Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • WinDeals
  • E-Books
  • Lounge
  • Polls
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Security Baseline provides basic PC protection

Windows Secrets Newsletter • Issue 212 • 2009-08-27 • Circulation: over 400,000


Table of contents 
  • Introduction: New info leads to today’s unscheduled newsletter
  • Top Story: Security Baseline provides basic PC protection
  • Woody's Windows: ISPs block some outgoing e-mail unexpectedly
  • Patch Watch: IE 8 is being pushed to systems that blocked it

 
Introduction

New info leads to today’s unscheduled newsletter

Brian Livingston 1 New info leads to todays unscheduled newsletter By Brian Livingston

We don’t usually publish new content during our summer break in the last two weeks of August, but an update to the WS Security Baseline is compelling us to release special content for you today.

Besides that, we’re also releasing breaking news by contributing editors Woody Leonhard and Susan Bradley on ways some Internet service providers may be blocking your e-mail (and how you can work around it) and on the fact that Microsoft has started pushing out Internet Explorer 8 even to people who previously declined it.

Security Baseline gets new list and new writer

As long-time readers know, Windows Secrets periodically publishes a feature called the Security Baseline. This advisory is intended to advise home and small-business PC users on the minimal setup they need to protect themselves against hackers.

I recently asked Robert Vamosi, an award-winning tech writer, to update the baseline with the latest findings from around the Web. Robert has written for CNET, CNN, the BBC, and many other outlets. His analysis of the latest test-lab reports will be welcomed by anyone whose security is, shall we say, not up to par.

Advanced Windows users should always conduct their own research on the best combination of security products for their specialized needs. But if your mom and dad think buying a PC in a store and plugging it into the Internet is all the security they need (or you think that’s all you need), take a minute to read Robert’s article in our free content. Or surf to our site’s Security Baseline page, which is updated whenever we find a major change.

Woody’s and Susan’s articles are contained in our paid content today. If you’re a free subscriber and aren’t receiving our paid content, it’s easy to get. There’s no fixed fee! Simply make a financial contribution of any amount — whatever it’s worth to you — and you’ll receive all WS paid content for one full year. More info on how to upgrade

New bonus download for all paying subscribers

A big benefit for our paying subscribers is the fact that we license valuable content several times a year and let our paid readers download it at no extra cost.

W20090820 TYV Windows7 small New info leads to todays unscheduled newsletter
This month’s bonus is a two-chapter excerpt from Teach Yourself Visually Microsoft Windows 7 by Paul McFedries. The book uses illustrations and screen shots instead of straight text to help make the transition to Windows 7 easier than ever for computer users.

The printed volume won’t be available in stores until late September. But all paid subscribers can receive our exclusive download now through Sept. 23. Free subscribers who upgrade to paid will see a download link thereafter. Paid subscribers can simply visit their preferences page and save any changes to see the download link. Thanks for your support!

Free subscribers: Upgrade to paid and get the bonus
Paid subscribers: Set your preferences and then download
Info on the printed book: United States / Canada / Elsewhere

Brian Livingston is editorial director of WindowsSecrets.com and co-author of Windows Vista Secrets and 10 other books.

 
Top Story

Security Baseline provides basic PC protection

Robert Vamosi 1 Security Baseline provides basic PC protection By Robert Vamosi

The Windows Secrets Security Baseline describes products and services that serve as a minimum safe PC configuration.

This week, I’m updating the latest findings on a set of hardware and software that should meet the needs of individual PC users, though more-advanced users and large businesses may want a more-sophisticated approach to computer defense.

It sometimes seems like we spend more time protecting our PCs than actually using them. Sadly, in the modern computer age our systems are under continuous attack. Even worse, those attacks take ever-new approaches to break into our PCs and steal our personal data.

Fortunately, you can put the odds against becoming a malware victim decidedly in your favor by taking a few relatively simple precautions. That’s the purpose of the WS Security Baseline. Windows Secrets doesn’t have a test lab and ordinarily doesn’t test hardware, so we analyze the results of independent labs to determine which products provide a balance of security and convenience for individual PC users.

The baseline’s four components are a hardware firewall that’s built into your router, security software that guards against all types of malware threats, a software-update service to ensure that your applications are patched against the latest exploits, and a secure browser.

