Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Security for the Paranoid
Mark Burnett, 2005-04-26

Paranoia is the key to success in the security world. Is it time to worry when other security professionals consider you too paranoid?

Comments Mode:
Security for the Paranoid 2005-04-26
norwegian
Security for the Paranoid 2005-04-26
Anonymous (5 replies)
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-27
Rickard Johansson (1 replies)
Re: Security for the Paranoid 2005-06-09
Anonymous
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-05-25
Bradbury9
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-26
Times Enemy <times@krr.org>
Security for the Paranoid 2005-04-26
styliee
Security for the Paranoid 2005-04-26
Jeroen Kemperman (2 replies)
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Shadowkill
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous (1 replies)
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous
Security for the Paranoid 2005-04-26
Anonymous
know your enemy 2005-04-26
Anonymous
When Paranoia Annoys Ya 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
There is a very thin line between genius and insanity.

The main question here is that you asked if you're bordering insanity. My wife calls me Mr.P (not for you now what, she has another name for that) so I feel qualified enough to give my opinion of where you've crossed the line.

1- three firewalls
That depends if you mean three hardware or two hardware and one software. Three hardware is over the line. Unless you have a very complicated network.

Two hardware and one software may have reason. For example if you have many computers using a single IP. Having one hardware at the network entry point and another to protect your PC from the rest of the network makes sense. Then a software firewall to block any out going calls and you have a reasonably safe system.

2- Password day
The frequency on that depends on the environment. At home should be very sparingly. At work more often. But how often depends on your environment so I can't give you any judgement.

But changing after travels reveals fear of physical intrusion which could be justified at work but not at home. Unless you blocked your son's access to porn sites and you feel he wants to use your computer for that. Mine did that once, but the poor kid couldn't figure out my password and I caught him trying. So here you have a strong maybe.

3- always best security
Nothing wrong with consistency.

4- 14 characters at home
On the line I would say. Excessive for home but not crazy.

5- Smart card
Good idea

6- Wife not knowing network password.
Insane. What if you hit your head on the pavement and lose your memory of your password? How you gonna play solitaire then? Let alone access your important documents to file for divorce. Seriously, if you don't trust your wife you have bigger problems than being too paranoyd. You need to find another wife.

7- mulched documents
recycling is good. Hope you don't do that with your credit card and cds as well. That's not good for the environment.

8- unique email accounts.
thanks for confirming that I'm not uniquely insane. I have one for evey single person, not only online accounts. It's a pain to manage sometimes but it is very easy to identify whose computer got infected and provide me some extra income when they ask me to fix.

9- protect against future threats
If you can think of it, so will somebody else.

10- hardware keyloggers
At work ok. At home... means that you're either insane or that someone in your family is. A professional should be contacted in this case.

11- carry on lugage only
either you don't stay very long or you're very stingy with your presents for your family. I'm starting to understand your family now...

12- surf in a locked box
good practice

13- terrafly
is that a marijuana tree I see on the side of your house?

14- five passwords to email
hmmm... can't think of where two of them are. It's gotta be over the line.

15- Fifty character password for email???
If you type it, yes it is insane. If it is called from an application then it's just weird.

16- delete unused services
good

17- block unused ports
good

18- same day hotfix
risky. Gotta wait a couple to see if the fix is not killing other systems. Or if it's not a trojan from bill.

Conclusion:
You are way over the line on 6, 13, 14, 15. Just passed the line on 1, 2 and 11. On the line on 4, 10, 18. Near the line on 7. And far from the line on 3, 5, 8, 9, 12, 16, 17.

Overall, under my arbritary weighed system you are at 42% where the line is at 50%.

The key here is to see whether you are approaching the line, not moving, or moving away from the line.

By the tone of your article I think that you're moving towards the line, so you may need to take some measures to slow down the approach.

a- Install a keylogger and leave a note on your home desk with a list of your passwords for a couple days when you know people are at home. That may relax you more, or make you look for professional help for your family.

b- Stop spraying that plant with pesticides. I heard they have weird side effects.

c- Find a non-competitive hobby that takes you away from computers and allows you to meet non-computer people. A risky one like riding motorcycles is even better. Or cooking. That will probably make your wife think twice before signing the divorce papers.

Ok, hope you enjoyed my analysis. I'm taking $85 off your bank account now, thanks :-b

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/320/31603#31603
Security for the Paranoid 2005-04-27
Kron
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
dan@3-e.net
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-06-23
Morris Cox
Answers and clarifications 2005-04-27
Mark Burnett (1 replies)
Answers and clarifications 2005-04-28
Chatos Anonymous
sounds to be a reflection myself 2005-04-27
<visitbipin hotmail com>
Security for the Paranoid 2005-04-27
Anonymous
What OS are you using? 2005-04-27
Anonymous (1 replies)
What OS are you using? 2005-04-27
Zachary Palmer
Yet you use microsoft products? 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous coward
Security for the Paranoid 2005-04-27
ORBVS
Security for the Paranoid 2005-04-27
Anonymous (1 replies)
Re: Security for the Paranoid 2005-06-23
Morris Cox
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Stephen
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Forget TerraFly, use Google! 2005-04-27
Anonymous Bastard
Security for the Paranoid 2005-04-27
f1r3f1ght3r
Security for the Paranoid 2005-04-27
Anonymous Coward
Security for the Paranoid? 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
josh
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Autoversicherung
Not all that Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
JB kybrdcowboy@hotmail.com
the 50 character password 2005-04-27
Chirayu
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Security for the Paranoid 2005-04-27
Anonymous
Windows? 2005-04-27
Anonymous (1 replies)
Windows? 2005-05-02
Anonymous
Security for the Paranoid 2005-04-28
SafeCracka
Security for the Paranoid 2005-04-28
cornhead
Security for the Paranoid 2005-04-28
ZeroXeal
Absolutely right, although... 2005-04-28
Dmitry Kirsanov
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-28
Anonymous
Security for the Paranoid 2005-04-29
Anonymous
my password is my wife's name 2005-04-29
Anonymous
Due Dilligence vs. Effeciency 2005-04-29
Anonymous
Security for the Paranoid 2005-04-29
Anonymous (1 replies)
Security for the Paranoid 2005-05-02
Anonymous [Information Security Defender]
50-character password is overkill 2005-05-03
Anonymous (1 replies)
Security for the Paranoid 2005-05-06
Anonymous (1 replies)
Re: Security for the Paranoid 2006-05-25
Anonymous
Links for the Paranoid 2007-06-16
Anonymous
Security for the Paranoid 2008-02-17
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus