Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Computer log on security advice

Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Computer log on security advice

Thread Tools
 
Search this Thread
 
Old 24th Dec 2010, 14:27
  #1 (permalink)  
Thread Starter
 
Join Date: Jun 2005
Location: heathrow
Posts: 54
Likes: 0
Received 21 Likes on 9 Posts
Computer log on security advice

Hi,

I will shortly be going abroad for a few weeks and will be taking my laptop with me, At present I don't have any log on password set up on it as it's only ever used in my house and there isn't anything too important or personal stored on it.

However, while I'm away I will be accessing and storing quite a few work related e-mails, so I thought it would be a good idea to secure the computer a bit.
Reading up on this, I've been lead to believe that the windows log on password system isn't very secure and can easily be bypassed by someone with a little bit of knowledge, so I was hoping someone on here could give me some recommendations or advice as how best to go about making my laptop a bit harder for someone to get into.

many thanks, and Christmas wishes to all.
747 jock is offline  
Old 24th Dec 2010, 16:19
  #2 (permalink)  
Spoon PPRuNerist & Mad Inistrator
 
Join Date: Sep 2003
Location: Twickenham, home of rugby
Posts: 7,401
Received 274 Likes on 174 Posts
Here's a few suggestions:
  • Password protect the BIOS. Set a Power-on password.
  • Don't allow booting from removable media - USB / CD / floppy.
  • Set strong passwords for any required accounts, including administrator - min. 10 characters, combining alpha / numeric / special characters.
  • Rename the Administrator account to something else - e.g. "&^admin" that is easy for you to remember but hard for someone to guess.
  • Disable or delete unnecessary accounts, e.g. Guest.
  • Consider installing whole-disk or folder encryption if you have sensitive data.
  • Ensure that you have at least Windows firewall running, preferably something a little stronger.
  • If using wifi, configure to only connect to Access points, not ad-hoc devices (other PCs).

SD
Saab Dastard is offline  
Old 24th Dec 2010, 20:13
  #3 (permalink)  
 
Join Date: Nov 2000
Location: Cambridge, England, EU
Posts: 3,443
Likes: 0
Received 1 Like on 1 Post
What are you trying to protect against?

If you're trying to stop someone who has physical access to the machine and who is seriously keen on accessing your data reading stuff that's on it ("evil maid attack"), then forget it, you can't win that one.

If you are trying to protect against incoming nasties over the wire or wi-fi, because when travelling you won't have your normal sleath mode router in between you and the internet, then getting patched up to date is what's most important. (You could try switching on a firewall but I've always found them more trouble than they're worth.)

Yes you probably should set a password. It'll be a small stumbling block to a casual thief, who is after the hardware not the data. Just about worth the effort.
Gertrude the Wombat is offline  
Old 24th Dec 2010, 22:12
  #4 (permalink)  
Thread Starter
 
Join Date: Jun 2005
Location: heathrow
Posts: 54
Likes: 0
Received 21 Likes on 9 Posts
Thanks Saab. I've set a BIOS password and also a fairly strong account password.

All I'm trying to protect against Gertrude is someone getting easy access to the laptop and getting to read some of the stored e-mail I have on there.
There's nothing too valuable or important on there and the computer itself is only a low budget model so I don't even think it would be worth banyone trying to break it up for spares.
It was only access by opportunists that I am trying to avoid. (hotel staff for example).

I always keep my antivirus and spyware progs up to date and try not to view any "dodgy" or suspect sites when I'm travelling.
747 jock is offline  
Old 24th Dec 2010, 22:44
  #5 (permalink)  
 
Join Date: Nov 2000
Location: Cambridge, England, EU
Posts: 3,443
Likes: 0
Received 1 Like on 1 Post
It was only access by opportunists that I am trying to avoid.
A password will protect against a nosey person who tries to log in, fails, and gives up. That's about all it will do though.

Always a good idea to say what threat model you're worried about when asking for security advice, otherwise you could get wildly different answers each of which would be correct for a different scenario.
Gertrude the Wombat is offline  
Old 25th Dec 2010, 17:18
  #6 (permalink)  
 
Join Date: Nov 2000
Location: Pewsey, UK
Posts: 1,976
Received 12 Likes on 6 Posts
It's not just logon passwords - physically protecting the laptop will help against theft.

However, check out the noise about FireSheep.

In essence if you use your laptop to access services from somewhere other than your own home or corporate network - and even then there's no 100% guarantee - use a VPN, or make sure that the web page / internet accessible service you use makes EXCLUSIVE use of secured protocols - HTTPS, S/IMAP, etc.

Edited to add this after I'd digested Gertrude's advice - what things are important to you when you use the computer that you're trying to protect ? Answer that, and we'll help you out more than we can by blind posting.
The Nr Fairy is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.