beeldings
April 24th, 2005, 09:31 PM
One of the main reasons why I switched from Windows to Linux was due to a growing number of concerns about my privacy and malicious software. I have always been very cautious about who I give my personal information out to and what accounts I have opened with on-line merchants. While I strive to do whatever it takes to properly secure my PC and change my passwords every few months, I decided to make a new thread so the Ubuntu Community can share their tips and tricks for protecting their Linux machines and their privacy. I would now like to share with you what I've done to protect my PC and my privacy.
I have my Internet connection wired through a Linksys router which then connects to a hub, and from there the correct connection is made. On the software side of things, I have Firestarter installed with ICMP filtering enabled along with a number of outgoing ports blocked. I use Firefox with Adblock and the latest version of filters, as well as a hefty 1MB hosts file. Javascript is almost entirely blocked, I do need it to access my free web-based e-mail accounts. I only accept cookies from the web sites I shop at, everything else is blocked.
For e-mail my family and I use Thunderbird with HTML and remote images disabled. I am considering setting up PGP for the family e-mail account, but my main concern with using PGP on the family account is that most of the people we contact don't have PGP or don't know what PGP is (besides the fact that they use Windows), and it would be a lot of time and effort to convince them to use PGP.
About every two to three months, I use a random password-generator (http://www.msdservices.com/apg/index.php) to create new passwords for my accounts. My primary focus is on my bank account password. While I don't conduct any actual banking (i.e transfer funds or pay bills), I use my bank's web access feature to check my account statements and make various service inquiries. When I do access my bank account on-line, I always make sure to clear out the cache and any existing cookes and log-on to the account in a new browser window. When I log out of my account, I clear everything, and then shut down the browser.
As a personal rule, I do not store any sensitive information on my computer. Any files containing private information are copied to CDs, which I store in a safe, and then I delete the file from the hard drive.
I would consider myself to have a secure setup in terms of hardware and software-based solutions for my PC. However, I do have some concerns that I would like to share with the Community:
My number one concern is general web browsing. While I have taken steps to protect the integrity of my privacy, I feel as though I should take an additional step and use a proxy for HTTP access, not HTTPS access. However, I cannot seem to locate information regarding a trustworthy, free HTTP web proxy. Does anyone know of a solution?
My next problem is that I would like to further lock-down my PC. I have Firerstarter and the firewall in my Linksys router, but I'm not confident that they are truly securing my PC. I have recently started to enter all entries from the "Events" section in Firestarter into my hosts.deny file, and I have ALL:ALL and ALL:PARANOID in that file as well. What else should I install or configure in order to properly secure my PC? I would like to be able to freely access the Internet while keeping intruders out. Scans of my PC at GRC.com reveal that my machine passes the stealth portion of the tests, but I don't want to be lured into a false sense of security.
Finally, I would like to know if it is possible to encrypt the contents of my hard drive, and if and when I get rid of my PC or decide to sell my hard drive, I would like to know if there are any programs for Linux that would allow me to securely wipe all data from the drive so that it could not be recovered.
People tell me I'm a little too paranoid when it comes to this sort of thing, but my I believe that it's better to be safe and paranoid than a victim of ID theft and sorry.
I have my Internet connection wired through a Linksys router which then connects to a hub, and from there the correct connection is made. On the software side of things, I have Firestarter installed with ICMP filtering enabled along with a number of outgoing ports blocked. I use Firefox with Adblock and the latest version of filters, as well as a hefty 1MB hosts file. Javascript is almost entirely blocked, I do need it to access my free web-based e-mail accounts. I only accept cookies from the web sites I shop at, everything else is blocked.
For e-mail my family and I use Thunderbird with HTML and remote images disabled. I am considering setting up PGP for the family e-mail account, but my main concern with using PGP on the family account is that most of the people we contact don't have PGP or don't know what PGP is (besides the fact that they use Windows), and it would be a lot of time and effort to convince them to use PGP.
About every two to three months, I use a random password-generator (http://www.msdservices.com/apg/index.php) to create new passwords for my accounts. My primary focus is on my bank account password. While I don't conduct any actual banking (i.e transfer funds or pay bills), I use my bank's web access feature to check my account statements and make various service inquiries. When I do access my bank account on-line, I always make sure to clear out the cache and any existing cookes and log-on to the account in a new browser window. When I log out of my account, I clear everything, and then shut down the browser.
As a personal rule, I do not store any sensitive information on my computer. Any files containing private information are copied to CDs, which I store in a safe, and then I delete the file from the hard drive.
I would consider myself to have a secure setup in terms of hardware and software-based solutions for my PC. However, I do have some concerns that I would like to share with the Community:
My number one concern is general web browsing. While I have taken steps to protect the integrity of my privacy, I feel as though I should take an additional step and use a proxy for HTTP access, not HTTPS access. However, I cannot seem to locate information regarding a trustworthy, free HTTP web proxy. Does anyone know of a solution?
My next problem is that I would like to further lock-down my PC. I have Firerstarter and the firewall in my Linksys router, but I'm not confident that they are truly securing my PC. I have recently started to enter all entries from the "Events" section in Firestarter into my hosts.deny file, and I have ALL:ALL and ALL:PARANOID in that file as well. What else should I install or configure in order to properly secure my PC? I would like to be able to freely access the Internet while keeping intruders out. Scans of my PC at GRC.com reveal that my machine passes the stealth portion of the tests, but I don't want to be lured into a false sense of security.
Finally, I would like to know if it is possible to encrypt the contents of my hard drive, and if and when I get rid of my PC or decide to sell my hard drive, I would like to know if there are any programs for Linux that would allow me to securely wipe all data from the drive so that it could not be recovered.
People tell me I'm a little too paranoid when it comes to this sort of thing, but my I believe that it's better to be safe and paranoid than a victim of ID theft and sorry.