With all the recent hoopla about security issues going around, I thought I’d share some tips on how to keep your computer safe. I assume that you already know not to open attachments from strangers, and that you should always have a firewall and anti-virus program installed. This entry goes into a little bit more depth than that.

The router. Having a router is a first line of defense. Do not ever connect your computer directly to the modem. Due to how routers work, outsiders are unable to have direct access to your computer – unless you initiate the connection with them first, or modify the settings in your router to allow them to have access. An unpatched Windows XP machine that’s connected to the modem directly will be compromised in minutes.

The Internet browser. Aside from trying to get you by sending you virus-laden emails, the big way that the bad guys will try to get at you is through your web surfing. There’s two facets to this. Some bad guys will try to infect your computer outright, and turn it into a spam-machine. However, the more recent trend is to compromise your online identity: load custom code that gets your computer to spam Facebook or Twitter, without your computer itself being infected. This works by turning your web browser against you, and its much easier to pull off – all you have to do is surf to a website.
Older web browsers have no defense against this type of attack and will fall right for it. So if you’re one of the millions that still use the ancient Internet Explorer 6, switch. Newer browsers such as Mozilla Firefox and Google Chrome check what websites are getting your traffic, and look at the behaviour of the websites you’re on, and will try to warn you if it detects anything suspicious.
At the present time, Google Chrome is my browser of choice. I especially like that it patches itself regularly to defend against the latest attacks aimed at the browser itself. Firefox auto-updates as well, but usually you have to press a few buttons and it’s an invasive process. Chrome does it in the background and doesn’t require any user intervention.

Block ads. Even if you surf sites that are well-known and considered safe, the bad guys can still get some of their code to be loaded by your web browser. Third-party ads are one such approach. The ad company might be legit, but they might sell some advertising space to company B, who divides it up and sells it off to company C, D, and E. Company E might actually be a front for a cyber criminal. He loads in custom code, which then gets displayed on the legitimate site you surf. You and thousands of others get compromised.
Modern browsers such as Mozilla Firefox and Google Chrome have plug-ins you can download to block ads. I very much recommend that you make use of these.

USB Sticks. If someone else passes me a USB stick, I never run anything that’s on it without first scanning its contents with an anti-virus. If you have Windows XP, disable AutoRun, otherwise, the contents could be made to run automatically as soon as the device is inserted into your computer – and inject a virus along with it.
I remember that there was this kid whose computer I cleaned from malware. He put a USB stick that he had used during the infection back in, and his computer got infected all over again.

Beware of PDFs. Alright, so you already know to not open executable files (.exe and .scr) when you check your emails from anyone, including your family. You have to be careful with PDFs as well. Adobe Acrobat is a pretty popular target for bad guys. If you must open the files, then I use something like the Google PDF Viewer, which takes out the offending code.
Update: Check the comments section for some great tips from Sakuramboo!



















