|
1. Security! |
I'm basing this newsletter on a chapter in my e-book where you can find much more detailed information, including screenshots and step-by-step instructions about processes.
Before we get started, let me make this clear: I am not paranoid about security, and I don't even use some of the things I'll be listing. Still, it is helpful to know that they are around and can be used.
Plus, as translators we would be foolish to completely ignore security concerns. Aside from the fact that we should be concerned about our own private data, we are also dealing with sensitive data belonging to our customers, and that comes with a certain amount of obligation and reputation to uphold. First we'll talk about the most common terms you'll run into regularly when investigating security issues. Then we'll talk about hardware and software strategies for protecting ourselves. |
| ADVERTISEMENT |
MemoQ - the very user friendly integrated translation environment which surpasses its competitors with its performance, savvy user interface and integration capability. MemoQ 3.0 is out with more than fifty new features, a brand new term base engine and simultaneous translation and proofreading of the same document. LSP customers report 100% satisfaction. Download the tool now and join the community! MemoQ users have even more fun now. |
| 1.2. The Terms |
|
Essentially we are concerned with two categories: malware and attacks. Malware -- malicious software -- is software that was designed to harm or enter into your computer system without your consent (duuuh). These are the most common types of malware:
- Virus -- Clearly, most if not all of us have been exposed to computer viruses, or at the very least we've heard about them. A virus is a program that can copy itself and infect your computer without you knowing about it. These days viruses are typically transmitted through web-based means (e-mail, web pages, instant messaging, etc.), but they can certainly also be contained on a CD or memory stick. Just as in real life, viruses usually require an infected host.
- Worm -- Here's a little application that can spread itself to other computers without requiring a host for the transfer. Once it's on a computer, it can do a whole lot of things, including turning the computer into a zombie (see below).
By the way, if there is anything cool about all these ugly intruders, it clearly must be the names. "Worm" happens to come from the 1975 science-fiction novel The Shockwave Rider, and we probably don't have to spell out where "zombie" or "Trojan horse" come from.
- Speaking of Trojan horses: these are computer programs that disguise themselves as something else while installing malicious software on your computer. Once the program is executed, a backdoor program (see below) can allow unauthorized access to your computer by other parties. Or a keylogger may capture entered data, such as login and password information, account and PIN numbers, which then are transmitted to a third party who will likely abuse them for personal gain. Often "social engineering" techniques, i.e., methods for manipulating us into stupidly giving out information or performing certain activities, are used to open or execute such files and programs.
- Spyware is software which in most cases is installed secretly on your computer. Just as the name implies, spyware primarily tries to spy on your habits and then transfers that information to third parties who use it for any number of things.
- Backdoor -- This is sort of a self-explanatory term. It's a program or a method that bypasses normal authentication and protection and allows remote access to your computer.
- Adware is probably the least malicious of the lot and is often used and installed with the users' consent. Especially in the early days of the Internet, this was a way to support free programs through advertising, such as the Web browser Opera or various e-mail clients. Some of the more obnoxious specimens of this kind may also generate pop-up ads.
Let's move on to attacks, those intrusions to your computer that take place without any malware.
- Phishing is an attempt to acquire sensitive information, e.g., usernames, passwords, account information, or social security numbers, by pretending to be someone else. To achieve this, phishing tends to employ social engineering techniques in an effort to fool you and have you hand over that information.
I cannot even imagine that you haven't received e-mails pretending to come from banks, PayPal, or any other paid service provider that ask you to just quickly reenter your credit card number or your Social Security number for verification purposes. The quick and easy way to find out whether these e-mails are real is to hover with your mouse over the URL and see whether the real URL matches the one that is being displayed, or whether it has anything to do with the sender.
- Drive-by download -- No, this is not a gang-related activity, though I could imagine that there might be a certain overlap among the practitioners. Essentially what it refers to is the download installation of a program without you knowing it, just by visiting a web site or displaying an e-mail message. This is one of the places where vulnerabilities in your operating system or your browser come into play, so it's always a good idea to have the latest round of patches.
- Denial-of-Service (DoS) -- This term sounds militaristic for a reason. A DoS attack is a well-planned and executed effort to cripple a computer resource such as an Internet site or a service. Typically, DoS attacks attempt to consume the resources of a targeted computer so that it can no longer provide its services to communicate with its users. It usually achieves this by using a lot of zombie computers (which could be your computer or mine) that are organized in a so-called botnet as the organizational structure that coordinates their wrongdoings.
