<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber-Smarty.com &#187; Cyber tips</title>
	<atom:link href="http://cyber-smarty.com/category/cyber-tips/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyber-smarty.com</link>
	<description>Helping You to be Secure and Smart - Online</description>
	<lastBuildDate>Fri, 06 Jan 2012 07:00:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>How to Make Secure Settings for Facebook User Profile Page</title>
		<link>http://cyber-smarty.com/2011/12/secure-settings-facebook-profile-page/</link>
		<comments>http://cyber-smarty.com/2011/12/secure-settings-facebook-profile-page/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 10:21:59 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Social Networking Sites]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=542</guid>
		<description><![CDATA[Displaying the information which is useful for your friends to search you online is equally important to limiting the visibility of the information which is more personal, which let the hackers hack your page quiet easily. Following are the few tips which helps you to make you profile page of Facebook more secured. Besides, all [...]]]></description>
			<content:encoded><![CDATA[<p><!--OffDef-->
<p style="text-align: justify;"><img class="alignleft size-full wp-image-545" title="fb-privacy" src="http://cyber-smarty.com/wp-content/uploads/2011/12/fb-privacy.jpg" alt="" width="251" height="200" />Displaying the information which is useful for your friends to search you online is equally important to limiting the visibility of the information which is more personal, which let the hackers hack your page quiet easily. Following are the few tips which helps you to make you profile page of Facebook more secured.</p>
<p style="text-align: justify;">Besides, all the privacy setting you made for your profile there are few things which cannot be hidden by any user, that is they will be displayed for every profile. They are called as Publicly Available Information (PAI) according to Facebook, which includes full name, profile picture, gender, and networks. These things are commonly visible to any facebook user.</p>
<p>
<p style="text-align: justify;">However, you can reduce the visibility of the remaining information by making the necessary settings. Let us see how to choose the options that makes your profile more secure.</p>
<ul style="text-align: justify;">
<li>It is always better to use your full names which are hard for others to guess, but are easy for friends to recognize. It also limits the search results related to your usual name. Coming to the settings, &#8216;Search for me on facebook&#8217; is available so that you can choose the people who can search for you. It is better to go for &#8216;Friends only&#8217; if you want yourself limit to your friends.</li>
<li>&#8216;Send me friend request&#8217; – this option doesn&#8217;t make much difference because unless you accept the request of that person you cannot view your information. So, choose &#8216;any/every one&#8217; or &#8216;friends of friends&#8217; since the final decisions rests on you.</li>
<li>&#8216;Send me a message&#8217;, &#8216;See my friends list&#8217;, &#8216;See my education and work&#8217;, See my interests and other pages&#8217;- reserve these rights only for your friends by choosing &#8216;Friends only&#8217; in order to make your information more secure.</li>
<li>Finally &#8216;see my current city and home town&#8217; – it is better to choose &#8216;only me&#8217; or not entering that info is better.</li>
</ul>
<p style="text-align: justify;">These are the few recommendations which can help you secure your account.</p>
<p><span id="more-542"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.allfbcovers.com">Facebook covers</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2011/12/secure-settings-facebook-profile-page/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Most Dangerous Activities to Avoid Online</title>
		<link>http://cyber-smarty.com/2011/04/dangerous-activities-to-avoid-online/</link>
		<comments>http://cyber-smarty.com/2011/04/dangerous-activities-to-avoid-online/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 09:17:53 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[downloading]]></category>
		<category><![CDATA[password security]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=417</guid>
		<description><![CDATA[The Internet today is filled with huge amount of malware activities and one small mistake can make you fall prey to them. These mistakes often end up in infection of the PC or exploit online accounts (bank accounts, credit cards, etc.) of the user. The activities you need to avoid online are as follows: Not [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The Internet today is filled with huge amount of malware activities and one small mistake can make you fall prey to them. These mistakes often end up in infection of the PC or exploit online accounts (bank accounts, credit cards, etc.) of the user. The activities you need to avoid online are as follows:</p>
<p style="text-align: justify;"><strong>Not dealing seriously with passwords</strong><br />
