Original URL: https://www.theregister.com/2001/07/24/everything_you_ever_wanted/

Everything you ever wanted to know about PC security

But were too stupid to ask

By John Leyden

Posted in Security, 24th July 2001 15:51 GMT

Security clearing house CERT has published advice on how home PC users can protect themselves from the security threats posed by the Internet.

Traditionally the importance of consumers becoming aware of security risks has been a neglected area, but the emergence of Trojan horses which can turn domestic PCs in zombie clients that can harm enterprise Web sites has meant everyone needs protection. Throw into the mix the increasing prevalence of email-aware worms and the use of always on connections, which makes machines far easier to hack, and you have the makings of a serious problem.

To its credit CERT have recognised this and produced a document (CERT's guide to home network security) that explains to the consumer what the main Internet security risks are and how best to defend against them. It's also commendably honest by stating that its very much up to users to make sure they're secure - ISPs can't be relied on to protect their customers.

For the most part the document is clearly written and provides good arguments why it is a user's own interests to keep security patches and antiviral protection up to date (no-one likes to have their email riffled through). It also explains why it might be a good idea for consumers to use personal firewalls (such as Zone Alarm) to protect PCs linked to the Internet via always-on broadband connections.

Parts of the document get rather more technically involved and we wonder whether newbies really need to know the finer points of Network Address Translation (NAT) or UDP (User Datagram Protocol). Also we feel that the guide doesn't mention digital certificates, an understanding of which would help consumers to be more clued up about ecommerce. But these are minor quibbles.

The top twelve security risks for domestic users to be wary of (according to CERT) are:

CERT doesn't neglect risks that can arise even if you're nowhere near the Internet, such as disk failure or (obviously) physical theft. Helpfully it's come up with an action plan for consumers to consider:

Useful advice, which bears a quick read even for those consumers who are quiet knowledgeable about computers. If more people took on board what CERT had to say (well we can hope?) then the Internet would be a far more secure place. ®

External Links

CERT guide to home network security

Related Stories

IIS worm made to packet Whitehouse.gov
Internet survives Code Red
Privacy threatening worm on the loose
Users haven't learned any lessons from the Love Bug
Reports of death of email viruses greatly exaggerated?
IRC network comes under denial of service attack
Massed hack attack hits major Web sites
Hackers run amok during Defcon