Firefox 3.0: EULA: "Phone home"?

[quote author=drygol]
C`s rule about getting knowledge , therefore raising awareness , also applies here
[/quote]

I agree totally. This discussion is raising my awareness in certain areas. I am very new to these forums so I may be misinterpreting some part of the focus, but I am supposing that in the material sense of this discussion it is useful and helpful to gain awareness and knowledge about some of the different issues related to basic network security in the interest of DOing something so that it isn't quite so easy for some of the "lower-echelon" negative folks to bring trouble to us.

[quote author=drygol]
Tor wont give you any anonymity if you dont look at java-script.
[/quote]

I agree again. :) It is important not to rely on any one technology or approach, including tor. There are combinations of approaches that are very effective in offering basic protection. By "basic protection" I mean making it harder for others (e.g. individual entities or small negative hacker groups) to cause problems with personal network experience, using someone's machine without their knowledge, and stealing personal information. The protections are much less effective against a larger concerted effort.

[quote author=drygol]
If its about ff3 , IMO , every post that raises users awareness is ok but there is no point in being afraid of hackers/crackers.
[/quote]

I disagree here in certain respects, although it depends on how you characterize "afraid". Many users are "afraid" of being hacked/cracked/whatever term because of the disruption and problems this can cause in their life. The problems could include fraud, impersonation / identity theft, tracking behavior, and perpetrating other attacks. In the bigger picture this is might not be of high significance, but I think it is of some significance.

[quote author=drygol]
I agree. The SELinux MAC kernel module is the tightest control I know of,
There are a lot of tools that are faaar better ..... BUT always keep in mind that there is no real protection.
Unbreakable systems does NOT exist.
[/quote]

Well please list some and why they are better. This could be helpful to many of us with security concerns! I for one would like to research them. I'm aware of using AppArmor, SELinux, virtual machines, and chroot's for application security purposes. They each have their own strengths and weaknesses and aren't a solution in an of themselves.
 
I disagree here in certain respects, although it depends on how you characterize "afraid". Many users are "afraid" of being hacked/cracked/whatever term because of the disruption and problems this can cause in their life. The problems could include fraud, impersonation / identity theft, tracking behavior, and perpetrating other attacks. In the bigger picture this is might not be of high significance, but I think it is of some significance.

yes , you are right , maybe i wrapped that in wrong words.
What i wanted to say is that cracker/skiddie can steal your money , shutdown your website or do anything else , but thats it.
In general , script kiddies do most of above stuff , guys who really know stuff , just dont bother hacking your bank account.
But mass gathering information about users ( ggle ) and storing it is faaaar more dangerous. Thats basicaly what i meant.

Well please list some and why they are better. This could be helpful to many of us with security concerns! I for one would like to research them. I'm aware of using AppArmor, SELinux, virtual machines, and chroot's for application security purposes. They each have their own strengths and weaknesses and aren't a solution in an of themselves.

hard question , because we didnt specify against what exactly you want to protect.
if its about kernel , grsec is a good choice.
if its about app testing , its like you mentioned , chroot or vm.
if its about anonymity - go with wifi hotspots for example
JS in firefox - presonally i use NoScript plugin.

You can also use hardened distributions like Immunix as an example or simply try to harden your distro by yourself.
Using of various nids/hids is also recommended.

Almost always problems are with people , not programs and not clicking everything one sees on screen is number 1 method :D

topic wide and deep like ocean :)
 
dant, thanx for this! I would use Opera instead of (very hungry) Firefox on my linux box, but that operapluginwrapper is always zombie.
 
Back
Top Bottom