Download pdf - Fight Spam and Hackers!

Transcript
Page 1: Fight Spam and Hackers!

Fight Spam and Hackers!

BlogHer ’10Geek LabLiz Henry

[email protected]://liz-henry.blogspot.com

Monday, August 9, 2010

Page 2: Fight Spam and Hackers!

Look at me

✤ Now look at your blog.

✤ Now back to me.

✤ Now type your password.

✤ Your password is awful!

✤ Best defense against being hacked is thinking like a hacker.

✤ Your blog can think like me!

Monday, August 9, 2010

Page 3: Fight Spam and Hackers!

Surveys of the room

What blog platform:Blogger? (About a third)

Typepad? (A few)WordPress? (Most)

Others? (scattered few)

Social media sites: Facebook Myspace

Twitter (All but 3)Tumblr

PosterousOthers?

Blog Hacked?Big spam problem?Credit card stolen?

Complicated Identity Theft?

Monday, August 9, 2010

Page 4: Fight Spam and Hackers!

Monday, August 9, 2010

Page 5: Fight Spam and Hackers!

Freedom!!

✤ I believe strongly that as women we need free access to unfiltered information

✤ We must defend our right to speak in public, unfiltered

✤ Just like we can go outside into the world in public. A political right.

✤ Be cautious of being “protected”. What if your words or image are what others “need” to be protected from?

Monday, August 9, 2010

Page 6: Fight Spam and Hackers!

OMG Hackers

✤ No one really knows what they’re doing

✤ Pretty much anything can be hacked

✤ Because no one really knows what they’re doing, including security experts who revel in discovering each other’s silly mistakes. So don’t worry.

✤ You are more “at risk” from a piece of carbon paper from using your credit card in a store, or dumpster divers, than from being hacked.

Security advice constantly changes!

Monday, August 9, 2010

Page 7: Fight Spam and Hackers!

Where is the risk?

✤ On your computer. Keyloggers.

✤ Network traffic. Wireless.

✤ Web passwords to services.

✤ Widgets, pdfs, images, other people’s code on your blog.

✤ SQL injection.

✤ Your web host getting owned.

Monday, August 9, 2010

Page 8: Fight Spam and Hackers!

Shoulder surfing

✤ It’s pretty easy to watch someone type their password.

✤ Teach your kids password manners.

Monday, August 9, 2010

Page 9: Fight Spam and Hackers!

What do you risk?

✤ Bank accounts, credit card numbers. Other personal data.

✤ Losing your data - blog entries vandalized or deleted.

✤ Embarrassing vandalism - someone posting as you.

✤ Triggering security alerts on other people’s computers, getting blocked from search engines.

✤ Denial of Service attacks for malicious or political reasons.

Monday, August 9, 2010

Page 10: Fight Spam and Hackers!

Bad Passwords

✤ Your $%&#@! kitten’s name

✤ Your child’s name plus their birth year. Oh, please!

✤ Your favorite animal, sports team, pop star, or deity +123.

✤ Google for your password. Do you find it?

✤ Did you find it on a list of The 500,000 Most Popular Passwords?

Monday, August 9, 2010

Page 11: Fight Spam and Hackers!

Crackers!

✤ Educate yourself about how to crack a password!

✤ Google “how to crack passwords”.

✤ Google “choosing secure passwords”.

✤ Now you know how to make a much better password.

Monday, August 9, 2010

Page 12: Fight Spam and Hackers!

Password managers?

✤ 1password, keepass, other programs to track your passwords and keep them secure. Anyone use them? Kind of a pain.

✤ High security PWs: Don’t use them multiple places. Change more often. Longer. email. banks. money.

✤ Low security pw: have a few and use them for web apps, social media.

✤ Think about how to generate good passwords over your lifetime. You need a system - not one password.

Monday, August 9, 2010

Page 13: Fight Spam and Hackers!

Good password!

✤ Now your password is made of diamonds!

✤ Have a different password for email than for everything else. Email pw can compromise all your others.

✤ Wallet, file cabinet. All your other secure info is there anyway.

Monday, August 9, 2010

Page 14: Fight Spam and Hackers!

Make backups!

✤ Back up your blog entries and comments!

✤ If you get hacked, or DoSed, you have a backup.

✤ Your web host may have backups for you too.

Monday, August 9, 2010

Page 15: Fight Spam and Hackers!

Malware

✤ Antivirus software for your computer, especially for Windows

✤ Get to know the security settings on your browser

✤ Keep your OS, browser, other software up to date

Monday, August 9, 2010

Page 16: Fight Spam and Hackers!

Check your site

✤ Google Webmaster Tools

✤ Set up alert on site:http://yoursite.com casino + viagra + (whatever other common spam terms show up)

✤ http://www.unmaskparasites.com/ is currently kind of nice

✤ More good advice: www.stopbadware.org

Monday, August 9, 2010

Page 17: Fight Spam and Hackers!

Encryption

✤ https is awesome

✤ ssl (secure socket layer) encryption

✤ https://www.eff.org/https-everywhere is nice for Firefox

Monday, August 9, 2010

Page 18: Fight Spam and Hackers!

WordPress security tips

✤ Keep it updated!!

✤ Keep it backed up

✤ Keep the plugins updated

✤ Install some security scan plugins from wordpress.org

✤ Exploit Scanner, WP Security Scan

Monday, August 9, 2010

Page 19: Fight Spam and Hackers!

Harden WordPress

✤ http://codex.wordpress.org/Hardening_WordPress

✤ This is the best advice!

✤ HighTechDadBlog has decent advice too

Monday, August 9, 2010

Page 20: Fight Spam and Hackers!

Hack party

✤ Have a hack date

✤ Try to crack each others’ passwords

✤ I’m totally serious!!!!

✤ No really!

Monday, August 9, 2010

Page 21: Fight Spam and Hackers!

“I can’t believe you guessed my password was “MrDarcyishot69”!”

Guess their passwords

Monday, August 9, 2010

Page 22: Fight Spam and Hackers!

Be a white hat hacker

✤ Warn your friends if you notice their security vulnerabilities.

Monday, August 9, 2010

Page 23: Fight Spam and Hackers!

Who has your data?

The companies you’re giving your data to may do something with it you don’t like. Read their privacy policy/ToS.http://www.tosback.org/ tracks changes in companies’ terms of service.

Monday, August 9, 2010

Page 24: Fight Spam and Hackers!

Your Privacy

✤ If you want to browse, IM, and use the net without family members or others on same computer having access to your info,

✤ Put Torbrowser on a USB stick, and use that. Very secure.

✤ https://www.torproject.org/torbrowser/

Medical issues.Visiting your in-laws.

Reading pages your husband might not be comfortable with.IM and email you don’t want your kid reading.

End of relationship, or domestic violence situations.

Monday, August 9, 2010

Page 25: Fight Spam and Hackers!

I’m on a horseWell, not in this

photo, but at some point in life I was.Unfortunately in

this photo I’m giving a lap dance

to a giant fiberglass

lumberjack rabbit and his enormous

carrot water fountain.

Monday, August 9, 2010

Page 26: Fight Spam and Hackers!

When you get hackedGet some help and adviceDo a little researchYou are now a computer forensics investigator! Congratulations!Don’t panicRemember, you have backups!

Monday, August 9, 2010


Recommended