Everyone knows that passwords are important. Yet most of them fail to create or maintain them properly. It might be because of the ignorance on the importance or on how to maintain them properly. Whatever may be the reason, the most <a href="http://cyber-smarty.com/2011/02/blunders-dealing-with-passwords/">common blunders to avoid while dealing with passwords</a> are:</p>
<ul style="text-align: justify;">
<li><strong>Creating easy-to-crack passwords</strong><br />
Hackers use ultra password cracking technologies. Not <a href="http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/">creating longer and complex passwords</a>, is actually equal to helping the hackers crack in to your account.</li>
<li><strong>Easy to guess password recovery options</strong><br />
Many websites use security questions to help people recover their password in case they lose it. Using simple questions like birth date, pet’s name which are either easy to guess or are visible openly on your social networking account, is another major blunder to avoid while dealing with passwords online.</li>
<li><strong>Using the same password for multiple online accounts </strong><br />
Same passwords for all online accounts are as safe as the weakest passwords. If one password is cracked or stolen, the chances for hacker to procure other online accounts of the user are high.</li>
</ul>
<p style="text-align: justify;"><strong>Getting lured into fascinating or controversial news</strong><br />
Malware authors know that people naturally are more interested in fascinating news or controversial rumors, and plan new attacks that are targeted specifically towards this crowd. This is called SEO poisoning. It&#8217;s estimated that more than 10 percent of search results for Google&#8217;s highest-ranked web sites are malicious sites.</p>
<p style="text-align: justify;"><strong>Failing to <a href="http://cyber-smarty.com/2009/11/why-should-we-run-windows-updates-regularly/">update Microsoft Windows OS</a> / Java / Adobe Reader / <a href="http://cyber-smarty.com/2010/10/updating-adobe-flash-player/">Adobe Flash</a></strong><br />
Updates are provided for software in order to patch-up security vulnerabilities in them. Especially, Windows, Java, Adobe Reader, Adobe Flash remain the most exploited software applications due to their vulnerabilities. Failing to update these leaves the PC potentially vulnerable for malware attacks.</p>
<p style="text-align: justify;"><strong>Opening an email attachment / Clicking on a link in an email &#8211; from someone you don&#8217;t know</strong><br />
According to a <a href="http://cyber-smarty.com/2011/02/email-spam-volumes-fall/">recent report</a> released by Symantec, spam now accounts for 78.6% of all email traffic in US and 75.7% of all email traffic, globally. Opening email attachments from unknown user may deploy malware into your PC. A link on a spam email may direct you to a spoofed website.</p>
<p style="text-align: justify;"><strong>Checking the &#8220;Remember Me&#8221; box in public PCs</strong><br />
This option saves cookies and login details of the user in the browser, until he signs-out manually. Thus, if the user checks back into the site later anytime, he doesn&#8217;t require to provide login details again, to access his account.</p>
<p style="text-align: justify;">However, while using public PCs, enabling this option is equal to providing your login details to the any user of that PC, who can check back at any time and access your account.</p>
<p style="text-align: justify;"><strong>Leaving Facebook privacy settings unchecked</strong><br />
Facebook is recently in the news for hacking of its CEO&#8217;s fan page. The most popular social networking site, Facebook, has many users who are not aware of its security features or privacy settings. Your personal information will be available for everyone to see if you leave privacy settings unchecked on Facebook.</p>
<p style="text-align: justify;"><strong>Using BitTorrent sites to download copyrighted content</strong><br />
<a href="http://cyber-smarty.com/tag/downloading/">Downloading illegal software</a> from BitTorrent sites can expose your computer to Trojans and Spyware.</p>
<p style="text-align: justify;"><strong>Playing free online games</strong><br />
There are many malicious websites online that lure users by providing free online games. Don’t play online games on unreliable websites. Also be cautious when asked to download free games.</p>
<p style="text-align: justify;"><strong>Connecting to unknown wireless networks</strong><br />
Many people log into unknown (private) wireless networks at public places like airports and hotels. These networks can be potentially harmful. Always be sure that you are logging into known (private) wireless networks only.</p>
<p style="text-align: justify;">These are the most dangerous online activities. Proper awareness and efficient precautions are required to stay away from committing those mistakes and stay safe and secure online.</p>
<p><span id="more-417"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.itcontractor.com">IT Contractor</a><br />
<a href="http://www.adspeed.com">ad serving</a><br />
