the CERT Coordination Center, we study Internet security vulnerabilities, provide incident response services to sites that have been the victims of attack, publish a variety of security alerts, research security and survivability in wide-area-networked computing, and develop information to help you improve security at your site.

Bastille Linux is a script for hardening an installation of RedHat (or RedHat derived, like Mandrake) Linux. It walks you through a long interview and writes a script, which you then run.

Gibraltar is a project that aims to produce a Debian features GNU/Linux-based router and firewall package. This package will be bootable directly from CD-ROM, so hard disk installation will not be necessary.

Linux Firewall and Security Site. This guy also wrote Linux Firewalls.

Security Watch.com Not Lynx friendly.

Linux Administrator's Security Guide

LinuxSecurity.com

Saint "The Security Administrator's Integrated Network Tool (SAINT?), an updated and enhanced version of SATAN, is designed to assess the security of computer networks."

The Top Ten Security Threatsat S.A.N.S Institute (System Administration, Networking and Security)

OpenSSH. "OpenSSH is a FREE version of the SSH protocol suite of network connectivity tools that increasing numbers of people on the Internet are coming to rely on. Many users of telnet, rlogin, ftp, and other such programs might not realize that their password is transmitted across the Internet unencrypted, but it is. OpenSSH encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other network-level attacks. Additionally, OpenSSH provides a myriad of secure tunneling capabilities, as well as a variety of authentication methods." Get it, use it. There are versions for most OS', and some incompatibility issues. Get it, use it, uninstall telnet.

viri

Virus Hype news from IBM

Ditto from CIAC

Computer Virus Myths homepage

F-Secure Virus Info Center

Gibson Research has a couple freeware utilities to help secure Windows. And some other cool stuff:

"Shields up!" will test your connection.

Sygate Online Systems has a similar firewall tester.

Opt Out Internet spyware detection and removal. "Spyware is ANY SOFTWARE which employs a user's Internet connection in the background (the so-called "backchannel") without their knowledge or explicit permission.

Spyware Suspects

A privacy analysis of your internet connection. Your mouth is shut. Is your computer spilling the beans?

Breaking, Sept. 1999: A Back Door for the NSA in Micro$oft Windows? Perish the thought!

ZoneLabs "ZoneAlarm - personal firewall that allows you to block/permit access from/to your 'puter. V. neat, and FREE for personal use." Appears to be for Windows.

" you can learn about threats from the internet as well as test how safe your computer is when connected to the internet by going to https://grc.com/x/ne.dll?bh0bkyd2" (but the usual Lynx won't take you there.)

"Do net lookups and what not at:http://SamSpade.org"

Security Focus. Not Lynx Friendly (but navigable).

Know Your Enemy: Motives

Steve Gibson of Gibson Research on Packet Sniffers

Freeveracity, an intrusion detection system.

The Complete, Unofficial TEMPEST Information Page. " TEMPEST is a code word that relates to specific standards used to reduce electromagnetic emanations. In the civilian world, you'll often hear about TEMPEST devices (a receiver and antenna used to monitor emanations) or TEMPEST attacks (using an emanation monitor to eavesdrop on someone). While not quite to government naming specs, the concept is still the same."

A paper describingTempest resistant fonts. The fonts themselves can be downloaded here.

more on Tempest.

Why Iptables rocks..