Keep in mind that the baseline is just that: the minimum precautions required to protect the average PC user. Depending on your activities and level of computer experience, your security may require added layers of protection, including encrypted data storage and transmission, PC virtualization, and parental controls.

For more information on virtualization software, see WS senior editor Gizmo Richards’ Dec. 18, 2008, column, “Keep your Net activities away from prying eyes.” Contributing editor Becky Waring offers sage advice on keeping your children safe online in her Dec. 4, 2008, column, “Tools let parents control their kids’ PC use.”

New top choice for router-based firewall

D-Link DIR-825 Xtreme N Dual Band Gigabit Router boasts an Editor’s Choice from PCMag and high marks from other publications as well. While wireless routers are not so secure as hard-wired units, this model includes a guest feature that lets you grant friends wireless access to your network while blocking them from accessing anything on the network except the Internet.

W20090806 DIR 825 2 Security Baseline provides basic PC protection
Figure 1. D-Link’s DIR-825 Xtreme N Dual Band Gigabit Router makes it easy to let friends use your wireless network securely.

Other features of the DIR-825 are device sharing via a USB port, support for 2.4-GHz and 5-GHz mixed-mode Wi-Fi, and the ability to connect a USB EV-DO card for use as a cell modem should your WAN link fail, according to PCMag. The product costs about U.S. $150 online. Visit the routers page on D-Link’s site for more information.

Security suites are simple and all-in-one

The most straightforward approach to PC security is to use a security suite — such as Symantec’s Norton Internet Security or Norton 360, McAfee’s Internet Security or Total Protection, and Kaspersky’s Internet Security — that protects your PC from viruses, Trojans, spam, and other malware. You benefit from having to install and maintain only one application, as opposed to the best-of-breed approach to security software that requires multiple installations and updates.

Many experienced PC users prefer to pick and choose their security programs so they get just the features and interfaces they prefer. Also, security suites have a reputation for being difficult to uninstall. Most importantly, many top-rated specialty apps are free. The suites cost from $30 to $70 a year for up to three PCs.

The benefit of a security suite for a home user is convenience. Only a single product needs to be purchased, configured, and updated.

Having achieved top or first-runner-up honors from the editors of PC World, PCMag, Maximum PC, and other reviewers, today’s consensus security-suite selection is Symantec’s Norton Internet Security 2009. The program pairs excellent malware detection with a good range of features. The latest release continues to be faster and less resource-hungry than previous versions, according to PCMag and other testers.

If you’re one of the many people who’ve sworn never to install a Norton or McAfee security product again, however, there are a lot of other strong contenders for security-suite top dog:

  • Maximum PC lists ESET Smart Security as its second choice; the program matched Symantec’s score of 9 out of 10. (Read Maximum PC’s most recent security-software reviews.)

  • Norton Internet Security shares its PCMag Editors’ Choice with ZoneAlarm Extreme Security. (Read recent PCMag security-software reviews.)

  • PC World rates G-Data Internet Security 2010 as its first choice — just ahead of Norton Internet Security — and ranks BitDefender Internet Security 2009 just behind Norton. (Read the full BitDefender review and all PC World security-app reviews.)

For those who’d rather select their security program solely on the results of independent antivirus test labs, visit AV-Comparatives.org’s list of recently tested antivirus apps, AV-Test.org’s comparison of AV test results, or Virus Bulletin’s summary of AV test results (free registration required). Many people rely on ICSA Labs’ AV test reports, but ICSA’s certification testing can be less stringent than the testing performed by the three antivirus test labs cited above.

If you choose a specialty antivirus program over a suite, you’ll need to download and install a good software firewall as well. (This is in addition to the firewall built into your network hardware.) The free Comodo Internet Security combines a firewall and antivirus app; more information and a download link are on the vendor’s site. An alternative is Agnitum’s Outpost Firewall Free; Agnitum’s site provides more information about the product.

One of the highest-rated free antivirus programs — by PC users and software reviewers alike — is Malwarebyte.org’s AntiMalware, available for download from the company’s site.

Update services identify unpatched applications

For novices, the free Microsoft Update service automatically patches Windows, Office, and other Microsoft programs. (The service requires Internet Explorer, which has security weaknesses of its own. However, it’s extremely unlikely that any malware will make it onto the Microsoft site and attempt to infect your PC by exploiting a vulnerability in IE.)

