-
Notifications
You must be signed in to change notification settings - Fork 8
/
security-general.slide
77 lines (49 loc) · 1.87 KB
/
security-general.slide
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
Security Tips for Non-Dev
Oursky
23 Sep 2016
Ben Cheng
Oursky
bencheng@oursky.com
* Oursky is a super geeky company
- We kind of assume dev knows basic security
- Not your fault -- we need non-coder to function as well
- Security is as strong as the weakest link
- *Open everything* can be kind of scary here
* 10 Tips for you
* Tips 1: Use 2FA whenver you can
- Use Authy.com, so you won't lose the code if you switch the devices
* Tips 2: Never re-use password
- Dropbox / Linkedin / Dropbox... all major services have breaches
- Same password = feel free to visit my other accounts
- https://haveibeenpwned.com/
- Use 1Password Team
* And you thought your password is difficult to guess?
.image security-general/password_strength.png
* Tips 3: Don't send password in plain text
- Use 1Password Team (again)
- https://go-talks.appspot.com/github.com/oursky/slides/gpg-at-oursky.slide#1
* Tips 4: Don't click random links...
- Pay attention to phishing site URL (domain name)
- google.random-things.com is probably NOT related with Google
- think twice whenever you're input a password
- Use guest account when in doubt
* Phishing Site...
.image security-general/phishing.png
* Tips 5: Use gmail preview to open attachment
- They scan malware, and it is pretty good.
* Tips 6: Enable full disk encryption
- No excuse, super easy on Mac (System Preference -> FileVault)
- iPhone: Enable PIN code
* Tips 7: Some Chrome extension are good
- https://www.eff.org/https-everywhere
- http://www.ghostery.com/
* Tips 8: Up-to-date iOS / macOS
- e.g. recently iOS 9.3.5 fixed CVE-2016-4655 - 4657
* Tips 9: Use signal if you need secure messaging
- Or at least use Telegram Secret Chat
- https://whispersystems.org/
* Tips 10: General things...
- Backup (Time Machine in office?)
- OFfice provides VPN if you work remote
- Wifi encryption at least WPA2
- Avast if you need an anti-virus software