View Single Post
Old 09-01-2006, 11:17 AM   #13 (permalink)
LoPo
Board Admin
Needs Help
 
LoPo's Avatar
 
Posts: 3,280
Shouts: 0
Join Date: Jun 2005
Location: Sparks, NV
Age: 29

Thanks: 62
Thanked 36 Times in 24 Posts
View LoPo's Gallery

Quote:
Originally Posted by Soul
Quote:
Originally Posted by LoPo
Quote:
Originally Posted by Smiley
Warning - off subject post:
You should be carefull not to log into any banking or financial account that could be used to hurt you when on any public system, including at work. I have a spyware program (Spector360) that is used to capture everything an employee does on their system here at work. It is placed on systems where it is suspected that the employee is running a second job from their desk, or some other unethical practice, etc. Many times I've seen employees entering their online banking, health insurance, investment, and other personal accounts that show usernames & passwords & account numbers. As mentioned above, keyloggers can capture everything you type.

Right now we are watching an employee that is using his yahoo email to get around our porn filters. He belongs to some yahoogroups that share porn as email attachments so he thinks that it will not be caught because it will not show in the logs as a porn website. Spector360 takes screenshots too, so everything is caught . . .

This can also be the case with public computers, they might have more than a keylogger on the system and thus can capture everything done on that system.

Also, be aware that deleted files can be resurrected on hard drives, internal cell phone flash memory, memory sticks/cards, etc unless a "wipe" program has scrambled the media. Nearly all deletes of files only changes the first character of the filename so the OS knows it can reuse the storage space that file was using. But if that storage space has not been reused yet then software can bring back the file. This included cookies and other temp files.

THis is computer/personal security best practice 101 and exactly why I don't do crap on any other machine outside my control.

I'm actually considering getting some form of 2 factor authentication for my home systems/laptops. Either smart card, RSA, or Biometic.

Ya I'm paranoid...everything I do is electronic. I have personal documents archived, etc

I bet I'm the only here that tunnels RDP over SSH.
I have done it for the sake of doing it, but I am not paranoid enough to feel the need to do it on a regular bassis

I do it to my house(over the open interweb), not interally.
__________________
There is no shame in survival.

http://www.lopo.com
LoPo is offline   Reply With Quote Submit this thread to digg Submit this thread to del.icio.us