Sponsored Community Message Browse Free. Go deeper with Full Access. Free visitors can browse public knowledge. Full Access unlocks participation, member areas, and an ad-free experience.

Firefox Chrome Security Settings-gctid82874

Started by Ajamu, May 31, 2013, 05:31 PM

Previous topic - Next topic
Five steps to ultimate Firefox security | PCWorld

Five steps to ultimate Firefox security


                                                                     
Eric Geier
                        @eric_geier

'"
    n".self::process_list_items("'.str_replace('
    ', '', '
  • May 28, 2013 3:00 AM
').'")."n[/list]"'

Over the years, many have touted Mozilla's Firefox as one of the most  secure Web browsers. But as with other browsers, the security level  offered depends on the settings. Some security features need to be  manually enabled. Those turned on by default should still be  double-checked.

 Follow these five steps to lock down Firefox. Start with the  essentials in the browser's own settings, then choose some useful  add-ons. Finally, keep track of your plug-ins so you can patch the  inevitable security holes.

Enable a master password

 Like other browsers, Firefox by default allows anyone who accesses  your computer to log in to sites where you've saved the password. And as  with Google Chrome, a list of the saved usernames and passwords can be  viewed via the Options menu of Firefox.


Eric GeierBy default, nothing prevents others from viewing all your saved login info in Firefox.
 Fortunately, Firefox offers a master password feature that encrypts  and password-protects the saved password list. When enabled, you must  enter the master password the first time you use a saved password, once  per browser session. Additionally, even though you enter the master  password the first time, you must always enter it before you can view  saved passwords via the Options menu. This is a great feature to help  prevent casual snooping of your passwords. It even prevents most  third-party utilities from recovering them.


Eric GeierCreating a master password prevents others from using or viewing your saved login info.
 To enable the master password feature, open the Firefox menu, select Options, select the Security tab, and then check the Use a master password option.

Use a strong password for syncing

 Like Google Chrome, Firefox has a syncing feature to synchronize your  bookmarks, passwords, and other browser data to Firefox browsers  running on other computers and devices. Fortunately, Firefox encrypts  all synced data, not just your saved passwords (as Google Chrome does).  Additionally, Firefox has more security than what Chrome offers by  default when you're setting up a new computer or device to sync. In  Firefox, you must log in with your Firefox Sync password. Then you must  either enter a random passcode from the new device into one that you've  already set up, or take the recovery key from a device you've already  set up and input that key into the new device.


Eric GeierSyncing conveniently syncs your saved login and other browser data across multiple computers.
 So you don't have much to worry about with Firefox syncing—as long as  you use a strong password, one with upper- and lowercase letters,  numbers, and special characters. If someone knows or cracks the  password, and has access to a device you've already set up with syncing,  they can then set up other devices with syncing and access your  passwords and other browser data.

 To enable or change sync settings, open the Firefox menu, select Options, and select the Sync tab.

Verify that security options are enabled

 Like other popular browsers, Firefox includes some basic security and  privacy settings. Though most are enabled by default, you should ensure  they haven't been disabled.


Eric GeierMake sure the first three security options are selected to protect against malware and phishing attacks.
 Start by opening the Firefox menu and selecting Options. In the Options window, select the Security tab. Ensure that the first option, Warn me when sites try to install add-ons,  is enabled to help prevent sites from automatically installing add-ons,  as some can be dangerous. Then ensure that the next two options, Block reported attack sites and Block reported web forgeries, are also checked to help enable protection against malware and phishing.


Eric GeierCheck the first privacy option to help prevent websites from tracking your online activity.
 Next, select the Privacy tab. And if you want more privacy online, select the first option, Tell websites I do not want to be tracked,  which isn't enabled by default. Although it can't prevent all tracking,  it will reduce tracking by those sites that support this type of  option.


Eric GeierEnsure that the first content option here is enabled to block pop-ups.
 Now, select the Content tab. To prevent pop-up windows that can be annoying and even contain phishing ads, ensure that the first option is enabled: Block pop-up windows.

 Lastly, select the Advanced tab, select the Update subtab, and ensure that Automatically install updates is selected.

Use add-ons for more protection

 Consider installing these security-related add-ons for extra protection:

 NoScript  helps you control which sites can use JavaScript, Silverlight, Flash,  and other embedded content, as they can be used maliciously to infect  your computer or for phishing attempts.

 Adblock Plus  blocks banners, pop-ups, and video advertisements on websites to reduce  clutter and the resulting annoyance; they can even reduce accidentally  stumbling upon adware, malware, and phishing attacks.

 Web of Trust (WOT)  shows the user ratings of sites and blocks dangerous sites—such as  those with malware—to increase safe surfing, shopping, and searching on  the Web.

 HTTPS Finder  automatically detects and enforces HTTPS/SSL-encrypted connections when  available—great in helping to reduce the chances of an eavesdropper on a  Wi-Fi network from capturing your login details.

 Xpnd.it! short URL expander  allows you to hover over shortened links to see the real URL and other  basic information about the site so you know where it leads before  clicking.

Check and update plug-ins

 Cyber criminals regularly use vulnerabilities in popular browser  plug-ins (like Java and Adobe products) to infect and invade computers.  Most plug-ins regularly release updates to patch security holes. Many  plug-ins are set by default to update automatically or at least to  notify you of them. However, it's a good idea to check periodically for  updates. Consider using the Mozilla plug-in checker or third-party sites like Qualys BrowserCheck for updates for other browsers.

