What is spyware?

What is spyware?

Spyware is a general term used for software that traces user activity on the PC and collects personal info or confidential data without user consent. Spyware can register the websites you visit, the time of visits, all clicks on the keyboard (this is how credit card numbers and pin-codes are often stolen) or monitor and register secretly for software that is in turn installed on a PC.

The most dangerous spyware one which self replicates via e-mail, and installs itself without your consent using software bugs. Software intercepting e-mails and instant messages can collect and transmit confidential information to Internet, and are also dangerous and valid security concerns. Some software may also change parameters of installed security software without your consent. All this makes your computer vulnerable to spyware attacks. Depending on the type of spyware, some programs may warn the developer about users running applications on their PCs, while others are able to make holes for intrusion into the system, or set the modem to make calls, which the PC owner will eventually be billed for. Recently, some shareware programs have been referred to as spyware, such programs extract files from your computer without your consent. One of the most dangerous features of spyware is the ability to transmit collected information to the developer’s PC.

Spyware can enter your PC in a number of different ways. The most common is via e-mail or a Web browser. Also such software may be integrated into “useful” software and downloaded at the moment of “useful” program start-up. Generally such programs are integrated into popular free software, which are downloaded from the Internet, or distributed on CDs attached to magazines.
Why spyware is dangerous?

Spyware doesn’t have much influence on the way your PC runs. Usually, it doesn’t contain viruses, however it can consume a huge amount of system resources. Spyware brings lots of damage in the sense of data confidentiality. Spyware programs register every user step, both inside the system and in the Internet. All information is delivered to the malefactor who collects data in his, not your, interest!

How do I protect my PC from spyware?

Most spyware programs are integrated into freeware that you have to install on your computer, but some are automatically downloaded when you enter a Web site. If a message pops-up on your screen proposing you install a program providing access to Web site content, don't hurry to press “OK” without checking the software. If there is no need to install some special software to view the Web site, it’s better to refuse downloading extra software.

On some Web sites you can find lists of programs containing harmful spy modules. Looking through these lists can help you learn if such programs have been installed on your computer. Sometimes PC system behavior such as slow typing, periodical alarms of installed firewalls, registration queries to unknown Web sites, system and network efficiency reduction and suspicious file discovery may indicate that spyware is inside. The best way to protect your computer from spyware is to install specialized anti-spy software.

How do I protect my PC from spyware?

A firewall is considered to be the most popular tool to protect a computer from spyware. Firewalls are integrated into operating systems (OS) and permanently examine incoming and outgoing addresses to computer network ports. They analyze data packages coming to Internet ports and mail ports according to the type of request and the addressee. Most firewalls allow or deny some types of addresses, but this is a weak point because spyware may be integrated inside many packages or disguised as a Web browser. This type of spyware cannot be detected by a firewall, and gets inside the PC to start its malicious activity. Also, firewalls are usually resource-consuming, so the price for relative security is your PC running much slower.

The problem of firewall relative protection is successfully solved by proactive security systems. Such systems analyze all application activity on the PC for its potential maliciousness, according to predefined rules of malicious or non-dangerous behavior. In case of a real threat, proactive systems block dangerous programs before any damage to the OS is done.

An anti-spyware solutions called Safe’n’Sec+Anti-Spyware, is a special solution consisting of Safe’n’Sec behavior analyzer -- which blocks previously unknown spyware (new modifications) -- and the Anti-Spyware module, which detects already known spyware with the help of extended anti-spyware signature databases. This Anti-Spyware module has the option to delete malware from the user's PC. The solution is absolutely compatible with any traditional security software installed on your computer. Anti-Spyware solutions efficiently protect your confidential data from unauthorized access, whether you work in the system or just browse the Internet.

World of Warcraft Attacked by Phishers

World of Warcraft players desperate for a new mount to traverse the online role-playing game's fantasy world are getting a reality check from hackers who have devised a clever pop-up phishing scam to spread malware.

Security technicians at F-Secure Security Lab on Tuesday posted a blog entry Tuesday detailing the latest scam making its way through the world's most popular massively multiplayer online role-playing game (MMORPG).

With more than 11.5 million monthly subscribers, Blizzard Entertainment's World of Warcraft is not only the most successful MMORPG in history, but also a very popular environment for hackers, phishers and assorted click-fraud scam artists.

