Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
A Home User's Security Checklist for Windows
Scott Granneman, 2004-02-13

Most people don't secure their computers or act in a secure manner, and the main reason is that the average user just doesn't know what to do. Here is a checklist on security for home computer users that you can share with your friends, family, churches and clubs.

Comments Mode:
A Home User's Security Checklist for Windows 2004-02-15
Anonymous (2 replies)
announcements, not patches 2004-02-23
Paul D
Phishing 2004-02-23
Al Macintyre
Addendum 2004-02-16
Dirk (4 replies)
Addendum 2004-02-17
Anonymous (1 replies)
Addendum 2004-02-18
Anonymous
Addendum 2004-02-17
Anonymous (2 replies)
Addendum 2004-02-24
Al Macintyre
Addendum 2004-02-23
Anonymous
A Home User's Security Checklist for Windows 2004-02-16
Arthur Tvikrok (3 replies)
A Home User's Security Checklist for Windows (Scott read this) 2004-02-19
Anonymous
This is to get Scott's attention to update his article before more people screw themselves... Thanks Arthur Tvikrok for pointing out KB 299958 that Regclean is incompatible with:

Microsoft Office 2003, All Editions
Microsoft Office XP (Setup)
Microsoft Office 2000 (Setup)

and has been specifically declared unsupported by MS.

Further, this list needs to note where there are differences between Win95/98/ME/XP, or that it applies to all platforms. In general it does, but you have to be clear. For example, XP Home default users don't use a password to login, and may not know that extra users they create are administrators too - so how to enable passwords & check privileges... Another person commented that many apps require Admin privileges - this is true and you should make them aware of that.

Why did you omit a section to help them recover from crashes and data corruption ?
All computer flavors need a backup & restore/recovery plan for:
- file loss or corruption
- application config/install corruption
- OS/System corruption
- hard disk failure (or laptop theft)

Surely there's a good link to point to that discusses options for the above per platform. Things like making sure XP System Restore point has been created (which doesn't happen on OEM pre-installs when you finish setup), Automatic System Restore diskettes created when you do a full-system backup (only external USB or writeable DVD drives can typically hold the backup files), and/or simple ntbackup backups for data subsets. Or 3rd party software like Norton Ghost which requires a bootable floppy if you want to use it to recover your hard disk from a complete failure using a new one HD.

Others have suggested disabling services. But my experience is that this breaks applications, or the apps just re-enable the required services. So I'd stay away from all but the simplest to disable and reenable. I would recommend making sure that your firewall isn't set on "medium" security or hasn't allowed inbound access to ports open by "trusted" programs.

I do like the list as a start though. Thanks !

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/220/25128#25128
Registry editors removed 2004-02-20
Kelly Martin
Norton Doctor 2004-02-24
Al Macintyre
A Home User's Security Checklist for Windows 2004-02-17
Anonymous (1 replies)
A Home User's Security Checklist for Windows 2004-02-18
Anonymous (1 replies)
A Home User's Security Checklist for Windows 2004-02-19
Anonymous (1 replies)
A Home User's Security Checklist for Windows 2004-02-20
Anonymous (1 replies)
Alternatives 2004-02-24
Al Macintyre
A Home User's Security Checklist for Windows 2004-02-18
Patrick Balleux (1 replies)
A Home User's Security Checklist for Windows 2004-02-18
Anonymous (2 replies)
Safer OS 2004-02-24
Al Macintyre
A Home User's Security Checklist for Windows 2004-02-18
Ron O (1 replies)
Opt-out 2004-02-23
Anonymous
Nice Windows Advert at the bottom... 2004-02-18
Penguinisto (1 replies)
A Home User's Security Checklist for Windows 2004-02-18
Anonymous (1 replies)
Email attachments and FTP 2004-02-23
Anonymous
Passwords 2004-02-23
Al Macintyre
Disconnect from the Internet 2004-02-25
Cornelius (1 replies)
Re: Disconnect from the Internet 2005-09-19
Anonymous
A Home User's Security Checklist for Windows 2005-10-11
nietsec@gmail.com
Shared folders 2005-11-04
Eric the Addict







 

Privacy Statement
Copyright 2008, SecurityFocus