"... What are you guys using? ..."
"... I don't go to places online where I fear I'll encounter malware, I
don't download much software at all, so not worried about that
vector. I don't really use email, so I don't have to worry about
getting phished. I'm also probably way too boring to be much of a
target ..."
I "go to" risky places all the time, and I copiously use multiple free
webmail POP and IMAP accounts through my PCs and phones, and
I download a ton of stuff from anywhere.
Considering that visiting ANY website, such as the supposedly safe
The Wall Street Journal website, may inflict malware on us because
many websites sell advertising space that is filled with stuff from
servers outside the main website's control, outside their ability to
securely prevent those unrelated remote and subordinate servers
from being cracked, let alone ANY web page getting cracked, I use
browser-based
adblockers,
script blockers, and
PrintFriendly ( that
harvests my behavior- doh ! ), to simplify web pages to the essential
articles and contents I seek, with a minimum of unintended invasive
uncontrolled content, and that somewhat reduces my exposure.
I use the free
Tor Browser,
Onion sites, and a
paid-for proxy when
wanting to be fully anonymous.
I use free
VirusTotal.com to scan any file downloaded, and then I
scrutinize that file's behavior, because even supposedly legitimate
software, like CCleaner, has been cracked at the source before even
leaving the vendor.
I manually scan with
AdwCleaner,
JRT Junk Removal Tool ( aging ),
Spybot Search & Destroy versions
1 ( ! ) and
2,
Super Antispyware,
and even ( gulp )
Malwarebytes, plus web-based scans from
Kaspersky ( ! ),
Eset,
Trend Micro, and so on, just to see how I'm
doing, but otherwise, I have no memory-resident anti-malware
program, though the free
Kerish Doctor does a good job of warning
me when stuff wants access to autorun on boot, install in my browser,
and so on.
And I keep a copy of every malware I find in
\Backup\- Malware\
as a test for the qualities of on-demand scanners to see what they
find compared to VirusTotal.
I leave
Microsoft's built-in
anti-
malware running on computers I
support that other people use.
I have the in-built "security" and
firewall from my
ISP,
router, and
Windows EXCEPT any memory-resident anti-malware.
That said, the only "invasions" I've experienced are out there, not in
here, that is, cracking our accounts at the other end, such as at the
government ( ! ) or at a service or facility such as Yahoo Email or
Target stores - the crackers know that an hour of their time at the
other end will get them thousands, if not millions of credentials,
versus a mere single credential for the same work at my end, though
once our credentials are obtained either way, we are at risk
individually, and have to deal with that.
The only compromises I've seen for other folks are the same as the
ones I see myself, plus they tend to believe errant on-screen messages,
they panic, they call the 1-800 numbers, and they whip out their credit
cards to solve imaginary problems, some even maintain long-term
relationships with supposed remote support.
More?
What is a comprehensive list of all web and online security
compromises stealing end user's credentials?
https://share.google/aimode/Y510gnF2jM5OyoXO7
What is a comprehensive list of specific incidents of massive
credentials harvesting?
https://share.google/aimode/f94zGea4rm0rsNkE0
I have stacks of security devices unplugged, sitting on shelves,
someday, I'm going to try to understand their implementation, or
maybe just put them on eBay for anyone interested in antiquity.
That's what I do.
So, I'm grateful for the opportunity to learn about yet another
security solution, such as the
Sophos UTM9, even though such
mini-exposure and mini-education for me only reinforces the
validity and simplicity - and low-budget, low-effort - preventative
energies that I throw at the problem.
Thanks.