3 ms·
Yes, I forgot to mention I don't visit any questionable sites whatsoever. I've extremely vigilant, more vigilant than 99% of the population I would think, and I
by docker_up 7y ago
Yes, I forgot to mention I don't visit any questionable sites whatsoever. I've extremely vigilant, more vigilant than 99% of the population I would think, and I take it very seriously. If I need to test a link, I'll use my phone. I built my own desktop so no worries there, I don't have a CD player and I only install trusted apps these days, the only ones in the last few years have been Chrome and Firefox.
It's not the most secure method, obviously, but it works for me. And if the environment gets more dangerous than the status quo, I'm flexible enough to know I'll probably be forced to upgrade.
I'm not security-ignorant btw. I used to subscribe to both BugTraq and NTBugtraq back in the day and kept up over the decades. I just haven't seen anything in the last several years that can't be solved via not clicking on random links or installing new software. As said, spear-phishing/breaking out of the sandbox or serving malware via ads is my biggest concern these days and if it gets more prevalent then it will warrant a change in my views.
- fencepost 7y agoI forgot to mention I don't visit any questionable sites whatsoever. The problem isn't questionable sites (including ad networks), it's 0 days and hacked sites. uMatrix won't protect you from malicious js fed from the same site, or perhaps a malicious malformed font download[1]. [1] https://threatpost.com/of-truetype-font-vulnerabilities-and-the-windows-kernel/101263/ https://threatpost.com/of-truetype-font-vulnerabilities-and-...
- Bartweiss 7y agoYes, exactly. The bad news is that most antivirus software also won't protect you from a hacked NYT server delivering 0-days, because it's generally reactionary. For this reason, I mostly don't worry too much about about while-browsing protection - if you're cautious, the remaining threats will also evade antivirus. In that sense, uMatrix and NoScript are more proactive. (uMatrix, for example, saved people from Magecart before it was ever discovered.) But if you do pick something up, there's no guarantee it'll be nice obvious ransomware, rather than something quietly sniffing your keystrokes. That's where I advocate antivirus even for careful users - it's a repository of known threats to tip you off that something is wrong. DoublePulsar was first discovered infecting Windows machines in the wild, so cautious browsing didn't save the people that hit.
- Bartweiss 7y agoApologies if I implied you were ignorant, or at more risk than most people. Hearing that description, I'm willing to bet you're safer than most people who do run antivirus and the newest OS versions. (And safer than me, for that matter.) As far as principle, though, I think there have been things which can't be solved by avoiding sketchy links and emails? Bemstour was a mix of two NSA-discovered 0-days, which spent a full year in the wild before it was patched or disclosed. (Admittedly, the only known deployments were highly targeted, so it's not exactly grounds for personal paranoia.) EternalBlue was spun into the widespread WannaCry after the Windows 7 patch was released, but before Windows 8. (Having spent a while on 8 instead of 8.1 while 8.1 was still broken, that hits close to home.) I don't follow Windows that closely anymore, but haven't there been a few other botnets initiated with unpatched vulnerabilities that didn't require browsing somewhere ugly?