A little vigilance goes a long way

 Firefox is pretty secure on its own, but you can make it even more  secure with the right settings and add-ons. Good password management  remains essential, too: Create and enable a strong master password so  others can't use or view your passwords. And if you use the syncing  feature to synchronize your passwords and browser data across devices,  use a strong password to prevent others from syncing. Finally, keep tabs  on your add-ons and plug-ins to make sure they're giving you the best  possible protection.

=======================================================================================

Google Chrome: Best security tips for safer browsing | PCWorld


                           
         Google Chrome: Best security tips for safer browsing

@eric_geier

'"
    n".self::process_list_items("'.str_replace('
    ', '', '
  • Mar 18, 2013 3:30 AM
').'")."n[/list]"'

There's a lot to like about Google Chrome's built-in security features.  The browser offers unique sandboxing functions and privilege  restrictions, and even updates itself in the background to help better  protect you from hackers and malware. But like all browsers, Chrome is  imperfect, and there are steps you can take to protect it from attack.  Here's how to get the most from Chrome's built-in security features, and  work around its security shortcomings.

Privacy features

  Chrome offers several privacy features that help protect you while you  browse. The most notable are its phishing- and malware-protection  schemes, and a tool that can auto-correct misspelled Web addresses.

  Chrome's phishing and malware protection put up a warning screen  whenever you visit a website that Google has identified as potentially  malicious, whether it spreads malware or tries to steal your personal  information. Meanwhile, Chrome's URL autocorrect feature usees a  Google-provided online service to fix misspelled URLS to help you avoid  visiting the wrong site—and perhaps a nefarious site—by accident.  Indeed, "typosquatting" is still a threat.

 Chrome has several useful features that can help you avoid dangerous sites.
  To use these features, open the browser's Settings panel and scroll down to the Privacy section (you may need to click Show advanced settings to get there), and check the boxes labeled Use a web service to help resolve navigation errors and Use a web service to help resolve spelling errors. Also, be sure to check the Enable phishing and malware protection box.

  Additionally, click the Content settings tab and consider  restricting some content. You can, for example, disable JavaScript  (which is often exploited by malware) and plug-ins. When you do so,  Chrome will notify you when a site is using them so that you  can voluntarily opt in for legitimate sites.

 Restricting and limiting Web content can help block some types of malware attacks.

  Protect your saved passwords and credit card details

  If you let Chrome save your website passwords, anyone who uses your PC  can easily access them with a little poking around in the Settings  panel. But unlike Firefox and its Master password feature, Chrome—and by  extension, third-party add-ons—won't let you encrypt your passwords or  saved credit card information.

  Luckily, there are a few things you can do to help protect your privacy.  First, don't allow people you don't trust to use your Windows user  account. Instead, either create a new Standard (non-administrative)  account for others to use or turn on the Guest account.

 It's ridiculously easy for someone to get at your saved passwords in Chrome.
  If creating another Windows account is too inconvenient, consider using a Chrome extension like ChromePW, Browser Lock, or Secure Profile  to password-protect Chrome. This effectively forces others to use  another browser on your system like Internet Explorer (which doesn't let  others easily view your saved passwords) or Firefox (which lets you  encrypt and password-protect your saved passwords).

  Another option is to securely store your sensitive data using a  third-party password manager. Some third-party password tools let you  sync your passwords across other browsers, which might be helpful if you  go from one computer to another. KeePass and Xmarks are two popular password managers worth trying.

Secure your synced data

  Chrome can sync most of your settings and saved data (including  passwords, but not credit card details) across multiple computers and  devices that have Chrome installed, but this creates a security  vulnerability. By default, Chrome requires you to enter only your  Google account password to set up a new computer or device to sync your  browsing data. So if your Google account password were hacked, an  intruder could potentially access a list of all your passwords.

 Adjusting your sync settings can better protect the data that Chrome saves.
  That is, unless you set a custom encryption syncing passphrase.

  Once you set a syncing passphrase, you have to first sign in with your  Google account password and then enter the passphrase to set up new  synced devices. This adds an important extra layer of security. To set  this up, open Settings, click Advanced sync settings, and select Choose my own passphrase.

  While you're there, also consider turning on encryption for all synced data instead of just passwords.

Secure your Google account

  Google offers several security features to help you better control and  protect your account, and you should definitely consider using them if  you use Chrome's sync feature. They help secure your entire Google  account, so you should also consider using these security features if  you tap into multiple Google services.

  On the Google Account Security  page, consider enabling Google's 2-step Verification. Once you've done  that, you'll have to enter a special code—which you'll receive via text,  voice call, or the Google app—whenever you attempt to sign in to Google  from a new PC or mobile device. This scheme ensures that anyone without  direct, hands-on access to your mobile hardware will be denied entry  into your Google data. When signing  in to applications or features that don't support the verification codes  (like Chrome's sync feature), you'll have to sign in to your Google  account, access the 2-step Verification settings, and generate an  application-specific password.

 Google offers many security features and functions so you can better protect your account.
  While on the Google Account Security  page, you might also want to turn on email and/or phone notifications  for password changes and suspicious log-in attempts. This way, you'll  know right away if someone tries to change your password or attempts to  log in to your account without your knowledge.

  Additionally, review your recovery options in case you forget your  password in the future. Last, review your authorized apps and sites and  remove those you don't use anymore.

Install extensions for additional protection

  We reviewed many of the security features offered by Google and Chrome,  but various extensions allow you to add even more security functions.  For example, Web of Trust (WOT) can warn you of dangerous sites, and ADBlock can remove annoying or malicious advertisements that can lead to malware or phishing sites. View Thru lets you see the destination of shortened URLs, and KB SSL Enforcer can help you take advantage of HTTPS/SSL encryption on sites that support it.