Susan Bradley and other WS contributing editors recommend that you configure Windows’ Automatic Updates service to Notify me but don’t automatically download and install. Before you install any Windows updates, read Susan’s twice-a-month Patch Watch column and other Windows Secrets articles to learn which patches might be risky or otherwise undesirable.

Many PC users don’t trust Microsoft’s opinion of what they should install, and neither of the MS programs report on patches for non-Microsoft programs. In her May 28 Top Story, Susan reviews Shavlik’s Patch Google Gadget, Secunia’s Online Software Inspector/Personal Software Inspector, and Belarc Advisor as alternatives to Windows Update and Microsoft Update.

The downside of using Shavlik’s updater is the program’s reliance on the Google Desktop program, which some analysts consider a privacy risk. If you wish to use the updater anyway, however, you’ll find it on Shavlik’s download page.

Secunia’s OSI runs in your browser, requiring no download or installation, while PSI is a standalone program that installs on your PC. You can download PSI from Secunia’s site.

If you find yourself forgetting to run either OSI or PSI after Microsoft releases updates, you can sign up for an automatic reminder. To do so, click Secunia’s reminder service link and enter your e-mail address. The company will notify you whenever a new update is released.

The free Belarc Advisor utility can be downloaded from the Belarc site. The program’s interface isn’t too pretty, but Belarc does the job.

Use a browser that will keep you safe

Until recently, most experts agreed that the safest way to surf the Web was to use Mozilla’s Firefox browser, available from the organization’s download page.

At present, Secunia’s Firefox 3.0.x advisory page states there’s a URL spoofing issue in that version of the browser. The equivalent report for Firefox 3.5.x indicates the same unpatched vulnerability.

By comparison, Secunia’s report for Google Chrome 3.x shows no advisories for that browser. Likewise, Google Chrome 2.x comes up clean in Secunia’s analysis. That gives Chrome a bit of an edge over Firefox security-wise, at least for the moment.

For added safety when using Firefox, download the donationware NoScript add-on, which is available from the vendor’s site. This extension automatically blocks JavaScript and Adobe media files on a site-by-site or source-by-source basis, allowing you to override the blocks as needed. NoScript can also thwart clickjacking attempts and other Web nasties. (Be sure to add WindowsSecrets.com and other trusted names to your list of sites that are permitted to use JavaScript, which is important for some Web functions.)

Windows Update and some other Microsoft services require Internet Explorer. Unfortunately, Susan Bradley hasn’t yet been able to give the latest version — IE 8 — the thumbs-up for large enterprises, due to incompatibilities it has with some sites.

I recommend that you use Firefox, Chrome, or another IE alternative as your default browser and open IE only when necessary.

Having a patched copy of Internet Explorer installed, however, keeps your PC free of exploits targeting Office and other Microsoft products that use IE’s HTML-rendering capabilities.

Secunia states on its IE 8 page that Microsoft has addressed only two of the four vulnerabilities found to date in the new browser. The service’s report of a URL path-spoofing vulnerability was posted on Aug. 19. A “Charset Inheritance Cross-Site Scripting Vulnerability” in IE 8 remains unpatched more than two years after the problem was first discovered, according to Secunia’s report. (The vulnerability also affects IE 7.)

To be sure, Firefox and other browsers periodically suffer from flaws such as IE’s. But until Microsoft learns to close its browser’s holes within days, as Mozilla and other browser developers do, using Firefox or another alternative to IE is still your best bet.

WS contributing editor Robert Vamosi was senior editor of CNET.com from 1999 to 2008, writing pieces such as Security Watch, the winner of the 2005 MAGGIE Award for best regularly featured Web column for consumers.

 
Woody's Windows

ISPs block some outgoing e-mail unexpectedly

Woody Leonhard 1 ISPs block some outgoing e mail unexpectedly By Woody Leonhard

Recently, many Windows Secrets readers — me among them — discovered that they could no longer send e-mail, although they could still receive messages.

In an attempt to reduce spam, many ISPs, including Verizon as of a few months ago, now block all outbound traffic on what used to be the de facto avenue for e-mail, port 25 — leaving customers in the lurch.

