»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 12-15-2003, 12:13 PM   #1 (permalink)
Guest
Guest
 
Posts: n/a
The Ten Immutable Laws of Security

http://www.microsoft.com/technet/tre...s/10imlaws.asp

for the security freaks


just and FYI if you didnt know

  Reply With Quote
Old 12-15-2003, 12:18 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Posts: 6,533
John Prophet is on a distinguished road
funny that it comes from msoft, lol.

Sorta like Enron doing an article on "How to find an accounting firm you can trust"
__________________
"Even a fool is thought to be wise if he is silent"
John Prophet is offline   Reply With Quote
Old 12-29-2003, 09:56 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Location: NC in the US
Posts: 3,732
Redwolf is on a distinguished road
Send a message via ICQ to Redwolf Send a message via AIM to Redwolf Send a message via Yahoo to Redwolf
Quote:
Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore.
Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore.
Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore.
Law #4: If you allow a bad guy to upload programs to your web site, it's not your web site any more.
Law #5: Weak passwords trump strong security.
Law #6: A machine is only as secure as the administrator is trustworthy.
Law #7: Encrypted data is only as secure as the decryption key.
Law #8: An out of date virus scanner is only marginally better than no virus scanner at all.
Law #9: Absolute anonymity isn't practical, in real life or on the web.
Law #10: Technology is not a panacea.
1) You mean like what is done automatically with IE?
Okay, low blow there, but it's true.

2) Yep.

3) So true. Get a firewall

4) *cough* *cough* Run Apache *cough*

5) Instead of using the recommended Biometrics as recommended (impractical unless you really need the security), use random passowrds. Some password generators make random-but-easy-to-remember passwords 5 chars in length. Always add numbers and symbols to a password (makes it harder to crack). Get i the habit, unlike me , of changing critical passwords every month or so (especially important for websites).

6) If using a UNIX/Linux system, be very very careful who gets access to the root password. That goes along with this rule.

7) This is where programs like PGP and GPG come in handy (for the uninitianted, both programs encrypt so that the information can is locked by 1 key, but can only be unlocked by another, different key (the public and private keys))

8) Yep

9) Yep

10) Highlight the part about social engineering.
Redwolf is offline   Reply With Quote
Old 12-29-2003, 10:03 AM   #4 (permalink)
Registered User
 
Bill in SD, CA's Avatar
 
Join Date: Oct 2002
Location: Bottom left of U.S.
Posts: 4,714
Bill in SD, CA is on a distinguished road
Law #11: Never buy an OS full of security issues.



Bill
Bill in SD, CA is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 04:33 PM.