11 ms·
Comparing how security experts and non-experts stay safe online
- phlo 11y agoBrilliant. Measuring how well typical users understand/implement security measures has long been overdue. Personally, I find Figure 2 (on Page 5) of the paper most interesting: it shows the difference between expert and non-expert mentioning certain practices -- which to me seems roughly equal to how under-/overappreciated that practice is. The top contenders for underrated (i.e. used more frequently by experts compared to non-experts) are: System updates, 2-factor-auth, password managers, unique passwords and checking for https. Most overrated: antivirus, password changes, only visiting known sites and using strong passwords. As a security community, we appear to have gotten the point across when it comes to antivirus and strong passwords. Anyone giving general advice should consider this and emphasize the "underrated" measures.
- sarciszewski 11y ago> Anyone giving general advice should consider this and emphasize the "underrated" measures. Funny enough, we did exactly that last month! https://paragonie.com/blog/2015/06/guide-securing-your-business-s-online-presence-for-non-experts https://paragonie.com/blog/2015/06/guide-securing-your-busin... Unfortunately, Archive.org did not crawl us before this Google blog post came out, so I can't prove that I did not ninja edit the post. Google has a cache from July 8, though: https://webcache.googleusercontent.com/search?q=cache:-ovweQsOFBMJ:https://paragonie.com/blog/2015/06/guide-securing-your-business-s-online-presence-for-non-experts+&cd=1&hl=en&ct=clnk&gl=us https://webcache.googleusercontent.com/search?q=cache:-ovweQ...
- tptacek 11y agoThe thing that software security people do that most normal people don't do is: browsing and accessing email in a virtual machine, not their actual machine.
- sarciszewski 11y agoThis is true. I'm hoping the "browse in a VM" thing catches on with the public, even if it's for the "I want to hide my browser history from my significant other" sort of reasons.
- EdwardCoffin 11y agoI'm a bit surprised that using a virtual machine was mentioned nowhere in the paper. Edit: I'm also surprised that we have such a large proportion of this discussion talking about something (using VMs) that is mentioned nowhere in the paper the thread is supposedly about. Perhaps if we were also discussing the (apparently) surprising fact that it was not mentioned it would make sense (to me, anyway).
- ihsw 11y agoCan we settle for containers instead? For example, running Chrome in a Docker container. Why not? Drawbacks? Security risks? Feasibility? I understand that users download things but personally I can't recall doing that in recent memory, other than things like news/tech spec PDFs for later review. Moving downloaded files out of the browser's container would involve a fair bit of ceremony (physically selecting files/folders and dragging them out of the browsers "Download" folder and onto the host's file system, disallowing saving files outside of that folder, and so forth) but it doesn't seem that bad. What do most users do with a browser other than open the thing, browse websites, and download files for later?
- tptacek 11y agoNo. I'm barely on board with the pain/benefit of running an isolation VM. Containers provide so much less isolation than VMs, it's hard to imagine they're worth the inconvenience. (I hate VMs so much I just use two computers).
- thematt 11y agoWhy do you hate VM's so much? Usability? Or is there some technical reason?
- JupiterMoon 11y agoDo security experts place less emphasis on virus scans because they do their browsing on OS for which virus scanning is less important? EDIT This question is partly motivated by wondering if a Linux browsing user should be running a virus scanner?
- sarciszewski 11y agoNot really. It's more of: - many would prefer to whitelist trusted software than blacklist malware - bypassing AV is trivial - http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf - https://github.com/Veil-Framework/Veil-Evasion That many security experts use GNU/Linux or *BSD is definitely a factor, but many people still use Windows. Great question, though. :)
- Zikes 11y agoSecurity experts have more faith in their ability to avoid triggering a scenario where a virus has the chance to gain a foothold. That's why there's such an emphasis on patches, to plug the holes they can't see to personally.
- gmac 11y agoI'm not a security expert, but I don't use any 'continuous scan' anti-virus on my Mac because I strongly suspect it would make the system more vulnerable, not less. See, for example, https://lock.cmpxchg8b.com/sophailv2.pdf https://lock.cmpxchg8b.com/sophailv2.pdf
- lmm 11y agoIME: No, it's because they know virus scanners are ineffective. Security experts on windows also don't run virus scanners.
- jcrawfordor 11y agoIn my personal and professional experience, A/V is effective but not in the way you might think. A/V has a very good detection and quarantine rate for situations where the infection vector is bloody obvious. When you open the .zip attachment to that email and then go right on ahead and run the .exe inside, that's when a good A/V product will save you. What I'm saying is that I view A/V as protection from users, not from malicious actors. In a corporate environment with mixed-skill users, A/V is key. On my own devices, I don't frequently get into situations where A/V would be effective, the threats that are more likely to get me are more sophisticated. This isn't to say that I don't have Windows Defender enabled, but I don't see a value return in purchasing a commercial product.
- progmal1 11y agoI am going to have to go with the non-experts on items 4 and 5.