- Man-in-the-Middle (MITM) -- A man-in-the-middle attack allows the attacker to read, insert, and modify messages between two parties without either party knowing that the link between them has been compromised. (If you're interested in more information about this particular kind of attack, I'm certain that the secret service organization of your country would be happy to provide it. . . .)
Of course, there are also things like banner ads, pop-up ads, spam, cookies, and other tracking methods. And, yes, these are annoying, but otherwise they're really not in the class of the above-mentioned perpetrators, so let's not worry about them for now.
|
| 1.2. Protection - Hardware |
|
So what -- aside from cutting our Internet connection and moving to some deserted island -- can be done to mitigate these risks?
Let's start with the most basic protection: the router.
By the way, many of you know that I just spent a year in Germany, and I can't begin to tell you how many discussions I've have about the pronunciation of "router." Most Germans are convinced that it is [roo'tər] rather than [rou'tər]. Still, that's not nearly as bad as their pronunciation of the application name Excel, which in German has the stress on the first syllable
The router is essentially a little magic box that sits between you and the Internet, preventing any incoming traffic to your computer unless you have specifically requested it in the form of webpages, e-mail, or a download. An additional benefit of routers includes the ease of a wireless or hardwired network set-up.
Typically a router comes with some small utility that allows you to set it up and get it going in no time. In case you don't have access to that program (anymore), it's easy to access your router by entering 192.168.1.1 (for routers from Linksys and Netgear) or 192.168.0.1 (for routers from Netgear and D-Link) into the address field of your browser. Enter your username and password (if you haven't changed it from the default username and password, it is most likely admin and admin) and set up the behavior of your router. If you choose to have wireless access, you should make sure to enter a password for that -- unless you would like your neighbors to join the party -- and you should choose the more secure Wireless G (802.11g) network type.
And while we're talking about handy hardware devices for protecting your computer equipment, here is one that I pooh-poohed for the longest time: cable locks. These are the things that hook into the so-called Kensington Security Slot (K-Slot) you can find on the side of most laptops, some monitors, and even desktop computers (I'm sure you've seen them used at your local computer dealer). Especially when you're traveling quite a bit, it's nice to be able to tie your laptop to some immobile object in your hotel room or at the airport to at least prevent a walk-by-stealing (how's that for a new term?) that might otherwise occur. |
| ADVERTISEMENT |
|
Jeromobot to the Rescue!
Overwhelmed by the wide array of translation environment tools out there?
Stumped by the myriad of features each tool says it offers?
Confused by trying to compare apples with oranges?
Translators Training was designed with you in mind. Providing unbiased, side-by-side comparisons of all the major tools, Translators Training saves you time and money as you choose the tool that's right for you.
Visit translatorstraining.com today and let Jeromobot guide you to clarity!
|
| 1.3. Protection - Software |
|
Now, let's talk about software. The most important programs you will want to have are a firewall, virus protection, and an anti-spyware program.
While most of these products come packaged in one of the various "Internet Security" suites, they are also available as standalone products.
Even if you (hopefully) already have a router in place to protect you from attempts to access your computer from the Internet, this protection is not available while you are traveling, nor does a router protect you from an infected computer located in your own network, for instance if your kid's or colleague's computer were infected or taken over by hackers. Also, most routers for the small office and home office market consider all outgoing network traffic to be benign, even though this is not always the case.
This is where firewall software comes into play. It checks both incoming and outgoing network connections, at least if it's a full-fledged firewall. (Up until Windows Vista, the Microsoft Firewall only inspected incoming traffic but did not look at outgoing traffic.)
Most of the current firewall products have taken into consideration that most users are not sufficiently familiar with the sometimes cryptic names of applications that try to connect to the Internet (would you have known that msimn.exe is the operating system's name for Outlook Express?) and therefore have mostly automated the decision-making process regarding which programs to allow access to and which to deny.
In those cases where no pre-defined rules are available, the firewall software typically generates a popup message asking you for a decision. To allow you to make a qualified and informed decision, generally a "more info" type link or button is provided which opens a browser window providing additional details about and/or regarding the application. More often than not there's also a recommendation on how to handle it.
If you feel that Microsoft's firewall is not enough for your protection, you can select from a large variety of products, including ZoneAlarm, Sunbelt Personal Firewall, and CA Personal Firewall.
Of course, firewalls are also included in many Internet Security suites that many of you will have purchased instead of a stand-alone antivirus software program.