<a href="http://itnewscast.com/underground-oracle-vm-manual">oracle vm</a><br />
<a href="http://www.apseratech.com/">wan optimization</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2011/04/dangerous-activities-to-avoid-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Your PCs from Notorious USB Drives</title>
		<link>http://cyber-smarty.com/2011/02/securing-pc-usb-drives/</link>
		<comments>http://cyber-smarty.com/2011/02/securing-pc-usb-drives/#comments</comments>
		<pubDate>Sat, 05 Feb 2011 04:41:33 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber Awareness]]></category>
		<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[USB Drives]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=328</guid>
		<description><![CDATA[No amount of precautions and security measures for a network will equal the vulnerability created by a small USB device. You can see all the pain you have taken to make your network secure, crumble in a matter of seconds, due to an issue caused by a USB drive. USB drives are small, handy and [...]]]></description>
			<content:encoded><![CDATA[<p>No amount of precautions and security measures for a network will equal the vulnerability created by a small USB device. You can see all the pain you have taken to make your network secure, crumble in a matter of seconds, due to an issue caused by a USB drive. USB drives are small, handy and convenient but one can&#8217;t imagine how notorious they are.</p>
<p>Few instances here will tell you how dangerous can a small USB drive be:</p>
<ul>
<li>According to research from Avast, roughly one in eight of the 700,000-plus malware incidents it identified in 2010 were due to tainted USB devices.</li>
<li>Security consulting and research firm the Ponemon Institute, found that more than 800,000 data-sensitive devices, including USB drives, portable hard drives and laptops, were compromised in 2009.</li>
<li>The top two virus threats reported by BitDefender, are actually spread through USB drives.</li>
<li>According to research by Panda Security, a whopping 25 percent of malware today is developed to spread through USB devices.</li>
<li>Recently, an assistant professor and his student at George Mason University, demonstrated how Operating Systems fail a USB Attack. They just used a smartphone connected to a PC through a USB cable and were able to hack it. The professor simply credited his successful exploit to the USB protocol which does not ask for authentication when an unknown device connects to a computing platform.</li>
</ul>
<p>These are only a few instances on what an infected USB drive can do.</p>
<p><strong><img class="alignright size-thumbnail wp-image-331" title="pendrive" src="http://cyber-smarty.com/wp-content/uploads/2011/02/pendrive-150x150.jpg" alt="" width="150" height="150" />USBs &#8211; a threat for Corporate Networks</strong><br />
An employee can simply bring in an infected USB drive to office, knowingly or unknowingly, and connect it to his system and get it infected. The system then spreads its infection to other PCs over the network. A research report from Avast says that more than 60 percent of all malware in circulation can be spread via USB drives. To corporate networks, notorious USB devices are not just confined to spreading malware. They simply offer a way for indiscernible data stealing.</p>
<p><strong>Precautions and necessary steps to be secure</strong><br />
The situation today isn&#8217;t so worse that the USB drives would simply force the users to face the threats they impose. It requires just a few changes in the default settings of USB ports to eliminate the hazards of notorious USB drives. Few of them are as follows:</p>
<ul>
<li><strong><a href="http://cyber-smarty.com/2011/02/disable-autorun-windows-pc/">Disabling autorun</a></strong> option (Windows PCs)</li>
<li>Blocking unauthorized USB devices</li>
<li>Maintain personal and business USB drives separate. So that you don&#8217;t contaminate your office network from threats  outside.</li>
<li>Do not plug an unknown USB drive into your computer. This is a simple precaution but works best.</li>
<li>As prevention is better than cure, you can just block USB drives on your computer/laptop (through registry key settings in Windows OS) permanently and use alternatives.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2011/02/securing-pc-usb-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting Yourself Online with Strong Passwords</title>
		<link>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/</link>
		<comments>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 07:57:09 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[password security]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=171</guid>
