Advertise Here

Support our Sponsors

Monday, October 12, 2009

Create a Virtual Machine of your Existing Computer With a Click

Whether you are a tech newbie or a geek, you’ll probably enjoy using this.

virtual pc - windows xp in vista Virtualization, in simple English, is a interesting technology that helps you run multiple operating systems on the same machine.

For instance, if you are running Windows Vista on a computer, you can create virtual machines for Windows XP or Ubuntu and run these operating systems on your existing Vista machine just like any other Windows application.

How to Create a Virtual Machine

Windows Virtual PC, Virtual Box and VMware Workstation are some popular applications that allow you to create new virtual machines on a Windows PC but the only problem with these programs is that they require you do everything from scratch.

That is, if you want to create a new virtual machine, you will have to install the whole operating system first using the original installer DVD and then configure it with your favorite programs. This can be both time consuming and difficult.

What if you could use your existing Windows computer, that already has all your favorite programs installed, and turn into a virtual machine?

Convert your Computer into a Virtual Machine

While it has always been possible to convert an existing hard drive into a virtual machine, the process was difficult and often required expensive programs.

Well, not anymore. There’s a new utility from Microsoft that makes it both simple and free to convert an existing installation of Windows into a virtual machine ready to run on any other computer.

Microsoft’s Sysinternals team has released a simple application called Disk2vhd, that lets you easily migrate an existing computer to a virtualized hard drive (VHD). It’s a tiny utility doesn’t even require instillation.

Create Virtual Hard Disks with Disk2VHD

When you run Disk2vhd, it will immediately show you all the drives and partitions on your computer that it can migrate to a VHD. Simply select a drive that you wish to create a VHD file from and click “Create.” Disk2vhd will convert the hard drive into a VHD file even if the computer /drive is currently in use.

create virtual machines

When the Virtual Machine VHD file is created, you can run it in any desktop virtualization program including the free Windows Virtual PC, Virtual Box, or VMware Player. You can also mount the virtual machine as a standard hard drive in Windows 7, and can even boot from it if your computer is running Windows 7 Ultimate.

You may use Disk2vhd to create virtual machines of your Windows XP, Windows Server 2003, Windows Vista and higher machines, including x64 systems.

Usage Scenario

Let’s say you have a computer that is already running all the software programs you frequently use, but you now want to move to a new computer or upgrade your operating system. You can then consider creating a virtual machine of your old machine using the Microsoft utility and this will help you use all your favorite programs (with the same settings) on the new machine.

You can also use virtualization to create a ghost image of your hard drive in a single file and this will be handy in the event of a disk failure.

Disk2vhd is an useful tool that will make it much easier for you to enjoy the benefits of virtualization without being too technical.

Find Emails with Large Attachments in your Gmail Mailbox

This article describes how you can free up space in your Gmail mailbox by removing bulky email messages and large file attachments. If you are on Windows (2000, XP, Vista or Win 7) and use Google email, this may be worth giving a shot.

The Gmail Advantage

gmail attachmentsWhile Yahoo! Mail and Windows Live Hotmail offer POP3 access to your email, GMail (and Google Apps for Email) is probably the only free web mail service that also provides free offline access to your email messages via the IMAP route.

The benefits of using IMAP4 far outweigh POP3 – the primary feature being instant synchronization of the action with the mail server. As an example, if you have configured Outlook or Thunderbird with your Gmail account using IMAP4, you can delete messages in the local client and they’ll get moved to the Trash folder in Gmail as well automatically.

Free up Space in Gmail via IMAP – The Strategy

Now the more interesting part. Let’s see how we can free up some important disk space in our Gmail inbox using a simple strategy:

Step 1: Track down bulky email messages in your Gmail inbox that contain large file attachments.

Step 2: Save these attachments to the local hard drive.

Step 3. After the attachments are saved locally, remove them from the online mailbox without deleting the corresponding email message(s).

gmail-folder-size

Unlike Outlook, Gmail doesn’t offer a “sort by size” feature so you would normally assume that to implement such a strategy, one may have to configure his desktop mail client with Gmail’s IMAP, perform the operations locally and then do a sync. Well, that’s not required anymore.

