<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6406&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Securing my/our computer systems]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6406</link>
		<description><![CDATA[The most recent posts in Securing my/our computer systems.]]></description>
		<lastBuildDate>Sat, 02 Mar 2024 07:24:39 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48609#p48609</link>
			<description><![CDATA[<p>Looks like Novacustom sells only laptops. While I prefer a desktop, they&#039;ve got great reviews and are worth considering. Still reading about nitrokeys. System76 has great reviews, too, with desktops and a mini with good spec options. </p><p>Saw Arkenfox&#039;s about-config settings: arkenfox.github.io/gui and recalled Ghack&#039;s and other&#039;s recommended settings. Have edited them by hand but many/most edits don&#039;t survive upgades. Using node.js would help. <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /> </p><p>The local computer shop only works with Windows, no coreboot help there. Found some mobos sold with libreboot and the Amibios site has an option for open source firmware. Hafta check first but either might be a way to go. The mobo/cpu are 8 yrs old and although they work great, your timing is appropriate. </p><p>Thanks, zapper.</p>]]></description>
			<author><![CDATA[dummy@example.com (fanderal)]]></author>
			<pubDate>Sat, 02 Mar 2024 07:24:39 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48609#p48609</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48589#p48589</link>
			<description><![CDATA[<p>@fanderal When you get another computer, I recommend either A:</p><p>novacustom or nitrokey</p><p>B: system76</p><p>or C: a computer with libreboot or coreboot that has me disabled.</p><p>Arkenfox disables a lot of garbage. Including that telemetry pocket crap for starters. <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Thu, 29 Feb 2024 23:44:50 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48589#p48589</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48506#p48506</link>
			<description><![CDATA[<p>I run lynis and netstat once in a while and the results are not extensive as there&#039;s no wifi, print or other server running. I&#039;ve used ss to see what&#039;s listening but haven&#039;t worked with nmap. Also run cli bleachbit with a script deleting dot dir files in mozilla, cache and local/share. And like many, run conky to spot odd usage.</p>]]></description>
			<author><![CDATA[dummy@example.com (fanderal)]]></author>
			<pubDate>Mon, 26 Feb 2024 22:03:41 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48506#p48506</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48485#p48485</link>
			<description><![CDATA[<p>Hi, I run a script as well as from time to time look at grc&#039;s shields-up.</p><p>nmap -v -A&#160; scanme.nmap.org<br />nmap -v -sS -p1-9000 -iL &gt; /home/glenn/build/logs/ip/ip.txt (edit, added redirection &gt; to file)</p><p>and for local net info...<br />netstat -r<br />netstat -i</p><p>and amongst that script I also have,<br />lynis audit system -Q --pentest</p><p>@aluma, I haven&#039;t seen that response from shields-up since I stopped using M$win</p><p>One Day At A Time.</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Mon, 26 Feb 2024 04:09:49 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48485#p48485</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48476#p48476</link>
			<description><![CDATA[<p>Daedalus 5.0 is almost default in terms of security. Result from here<br /><a href="https://www.grc.com/shieldsup" rel="nofollow">https://www.grc.com/shieldsup</a><br /><a href="https://postimages.org/" rel="nofollow"><span class="postimg"><img src="https://i.postimg.cc/bJkPQ2Kz/27.jpg" alt="27.jpg" /></span></a></p>]]></description>
			<author><![CDATA[dummy@example.com (aluma)]]></author>
			<pubDate>Sun, 25 Feb 2024 19:35:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48476#p48476</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48474#p48474</link>