		<description><![CDATA[The concept of having a password for any system is similar to a key for home. The key for home is essential in order to lock and protect personal belongings from others who are not authenticated or desired to enter home. Today, due to globalization and Internet revolution, a person may have several online properties [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The concept of having a password for any system is similar to a key for home. The key for home is essential in order to lock and protect personal belongings from others who are not authenticated or desired to enter home. Today, due to globalization and Internet revolution, a person may have several online properties or accounts that are as important as properties physically existing at home. Those may be e-mails, portal, website subscriptions, network servers, databases, online banking accounts, credit cards, etc. Strong passwords for these helps in having a secure and strong lock just like lock to home.</p>
<p style="text-align: justify;">Most people, who are new to the online world, have lack of knowledge on setting up a strong password for their online accounts. But the increasing cyber crime can easily trace the passwords. And the results can be as terrible as the attack on Microsoft&#8217;s Hotmail and other web-based email services. A recent survey on these missing passwords revealed that many of the accounts had easy-to-guess passwords and the most frequently used password among these was &#8220;123456&#8243;.</p>
<p style="text-align: justify;">Some general methods that attackers use for identifying a victim&#8217;s password include:</p>
<ul style="text-align: justify;">
<li>Guessing—The attacker tries to log on using the user&#8217;s account repeatedly by guessing probable or expected words and phrases like their children&#8217;s names, their birth city, and local sports teams.</li>
<li>Online Dictionary Attack—The attacker utilizes an automated program, which consists of a text file of many words. The program frequently tries to log on to the target system by testing a different word present in the text file on each attempt.</li>
<li>Offline Dictionary Attack— It is similar to the online dictionary attack, the attacker extracts a copy of the file in which the hashed or encrypted copy of user accounts and passwords are saved and runs an automated program to find out what password is used for each account. This type of attack can be finished very quickly if the attacker gains a copy of the password file.</li>
<li>Offline Brute Force Attack—This is a modified form of the dictionary attacks, and designed to discover passwords, which are not present or available in the text file used in those attacks. Even though a brute (very strong) force attack can be tried online, because of network bandwidth and latency they are generally attempted offline utilizing a copy of the target system&#8217;s password file. In a brute force attack, the attacker utilizes an automated program, which produces hashes or encrypted values for all possible passwords and analyzes them with the values in the password file.</li>
</ul>
<p style="text-align: justify;">Microsoft suggests that the use of strong passwords can slow or sometimes break the various attack methods. This shows the importance of having a strong password.</p>
<p style="text-align: justify;"><strong>Creating a Strong password:</strong></p>
<p style="text-align: justify;">Passwords are case-sensitive and may be as long as 127 characters. A strong password:</p>
<ul style="text-align: justify;">
<li>Should never consist of user name.</li>
<li>Should be minimum of eight characters long.</li>
<li>Should compulsorily include both lower case and uppercase alphabets (minimum one from each group is suggested).</li>
<li>Should consist of minimum one number (0 to 9).</li>
<li>Should consist of at least one symbol. (Eg: *, ^, $, #)</li>
</ul>
<p style="text-align: justify;">A string, which has all the above characteristics, is known as strong password. A complex password should not be something, which is difficult to remember. Forgetting a strong or complex password, which is difficult to remember, is as harmful as getting attacked by a weak password.</p>
<p style="text-align: justify;">The password created must be easier to remember but difficult for anybody to guess. It can also be a favorite phrase or quotation or mixture of two words. Substitutes for alphabets can also be used to satisfy the above criteria for a strong password. For example ‘a’ in password can be substituted with ‘@’, similarly ‘i’ can be replaced with ‘!’; and ‘o’ with ‘0’ or ‘()’.</p>
<p style="text-align: justify;">It is a good practice if password is changed periodically like monthly or quarterly.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2010/02/protecting-yourself-online-with-strong-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open Source Utility for Enhanced Password Security</title>
		<link>http://cyber-smarty.com/2009/10/open-source-utility-for-enhanced-password-security/</link>
		<comments>http://cyber-smarty.com/2009/10/open-source-utility-for-enhanced-password-security/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 11:19:19 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[downloading]]></category>
		<category><![CDATA[password security]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=136</guid>
