Quote:
Originally Posted by Valkyr
|
You don't *add* security, you remove what is insecure, you monitor what is sensitive and you establish *trust* relationships between nodes.
I will attempt to describe what basic hardening an home network/computer should go trough. ( DSL, behind a nat ).
[Router configuration]
Disable wireless if you don't need it.
Disable upnp.
Foward the ports used to configure the router to a non-existent node (usually only 80).
Change the router's password to a strong one. (also the default account name, if you can)
Use OpenDNS.
Disable dhcpd.
[Host configuration] (Windows)
Go to services.msc and disable what ever you don't need.
Install an anti-virus.
Upgrade to Vista, don't use the admin account as a main account. DO NOT disable UAC, it's the only fucking reason i'm advising you to upgrade to vista if you didn't already.
Install the updates. (This is THE most important part in the Host configuration)
Dont use p2p, if you do, use torrents, exclusively.
Make use of a password and disable the guest, don't enable public sharing, don't install third party apps that aren't:
From a major company (Oracle, Microsoft [...] )
With a very high price tag
Open Source (OSI approved license)
(not even a yahoo/google/whatever widget)
Particularily DO NOT install third party drivers, or even download those from the web site, install only from the cd and patch them
No cracks, warez, mods [...]
.
DON'T even type any personal info and/or make use of a webcam.
Disable flash, javascript and java in your web browser.
(or make use of a different profile)
Don't use common protocols that are known to be phisher's paradise, MSN, e-mail [...].
A tad bit more advanced:
Setup a rescue live cd, backups and integrity checks.
Encrypt the shit out of sensitive data.
Setup an hardware firewall.
[...] Will add more later if anybody is interested... or even got trough the whole thing.