This latest hoax preys on players' desire to add mounts for their online avatars to ride. After clicking on a link to get a new trial mount, players are redirected to a malicious phishing Web site that mimics an official WoW page.

Those players who are still hard up for a mount are then prompted to enter their WoW log-in details.

"Apart from losing all the gold and items saved, a compromised account could also be used to send out the malicious messages to other victims, adding insult to injury," the researchers warned in their blog post. "An interesting detail about this particular site is that a reverse-IP check on its IP address turned up over a dozen other WoW phishing sites."

F-Secure officials remind players that phishing sites like the one identified today are blocked by the security firm's browser protection software.

World of Warcraft holds an estimated 62 percent of the MMORPG market. The third expansion set, Cataclysm, was announced at the BlizzCon conference earlier this year.

Security Report: Firefox Most Vulnerable

Application security vendor Cenzic today released its security trends report for the first half of 2009 application. In it, Cenzic claims that the Mozilla's Firefox browser led the field of Web browsers in terms of total vulnerabilities.

According to Cenzic, Firefox accounted for 44 percent of all browser vulnerabilities reported in the first half of 2009. In contrast, Apple's Safari had 35 percent of all reported browser vulnerability, Microsoft's Internet Explorer was third at 15 percent and Opera had just six percent share.
The 2009 figures stand in contrast to Cenzic's Q3/Q4 2008 report, where IE accounted for 43 percent of all reported Web browser vulnerabilities and Firefox followed closely at 39 percent.
As to why Firefox's numbers were so high, Cenzic has a few ideas.

"It's a combination of different things," Lars Ewe, CTO of Cenzic, told InternetNews.com. "They've gotten more traction as a browser, which is good for them and the more you get used the more exposure you have. As well a fair amount of the vulnerabilities have come by way of plug-ins."
One key area that Ewe said was responsible for a number of reported Firefox vulnerabilities is with how the browser handles plug-ins.

"The plug-in architecture that they have is a selling fact for the browser and one of the reasons why I love using it," Ewe said. "They can't control security aspects of all the plug-ins and the vulnerabilities are a side effect of that."

Mozilla has made numerous efforts this year to bolster its plug-in security. Recently they launched a plug-in checker service to ensure that users are running up-to-date versions. The Firefox 3.0.9 update, which came out in April, specifically addressed several key plug-in vulnerabilities.

Though Firefox had the highest number of vulnerabilities, that doesn't necessarily mean that Firefox users were more vulnerable.

Ewe said that Cenzic looked at all reported vulnerabilities. There is no specific differentiation for zero day bugs in the browser vulnerability count either. All that raises the question of how Cenzic actually came up with their vulnerability counts in the first place.

"The process that we follow is looking at a number of different vulnerability databases and sources that we have and trying to come up with a fair percentage based on the deviations we see between the databases," Ewe said. "You could make the argument, that's its 40 percent or 42 percent and there might be some variation on how you analyze it, but certainly it's not off by 20 percent."

While the Cenzic report shows Firefox at the top of the browser vulnerability pile, Ewe was quick to note that Cenzic uses Mozilla technology within its own solutions.

"Full disclosure here, Mozilla plays an important role in Cenzic's solution," Ewe said. "We are actually sitting on top of Mozilla as our agent of preference for scanning sites."

Cenzic develops an application scanning solution that uses the underlying Mozilla browser technology to test out security on Web site insides of a real browser context.

"We have a technology that we refer to as stateful assessment technology," Ewe said. "The idea behind it is to have as faithful an interaction with a Web site as possible and to determine vulnerabilities not on simple signatures but on behavioral basis of the application."

Ewe explained that when you do a cross-site scripting attack with a signature-based approach you'd just look for a server response that would indicate that the script tag has been injected. He added that the problem with that approach is that it's not faithful and the security researcher doesn't know if there is any additional logic on the client side that takes care of the script tag.

"If you want to be really faithful in the process you need to have full rendering capabilities and have all the JavaScript event handling," Ewe said. "So we leverage the entire Firefox architecture in order for us to actually have as faithful an interaction with a server as possible and maintain the client state. That results in low false-positives."

Sensible Password Policy: Longer is Better

The SANS Institute recommends passwords should be at least 15 characters long, which effectively means that these password can't be carried around in end users' heads. Let's take a look at how secure a password this long would be.

If we take a scenario in which user passwords are made up of upper and lower case letters and numbers, each password character can be one of 62 possible characters. A fifteen character password thus has 62^15, or more than 750 million, million, million, million possibilities. That's a lot. If you got a pool of a million computers working on the problem, it would take about 2 million million years to check them all.

A healthy dose of realism is clearly in order. "A lot of guidance about password length and complexity is just a sticking plaster over an underlying problem with passwords," says Dr Ant Allan, a research vice president at Gartner. "It's important to remember that if you increase length or complexity you are only defending against some kinds of attacks anyway," he says. "If the end user's machine is infected with spyware then the password will still be discovered, regardless. And a long password does nothing to prevent a hacker getting a password using social engineering. These types of policies are beloved of auditors, trotting out established ideas."

Fifteen is an arbitrary figure for password length, so what would happen if shorter ones were used? They would certainly be easier to remember, and since, as Dr Allan points out, security is only as good as the weakest point, the reduction in security would not be as great as it might at first appear. The passwords might be a little more easy to crack, but since a ten character password would still take a great deal of time to crack, it's still far more likely that any security breach would come from an internal attacker, a social engineer, or through a malware attack than a successful brute-force attack.

Over time computers get more powerful, and the time needed to crack passwords of a given length goes down. Increasing password length by a single character is surprisingly effective at counteracting several years' of advances in technology: if the extra character is drawn from a pool of a hundred possibilities, then essentially adding a random character makes the password 100 times harder to crack.
Password Change Intervals

Password change intervals are usually also specified in corporate password policies, and the SANS Institute recommends that end user passwords are changed every four months. The rationale behind this is not clear: with this policy in force a hacker would still have an average of two months to exploit any password he acquired – more than enough time to do some harm.

Given that users forget passwords more often when they are changed regularly, and that there is a usually a significant cost involved in providing a help desk to reset large numbers of user passwords, you could argue that changing passwords is a fairly pointless but rather expensive exercise. "There has certainly been an argument around for a few years now that changing passwords is more trouble than it is worth", says Dr Allan. "People argue that it prevents employees who leave an organization from exploiting their passwords after they have left, but this is just a cover for poor administration."

One possible solution to the problem of using passwords which are difficult to remember is to use a password manager. These applications encrypt and store passwords securely for end users so they don't need to be written down, and ensure they can only be accessed by the user after entering a password. The virtue of these systems is that users are only expected to remember a single password instead of numerous different ones. In the final piece in this series we'll be taking a closer look at this type of application.

14 More Open Source Tools to Protect Your Identity

AS IN PREVIOUS POST I DID EXPLAIN 14 OPEN TOOL FOR SECURE YOUR DATA,IN THIS POST I ADD SOME MORE TOOL AND EXPLAIN TO--SO READ AND APLY THEN GIVE COMENT...AS ADVICE....YOUR ADVICE WILL PROVIDE ME A WAY AND ENERGY TO COLLECT MORE INFORMATION ABOUT YOUR NEED
To help you keep from making the same sort of mistake I did, we've compiled a list of 14 more open source apps that can help protect your identity. Some of these fit into traditional security categories, like anti-spam, anti-virus, and firewalls. Others, like browsers, e-mail, and PDF tools, we've included in this list because they include encryption or other security features that can help you protect yourself.
No one is likely to need all 14 of these apps, but the list should give you plenty of options for filling in any security gaps in your system.Open Source Anti-Spam=========

Open Source Compression

1. 7-zip

7-zip offers higher than normal compression ratios and supports multiple file formats. However, in order to take advantage of its strong AES-256 encryption capabilities, you'll need to create either 7z or zip files. Operating System: Windows, Linux, OS X.

2. PeaZip

One of the most flexible compression utilities available, PeaZip currently supports about 90 different archive file formats. It also supports multiple encryption standards and even offers a two-factor authentication option for maximum security. Operating System: Windows, Linux, OS X.

3. KGB Archiver

One big benefit of using this compression utility is that it encrypts files with AES-256 encryption automatically. It also supports multiple file formats and nine different languages (but not Russian, which seems odd for an app named after the KGB). Operating System: Windows.

Open Source Data Destruction

4. Darik's Boot And Nuke

Also known as "DBAN," Darik's Boot and Nuke allows you to create a boot disk (CD, DVD, thumb drive, or even an old floppy) which will completely erase all the drives it can detect on your system. It's a great tool if you're getting rid of an old computer, but not as helpful if you're just deleting a few files. Operating System: OS Independent.

5. Eraser

If you need to erase only a few files—perhaps your financial or tax records, work files, or as the website suggests, bad poetry—Eraser is the tool for you. It overwrites deleted data multiple times, making it nearly impossible to retrieve the "erased" files. Operating System: Windows.

6. BleachBit

Like Eraser, BleachBit can completely erase files, but it also includes a number of other features to help protect your privacy and speed up your system. For example, it can erase your cache, remove your browsing history and cookies, clean up junk left by more than 50 applications, and much more. Operating System: Windows, Linux.

Open Source Email

7. Thunderbird

This e-mail client from Mozilla (the makers of Firefox) includes built-in encryption capabilities, anti-spam, and phishing protection. It further protects you by blocking remote images in e-mail and alerting you when security updates become available. Operating System, Windows, Linux, OS X.

8. Zmail

Need to send a secret e-mail? Zmail lets you send e-mail messages anonymously if you know your SMTP server address. Operating System: OS Independent.

Open Source Encryption

9. AxCrypt

With more than 1.5 million registered users, AxCrypt has become one of the most popular open-source encryption applications. It integrates seamlessly with Windows—simply right-click a file to encrypt it. Operating System: Windows.

10. TrueCrypt

With more than 12 million downloads, TrueCrypt is also a very popular way to protect your files. While AxCrypt focuses on encrypting individual files, TrueCrypt makes it easy to encrypt a drive partition or an entire drive (including USB thumb drives). Operating System: Windows, Linux, OS X.

11. Gnu Privacy Guard

Also known as "GPG," Gnu Privacy Guard lets you encrypt and digitally sign documents before transmitting them. This is a command line tool, but the Web site includes links to a number of graphical interfaces for the software. Operating System: Windows, Linux, Unix, OS X.

Open Source File Transfer

12. FileZilla

FileZilla supports regular FTP and the more secure FTPS and SFTP protocols. While the client version should work with any operating system, the server version only works with Windows machines. Operating System: Windows, Linux, OS X.

13. WinSCP

This Windows-only file transfer tool has won tons of awards and supports FTP, SFTP, and the older SCP file transfer protocols. Note that it's a client-only tool—i.e., you can use it to download files from other sites, but you can't use it to set up your own FTP server. Operating System: Windows.

Open Source File Sharing

14. Waste

While most file sharing networks are designed to help users circumvent copyright laws, Waste at least claims to be aimed at law-abiding citizens. With it, small groups (10-50 nodes) can chat and share data securely without opening their systems to unauthorized users. Operating System: Windows, Linux, OS X.

Open Source Firewalls

15. Firestarter

Unlike most of the open-source firewalls, Firestarter can protect a single PC as well as a network. Best of all, you can probably install it and be up and running in just a couple of minutes. Operating System: Linux.

16. IPCop

IPCop is a complete Linux distribution designed to be used as a standalone firewall and boasts a very user-friendly interface. To use it, you'll need an old PC to connect to your network. Operating System: Linux.

17. Vyatta

Vyatta sells open source networking hardware and software commerically atwww.vyatta.com, and they also maintain the free, community version. With the community version, you can turn a PC into a network appliance that offers routing, firewalling, VPN, intrusion prevention, and WAN load balancing services. Operating System: Linux.
32. SmoothWall E
Because it's designed to be used by people with no knowledge of Linux, SmoothWall Express is an excellent option if you aren't a technical whiz, but want to tackle setting up your own network. A supported commercial version is also available. Operating System: Linux.
33. LEA
The "Linux Embedded Appliance Framework" (aka LEAF) can be used as an Internet gateway, router, firewall, or wireless access point. This app requires a little more know-how than some of the other choices in the category, but is a good option. Operating System: Linux.

14:-Open Source Tools to Protect Your Identity

Usually these lists of open source software start with statistics or general observations on current trends in the open source community. This one starts with a personal story.
I used to use a thumb drive to backup my budget software, and I also kept a copy of our tax returns on the same drive. While the files were password protected, I didn't encrypt them because the drive never left the house, and we don't exactly live in a high crime area.
Then one day my friend was looking for a drive to carry some files to the school where he teaches. As you probably guessed, he grabbed the drive with our financial info on it. And as you probably also guessed, someone stole his computer and the thumb drive right out of his classroom. As a result, I've had the great joy of spending many, many hours changing our account numbers, checking our credit reports, and setting up fraud alerts.
To help you keep from making the same sort of mistake I did, we've compiled a list of 14 open source apps that can help protect your identity. Some of these fit into traditional security categories, like anti-spam, anti-virus, and firewalls. Others, like browsers, e-mail, and PDF tools, we've included in this list because they include encryption or other security features that can help you protect yourself.
No one is likely to need all 14 of these apps, but the list should give you plenty of options for filling in any security gaps in your system.Open Source Anti-Spam
1. SpamAssassin
The highly acclaimed "#1 open-source spam filter," SpamAssassin, uses a number of different features to identify spam, including header tests, body phrase tests, Bayesian filtering, blacklists and whitelists, and others. It can be used on its own, but it's also been incorporated into a number of other commercial and open-source applications. Operating System: OS Independent.
2. ASSP
Humbly claiming to be "the absolute best SPAM fighting weapon that the world has ever known," ASSP is short for "Anti-Spam SMTP Proxy" Server. While it takes a little work to get it up and running at first, it doesn't require a lot of maintenance, and the site wiki includes extensive help on configuring the app so that it works for you. Operating System: Windows, Linux, OS X.
3. Spamato
Available as an Outlook add-on, as a Thunderbird extension, or as a stand-alone proxy, Spamato uses multiple filters to separate junk mail from the stuff you actually want to receive. Unlike some anti-spam tools, it also lets you see why a message gets classified as spam and adjust your settings as necessary. Operating System: Windows, Linux, OS X.
Open Source Anti-Spyware
4. Nixory
Nixory will quickly scan your system and remove any malicious cookies from Firefox. Unlike some similar apps, you can use it alongside other anti-virus or anti-spyware applications without first disabling those systems. Operating System: Windows, Linux, OS X.
Open Source Anti-Virus/Anti-Malware
5. ClamAV
One of the best-known open-source security projects, ClamAV provides e-mail virus and malware scanning for Unix-based systems. Its owners update its prodigious virus database several times each day to provide up-to-the minute protection from evolving threats. Operating System: Linux.
6. ClamWin
Based on the well-respected ClamAV engine, ClamWin integrates with Microsoft Outlook and Windows Explorer to scan files for viruses and other malware. You can set it up to automatically download the updated virus database, and you can schedule system scans. However, unlike many commercial products, it does not include a real-time scanner for files you receive by e-mail. You'll need to save files and right-click in order to scan them for viruses. Operating System: Windows.
7. ClamTK
As you might expect, this is another interface for ClamAV, this time for Linux only. Operating System: Linux.
8. Moon Secure
This app also uses the Clam AV engine (though developers claim to be working on one of their own), but offers a different interface and some different features. Operating System: Windows.
Open Source Backup
9. Amanda
Currently protecting more than 500,000 computers, Amanda is one of the most popular (if not the most popular) open-source backup and recovery program. Importantly, it encrypts backup data both in transit and at rest. Several commercial vendors (notably, Zmanda) use Amanda to offer cloud backup services for users who prefer to store archived data off-site. Operating System: Windows, Linux, OS X.
10. Areca Backup
Designed to be both flexible and simple, Areca Backup makes it extremely easy to archive your files and work with those archived files (browse, merge, track versions, etc.). It also gives users the option to encrypt backup files with strong algorithms. Operating System: Windows, Linux.
11. Bacula
While it's primarily aimed at enterprises and users with large networks, Bacula can also be used to backup a small home network or a single system. It's an excellent program (one of the most popular open source enterprise apps), but you need to be pretty tech-savvy to use it. Operating System: Windows, Linux, OS X.
Open Source Browser
12. Firefox
An independent study cited on the Firefox site claims that Internet Explorer users are vulnerable to threats 98 percent of the time while Firefox users are only vulnerable 2 percent of the time. In addition to being secure, Firefox is fast and highly customizable. Operating System: Windows, Linux, OS X.
13. Tor Browser Bundle
If you're really paranoid about privacy or have other reasons for wanting to browse the Internet anonymously, the Tor Bundle will install with your existing browser for ultimate protection. When its running, no one can tell what sites you are visiting, sites can't figure out your physical location, and you should be able to access sites that are blocked by governments or Web filtering software. You can also install it on a thumb drive for mobility. Operating System: Windows.
14. TorK
For Linux users, this Tor front-end lets you anonymously browse the Internet, send instant messages and e-mail, and more. Operating System: Linux.