		<description><![CDATA[With the increase of online banking, online e-mail, online purchases, etc., there is a need for increased password security. If you are like many people who use the same password for most sites, you are in trouble if your password gets hacked. You need to make your passwords complex and tough to crack and create [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">With the increase of online banking, online e-mail, online purchases, etc., there is a need for increased password security. If you are like many people who use the same password for most sites, you are in trouble if your password gets hacked. You need to make your passwords complex and tough to crack and create a separate password for each account. Once you create a different complex password for each site , the problem is how to remember these passwords. The last thing you want to do is write the passwords down on a paper or notebook and carry them in your wallet/purse.</p>
<p style="text-align: justify;">KeePass is an open source utility that works on almost any platform, including your smartphone ( Clients available for Windows, Ubuntu, Linux, MacOS X, J2ME (Cell Phones), Blackberry, Windows Mobile and more). You can store your passwords in a password protected and encrypted database and use the passwords when needed. It will even generate a complex password for you. KeePass supports the Advanced Encryption Standard (AES, Rijndael) and the Twofish algorithms to encrypt its password databases. There are many plugins available that will allow things like filling forms, onscreen keyboard, etc.</p>
<p>Click <a rel="nofollow" href="http://www.keepass.info/" target="_blank">here</a> for more information on Keepas.</p>
<p style="text-align: justify;">
<div id="attachment_144" class="wp-caption aligncenter" style="width: 310px"><a href="http://cyber-smarty.com/wp-content/uploads/2009/10/main_big.JPG"><img class="size-medium wp-image-144" title="main_big" src="http://cyber-smarty.com/wp-content/uploads/2009/10/main_big-300x206.jpg" alt="Keepas Demo Screenshot" width="300" height="206" /></a><p class="wp-caption-text">Keepas Demo Screenshot</p></div>
<p><span style="text-decoration: underline;"><strong>Source:</strong></span> <a rel="nofollow" href="http://vjalagam.blogspot.com/2009/09/keepass-opensource-password-safe.html">http://vjalagam.blogspot.com/2009/09/keepass-opensource-password-safe.html</a><br />
<span id="more-136"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.apseratech.com">Wan optimization</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/10/open-source-utility-for-enhanced-password-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Technical Tips to Prevent Phishing</title>
		<link>http://cyber-smarty.com/2009/10/technical-tips-to-prevent-phishing/</link>
		<comments>http://cyber-smarty.com/2009/10/technical-tips-to-prevent-phishing/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 14:02:30 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[phishing awareness]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=123</guid>
		<description><![CDATA[Many anti-phishing browsers have been implemented till date and some of them include embedding features in browsers, as extensions or toolbars in browsers, and as part of website login procedures. Most websites that are targeted for phishing are secure, meaning that SSL with strong cryptography is used for server authentication. In principle, it should be [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Many anti-phishing browsers have been implemented till date and some of them include embedding features in browsers, as extensions or toolbars in browsers, and as part of website login procedures. Most websites that are targeted for phishing are secure, meaning that SSL with strong cryptography is used for server authentication. In principle, it should be possible to confirm the site using the SSL authentication, but in practice, it is easy to deceive the user.</p>
<p style="text-align: justify;">The superficial flaw is in the browser&#8217;s security User Interface (UI) that is insufficient to deal with today&#8217;s strong threats. There are 3 parts for secure authentication: first,indication that the connection is in authenticated mode,second, the site which the user is connected to and third,which authority says it is the site that it claims to be.</p>
<p style="text-align: justify;"><strong>Secure Connection:</strong> The user easily misses the padlock that was the standard display for secure browsing from the mid-1990s to mid 2000s. Mozilla featured a yellow URL bar in 2005 as a better indication that the connection is secure. However, unfortunately, this innovation was then reversed due to the EV Certificates, which replaced high value certificates with a green display and the rest with a white display.</p>
<p style="text-align: justify;"><strong>Which Site:</strong> The user is expected to be sure that the domain name in the browser&#8217;s URL bar is in fact where they wanted to go. URLs can be too complex to be parsed and users often do not know or recognize the URL they intend to go making authentication meaningless. Many e-commerce sites will change the domain names within the overall set of websites making it harder for the user to trace himself. Also simply displaying the domain name of the visited website as some anti-phishing toolbars do is insufficient.</p>