E-mail glitches rate among the most difficult, distressing, and dire problems in all of computer-dumb. Orphaned e-mail programs, operating systems with more patches than a clown’s coat, the whims of intransigent e-mail and Internet service providers, and the phases of the moon combine to make e-mail problems devilishly difficult to solve.

And any e-mail glitches you fix today will undoubtedly require even more remedial attention in a month or a year.

One problem pops up regularly over the years because an ISP suddenly blocks all outbound communication using port 25. This glitch has a very specific symptom: your e-mail program — whether Outlook, Windows Live Mail, Outlook Express, Windows Mail, Thunderbird, or Eudora — suddenly loses its ability to send mail. You can receive messages with no problem, but every e-mail you try to send sticks in your outbox.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


 
Patch Watch

IE 8 is being pushed to systems that blocked it

Susan Bradley 1 IE 8 is being pushed to systems that blocked it By Susan Bradley

Microsoft has begun presenting Internet Explorer 8 as an available update to PCs that previously hid IE 8 from the update list.

If you’ve previously declined and hidden IE 8 in one of Microsoft’s update services, you’ll need to do so again to prevent the browser from being part of the download list.


The return of the Internet Explorer 8 download

On Aug. 25, Microsoft repackaged the IE 8 download, bundling with it all of IE 8′s cumulative updates and patches for Windows XP, Vista, Server 2003, and Server 2008.

The new patch bundle is being pushed out to PCs over a period of time via Microsoft Update, Windows Update, and WSUS (Windows Server Update Services). At present, the bundle is being offered even to systems that were previously configured to (1) scan for patches manually only and (2) hide IE 8 from the update list.

If your system didn’t have Automatic Updates (AU) completely disabled, Windows was set to one of three AU modes: download and install updates automatically, download updates but notify you before installing, or notify you when updates are ready but don’t download and install.

In any of those three modes, Internet Explorer 8 may not have been “pushed” to your PC via Microsoft’s update services — yet. However, you should expect that to change very soon, and IE 8 will be listed as an available update, even if you’ve declined and hidden it from the list in the past.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.


YOUR SUBSCRIPTION

The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008.

Publisher: WindowsSecrets.com, 1218 Third Ave., Suite 1515, Seattle, WA 98101 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine).

Editor in chief: Tracey Capen. Senior editors: Fred Langa, Woody Leonhard. Copyeditor: Roberta Scholz. Program director: Tony Johnston. Contributing editors: Yardena Arar, Susan Bradley, Scott Dunn, Michael Lasky, Scott Mace, Ryan Russell, Lincoln Spector, Robert Vamosi, Becky Waring. Product manager: Andy Boyd. Advertising director: Eric Gilley.

Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com. All other marks are the trademarks or service marks of their respective owners.

HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page.

WE GUARANTEE YOUR PRIVACY:

1. We will never sell, rent, or give away your address to any outside party, ever.
2. We will never send you any unrequested e-mail, besides newsletter updates.
3. All unsubscribe requests are honored immediately, period.  Privacy policy

HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
  • Visit our Unsubscribe page.
Copyright © 2012 by WindowsSecrets.com. All rights reserved.

Table of contents

Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.57
  • LizaMoon infection: a blow-by-blow account 4.46
  • RPV: Win7′s least-known data-protection system 4.35
  • Recovery: the last step in total data security 4.31
  • The sorry tale of the (un)Secure Sockets Layer 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Get wired performance from your Wi-Fi network 4.24
  • Caution: Bumps in the road to IPv6 4.23
  • Patch Watch adds problem-patch update chart 4.23
  • ZeuS Trojan reinvents itself as bots rock on 4.22
  • Pros and cons of a ‘keyfile’ password 4.21
  • April brings showers of browser patches 4.20
  • Readers comment on the LizaMoon infection story 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • The advanced system-recover toolkit 4.18
  • One year and 99 security bulletins later 4.18
  • Don’t pay for software you don’t need — Part 3 4.17
  • What to do when Windows refuses to boot 4.17
  • Make the most of Windows 7′s Libraries 4.16
  • Keeping you up to date: say no to .NET — again 4.16
  • Internet Explorer gets another round of patches 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Big-time Wi-Fi security for the small office 4.14
  • Office File Validation patch leads to problems 4.14
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb