<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Brightwork Blog &#187; Security</title>
	<atom:link href="http://brightwork.wordpress.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://brightwork.wordpress.com</link>
	<description>Tech reviews and thoughts, tips and tricks</description>
	<lastBuildDate>Thu, 02 Oct 2008 02:35:12 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='brightwork.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/7fc3926a8d6739485b97def0d0ea63f4?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>The Brightwork Blog &#187; Security</title>
		<link>http://brightwork.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://brightwork.wordpress.com/osd.xml" title="The Brightwork Blog" />
		<item>
		<title>Security, it&#8217;s not rocket science.</title>
		<link>http://brightwork.wordpress.com/2008/08/03/security-its-not-rocket-science/</link>
		<comments>http://brightwork.wordpress.com/2008/08/03/security-its-not-rocket-science/#comments</comments>
		<pubDate>Sat, 02 Aug 2008 17:07:07 +0000</pubDate>
		<dc:creator>robsonde</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://brightwork.wordpress.com/?p=20</guid>
		<description><![CDATA[Why do people have security issues?
A large number of home users are infected with spyware or trojans, most home users talk of very slow computers. all of this is caused by bad security.
Some people don&#8217;t know how to be secure, some don&#8217;t care, other know what to do but see it as too hard.
the problem [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brightwork.wordpress.com&blog=4205097&post=20&subd=brightwork&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3>Why do people have security issues?</h3>
<p>A large number of home users are infected with spyware or trojans, most home users talk of very slow computers. all of this is caused by bad security.</p>
<p>Some people don&#8217;t know how to be secure, some don&#8217;t care, other know what to do but see it as too hard.</p>
<p>the problem is that the bad guys (hackers) are interested and motivated in getting into your computer.<br />
the users are not very motivated or interested in keeping them out.</p>
<p>about 80% of all email is spam, and most of it is sent from computers that have been hacked.<br />
you want less spam?<br />
then start to be more interested in security.</p>
<h3>What can you do to be secure?</h3>
<p>get an anti-virus program, you can even get a free program.<br />
get a firewall, the windows built in firewall is a good start, a NAT router is also good.<br />
get a spam filter, thunderbird can do spam filtering for you.</p>
<p>update your OS and programs, update , update , update&#8230;..<br />
use auto-update if you can , browsers, mail programs, anti-virus, all must be updated.</p>
<h3>Change your behavior</h3>
<p>Don&#8217;t click on links in email, don&#8217;t do it, don&#8217;t even think about it.<br />
Don&#8217;t open attachment in emails, unless you trust then sender then don&#8217;t open attachments.<br />
Don&#8217;t browse to dodgy web sites, this means no searching for warez, porn, free ringtones.<br />
Virus scan you computer every week.</p>
<h3>Will this change the world?</h3>
<p>This is just a start, think of it as bailing out a sinking boat with a tea spoon&#8230;.<br />
it will buy you time, others will notice what your doing and start to help.</p>
<p>the hackers will always have a new way to get in to your computer, the tips above will help.</p>
<p>As long as you keep your system patched, run a firewall and change you habits then you become a much harder target, you will be more secure than most home users.</p>
<h3>links</h3>
<p>free firewall<br />
http://www.personalfirewall.comodo.com/<br />
Or even zonealarm<br />
Http://zonelabs.com</p>
<p>free mail program<br />
http://www.mozilla-europe.org/en/products/thunderbird/</p>
<p>free anti-virus<br />
<span class="a">http://www.avast.com/</span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/brightwork.wordpress.com/20/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/brightwork.wordpress.com/20/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/brightwork.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/brightwork.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/brightwork.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/brightwork.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/brightwork.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/brightwork.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/brightwork.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/brightwork.wordpress.com/20/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/brightwork.wordpress.com/20/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/brightwork.wordpress.com/20/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brightwork.wordpress.com&blog=4205097&post=20&subd=brightwork&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://brightwork.wordpress.com/2008/08/03/security-its-not-rocket-science/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f42672cdbf34677d7457b0036a582d75?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">robsonde</media:title>
		</media:content>
	</item>
		<item>
		<title>Data destruction the secure way.</title>
		<link>http://brightwork.wordpress.com/2008/07/16/data-destruction-the-secure-way/</link>
		<comments>http://brightwork.wordpress.com/2008/07/16/data-destruction-the-secure-way/#comments</comments>
		<pubDate>Wed, 16 Jul 2008 07:11:22 +0000</pubDate>
		<dc:creator>robsonde</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://brightwork.wordpress.com/?p=5</guid>
		<description><![CDATA[Why do we want to securily remove data?
A good number of second hand computers still have data on them, credit card number, passwords and even medical records and e-mail.
if you are selling a computer or even giveing it away it pays to clean the drive of all your data first.
Technical information
The disks of a hard [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brightwork.wordpress.com&blog=4205097&post=5&subd=brightwork&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Why do we want to securily remove data?</strong></p>
<p>A good number of second hand computers still have data on them, credit card number, passwords and even medical records and e-mail.</p>
<p>if you are selling a computer or even giveing it away it pays to clean the drive of all your data first.</p>
<p><strong>Technical information</strong></p>
<p>The disks of a hard drive are divided into lots of little parts called sectors, each sector holding 512 bytes of data. So that the computer knows which sectors are being used to hold data, there is a reserved and protected part of the disk called the FAT (file allocation table).</p>
<p>When a file is written to the disk, the OS marks off in the FAT each sector used by the file. It also makes a note of the file name and the first sector of that file. When the file is read back, the OS looks up the first sector of the file and then reads-in the 512 bytes from the sector along with the address of the next sector for the file, and so on to the end of the file.</p>
<p>When you permanently delete a file (by emptying the recycle bin, allowing the bin to get full so that it overwrites the oldest files, or using a utility that bypasses the recycle bin) the OS does not delete data from every sector because this takes time. Instead it simply marks as free in the FAT every sector used by that file, and then removes the file name from the directory listing. It also makes the file name invisible to normal disk search methods, usually by replacing the first letter. This means that the space is now free to be used by other files, but the actual data is still present on the drive and can be recovered using undelete utilities provided it has not been overwritten by newer files.</p>
<p>Formatting the drive will empty the FAT and directory listing but again, it will not remove the data, and at this point your data can be recovered by reading directly from the sectors and putting the files back together like a puzzle.</p>
<p><strong>How to stop people getting the data back</strong></p>
<p>This depends on how much you care and how much cash you have.</p>
<p>The first and easiest way is just to reformat the drive. This will be OK if you just want to keep the drive and reuse it for other data. Your original data could still be recovered if a person wanted to, but it will get rid of data that you don&#8217;t want, clearing the disk for you to reuse.</p>
<p>The next level of security is provided by wiping the free space using a program like pgp or drive-crypt. This writes random data to all unused parts of the drive and is a good plan if you are selling the drive. If you do this and then change your mind, then nobody can (economically) help you recover your data.</p>
<p>Note that some programs don&#8217;t write random data but instead they only write lots of 0&#8217;s (zeros) to fill up the drive.</p>
<p>There are several programs that you can use to perform a random wipe:</p>
<p>pgp: <a href="http://www.pgp.com/">http://www.pgp.com/</a><br />
Partition Magic: <a href="http://www.powerquest.com/">http://www.powerquest.com</a><br />
Window Washer: <a href="http://www.webroot.com/washer.htm">http://www.webroot.com/washer.htm</a><br />
ERASER: <a href="http://sourceforge.net/projects/eraser/">http://sourceforge.net/projects/eraser/</a><br />
Steganos: <a href="http://www.steganos.com/">http://www.steganos.com/</a><br />
KillDisk: <a href="http://www.killdisk.com/features.htm">http://www.killdisk.com/features.htm</a><br />
Darik&#8217;s Boot And Nuke: <a href="http://dban.sourceforge.net/">http://dban.sourceforge.net/</a></p>
<p>I don&#8217;t know how well each of the above programs work, so do your own research. Read the info about them at their web pages and see if it is a random wipe or a 0&#8217;s fill, because a 0&#8217;s fill is not quite as good. Search for and read any user reviews to help you decide.</p>
<p><strong>If you are a Linux user then a random wipe can be done as follows:</strong></p>
<p>dd if=/dev/random of=/dev/hda bs=1024k count=4096</p>
<p>The Linux &#8220;dd ..&#8221; method requires care. You need to calculate the &#8220;count=&#8221; value to match the size of the disk (or not include it&#8230; no &#8220;count=xxxx&#8221; will &#8220;probably&#8221; write the whole disk). The &#8220;hda&#8221; in the example means &#8220;the whole of the first disk on the first IDE interface&#8221;. That might be your system disk. There is no permission byte for &#8220;the whole disk&#8221;; it&#8217;s not part of a file system &#8212; it&#8217;s the whole disk. So use the correct &#8220;/dev/XXX&#8221; value, the idea is to unrecoverably erase a disk. For &#8220;complete&#8221; erasure, repeat the command a few times. Seven seems to be the US DoD number.</p>
<p><strong>Keep in mind that any true random wipe program will take a lot of time to run:</strong></p>
<p>don&#8217;t trust any program that says it can wipe a disk in under 10 minutes. Just stop for a moment and consider how long it should take to write 40Gb of data to the drive 7 times over!</p>
<p><strong>A special note for the paranoid or those who have something to hide</strong></p>
<p>Even after random data has been written to the drive it is still possible to recover data using special tools that security consultants, police and government agencies have access to.<br />
If this is a problem for you and you really think that the government is out to get you, then you should simply destroy the drive and buy a new one. Exactly how you destroy it is up to you but I read that the US government has a system for destroying computer equipment by cross cut, crush, grind, burn and then spread on the roads as grit in winter.</p>
<p>For more info about data recovery and the art of data destruction, have a read <a href="http://www.usenix.org/publications/library/proceedings/sec96/full_papers/gutmann/">here</a>.</p>
<p>As for setting up a system that will destroy the drive at time of boot unless some special start-up procedure is followed, this might have worked in years gone by but in today&#8217;s world serious investigators won&#8217;t boot a system until the drive has been copied.</p>
<p>Use of any of the programs in this article will wipe ALL your DATA and it will no longer be recoverable by any <strong>ECONOMICALLY AVAILABLE</strong> means so be very very sure you want (or need) to do this before you start.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/brightwork.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/brightwork.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/brightwork.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/brightwork.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/brightwork.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/brightwork.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/brightwork.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/brightwork.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/brightwork.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/brightwork.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/brightwork.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/brightwork.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=brightwork.wordpress.com&blog=4205097&post=5&subd=brightwork&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://brightwork.wordpress.com/2008/07/16/data-destruction-the-secure-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f42672cdbf34677d7457b0036a582d75?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">robsonde</media:title>
		</media:content>
	</item>
	</channel>
</rss>