<p style="text-align: justify;">Firefox offers an alternative- a pet name extension which lets users type in their own labels for websites that they can recognize when they later return to the website. In addition, if the site is not recognized then the software warns the user or detects it outright. This symbolizes the user-centric identity management of the server. A graphical image selected by a user could be a better identification.</p>
<p style="text-align: justify;">With the introduction of EV Certificates, browsers display the organization&#8217;s name in green making it more visible ad hopefully more consistent with the user&#8217;s expectations. But then the browser vendors have limited this display to only EV Certificates, leaving the user groping in the dark for other certificates.</p>
<p style="text-align: justify;"><strong>Who is the Authority </strong>As far as the user is concerned, the browser is the authority at the simplest level since no authority is stated at this stage. The current practice is for the browser vendors to control a root list of acceptable Cas. The problem is that all Certification Authorities (CAs) employ neither good nor applicable checking. In addition, neither do all CA s subscribe to the same model and concept that certificates are only about authenticating web sites or e-commerce organizations. Certificate Manufacturing is the term given to low value certificates that are delivered on a credit card and an email confirmation, which can be easily perverted by fraudsters. Thus, a valid certificate issued by another CA may spoof a high value site. This could happen because the CA is in another part of the world and it is unfamiliar with high value e-commerce sites. Nevertheless, since the CA is charged with protecting its own customers and not the customers of another CA there is an inherent flaw in this model.</p>
<p style="text-align: justify;">The solution to the above problem is that the browser should show and the user must be familiar with the name of the authority that issues the certificate. This projects that the CA as a brand and allows the user to come in contact with the handful of CAs in their country. The use of brand provides the CA with an incentive to improve their checking and the user would demand good checking for high value sites.</p>
<p style="text-align: justify;">This solution was put into action in early versions of IE7 when displaying EV Certificates where the issuing CA was displayed. Nevertheless, this turns out to be an isolated case. There is resistance for branding CAs on the chrome resulting in a fallback to the simplest level above: the browser is the user&#8217;s authority.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/10/technical-tips-to-prevent-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How safe are you browsing with Firefox?</title>
		<link>http://cyber-smarty.com/2009/10/how-safe-are-you-browsing-with-firefox/</link>
		<comments>http://cyber-smarty.com/2009/10/how-safe-are-you-browsing-with-firefox/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 14:50:26 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[Secure Downloading]]></category>
		<category><![CDATA[Computer Maintenance]]></category>
		<category><![CDATA[downloading]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=97</guid>
		<description><![CDATA[Mozilla Firefox is a popular browser used by millions of Internet users all around the world. The coolest feature of Mozilla Firefox is its compatibility to add more and more plugins and enable yourself with advanced browsing. However, we need to update our plugins as soon as a new version is available. Updates of these [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Mozilla Firefox is a popular browser used by millions of Internet users all around the world. The coolest feature of Mozilla Firefox is its compatibility to add more and more plugins and enable yourself with advanced browsing.</p>
<p style="text-align: justify;">However, we need to update our plugins as soon as a new version is available. Updates of these plugins will not only cover new features of the plugin, but also will address some vulnerability to security threats during browsing. Many people ignore it as it takes little time (a matter of no more than 2 minutes) for the plugin to update and restart the browser. This increases their risk to security threats online like malware, viruses, botnets, etc.</p>
<p style="text-align: justify;">How to check if your plugin is up-to-date? Just click <a href="https://www-trunk.stage.mozilla.com/en-US/plugincheck/" target="_blank">here</a> or copy paste this URL in your browser <strong>https://www-trunk.stage.mozilla.com/en-US/plugincheck/</strong>.</p>
<p style="text-align: justify;">The window that opens will let you know the status of your plugin.</p>
<ul style="text-align: justify;">
<li>Green indicates that your plugin is up-to-date.</li>
<li>Yellow indicates outdated but without known      vulnerabilities.</li>
<li>Red indicates that the plugin is known to have      security holes and is outdated.</li>