			<description><![CDATA[<p>@GlennW</p><p>You&#039;re welcome, Glenn. WinXP days, with Netscape, Winamp, Zonealarm and stopping by grc to read and learn. Ever use BlackViper&#039;s site to configure services? </p><div class="quotebox"><blockquote><div><p>I keep finding some ports open, like telnet and LP...</p></div></blockquote></div><p>Haven&#039;t seen it here but I&#039;ll keep an eye out. Did you find that from grc&#039;s All Ports test, another site&#039;s test or local? </p><div class="quotebox"><blockquote><div><p>I reseated the nvme ssd I haven&#039;t had any crashes.</p></div></blockquote></div><p>That&#039;s good news. Hard to tell initially... sometimes it&#039;s easy and sometimes it&#039;s anything but. </p><p>You might try LibRedirect when at FB. It&#039;s a FF addon that redirects the connection to youtube and most social sites through privacy friendly frontends. </p><p>I used to use LibRedirect to watch/download youtube videos with youtube and googlevideo disabled in NoScript. Since youtube began splitting audio from video I had to download them separately. Used ffmpeg to join the m4a and mp4 but it became tedious. Started using sites like youtube4kdownloader_com and 9convert_com/en404 to download a video with audio. </p><p>Thanks for starting this thread, Glenn.</p>]]></description>
			<author><![CDATA[dummy@example.com (fanderal)]]></author>
			<pubDate>Sun, 25 Feb 2024 18:41:45 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48474#p48474</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48473#p48473</link>
			<description><![CDATA[<p>@zapper</p><p>The iucode leak was discovered and a free fix is available, but I didn&#039;t wanna mess with replacing bios code. Same reason I haven&#039;t done the coreboot. Got a good repair shop in a local retailer and I&#039;ll ask the next time I&#039;m there. </p><p>Intel&#039;s me expanded into more modules, same for the expanding aes* security modules. Seems more of their stuff is added to each new kernel version... the difference between Beowolf and Ceres kernels in CPU use and ram is noticable. </p><p>Agree with you about security. Wifi isn&#039;t a problem &#039;cause I use a wired connection, and only turn on the router&#039;s wifi when family or friends are here. </p><p>Used eMatrix for a while with PaleMoon and liked it. Got Icecat installed but haven&#039;t used it much. Hadn&#039;t heard of arkenfox but looked into Ghack&#039;s user.js. Do you know if it&#039;s as effective as claimed? </p><p>Hyperbola seems a fine OS. Tried installing in VBox and after much effort, realized I was using instructions of a different version than I was trying to install. One of those duh moments. <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /> I&#039;ll give it another go soon. </p><p>Thanks zapper.</p>]]></description>
			<author><![CDATA[dummy@example.com (fanderal)]]></author>
			<pubDate>Sun, 25 Feb 2024 18:40:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48473#p48473</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48450#p48450</link>
			<description><![CDATA[<p>@glennW the coreboot + intel me disabled + ath9k wifi card thoughts should be more than sufficient for most.</p><p>The ath9k wifi card is if you don&#039;t want to depend on non-free software blobs in particular.</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Sun, 25 Feb 2024 05:20:45 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48450#p48450</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48446#p48446</link>
			<description><![CDATA[<p>Thanks zapper...</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Sat, 24 Feb 2024 23:02:35 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48446#p48446</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48441#p48441</link>
			<description><![CDATA[<p>Hi fanderal, thank you for your post.</p><div class="quotebox"><blockquote><div><p>I&#039;ve tested ports at grc_com going back to WinXP days.</p></div></blockquote></div><p> me too, and I agree.</p><p>I keep finding some ports open, like telnet and LP... </p><p>I used zonealarm with winxp and it seemed secure enough to stop all but serious targeted attacks (which I had no evidence of, or effects)</p><div class="quotebox"><blockquote><div><p>Facebook was stealing members&#039; contact lists and sending invites to contacts in the member&#039;s name. Dunno if they still do it but I&#039;ve stayed away from social networks since then.</p></div></blockquote></div><p>I think FB is still doing that. Any of my actual friends have denied trying to contact me via those methods.</p><p>I&#039;ll have a read of the schneier post very soon. I find this topic very interesting, to say the least.</p><p>I must say, I am not a gold digger and I don&#039;t have anything to steal, or hide for that matter but it&#039;s annoying when the pc crashes.</p><p>But please keep in mind that since I reseated the nvme ssd I haven&#039;t had any crashes.</p><p>So, as educational as this experience has been it seems more and more that this was my mistake, <br />poor eyesight when I installed and started using the nvme drive.</p><p>Thank you for the info.... I am in the process of weening myself off FB and google apps, including email and chat.</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Sat, 24 Feb 2024 22:31:10 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48441#p48441</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48438#p48438</link>
