TECHNOLOGY: Prudent Computing

Royal Van Horn · Phi Delta Kappan · 2003

RECENT REPORTS show that 90% of all large corporations and government agencies have experienced a computer security attack. Furthermore, in a recent survey of its readers, Consumer Reports found that 58% of respondents had discovered at least one computer virus on their computers in the last two years and 10% had incurred serious virus damage. Incidentally, the Consumer Reports survey also found that Windows users were three times more likely to encounter a virus than Mac users (62% versus 23%). Eleven percent of Windows users reported damage, while only 2% of Mac users did.1 Given such data and the early fall outbreak of Blaster and other viruses, computer users everywhere need to become more prudent. There are two main computer security issues. How can you protect your computer from attack or damage, and how can you protect sensitive personal information, including your identity? My focus here will be on the desktop computer you use and not on networks or Internet service providers. If you do most of your computing on a school or business network, you should seek out advice from your network administrators. Specifically, do not install software on your computer without consulting a network administrator. The most fundamental way to protect your computer from attack is to turn it off when you are not using it. Most people turn their computer on in the morning, check their e-mail, and then go about their business -- often ignoring the computer until late afternoon. If you want to work on your computer, but don't need e-mail or Web access, you can protect yourself by simply turning off the computer's Ethernet network connection. You are especially at risk if you leave Instant Messaging (IM) software on unattended. It helps if you configure your IM software to not send or receive anything except text, but few people do this. And I have been guilty of ignoring this advice myself. Several years ago, I had a computer that I did not turn off for two years. Another fundamental way to protect yourself is to be careful about your passwords. Use different passwords for different software, pick passwords that are hard to decrypt or guess, and do not let your computer remember your password for you. Almost no one I know follows this simple advice. Here are a few password do's and don'ts from the Center for Information Technology at the National Institutes of Health: * Don't use your log-in name in any form (as-is, reversed, capitalized, doubled, etc.). * Don't use your first or last name in any form. * Don't use the name of your spouse or child. * Don't use other information about yourself that can be easily obtained: license plate numbers, telephone numbers, social security numbers, the brand of your automobile, the name of your street. * Don't use a password made up of all digits or all the same letter. * Don't use a word contained in dictionaries (English or foreign language), spelling lists, or other lists of words. * Don't use a password shorter than six characters. * Do use a password with mixed-case alphabetic characters. * Do use a password with nonalphabetic characters, e.g., digits or punctuation. * Do use a password that is easy to remember, so you don't have to write it down. * Do use a password that you can type quickly, without having to look at the keyboard. This makes it harder for someone to steal your password.2 I concur with the advice above, except for using mixed-case passwords, which I believe contradicts the last item -- be able to type it quickly. This fall's e-mail virus epidemic was caused in large part by users who failed to follow this simple rule: never open e-mail attachments -- even if they are from a friend -- unless you are certain they are legitimate. The fall viruses used spoofing, which is a technique hackers use to make you think you are receiving mail from a friend. …

Read the paper · More papers on PaperTik