<li>Don’t worry about the Grey colored plugin.</li>
</ul>
<p style="text-align: justify;">
<p style="text-align: justify;">Update your plugin frequently for safe and better browsing.</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/10/how-safe-are-you-browsing-with-firefox/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing &#8211; Types And Precautions</title>
		<link>http://cyber-smarty.com/2009/09/phishing-types-and-precautions/</link>
		<comments>http://cyber-smarty.com/2009/09/phishing-types-and-precautions/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 06:43:23 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[Secure Downloading]]></category>
		<category><![CDATA[Spam Awareness]]></category>
		<category><![CDATA[downloading]]></category>
		<category><![CDATA[phishing awareness]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=58</guid>
		<description><![CDATA[The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication is known as Phishing. Types of Phishing Phishing is usually carried out by email or instant messaging and it often directs users to enter details at a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication is known as Phishing.</p>
<p style="text-align: justify;"><strong><span style="text-decoration: underline;">Types of Phishing</span></strong><br />
Phishing is usually carried out by email or instant messaging and it often directs users to enter details at a fake website, which is similar to the legitimate one. Since the fake website is similar to the original one, it requires tremendous skill to determine whether a website is fake or not.</p>
<ol style="text-align: justify;">
<li><strong>Misspelled URLs</strong>: Phishers use some sort of deceptive techniques, which design a link in an e-mail (and the spoofed website it leads to) apparently belong to the spoofed organization by using <strong>misspelled URLs</strong> or of sub-domains. Sometimes the phishers make the anchor text for a link <strong>appear</strong> to be valid, whereas the link actually goes to the phishers site.</li>
<li><strong>Whaling:</strong> Phishing attacks directed specifically at senior executives and other high profile targets within businesses is known as Whaling.</li>
<li><strong>Image Phishing: </strong>Phishers have also used <strong>images</strong> instead of text to make it difficult for anti phishing filters.</li>
<li><strong>Cross site scripting</strong>: An attacker can even exploit flaws in the original website&#8217;s script against the victim making it even more difficult to detect since everything from the web address to the security certificates seem to be original. This technique is known as <strong>cross site scripting</strong>.</li>
<li><strong>Phone</strong> <strong>Phishing</strong> is the case where in a customer gets a call asking him to call back to discuss his problems while accessing his bank accounts. The person then is trapped into giving his sensitive information such as credit card information and the like.</li>
</ol>
<p style="text-align: justify;"><strong><span style="text-decoration: underline;">Measures to counter phishing</span></strong><br />
People need to change their browsing habits when it comes to phishing. For example, when asked to reveal their sensitive information they should directly contact the company to make sure the mail is genuine and shouldn&#8217;t fall prey to mails that address them as “Dear Customer”. <strong>Paypal</strong>, for instance makes it a point to address the users by their usernames.</p>
<p style="text-align: justify;">One of the major flaws of the user is the <strong>Click-through</strong> syndrome where he treats any pop-ups as a case of misconfiguration and proceeds with his work without heeding to the warning of the computer.</p>
<p><span id="more-58"></span><br />
<strong>Related Links:</strong><br />
<a href="http://www.itcontractor.com">Umbrella Company</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/09/phishing-types-and-precautions/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Safety measures to buy a Product Online Securely</title>
		<link>http://cyber-smarty.com/2009/08/safety-measures-to-buy-a-product-online-securely/</link>
		<comments>http://cyber-smarty.com/2009/08/safety-measures-to-buy-a-product-online-securely/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 04:44:34 +0000</pubDate>
		<dc:creator>cyber-geek</dc:creator>
				<category><![CDATA[Cyber tips]]></category>
		<category><![CDATA[Online Shopping]]></category>

		<guid isPermaLink="false">http://cyber-smarty.com/?p=9</guid>
		<description><![CDATA[The main advantage of online shopping is its convenience where anybody can search and buy a product at a click of their mouse of their PC. However, online shopping has some concerns and risks associated with it. A lot of these risks are basically people dependent and can be prevented by being a little vigilant [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 12pt; font-family: Times New Roman ;">The main advantage of online shopping is its convenience where anybody can search and buy a product at a click of their mouse of their PC.</span></p>
<p><span style="font-size: 12pt; font-family: Times New Roman ;">However, online shopping has some concerns and risks associated with it. A lot of these risks are basically people dependent and can be prevented by being a little vigilant and following some basic precautions.</span></p>
<p><strong><span style="text-decoration: underline;"><span style="font-size: 12pt; font-family:  Times New Roman ;">Precautions to keep online shopping secure:</span></span></strong></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Selecting a website:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> It is little difficult to check for a reliable website for shopping online. As we know, creating a website is quite easy has no restrictions. One must make sure that the website that they are transacting with is reliable. Always opt for buying from companies you already know. If you are planning to buy from an unknown website, start with smaller orders till you are contented with their service and reliability.</span></p>
<p><span style="font-size: 12pt; font-family:  Times New Roman ;">The URL of the website also helps you to find if the website is reliable or not. It should start with https://. The &#8220;s&#8221; that is displayed after &#8220;http&#8221; indicates that Web site is secure. Often, you do not see the &#8220;s&#8221; until you actually move to the order page on the Web site.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Checking if website is secure: </span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Make sure the website is consistent on security grounds. The company may be reliable, but if it has no proper mechanism to secure their customer’s information from hacking, it is troublesome. Try to find if the merchant stores your data in encrypted form. Be sure to read privacy and security policies of the website before providing your personal information to them.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Checking for its reputation:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> Though there is no good logic to prove relation between reputation and reliability, reputed businesses cheat very rarely. Thus, it is good to go with the reputation of the website before doing business with it. You can check this with the help of search engines. Reputed businesses often have first page search listings.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Checking for its usability:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> Usability of the website helps you to attain certain knowledge on its credibility. Popup windows are always troublesome while doing the transaction in any website. Stay away from popup windows, and if possible, from the sites which allow them.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Run Antivirus Software: </span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Before doing any online transaction one must update their antivirus software, which can help you to stay secure from unwanted cookies and applications.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Reveal Only the Bare Facts:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> It is common for any online merchant to ask you to signup before ordering a product. However, make sure you disclose only data which is mandatory and makes sense to provide. You do not require providing your social security number to any eCommerce merchant. If the site is trying to push you on edge to get too much information, it is recommended to simply leave the website.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Rechecking:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> Before doing or finalizing payment to the merchant make sure that the shopping cart has all and only the products that you have selected. You can add or delete any product only at this stage.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Payment Options:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> When it comes to payment options for purchasing online, there are many options like credit cards, debit cards, cash and cheques. Of all these options, credit cards are the safest option for purchasing online. It is recommended to have a separate credit card for e-commerce purchasing so that it will help in tracking dissolute credit charges easily.</span></p>
<p><strong><span style="font-size: 12pt; font-family:  Times New Roman ;">Recheck again:</span></strong><span style="font-size: 12pt; font-family:  Times New Roman ;"> After the transaction is complete, recheck for transaction details. Try to record them if possible. Finally, don’t forget to sign off from the site.</span></p>
<p><span style="font-size: 12pt; font-family:  Times New Roman ;">Online shopping is a trendy boon for shoppers, only if they are cautious during the transaction.</span></p>
<p><strong>Related Links:</strong><br />
<a href="http://www.searchoptics.com">Automotive marketing</a><br />
<a href="http://www.apseratech.com">Wan optimization</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber-smarty.com/2009/08/safety-measures-to-buy-a-product-online-securely/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