- JupiterMoon 11y agoIn terms of only visiting websites you know. Unless you block adverts most websites you know serve a lot of content from organisation you don't know.
- noipv4 11y agoNamebrand home router vs pfSENSE router.
- nhf 11y agoA plug for our paper, also at the SOUPS conference. We tackled a similar topic, but with a different method and broader focus (how experts and non-experts in general conceptualize the internet as a system): https://www.usenix.org/system/files/conference/soups2015/soups15-paper-kang.pdf https://www.usenix.org/system/files/conference/soups2015/sou... It's great to see a large company like Google focusing on this kind of work though.
- taeric 11y agoI am personally concerned with the "patch, patch, patch" message. Stated that way, I completely agree with it. However, for many it is just "update, update, update." I'm all for getting the latest security patches. Or any security patches, really. I'm growing tired of getting the latest possibly risky feature from a product because it is the only way I can get a security patch.
- gesman 11y agoTwice daily "Adobe updates are available, please download and install!" - annoys me to no end
- stephengillie 11y agoIt frustrates me that EVERY day when I open the Pandora windows desktop app(lication), an Adobe AIR popup asks to install an update. EVERY day! I know Agile is hot and all, but is their AIR framework so fresh that they constantly have to fix things?
- wlesieutre 11y agoThis is an exaggeration. I did not have to update Adobe AIR today. I did update it yesterday though!
- wlesieutre 11y agoAnd hey, at least they didn't make an "Adobe AIR Update Manager" that wants to run in the background 24/7. I'm honestly surprised.
- JupiterMoon 11y agoThis is what the average Linux distributions repositories are for.
- wlesieutre 11y agoJust yesterday, Windows Update automatically installed a driver for my GTX 970. It broke OpenGL and I had to go to Nvidia's website to get their standard driver and reinstall it. And since Windows 10 breaks the ability to block specific updates, I'll probably have to keep the installer around and reinstall it every damn time that Windows Update decides that the driver MS is distributing is better than the one from nvidia.com. I'm a techy and I completely understand why users ignore updates. Either it's invisible and the user doesn't know it happened, or it breaks something with no obvious way to revert, or it arbitrarily changes things that were fine how they were. So their perception ends up being "every time it updates, things get worse."
- joosters 11y agoBut are the security experts actually safer online? The study seems to assume that they are. It may be a fair assumption, but it would be interesting to know if it actually is true or not. It would also help validate the security practices. If it turns out that the security experts got infected just as much, or only slightly less than the non-experts, then following their practices might not be worth the effort...
- theseatoms 11y agoIf they aren't safer online, that'd be a sign to me that I shouldn't bother trying to do everything right. I don't want invest the time and energy developing expertise when even those that have it don't use it.
- TempaTaccount 11y agoAre the security experts are target more likely to attract those who might want to compromise them for bragging rights?
- joosters 11y agoYes, plus it might be true that security experts visit riskier websites because of the nature of their research. It's a difficult task to try and balance these factors out to make a useful comparison.
- dublinben 11y agoIt depends on what your definition of safety is. The perspective of this paper probably relates to compromised accounts and information leaks, not adware infections.
- joosters 11y agoI haven't completely read the full paper yet (it's pretty big), but in a brief scan, I can't actually find any definition they use for staying safe. They talk about 'protecting their security online' and 'to stay safe online', however I didn't spot anything more specific. As you point out, there are a variety of attacks and big differences between e.g. leaking a password or getting a virus infection. But since their highlighted techniques cover both of these attacks (virus scanners, password best practices), you have to assume that they are relating to a whole range of attacks.
- platz 11y agoHow do I apply my patch,patch,patches to TurboTax, Adobe Reader, and Skype? I don't think we're talking about the same applications here when comparing security experts and non-experts.
- emergentcypher 11y agoOne bit of advice that should be up there is to run an ad blocker and a flash blocker (not so relevant anymore now that FF started blocking by default). I know, I know, websites depend on ads for revenue. But ads are also a great way to deliver exploits, in addition to all the personal tracking ad networks do. Our number one priority is to protect ourselves, not to protect website revenue.
- Balgair 11y agoFor the lazy: https://addons.mozilla.org/en-us/firefox/addon/ublock/ https://addons.mozilla.org/en-us/firefox/addon/ublock/ https://www.ghostery.com/en/ https://www.ghostery.com/en/ https://cs.nyu.edu/trackmenot/ https://cs.nyu.edu/trackmenot/ https://addons.mozilla.org/en-us/firefox/addon/self-destructing-cookies/ https://addons.mozilla.org/en-us/firefox/addon/self-destruct... https://noscript.net/ https://noscript.net/ Anything I missed?
- asquabventured 11y agoublock origin is the original creator maintaining the code. it is better than ublock! https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ https://addons.mozilla.org/en-US/firefox/addon/ublock-origin... Some others potentially worth installing: https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere https://www.eff.org/privacybadger https://www.eff.org/privacybadger I prefer this over Ghostery. You can also for the most part replicate Ghostery by just downloading an appropriate filter for Ublock Origin. https://addons.mozilla.org/en-US/firefox/addon/betterprivacy/ https://addons.mozilla.org/en-US/firefox/addon/betterprivacy...