			<description><![CDATA[<p>@fanderal</p><p>Interesting, didnt &#039;know that intel ucode did that. Although there is a better option still, use a more libre bios, such as coreboot and have intel me disabled. You need to buy from an OEM though who would disable it for you though.</p><p><img src="https://dev1galaxy.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>Otherwise, you are on your own regarding intel me.</p><p>Securing a computer requires three things to my knowledge:</p><p>Using as few blobs as possible, wifi included preferably meaning ath9k or similar</p><p>Coreboot + disabled me or similar</p><p>A distro that doesn&#039;t have blobs installed and refusing proprietary software that does remote dialing which means basically most of it.</p><p>Technically, emulators do use proprietary software, but they don&#039;t escape their sandboxes much if at all.</p><p>I currently use iceweasel-uxp + ematrix, httpsalways, httpsinquirer, modifyhttpresponse (blocks some useragentsniffers!) a custom ublock origin legacy, getemall, greasemonkey fork and other minor stuff.&#160; icedove-uxp and no other addons which means no google accounts!</p><p>Using a firefox equivalent, with arkenfox config and privacy badger, ublock origin and some script blocker is wise too though if you don&#039;t use the above.</p><p>The rest? Idk... </p><p>I still been using Hyperbola. They were struggling with some issue, but I think they are getting back on track now.</p><p>Devuan however, I have on my other SSD for disk cloning.</p><p>Having two SSDs on a computer can be wise sometimes. <img src="https://dev1galaxy.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Sat, 24 Feb 2024 22:22:50 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48438#p48438</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48435#p48435</link>
			<description><![CDATA[<div class="quotebox"><cite>GlennW wrote:</cite><blockquote><div><p>securing my system from being hacked</p></div></blockquote></div><p>Great thread. Got me curious so I looked up &#039;hacked bios&#039; and in the list of alternate searches was &#039;hacked bios download.&#039; A number of sites have tools (for good or ill) to hack/edit most any bios.</p><p>Among many similar, null-byte.wonderhowto_com had these articles:</p><div class="quotebox"><blockquote><div><p>How To Scan for Vulnerabilities on Any Website Using Nikto<br />How To Crack SSH Private Key Passwords with John the Ripper<br />How To Crack Shadow Hashes After Getting Root on a Linux System<br />How To Gain SSH Access to Servers by Brute-Forcing Credentials<br />Hack Like a Pro How to Find Directories in Websites Using DirBuster<br />iOS 17 Tips, Tricks, How-Tos, News<br />How To Find Anyone&#039;s Private Phone Number Using Facebook</p></div></blockquote></div><p>Found a 2015 &#039;BIOS Hacking&#039; article at Schneier:</p><div class="quotebox"><blockquote><div><p>We’ve learned a lot about the NSA’s abilities to hack a computer’s BIOS so that the hack survives reinstalling the OS. Now we have a research presentation about it.</p></div></blockquote></div><p><a href="https://www.schneier.com/blog/archives/2015/03/bios_hacking.html" rel="nofollow">https://www.schneier.com/blog/archives/ … cking.html</a></p><p>I&#039;ve tested ports at grc_com going back to WinXP days. Good site for learning although it&#039;s mainly for Windows. A recent test on Common Ports with NoScript set to &#039;Trusted&#039; for grc: </p><div class="quotebox"><blockquote><div><p>GRC Port Authority Report created on UTC: 2024-02-14 at 00:20:52</p><p>Results from scan of ports: 0, 21-23, 25, 79, 80, 110, 113, <br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; 119, 135, 139, 143, 389, 443, 445, <br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; 1002, 1024-1030, 1720, 5000</p><p>&#160; &#160; 0 Ports Open<br />&#160; &#160; 0 Ports Closed<br />&#160; &#160;26 Ports Stealth<br />---------------------<br />&#160; &#160;26 Ports Tested</p><p>ALL PORTS tested were found to be: STEALTH.