Author Topic: SECURITY WARNINGS & Notices - Please post them here  (Read 2886215 times)

0 Members and 2 Guests are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3840 on: June 30, 2015, 01:40:41 PM »
Most internet anonymity software leaks users’ details -
VPN Services are secure is a myth!
Read: http://www.qmul.ac.uk/media/news/items/se/158459.html
Research paper: http://www.eecs.qmul.ac.uk/~hamed/papers/PETS2015VPN.pdf

See survey attached.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48553
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3841 on: June 30, 2015, 02:26:12 PM »
Most internet anonymity software leaks users’ details -
VPN Services are secure is a myth!
Read: http://www.qmul.ac.uk/media/news/items/se/158459.html
Research paper: http://www.eecs.qmul.ac.uk/~hamed/papers/PETS2015VPN.pdf

See survey attached.

polonus
It's nice to see that Avast's SecureLine isn't on that list. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline merckxist

  • Jr. Member
  • **
  • Posts: 76
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3842 on: June 30, 2015, 07:15:38 PM »
Most internet anonymity software leaks users’ details -
VPN Services are secure is a myth!
Read: http://www.qmul.ac.uk/media/news/items/se/158459.html
Research paper: http://www.eecs.qmul.ac.uk/~hamed/papers/PETS2015VPN.pdf

See survey attached.

polonus
It's nice to see that Avast's SecureLine isn't on that list. :)

I believe the absence of Avast SecureLine means that it wasn't part of the test as indicated by the subtitle of the attachment. It would have been "nicer" to see that it WAS on the list with a green "N" in each column. Since it apparently wasn't tested there's no way to know whether its absence is a good or bad thing.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
« Last Edit: June 30, 2015, 10:41:18 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3844 on: July 01, 2015, 07:18:59 PM »
The NoScript extension in firefox can be circumvented via Google cloud and whitelisted by default googleapis dot com.
Read: http://thehackerblog.com/the-noscript-misnomer-why-should-i-trust-vjs-zendcdn-net/
link article author = Matthew Bryant
Code to bypass noscript: https://twitter.com/avlidienbrunn/status/615659880788193280 (Mathias Karlsson).
The original idea: http://labs.detectify.com/post/122837757551/using-google-cloud-to-bypass-noscript
by Linus Särud, junior security researcher.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3845 on: July 01, 2015, 08:31:46 PM »
The NoScript extension in firefox can be circumvented via Google cloud and whitelisted by default googleapis dot com.
Read: http://thehackerblog.com/the-noscript-misnomer-why-should-i-trust-vjs-zendcdn-net/
link article author = Matthew Bryant
Code to bypass noscript: https://twitter.com/avlidienbrunn/status/615659880788193280 (Mathias Karlsson).
The original idea: http://labs.detectify.com/post/122837757551/using-google-cloud-to-bypass-noscript
by Linus Särud, junior security researcher.

polonus



I wiped NoScript's default whitelist long ago.  This is actually old news, since any whitelisted site (even by the user) can execute scripts and other content on the page.

Edit: Took my reply out of the quote.  Sorry
« Last Edit: July 02, 2015, 12:32:54 AM by Gopher John »
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89033
  • No support PMs thanks
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3846 on: July 01, 2015, 08:39:45 PM »
The NoScript extension in firefox can be circumvented via Google cloud and whitelisted by default googleapis dot com.
Read: http://thehackerblog.com/the-noscript-misnomer-why-should-i-trust-vjs-zendcdn-net/
link article author = Matthew Bryant
Code to bypass noscript: https://twitter.com/avlidienbrunn/status/615659880788193280 (Mathias Karlsson).
The original idea: http://labs.detectify.com/post/122837757551/using-google-cloud-to-bypass-noscript
by Linus Särud, junior security researcher.

polonus

Generally I allow googleapis.com in noscript - But another blocking function could be to use RequestPolicy to specifically block *.googleapis if required.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3848 on: July 01, 2015, 10:31:28 PM »
Not only snakeoil but snakeoil that normally comes free as free driver downloads on the Interwebs while these services come to charge you for similar driver downloads, an outright scam. Scammers always on the look-out to rip off an extra buck from the backs of the unaware and the meek. We won't be fooled again! (same goes for registry vacuum cleaners also added to PUP detection by MBAM, (good action, folks, good action).

pol

« Last Edit: July 01, 2015, 10:34:25 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48553
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3849 on: July 01, 2015, 11:06:28 PM »