How to Be Safer on Twitter

“Twitter is insecure. Twitter is the root of all evil.”

Right. Much has indeed been written about Twitter’s security – or lack thereof– in just the past couple of months. In taking in what others have to say, though, I can’t help but think it’s being unfairly attacked.

Let’s take a fair and objective view of some of the issues, and see what, if anything, a user can do to reduce her risk.

Twitter, the wildly popular micro-blogging web site, has roared onto the scene in an amazingly short time, even by Internet standards. Twitter users can post short (140-character) messages known as “tweets” to all their followers. Pretty much anyone can follow anyone else’s tweets on Twitter, although there are some minimal privacy settings and such for those who want to limit the scope of where their tweets go and who can see them.

It’s through this simple matrix of followers and writers that communities of like-minded people have joined one another in reading and posting their tweets.

But several articles and blog entries have been published declaring Twitter to be insecure. A common theme among the naysayers has been Twitter’s use of TinyURL, a site/service that encodes long URLs—we’ve all seen them—to be just a few characters long. No doubt this is used so that people can post tweets with URLs and still fit within the 140-character tweet limit.

The problem with TinyURL and similar encoding mechanisms is that the end user really doesn’t know what’s in the original URL itself. Thus, a tweet could be pointing the reader to a hostile site containing maliciously formed data that could quite conceivably attack the reader’s browser.

All of this is true, of course, but so what? The truth is that any URL we click on or enter into our browsers manually can take us to sites that contain malicious data. Granted, some sites are going to seem more trustworthy than others: a respected news outlet is likely to be more trustworthy than (say) www.click-here-to-infect-your-computer.com—which, by the way, I think is not a registered domain.

Even still, I again ask the question: so what? There is an inherent risk in pointing your browser to any web site. We’ve discussed here numerous ways of shoring up your browser so that you’re less likely to have your system compromised, even if you visit a site containing malicious data. All of these things are entirely relevant in the context of Twitter, of course.

Another common complaint is that there’s no verification of a Twitter user’s identity, so someone could trivially pose as (say) a celebrity and the public would be none the wiser. This too is quite true, but it’s nothing new with Twitter.

Anyone still remember the old “kremvax” April Fools’ joke from 1984? Spoofing an identity was as true then as it is now. In the absence of a trustworthy cryptographic signature, digital identity must not be trusted.

Now, to be fair, there have been a few published coding vulnerabilities on Twitter, including some cross-site scripting problems, “clickjacking” problems, etc. But from what I can tell as an outsider (and a Twitter user), the folks at Twitter have fixed these problems on the server as they’ve been reported. I don’t have data on how rapidly they’ve been fixed, but they do appear to be addressing them.

All of these security and privacy concerns are valid, but they’re by no means new or unique to Twitter. No, it seems to me that Twitter is being unfairly attacked for whatever reasons. I’ve heard many folks complain about Twitter’s 140-character tweet limit, saying that nothing of value can be communicated in such a small message, therefore Twitter must be without merit.

I won’t get into a debate of whether one can say something valuable on 140 characters or not, but suffice to say that I’ve seen many 140-character tweets that were of value to me. But let’s get past that and consider some positive recommendations on how to safely use twitter, assuming that you also want to hear what some of your colleagues want to say in 140 characters.

  1. • Don’t click on encoded URLs if you at all doubt them. If they point to something you feel you do want to read, direct message or email the tweet’s author and ask for the full citation, and then decide whether it deserves your trust.
  2. • Harden your browser anyway, just like I’ve suggested here many times.
  3. • Follow people who post things you’re genuinely interested in. Follow people you trust. Verify their Twitter identities via a trustworthy channel like, for instance, an encrypted or cryptographically signed email.
  4. • Avoid twits. There is a lot of noise on twitter. Life is too short for that blather. Shut it off.
  5. • If you’re concerned about the privacy of what you post, set your own account to “protect my posts,” which restricts your tweets to only your followers. Approve (or disapprove) your followers. Block followers you don’t know or otherwise don’t want reading your tweets.
  6. • Avoid posting URLs, or post really short URLs so that your tweets don’t automatically invoke TinyURL. If you want to point to a URL, tell your followers to direct message you to request the full URL.