</p><p>TruStealth: PASSED - ALL tested ports were STEALTH,<br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;- NO unsolicited packets were received,<br />&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;- NO Ping reply (ICMP Echo) was received.</p></div></blockquote></div><p>Did a test at youtube. Ran macchanger and restarted the router for a new IP, and found youtube&#039;s &#039;suggestions&#039; were the same videos I&#039;d watched the day before, despite watching a completely unrelated video. Next day, after macchanger and router, I booted TinyCore from a USB. Although watching a video unrelated to those I&#039;d previously watched, youtube&#039;s &#039;suggestions&#039; were what I&#039;d watched both previous days. </p><p>Seems youtube&#039;s had my MAC address, stats and profile for as long as I&#039;ve had this hardware. Google&#039;s everywhere and can likely identify public facing hardware no matter what security is used. I assume the other major and social networks can do the same. </p><p>While talking with neighbors when Facebook first became a hot site, I mentioned to one I wasn&#039;t interested in joining Facebook. When she said she&#039;d never emailed me about joining I rechecked her email. Facebook was stealing members&#039; contact lists and sending invites to contacts in the member&#039;s name. Dunno if they still do it but I&#039;ve stayed away from social networks since then. When I vounteered I suggested members change their Facebook&#039;s registered email to another email with no contacts, and not use FB&#039;s in-house mail.</p><p>Got two versions of Devuan, each on a SSD, and keep personal stuff and backups on two parked HDDs. FF is for general and Waterfox for email, with NoScript, PrivactBadger, a few &#039;about&#039; page tweaks and no stored passwds. I try to keep apps/services/firmware which listen to a minimum, or block when possible. Eg: iucode-tool firmware is not installed as a tiny OS inside Intel CPUs uses it to &#039;phone home.&#039; Also keep ~50 default modules blacklisted. </p><p>Guess it&#039;s a balance between security and what&#039;s comfortable to maintain. It&#039;s feeling like I&#039;m doing something yet knowing nothing I do can prevent a seriously targeted attack. </p><p>Appreciate all the tips and ideas.</p>]]></description>
			<author><![CDATA[dummy@example.com (fanderal)]]></author>
			<pubDate>Sat, 24 Feb 2024 21:59:23 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48435#p48435</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48390#p48390</link>
			<description><![CDATA[<p>@ zapper</p><p>Oh,...my bad, I didn&#039;t mean to leave out the kernel... like &quot;madaiden&#039;s&quot; page. </p><p>I am talking about the entire system, motherboard controls, booting and the OS. </p><p>Only Devuan for security (keeping things out), the other os&#039;s are for test-driving and ideas.</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Thu, 22 Feb 2024 22:02:22 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48390#p48390</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48385#p48385</link>
			<description><![CDATA[<p>@pcalvert</p><p>He doesn&#039;t really make it clear that he is talking about the kernel and also, windows security features of being locked down are largely meaningless due to being proprietary and it having backdoors.</p><p>Linux can be hardened if you know how, however. firejail is one way. I don&#039;t understand the criticisms about firejail either. Besides, windows executables are marked as executable once downloaded. The same is not true for linux. Which is why windows gets malware easily... so yeah...</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Thu, 22 Feb 2024 12:21:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48385#p48385</guid>
		</item>
		<item>
			<title><![CDATA[Re: Securing my/our computer systems]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=48354#p48354</link>
			<description><![CDATA[<p>That&#039;s quite alright, I was not very particular in my description either.</p><p>This pic is my &quot;GamesBox&quot;, everyday computing. I have 4 distros installed, and 2 of them are basically unused. Debian Bookworm, Kali (rolling release), Ubunto-Studio &amp; Devuan Daedalus-Plasma.</p><p>this pic was after I re-assembled and checked if it would still work :-) All my fingers were crossed, static is a real danger...<br /><a href="https://ibb.co/JkcHyf3" rel="nofollow">GamesBox, Fractal Case</a></p><p>Cheers</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Tue, 20 Feb 2024 22:50:32 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=48354#p48354</guid>
		</item>
	</channel>
</rss>
