Security notes - security for the everyday person: Difference between revisions

From Helpful
Jump to navigation Jump to search
 
Line 395: Line 395:




Most people are not helped by them, but it depends on your [[threat model]].


If not, you might just buy into [[fear, uncertainty, and doubt]], and/or a sales pitch, and are not more secure.
Which can even have net-negative effect, when nothing changed,
when you only ''think'' you are safer, and act more careless.
'''Do you want to be anonymous?'''
Your ISP knows who you are.
You specifically told them when you asked them to put hardware in your house.
Instagram, facebook, and twitter know who you are.
You specifically tell them every time you log in. VPN ''cannot'' do anything to change that.
Sites that do not ask for login (and do not try to track you) already didn't know before, and still don't with VPNs.
Sites that do [[browser fingerprinting]] tricks to try always worked, and still do with VPNs.
So nothing changed.
'''Do you want to be harder to place?'''
Internet address based [[geolocation]] will generally do no better than place you in a city
(See also [[Javascript_notes_-_browser_related,_APIs#Geolocation_API]]),
but there are people, such as livestreamers, who do care about that.
With VPNs, IP geolocation will locate the VPN servers instead.
...assuming, of course, you don't tell that site it is allowed to geolocate you in other ways.




Depends.


In security, you do [[threat modeling]], a.k.a. figuring out '''what problem you are trying to solve''',
'''Do you want to hide your browsing traffic from passive snooping (e.g. coffee shop)?'''
because it's easy to solve a problem you didn't really have, or focuses on a smaller but forgets a larger issue.


In which case we bought into [[fear, uncertainty, and doubt]], and/or a sales pitch, and are not more secure.
For one, this is sort of illegal, so generally not done
 
 
If you want to hide your browing traffic -- -- it 99% was already


Which can even have net-negative effect, when nothing changed,
when you only ''think'' you are safer, and act more careless.





Latest revision as of 17:32, 27 June 2024

Security related stuff.


Linux - PAM notes · SELinux

Securing services


A little more practical


More techincal waffling

Message signing notes · Hashing notes ·
Auth - Kinds of auth setup · identity and auth notes ·· OAuth notes · OpenID notes Kerberos notes · · SASL notes
Encryption - Encryption notes · public key encryption notes · data-at-rest encryption ·pre-boot authentication · encrypted connections

Unsorted - · Anonymization notes · website security notes · integrated security hardware · Glossary · unsorted

Is it important to use antivirus/malware protection?

Is it important to encrypt...=

Is it important to encrypt my laptop or phone?

Is it important to encrypt my PC?

Is it important to encrypt my external drive?

Is it important to use two-factor authentication?

Is it important to use a password manager?

Is it important to use a VPN?

Is it important to use secure mail?

So these messenging apps are the end-all then?