And that brings us to antivirus software. As you know, this kind of software attempts to identify, fend off, and remove computer viruses and some other malware. Essentially, there are two strategies for doing this:
- Your computer is monitored for suspicious behavior, and all programs and files that are opened are inspected for certain "signatures" typical of such malware. This also includes the content of web pages you are browsing.
- Scans of all the files on your computer's hard disk(s) are regularly scheduled to look for files containing those aforementioned "signatures" indicative of an infection.
There is also a more proactive approach in the form of behavior-based detection that is only now gaining more recognition in the mainstream products.
There seems to be a large variety of programs on the market, but maybe there are not quite as many as there pretend to be. Just recently a number of products have flooded the market that are "false" products, i.e., malware on their own. They are usually offered for free, of course, but as a rule of thumb it's a good idea to stay with the better-known -- and sometimes also free -- products.
You can find a long list of products at http://en.wikipedia.org/wiki/List_of_antivirus_software, many of which also come in larger Internet Security packages. The ones that I have used in the past include F-Prot, Norton Antivirus, McAfee Antivirus, CA Antivirus (all of which allow the installation on three different computers), Panda, Trend Micro, Kaspersky, and Grisoft AVG. You can find the links in the Wikipedia list.
If you have the "large version" of these products it may also contain Anti-Spyware, i.e., software that attempts to identify, block, and remove spyware and some other malware, such as adware.
Anti-Spyware software again looks for certain "signatures" typical of such malware -- also including the content of web pages that you're browsing. Just as with antivirus software, you are also prompted to regularly scan all the files on your computer's hard disk(s) as well as your computer's registry to look for files and/or entries that are indicative of an infection.
Some anti-spyware products also include "anti-drive-by features" to prevent the installation of certain spyware and/or -- more importantly -- protect your browser from landing on websites known for such exploits.
Starting with Windows XP, the free Windows Defender has either come with the operating system or can be downloaded. However, it may be a good idea to have an additional product such as Spybot - Search & Destroy or Ad-aware. The former program is free, but the latter is free only for personal and noncommercial use
While Anti-phishing measures can be found embedded in most of the recent versions of the popular browsers, such as Internet Explorer, Opera, Google Chrome, and Mozilla Firefox, it is also supported by most of the security packages or standalone tools (such as the Netcraft toolbar). However, I have found that the third-party products tend to slow the browser down.
To set up the browser-internal phishing filter:
- In Internet Explorer 7/8: Tools > Phishing Filter (SmartScreen Filter)
- In Firefox: Tools > Options > Security
- In Chrome: Tools > Under the hood > Security
- In Opera: Tools > Preferences > Advanced > Security > Fraud Protection
|
|
1.4. Now What? |
|
To repeat myself, there is no need to be scared, worried, or overly paranoid about securing your computer and protecting the information stored on it.
Simply install a router in between your high-speed DSL or cable-modem connection and your computer or home/office network, put one of the various Internet security suites mentioned above on your computer, and you have already established a very good baseline of protection. But most important of all, apply common sense:
- You wouldn't want to fall prey to a scammer or non-reputable business, so apply due diligence and briefly google the name of new tools you are considering buying.
- Be cautious with the use of repair services for your computer and hard drive. If you have information on your hard drive that you would prefer not get into the wrong hands, consider having your computer looked at with its hard disk removed.
- Be cautious about selling your old computer or hard drive. If you have information on your hard drive that you would prefer not get into the wrong hands, consider removing your hard disks and physically destroying them -- for example, with a sledge hammer. If this step strikes you as too violent, consider using the secure shredder function provided by various security products, including Spybot - Search & Destroy and PGP Desktop.
- Stay up-to-date on security-related patches for both your operating system and any applications you are running.
A very cool program to do this with is Secunia Personal Software Inspector -- it gives you a list of all necessary updates and links to those in one fell swoop.
- Stay up-to-date on firewall, antivirus, and anti-spyware signatures so that you always have the most current protection.
And, if you want to go the extra mile, consider the various kinds of disk encryption or use Digital Signatures.
|
| The Last Word on the Tool Kit |
|
If you would like to promote this newsletter by placing a link on your website, I will in turn mention your website in a future edition of the Tool Kit. Just paste the code you find here into the HTML code of your webpage, and the little icon that is displayed on that page with a link to my website will be displayed.
Here's a website that added the Tool Kit icon this week:
www.irox.de
© 2008 International Writers' Group | |