Driver Updaters: Digital Snake Oil, Part 2

https://blog.malwarebytes.org/social-engineering/2015/06/driver-updaters-digital-snake-oil-part-2/?utm_source=Gplus&utm_medium=social
Quote
Everything would seem to indicate that updating drivers should be a good thing, and there are several reputable driver updater programs in existence.[/font][/size]
The secret is in eliminating the crap and picking out a good one. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3850 on: July 01, 2015, 11:59:01 PM »
Hi bob3160,

The bad thing is the user has to fend for himself more and more now.
You are no longer protected, you are out on your own.
You have to block, you have to take the crap from downloads.
You have become both product and often also become a victim of cheap tricks.
How can you trust anything online as an unaware user finding yourself in such a situation,
Users are had big time when not from the one side then from the other.
It is a dangerous digital world out there and one is out on one's own.

Conclusion.

Good we have the Avast support forums to provide users with a bit of honest guidelines,
Here we still say - a man a man - a word a word - rare to be found nowadays a place to trust,
let cherish that, bob3160, let us cherish that. It is so rare these days.

polonus

P.S. Updating drivers is not always and under all circumstances a good thing or needed, it might sometimes add to your problems, forewarned is forearmed/.

D
« Last Edit: July 02, 2015, 12:05:29 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48553
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3851 on: July 02, 2015, 12:40:13 AM »
Hi bob3160,

The bad thing is the user has to fend for himself more and more now.
You are no longer protected, you are out on your own.
You have to block, you have to take the crap from downloads.
You have become both product and often also become a victim of cheap tricks.
How can you trust anything online as an unaware user finding yourself in such a situation,
Users are had big time when not from the one side then from the other.
It is a dangerous digital world out there and one is out on one's own.

Conclusion.

Good we have the Avast support forums to provide users with a bit of honest guidelines,
Here we still say - a man a man - a word a word - rare to be found nowadays a place to trust,
let cherish that, bob3160, let us cherish that. It is so rare these days.

polonus

P.S. Updating drivers is not always and under all circumstances a good thing or needed, it might sometimes add to your problems, forewarned is forearmed/.

D
I've never had an outdated driver replaced with a newer signed driver that presented a problem.
Legitimate programs also don't request that you pay to update. You'll find a recommendation  at:
https://forum.avast.com/index.php?topic=19387.msg1205358#msg1205358
(I don't allow it to run at system start. I start it manually when I want to check for updates; both program and driver updates.)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3852 on: July 02, 2015, 07:42:54 AM »
The NoScript extension in firefox can be circumvented via Google cloud and whitelisted by default googleapis dot com.
Read: http://thehackerblog.com/the-noscript-misnomer-why-should-i-trust-vjs-zendcdn-net/
link article author = Matthew Bryant
Code to bypass noscript: https://twitter.com/avlidienbrunn/status/615659880788193280 (Mathias Karlsson).
The original idea: http://labs.detectify.com/post/122837757551/using-google-cloud-to-bypass-noscript
by Linus Särud, junior security researcher.

polonus
Fixed in V2.6.9.29 :) -> https://noscript.net/changelog
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3853 on: July 02, 2015, 03:36:58 PM »
Is your Google Chrome browser hooked into BeEF? Protect with Vegan, read: http://blog.cylance.com/vegan-chrome-extension-to-defeat-beef

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: SECURITY WARNINGS & Notices - Please post them here
« Reply #3854 on: July 02, 2015, 04:32:25 PM »
You want to share Wifi access with all of your Outlook-, Skype - and Facebook contacts within reach of your local network access point?
You have second thoughts also, then read on.
Wifi Sense does just that and has been introduced for the first time as it  sneaked into Windows Phone 8.1. and no-one reacted, but now that this feature comes to Windows 10 security experts make some really deep frowns. Windows stores your password encrypted in the cloud and then shares it with all your acquantances (contacts) within the reach of your local network. This feature is on by default and the user has to disable it actively (only for that particular device) For the network an adaptation of the SSID is necessary by adding the string "_optout". Security experts call the feature "a cheap hack" and a security breach of Wifi networking as such! Certainly a risk for the not so technically adept user. Modern OS gets more and more one way invasive and one has to go into technical trouble to get at the settings that one really prefers. It is almost like "we will decide what is good for you whether you share your access, whether we will show you personalised ads that are very difficult to block etc. etc. and all these "handy features whether you like it or not are slowly creeping in so young users do not know of an alrternative situation as where we came from to land here.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!