We’ll use a portable (meaning it doesn’t need to be installed) and freeware utility called IMAPSize – at the outset, let’s be quite clear – this isn’t an email client per se. This Windows only application has been created solely to perform maintenance tasks on any IMAP mailbox from the desktop.

Find space-hogging Email Attachments in Gmail

add GMail account in IMAPSizeLet’s start off by adding a GMail or Google Apps for Domains mailbox.

Usually, on first starting the IMAPSize program, a dialog box pops up asking if you’d like to add a new email account. If it doesn’t, one can always add an account from the Account > New menu option.

To configure your Gmail account, fill in your email address as the username and your Gmail password. Enter imap.gmail.com as your server and the port number as 993. Be sure to check the SSL secure connection option so that data sent between your computer and the GMail server can’t be intercepted.

If you are a Google Apps user, please enter username@your_domain.com for the username field.

You’ll now see a tree indicating the size of individual Gmail folders (labels). Even with the exceedingly generous storage quota offered by GMail, if you have an IMAP account with another provider like FastMail.fm, VFEmail.net, 1and1.com or RackSpace, it might be worth noting which folders in particular are occupying the maximum space.

Now the next step – double-click any Gmail folder in the tree to see all message within that folder. IMAPSize will only download the headers and not the entire message so the wait may not be that long.

find-emails

Once your message list is available locally, invoke the “Advanced Search” function to filter out large emails (or ones that contain huge attachments). You need to specify the size in kilobytes so 500000 would filter out emails that are larger than 0.5 MB or 500 KB.

Go through the filtered list and select emails messages that you either want to remove completely or just need to detach the attachments. You can do that by right clicking the selected messages and choosing “Save Attachments locally” – this will save of copy of file attachments to the local drive.

save_attachments

Now use the Delete Attachments option for the same selection. This will make a copy of the original email in same the Gmail folder buts sans the attachment while the original message is moved to Trash after you choose “Expunge this mailbox”. (Outlook has such a feature by default).

All this happens without the main body of the email getting downloaded thereby saving on bandwidth as well as on time. And this may be neat option for saving those images and media files for offline use when GMail is not available.

remove-attachments

Last, but by no means least is an option to backup your IMAP account to your local disk while preserving the folder structure. Use the Account > Account Backup [CTRL+B] option to select the folder you want to backup – most GMail users would be better off backing up the All Mail folder to archive everything locally.

Naturally, expect a great deal of time to elapse if you have lot of messages and a slow Internet connection. Incremental backup is an in-built feature, so your next backup shouldn’t take as long as only the changes made to the mail account will be taken into consideration.

For Desktop Mail Clients

If you are already using Outlook or another desktop client with Gmail, seee this guide on how to reclaim lost space in Gmail using a similar approach. And if you aren’t happy with speed, here’s another guide on improving Outlook performance with GMail IMAP.

By Shahrzaad M Parekh.

Use Facebook Chat without opening Facebook.com

disable facebook chatFacebook includes an awesome chat feature that lets you instantly start conversations with your Facebook buddies without installing any IM software but the only small issue is that you need to be on the Facebook.com website in order to use Facebook chat.

If you find this a bit inconvenient, here are some good workarounds that will let you chat on Facebook from anywhere without even having to open the Facebook site in your browser.

Facebook Chat Inside the Web Browser

If you have Google Chrome or Prism for Firefox, you can open this address in your browser address bar and then create an application shortcut to Facebook chat on your desktop.

Firefox users may bookmark the above link and set the "Load this bookmark in Sidebar" property to true in order to use Facebook chat from the Firefox sidebar.

If you an IE user or hate to use Facebook chat from the sidebar, try Gabtastik – this is a minimal desktop client for Facebook that looks exactly like the web version of Facebook chat but will also send you notifications of new messages and chat requests from the system tray.

meebo - facebook chat

Meebo, the very awesome web based instant messaging service, now supports Facebook chat as well. You can connect your Facebook account with meebo via the Facebook Connect service (so there’s no need to share your Facebook credentials with anyone) and instantly chat with your online buddies inside the web browser.

There are two advantages here – you can use Facebook chat even if the main Facebook.com site is blocked in your office and two, you can simultaneously connect with friends on other IM networks from the same website.

Facebook Chat Clients for your Desktop

facebook messenger

ChitChat – If Facebook were to develop a standalone messenger on the lines of Yahoo! or Google Talk, it might look something like ChitChat.

ChitChat is a Windows-only desktop client for Facebook that provides a tabbed window to make it easy for you to talk to may friends at once. It will also show notifications in the tray when your friends go online or when they have signed out. The application is in RC stage so expect a few bugs.

digsby for facebook

Digsby – This is again a very useful all-in-one app that helps you stay up to date with everything happening on your Facebook, Twitter, Gmail, LinkedIn and other online accounts.

If you have multiple accounts on Facebook (like you and your spouse), you can associate all of them with your Disgsby messenger and chat with the combined buddy list simultaneously. Facebook doesn’t allow audio or video calls but Digsby indirectly brings that feature to Facebook Chat via tokbox.

There were reports (1,2,3) that Digsby’s installer can add some crapware to your computer but that should not hold you back as there’s an alternate installer (direct link) that will bypass the non-essential stuff.

adium on facebookAdium – If you are on Mac, Adium is probably the best choice for you to chat with Facebook friends from the desktop.

Like Pidgin and Digsby, Adium too supports multiple IM networks, including Windows Live Messenger, Google Talk, AOL AIM, ICQ, Yahoo! Messenger, Skype, Twitter and Jabber (XMPP). And it uses the same Facebook Chat plugin that is available for Pidgin users on Google Code.

pidgin with facebook chat

Pidgin – While Facebook Chat is not officially supported in Pidgin, there’s a free plug-in that lets you connect to the Facebook chat server from Pidgin. And like Digsby, Pidgin too would let you chat with buddies on multiple Facebook accounts from the same interface.

Pidgin vs Digsby – Pidgin is purely for instant messaging while Digsby will also display notifications like when a friends sends you a message using Facebook email or if he or she writes something on your Facebook wall. Some people in the comments say that even Pidgin displays notifications but at least that doesn’t work in Windows 7.

Pidgin will show all your Facebook contacts in one giant list (see update) while Digsby will group contacts under logical "Friends list" just the way you have them on the main facebook.com site. Update: The new version of Facebook Chat plugin for Pidgin displays your online friends under groups just like Pidgin.

SnagIt Tips and Tricks – Capture Great Looking Screenshots & more

SnagIt Tips and Tricks SnagIt has always been the most powerful screen capture program for Windows but its usage may have touched an all-time high ever since TechSmith released the full licensed version of SnagIt for free – that promotion is still active.

SnagIt screen capture program is more than just a replacement of your PrtScrn key – it can help you record destkop movies, leech websites, add image watermarks, extract text from dialogs and much more.

1. Use SnagIt to Make Short Movies (Screencasts)

You don’t need a copy of Camtasia Studio to capture that 30 second movie of your desktop as SnagIt can record small desktop videos very easily. Select “Record a Video of the Screen” profile, draw a rectangle around the desktop area that you want to record and hit Print-Screen.

long-webpage 2. Capture Long Scrolling Webpages (both vertical and horizontal directions)

SnagIt can capture extremely long web pages that extend several pages (like a long conversation thread on Gmail or a one-page print version of some NY Times story).

Under Input, select Scrolling -> Auto Scroll Window. Then open the Options window and specify the Scroll direction.

3. The Right File Format for Saving Screenshot Images

When you take a screen capture with SnagIt, it lets you save the graphic in different image formats. Here’s how I decide the extension of screenshot images:

(a) Use GIF when the screenshot has lot of text or it is taken from a movie (like a YouTube video).
(b) Use PNG (True Color) if the captured image is a photograph or when file size is not a constraint.
(c) Use JPG (Automatic Color) in all other cases.

4. Leech Images from any Website

SnagIt, like wget or Teleport, can help you download all images from a website. Say you are on this Vista Wallpapers page and want to download each of the image locally.

Choose the “All Images from a Website”, set the parameters like link depth, file extension type, minimum file size, etc and click capture. [related: How to Leech Pictures]

5. Capture and Extract Text from Dialog Windows

cannot delete fileWhen we get an error message on Windows, we normally type that “text string” on Google to find the cause of error and how to fix it.

With SnagIt, you can do a Text Capture using “Text from Window” profile so it automatically extracts the text out of the window without you having to type anything manually. [related: Screen Capture OCR]

6. Activate the Burst Mode in SnagIt

SnagIt has a “burst” mode that you normally see in DSLR cameras. Under the “Output Properties”, set the “Automatic File Name” option and turn off “Preview”.

Now when you hit the capture hotkey, the screenshot is automatically saved to the computer. And to simulate the Burst effect, keep clicking the hotkey at very short intervals.

watermark 7. Add Visible Watermarks to your Screen Capture Images

This is useful if you want to add your own branding to screen captures. From Images Tasks, select Watermark – you can embed either normal text or some image like a logo.

8. Join and Restore Image Screenshots

Join and Restore (available under Edit menu) are probably the most unused features in SnagIt image editor. Restore is like a “complete Undo” while the Join command lets you remove selected portions from a screenshot and joins the image on either sides of the selection. Extremely useful.

snagit-firefox

9. Use SnagIt Inside Firefox

Like Internet Explorer, TechSmith provides a Firefox extension for SnagIt that allows you to capture web content without leaving the browser. Get SnagIt for Firefox here or read help.

10. SnagIt Accessories, Downloads and Tutorials

A bunch of useful extras, stamps and capture profiles for SnagIt are available here. Betsy Weber did a 24 video series with SnagIt team which is again very helpful. The TechSmith website has a good collection of SnagIt tutorials (in text and video) here.

Related: Learn how to create very large Wallpapers from Google Maps using SnagIt.

Your favorite SnagIt Tips: If you know of any cool SnagIt trick, please share.

How to Secure Your Wireless Network at Home

FacebookTwitter

How to Secure Your Wireless Network at Home

This article describes how you make your Wireless Network more secure and you’ll also learn about free tools that even hackers and non-hackers generally use to intercept your Wi-Fi signals.

Wireless networks (wi-fi)Wireless Networking (Wi-Fi) has made it so easy for you to use the computer, portable media player, mobile phones, video game consoles, and other wireless devices anywhere in the house without the clutter of cables.

With traditional wired networks, it is extremely difficult for someone to steal your bandwidth but the big problem with wireless signals is that others can access the Internet using your broadband connection even while they are in a neighboring building or sitting in a car that’s parked outside your apartment.

This practice, also known as piggybacking, is bad for three reasons:

  • It will increase your monthly Internet bill especially when you have to pay per byte of data transfer.
  • It will decrease your Internet access speed since you are now sharing the same internet connection with other users.
  • It can create a security hazard* as others may hack your computers and access your personal files through your own wireless network.

[*] What do the bad guys use - There have been quite a few instances where innocent Internet users have been arrested for sending hate emails when in reality, their email accounts where hacked though the unsecured Wi-Fi networks that they had at home. Wireshark is a free packet sniffing tool for Linux, Mac and Windows that can scan traffic flowing though a wireless network including cookies, forms and other HTTP requests.

How to Secure Your Wireless Network

The good news is that it is not very hard to make your wireless network secure, which will both prevent others from stealing your internet and will also prevent hackers from taking control of your computers through your own wireless network.

Here a few simple things that you should to secure your wireless network:

Step 1. Open your router settings page

First, you need to know how to access your wireless router’s settings. Usually you can do this by typing in “192.168.1.1” into your web browser, and then enter the correct user name and password for the router. This is different for each router, so first check your router’s user manual.

You can also use Google to find the manuals for most routers online in case you lost the printed manual that came with your router purchase. For your reference, here are direct links to the manufacturer’s site of some popular router brands – Linksys, Cisco, Netgear, Apple AirPort, SMC, D-Link, Buffalo, TP-LINK, 3Com, Belkin.

Step 2. Create a unique password on your router

Once you have logged into your router, the first thing you should do to secure your network is to change the default password* of the router to something more secure.

This will prevent others from accessing the router and you can easily maintain the security settings that you want. You can change the password from the Administration settings on your router’s settings page. The default values are generally admin / password.

[*] What do the bad guys use - This is a public database of default usernames and passwords of wireless routers, modems, switches and other networking equipment. For instance, anyone can easily make out from the database that the factory-default settings for Linksys equipment can be accessed by using admin for both username and password fields.

Step 3. Change your Network’s SSID name

The SSID (or Wireless Network Name) of your Wireless Router is usually pre-defined as "default" or is set as the brand name of the router (e.g., linksys). Although this will not make your network inherently* more secure, changing the SSID name of your network is a good idea as it will make it more obvious for others to know which network they are connecting to.

This setting is usually under the basic wireless settings in your router’s settings page. Once this is set, you will always be sure that you are connecting to the correct Wireless network even if there are multiple wireless networks in your area. Don’t use your name, home address or other personal information in the SSID name.

[*] What do the bad guys use - Wi-Fi scanning tools like inSSIDer (Windows) and Kismet (Mac, Linux) are free and they will allow anyone to find all the available Wireless Networks in an area even if the routers are not broadcasting their SSID name.

Step 4. Enable Network Encryption

In order to prevent other computers in the area from using your internet connection, you need to encrypt your wireless signals.

There are several encryption methods for wireless settings, including WEP, WPA (WPA-Personal), and WPA2 (Wi-Fi Protected Access version 2). WEP is basic encryption and therefore least secure (i.e., it can be easily cracked*, but is compatible with a wide range of devices including older hardware, whereas WPA2 is the most secure but is only compatible with hardware manufactured since 2006.

To enable encryption on your Wireless network, open the wireless security settings on your router’s configuration page. This will usually let you select which security method you wish to choose; if you have older devices, choose WEP, otherwise go with WPA2. Enter a passphrase to access the network; make sure to set this to something that would be difficult for others to guess, and consider using a combination of letters, numbers, and special characters in the passphrase.

[*] What do the bad guys use - AirCrack and coWPAtty are some free tools that allow even non-hackers to crack the WEP / WPA (PSK) keys using dictionary or brute force techniques. A video on YouTube suggests that AirCrack may be easily used to break WiFi encryption using a jail-broken iPhone or an iPod Touch.

Step 5. Filter MAC addresses

Whether you have a laptop or a Wi-Fi enabled mobile phone, all your wireless devices have a unique MAC address (this has nothing to do with an Apple Mac) just like every computer connected to the Internet has a unique IP address. For an added layer of protection, you can add the MAC addresses of all your devices to your wireless router’s settings so that only the specified devices can connect to your Wi-Fi network.

MAC addresses are hard-coded into your networking equipment, so one address will only let that one device on the network. It is, unfortunately, possible to spoof a MAC address*, but an attacker must first know one of the MAC addresses of the computers that are connected to your Wireless network before he can attempt spoofing.

To enable MAC address filtering, first make a list of all your hardware devices that you want to connect to your wireless network**. Find their MAC addresses, and then add them to the MAC address filtering in your router’s administrative settings. You can find the MAC address for your computers by opening Command Prompt and typing in “ipconfig /all”, which will show your MAC address beside the name “Physical Address”. You can find the MAC addresses of Wireless mobile phones and other portable devices under their network settings, though this will vary for each device.

[*] What do the bad guys use - Someone can change the MAC address of his or her own computer and can easily connect to your network since your network allows connection from devices that have that particular MAC address. Anyone can determine the MAC address of your device wireless using a sniffing tool like Nmap and he can then change the MAC address of his own computer using another free tool like MAC Shift.

Step 6. Reduce the Range of the Wireless Signal

If your wireless router has a high range but you are staying in a small studio apartment, you can consider decreasing the signal range by either changing the mode of your router to 802.11g (instead of 802.11n or 802.11b) or use a different wireless channel.

You can also try placing the router under the bed, inside a shoe box or wrap a foil around the router antennas so that you can somewhat restrict the direction of signals.

Apply the Anti-Wi-Fi Paint – Researchers have developed a special Wi-Fi blocking paint that can help you stop neighbors from accessing your home network without you having to set up encryption at the router level. The paint contains chemicals that blocks radio signals by absorbing them. "By coating an entire room, Wi-Fi signals can’t get in and, crucially, can’t get out."

Step 7. Upgrade your Router’s firmware

You should check the manufacturer’s site occasionally to make sure that your router is running the latest firmware. You can find the existing firmware version of your router using from the router’s dashboard at 192.168.*.

Connect to your Secure Wireless Network

To conclude, MAC Address filtering with WPA2 (AES) encryption (and a really complex passphrase) is probably the best way to secure your wireless network.

Once you have enabled the various security settings in your wireless router, you need to add the new settings to your computers and other wireless devices so that they all can connect to the Wi-Fi network. You can select to have your computer automatically connect to this network, so you won’t have to enter the SSID, passphrase and other information every time you connect to the Internet.

Your wireless network will now be a lot more secure and intruders may have a tough time intercepting your Wi-Fi signals.

Who is Connected to your Wireless Network

If you are worried that an outsider may be connecting to the Internet using your Wireless network, try AirSnare – it’s a free utility that will look for unexpected MAC addresses on your Wireless network as well as to DHCP requests. Another option is that you open your router’s administration page (using the 192.168.* address) and look for the DHCP Clients Table (it’s under Status > Local Network on Linksys routers). Here you will see a list of all computers and wireless devices that are connected to your home network.

*It is also a good idea to turn off the router completely when you are not planning to use the computer for a longer period (like when you are out shopping). You save on electricity and the door remains 100% shut for wireless piggybackers.

**If you ever want to let a new device connect to your network, you will have to find its MAC address and add it to your router. If you simple want to let a friend connect to your wireless network one time, you can remove his MAC address from the router settings when he or she leaves your place.

Tuesday, October 6, 2009

Chosing A Smart Password

As part of National Cyber Security Awareness Month, we'd like to take this opportunity to remind you about smart password practices. Help ensure you're protecting your computer, website, and personal information by checking out our security series on the Google blog or visiting http://www.staysafeonline.org.

Phishing, a topic that's been in the news, is unfortunately a common way for hackers to trick you into sharing personal information like your account password. If you suspect you've been a victim of a phishing attack, we recommend you immediately change your password, update the security question and secondary address on your account, and make sure you're using a modern browser with anti-phishing protection turned on. Keep an eye out for the phishing warning Gmail adds to suspicious messages, and be sure to review these tips on how to avoid getting hooked.

Creating a new password is often one of the first recommendations you hear when trouble occurs. Even a great password can't keep you from being scammed, but setting one that's memorable for you and that's hard for others to guess is a smart security practice since weak passwords can be easily guessed. Below are a few common problems we've seen in the past and suggestions for making your passwords stronger.

Problem 1: Re-using passwords across websites
With a constantly growing list of services that require a password (email, online banking, social networking, and shopping websites — just to name a few), it's no wonder that many people simply use the same password across a variety of accounts. This is risky: if someone figures out your password for one service, that person could potentially gain access to your private email, address information, and even your money.

Solution 1: Use unique passwords
It's a good idea to use unique passwords for your accounts, expecially important accounts like email and online banking. When you create a password for a site, you might think of a phrase you associate with the site and use an abbreviation or variation of that phrase as your password — just don't use the actual words of the site. If it's a long phrase, you can take the first letter of each word. To make this word or phrase more secure, try making some letters uppercase, and swap out some letters with numbers or symbols. As an example, the phrase for your banking website could be "How much money do I have?" and the password could be "#m$d1H4ve?" (Note: since we're using them here, please don't adopt any of the example passwords in this post for yourself.)

Problem 2: Using common passwords or words found in the dictionary
Common passwords include simple words or phrases like "password" or "letmein," keyboard patterns such as "qwerty" or "qazwsx," or sequential patterns such as "abcd1234." Using a simple password or any word you can find in the dictionary makes it easier for a would-be hijacker to gain access to your personal information.

Solution 2: Use a password with a mix of letters, numbers, and symbols
There are only 26^8 possible permutations for an 8-character password that uses just lowercase letters, while there are 94^8 possible permutations for an 8-character password that uses a combination of mixed-case letters, numbers, and symbols. That's over 6 quadrillion more possible variations for a mixed password, which makes it that much harder for anyone to guess or crack.

Problem 3: Using passwords based on personal data
We all share information about ourselves with our friends and coworkers. The names of your spouse, children, or pets aren't usually all that secret, so it doesn't make sense to use them as your passwords. You should also stay away from birth dates, phone numbers, or addresses.

Solution 3: Create a password that's hard for others to guess
Choose a combination of letters, numbers, or symbols to create a unique password that's unrelated to your personal information. Or, select a random word or phrase, and insert letters and numbers into the beginning, middle, and end to make it extra difficult to guess (such as "sPo0kyh@ll0w3En").

Problem 4: Writing down your password and storing it in an unsecured place
Some of us have enough online accounts that we may need to write our passwords down somewhere, at least until we've learned them well.

Solution 4: Keep your password reminders in a secret place that isn't easily visible
Don't leave notes with your passwords to various sites on your computer or desk. People who walk by can easily steal this information and use it to compromise your account. Also, if you decide to save your passwords in a file on your computer, create a unique name for the file so people don't know what's inside. Avoid naming the file "my passwords" or something else obvious.

Problem 5: Recalling your password
When choosing smart passwords like these, it can often be more difficult to remember your password when you try to sign in to a site you haven't visited in a while. To get around this problem, many websites will offer you the option to either send a password-reset link to your email address or answer a security question.

Solution 5: Make sure your password recovery options are up-to-date and secure
You should always make sure you have an up-to-date email address on file for each account you have, so that if you need to send a password reset email it goes to the right place.

Many websites will ask you to choose a question to verify your identity if you ever forget your password. If you're able to create your own question, try to come up with a question that has an answer only you would know. The answer shouldn't be something that someone can guess by scanning information you've posted online in social networking profiles, blogs, and other places.

If you're asked to choose a question from a list of options, such as the city where you were born, you should be aware that these questions are likely to be less secure. Try to find a way to make your answer unique — you can do this by using some of the tips above, or by creating a convention where you always add a symbol after the 2nd character in the answer (e.g. in@dianapolis) — so that even if someone guesses the answer, they won't know how to enter it properly.

Saturday, October 3, 2009

Did you realize some Facebook apps are being used to steal your data?



Phishing [Wikipedia] is nothing new. The bad guys have been spamming our inboxes for a long, long time hoping we'll click on some bogus link and provide them with important personal info like usernames, passwords, and credit card numbers.

Attacks like this rarely limit themselves to one avenue. So where do the bad guys go to find victims when they're not busy spamming? Why, the world's number one social networking site, of course!

Yep. Facebook, with its millions of users and juicy apps platform make it the perfect place for this type of vermin to set up shop. Trend Micro has found several phishing scams before that lured people to fake (but convincing) Facebook sites to harvest data. Now, however, they're doing it to you from the inside.

Trend researchers have discovered three applications so far that run on the Facebook apps platform. They can post notifications to your timeline, just like any legitimate app. The actual phishing is still done off-site, but the look is very, very convincing and you're returned to your Facebook profile afterward. It looks innocent enough, but once you've entered your credentials there's no telling what someone has planned for them.


Once Facebook receives notice that something like this is going on, the apps are typically shut down very quickly. They can, however, reappear with different names and the same old tricks.

How do you protect yourself? Many antivirus products include some element of phishing defense, but you may also want to use additional protection like WebOfTrust or AVG's LinkScanner. They'll notify you with big, read warnings when you're on a website that isn't trusted.

Apart from that, be careful what apps you install and make sure you only enter your Facebook username and password on Facebook.com. If the domain in your web browser's address bar doesn't match, exercise caution.

Get Thousands of Visitors for Your Website

autosurf

Get Free Dot Tk Domain

Earn Money by Just Shortening URL