- ipsn 11y agoOdd that they did not mention VPN, Tor, User Agent spoofing, tracker blockers, flash blockers, and so on.
- medmunds 11y agoNot entirely surprising the experts ranked "install software updates" #1, but it didn't even make the non-experts' top 5. We, as an industry, still have a long way to go in making it easy and safe for consumers to keep their software up to date. Have you ever tried to explain to someone (outside the industry) which "click to install the latest version" messages are important to obey, and which are malicious?
- jacquesm 11y agoAnd which, even when they are not intended to be malicious will break your system in an unrecoverable way...
- modeless 11y ago[Non-experts] mistakenly worry that software updates are a security risk. I think this betrays a lack of thought about the risks to non-experts. Tons of malware masquerades as legitimate updates, and non-experts don't always have the knowledge to distinguish legitimate updates from malicious ones. Therefore, to non-experts software updates are a security risk. Edit: And this is why Chrome's policy of updating automatically and completely silently is the right thing to do, and everyone else (Adobe, Oracle, Microsoft, looking at you) is doing it wrong.
- gruez 11y ago>Microsoft With windows 10 they're doing forced updates for home editions, so there's that.
- modeless 11y agoBut are they doing silent updates? Any update that requires a reboot is not silent, and as far as I can see there's been no progress in silent updating since Windows 7. It is definitely possible to patch vulnerabilities in memory without rebooting my computer; heck, most malware will silently patch the vulnerability it used as part of the infection process; Microsoft just can't be bothered to do it themselves.
- scholia 11y agoIt's more reliable to install patches as part of a reboot because you know what's loaded and where it is. When you have 1.6 billion users with such disparate hardware and software, even a small improvement can help tens of millions of users. I expect Microsoft has lots of telemetry on this....
- modeless 11y agoWhen you have 1.6 billion users, every time you waste 5 minutes of their time installing updates and rebooting, that wastes 190 human lifetimes worth of man-hours. I know that Microsoft does not properly account for this when deciding how much effort to allocate to making updates less intrusive.
- zzzcpan 11y ago> The high adoption of antivirus software > among non-experts ... might be due to the > good usability of the install-once type of > solution that antivirus software offers. Or due to the fact, that antivirus companies make money on selling antivirus software to non-experts and have a long history of advertising it to non-experts as a security solution.
- iulia_ion 11y agoYep, it seems that marketing works. :D
- Canada 11y agoSomething obvious seems missing: Our systems can be hacked, expert or not. Minimize online footprint. Do not keep years and years of email and other stuff on Internet connected devices, back it up to external media.
- rilita 11y agoWhat kind of security experts are they talking to... My personal list of most important things to do: 1. Run a version of Linux ( Windows is simply insecure ) 2. Use Firefox + NoScript and only ever temporarilly allow JS to run as needed. ( JS is -not- safe and at any point in time there are at least a handful of zero day exploits ) 3. Use an offline password manager ( KeePass ) 4. Use a secure anonymous non-logging VPN for all internet use 5. Use a paid private email account, not some free one 6. Use VMs for running software that may not be safe
- eldridgea 11y agoThose sounds good but I'm shying away from Firefox at the moment for security. I love their open source approach and would prefer my browser to be open source. However Firefox does not have tab sandboxing, extension sandboxing, or process isolation. These are pretty standard features in most browsers now (except for process isolation which seems to be Chrome only at present).
- peterwwillis 11y agoThis seems misleading. Good security jerks know that there isn't a rule that works for everything. This list might be a little misleading to the non-security jerks. For example, 'software updates' are half the battle, but the other half of the battle is configuring your software to be more secure (browser sandboxing, NoScript, pop-up blockers, malware detectors, OS hardening). All the rest of the security concerns are authentication-based, but there are very few accounts that are important enough to need a secure account. Banks and money transfer services, business accounts (taxes, professional services, ebay/etsy merchants, etc), followed e-mail accounts, are probably the only really critical accounts most people have. You can hack my Facebook or my Huffington Post account; it doesn't really threaten my safety. I think the one thing nobody does that would actually matter to them eventually is keep offline backups. Facebook might lose all your pictures and FB messages tomorrow. They have zero responsibility to keep that crap for you. If you do get hacked and someone deletes all your pictures, don't go crying to Facebook; they have enough problems. At the end of the day, the biggest threat to your online safety in general is malware. Once malware is on your device it's game over.
- ozim 11y agoSeems like another attempt of google to get phone numbers from users. Experts are using two factor authentication, review your security settings and give us your phone number. Maybe I am a bit paranoid...
- cmurf 11y agoI've had my mom use lastpass for a couple of years, and just recently enabled grid multifactor auth (free). The main thing about their multifactor options is you can optionally "trust" a computer and only do multifactor on it once. So she won't have to ever use multifactor, but it's mandatory elsewhere which essentially keeps everyone else out while not changing her workflow.