These, of course, are just some basic precautions you could take if you wanted to use Twitter in a reasonably safe way. Above all, though, treat it for what it is—a means of posting short bursts of information to people. If you want your own tweets to be valuable to others, be concise. Very concise

How to Keep Cloud Computing Secure

How to Keep Cloud Computing Secure

Working off an external network in the cloud brings the benefits of offsite storage backup, but also comes with some dangers: Viruses, spam, malware and identity theft are among the threats you may face.

Along with the dangers of sharing your data externally with outside parties comes some security benefits as well, according to Eran Feigenbaum, director of security for Google Apps. Although companies now allow cloud vendors access to their data, "just sharing a document and not an entire infrastructure is a tremendous benefit," he says.

"You don't have to figure out multiple security zones, only one front-facing connection," adds Treb Ryan, CEO of OpSource, a company that provides data management and data-transfer backup for software-as-a-service and Web companies.

Here we provide some tips from experts on how to keep your cloud computing setup secure.

Watch what you open

Cloud provider Salesforce warns on its trust site not to open suspect e-mails. This may seem like common sense, but many people don't follow this advice. Watch suspicious links as well.

Ask your provider about incident response, Balding advises. The provider should be able to help in the event of an intrusion attempt, he says. You should also ask if the company will take an image of the machine or whether you must do this yourself.

When you open files, make sure your network access is encrypted, suggests Craig Balding, a technical security lead at a Fortune 500 firm and author of a blog on cloud computing security. Balding notes that Amazon doesn't encrypt data for its Web Services business. On its trust site, Salesforce.com recommends two-factor authentication techniques such as RSA tokens or Smart Cards.

Protect your cloud API keys

You want to make sure your cloud API keys are secure, Balding warns. "If someone gets hold of your access key, they've got everything," he says. "Require the provider to give you keys for different sets of data and risk classification," Balding suggests.

He also advises putting your production data in one account and your development data in another account. This will lessen the risks of someone breaking into your less secure development machine, he says.

Pay as you go

To avoid competitors running up the bill, pay for cloud services as needed, Balding advises. "It's good to have a threshold if usage goes way up, he says.

Replicate data

Google's Feigenbaum stresses the importance of data replication across multiple data centers. In the event of a disaster in the Northeast, for instance, data could still be accessed from other regions. "If something bad would happen to the Northeast such as a snowstorm, and cut off power, your data would be served from another data center, and no one would really know," Feigenbaum says.

Reduce endpoint reliability

"The concept of the cloud is to store minimal data on your endpoint devices," Feigenbaum says. "Endpoint devices are hard to secure -- you're taking security out of the experts' hands and putting it into the users' hands." The FBI reports that 1 out of every 10 laptops is stolen in its first 12 months since purchase. And though USB keys are convenient, they're easily lost.

"Don't overlook client-side security," advises Joe Krause, director of product management for information security consulting firm Trustwave.

Ensure proper compliance and certifications in data transactions

OpSource's Ryan advises that transactions involving credit cards should be PCI compliant. "If our system is not PCI compliant, the system breaks and you don't have a secure transaction of Web data," Ryan explains.

Ryan says in corporate environments, enterprises should follow SaaS 70, a safety protocol. Meanwhile, health care companies need to heed HIPAA regulations as medical data travels in the cloud.

Understand vulnerability management

Trustwave's Krause says providers need to be able to manage the vulnerability of a single piece of data to affect a large number of clients. "A single vulnerability has the potential to expose the critical assets of a large number of their clients," Krause says. "Cloud computing providers have to be able to show that they're aware of the vulnerabilities of the cloud and that they're not waiting for someone else to show them there's a vulnerability," he explains.

Keep a forensics and Web log

Providers need to know where their customers' data is at all times, Krause says. "There's got to be a way to follow the audit trial, where the data was at any point in time," he says. A forensics and Web log accomplishes this, he says. "Enable logging so you get visibility on how people are using your services you put in the cloud," Balding suggests. "You might detect some attacks that way. If you don't turn on the logging, you're not seeing any of the bad stuff or hacker potential," Balding says.

Also check with IT to see if other divisions of the company have already signed up for the cloud service, because if they have, a security breach can occur. Balding says to confer with the finance department to see if anyone else in the company has spent money on that service. It's a company hazard if the same information is in the cloud twice