uTalk

Official forum for Utopia Community

You are not logged in.

#51 Re: Off Topic » How to isolate a home server from the local network? » 2021-02-08 13:41:19

HanBaoCinch;269 wrote:

Your choices.

For me I could use netmask (that's singular) to virtually sequester this server from other computers on a LAN. It's simple, effective and uses a basic skill networkers know.

-> Since you have your own design that works (otherwise you would not be using it) why not call it solved?

Thanks. Yes, maybe netmask is the way to go. I need a second device on my network anyway to give me more ports so I had the DD-WRT router already hooked up.

I'm not a networker so getting my head around netmasks has been a bit of a challenge and a bit of research. I'm still not completely sure that I understand.

My understanding of netmasks now is that netmask is essentially to do with the binary nature of network addressing. In my case I would "borrow" bits from further down the local address and essentially split the addressing into 4 parts. The down side is that you loose a few possible addresses. The up side is you get four separated networks. Is this about right?

The more I research networking the more I find out how much there is know and how little I understand it all Sad

I'm happy to mark this as solved, but as I say, I'm not a networker and I would appreciate any comments concerning if my system really does add security for machines on both my local network "outer" and "inner" networks? And regarding the pros and cons of my set up vs netmask?

Thanks again.

#52 Off Topic » Free Anti-Bot Scanner from Spectrum Cable » 2021-02-08 13:36:57

Drassen
Replies: 3

Customers of Spectrum Cable can get free security software that they call Security Suite. Part of that software package is a program called Anti-Bot Scanner. However, you do not have to install the Security Suite software to use it. Just go to this page:

https://www.spectrum.net/security-suite … c-cbm-0118

Scroll down toward the bottom until you come across the Anti-Bot scanner, click it to download the installer and then run the program. It only takes a couple of minutes and it scans the hard drive and memory. I am a Spectrum customer, but it doesn't appear that you have to be a customer to use it.

#53 Off Topic » Is MediaFire safe? » 2021-02-05 14:01:55

Drassen
Replies: 5

Hello all,

I have a question about mediafire. I am interested in downloading a file from there, which itself seems legitimate. It is a demo version of an upcoming Titanic PC game. ("Honor and Glory".) When hovering over the "download" button on the game website, (http://www.titanichg.com/demo/), I'm presented with a link to Mediafire, which is ".../download/0h8x0ukru7y1pbr/Titanic+-+Honor+and+Glory+Demo.zip"

I have heard of some security flaws in the site, and read reports about numerous infections taking place there, drive-by downloads and such. I usually stay away from sites like this, although in this case, this file seems to be from a legitimate developer. What I am concerned about though is the possibility of picking up some malware from the site in general, or that the file, or its page, since its upload, may have been injected with something malicious.

Does this seem like a secure thing to do, or is there a substantial risk of malware here? Any input is appreciated.

#54 Re: Off Topic » Whatsapp New terms of Service » 2021-02-04 08:49:15

without explain, It’s a product under facebook management and both of its CEOs left (the people who created what’sapp) after some time and later it turned out they left because facebook wants to feed more on users data so yup its bad! the new terms is going to take your battery status, the strength of power of your internet, the version of whats’app, the browsers, the phone number, what sim you use (like provider), ISP, Language, Time, IP, and any relations with facebook and i’m sure more like contacts and others

#55 Re: Off Topic » How to isolate a home server from the local network? » 2021-02-04 08:46:47

I've done a little research into Netmasks, which is when you split the network into segments, right? That would probably do the trick.

The reason I want to isolate the Raspberry Pi 3B+ web server is that I had it set up with Freedombox, NextCloud and Wordpress and someone hacked into it and changed the web root's index.html file. There wasn;t anything sensitive on the Pi, but did did freak me out that it could be a possible way to break into the local network and start SSH brute forcing other accessible machines on the local network.

Yes, I agree firewalls go a long way. But I don't really want to have to turn into a paranoid sys admin having to open and close ports on local machines all the time. I would at least rather start with a robust network configuration and then worry about each machine on the local network as best I can.

I'm testing a setup using two routers and two separate DHCP fire-walled networks, based on the concept described here and tutorial here (though I'm not using VPN). See the attached image for a visual layout of the set up I'm testing - any advise comments regarding if my set up makes sense, or about weaknesses or strengths are much appreciated.

From information I have found it seems that network two (IP: 192.168.11.x - the "inner" network) can reach out to network one (IP: 192.168.10.x - the "outer" network) and to the internet. But the outer network can't (easily) get past the second routers firewall and into the inner network.

This works because data is passed back though the NAT to the originating address and all other traffic is stopped by the firewall.
So local machines on the inner network can reach out and SSH into the server on the outer network, but the server can't break through the inner firewall to reach the local machines on the inner network.
I tested and I can SSH from the inner network to the server on the outer network. But I don;t seem to be able to SSH from the server to a machine on the inner network, so it and this does seem to be the case.

I am new to all of this though, so I could be missing something obvious here.

Does my set up this make sense in the way I have described what I want?

#56 Re: Off Topic » How to isolate a home server from the local network? » 2021-02-02 13:30:01

Thanks - that's helpful.

Have you got any suggestions regarding best practice for configuring an internet available home web server on a home network from a security perspective?

For example, could I create two separate networks (I'm not sure how this would be accomplished): one exclusively for the web server, that I could connect to with with my laptop when I want to SSH into it, and; a second for my home devices?

Thanks for your help.

#57 Re: Off Topic » Is veracrypt safe? » 2021-02-02 13:20:33

CCleaner is one of the safest programs of its kind, It has everything you need to keep your computer clean of junk. You can expand the cleaning capabilities with CCEhancer.

While Advanced System Care itself is safe, using the program will cause more problems than it can fix.

#58 Re: Off Topic » How can i improve security and privacy? O.S, Cloud Storage, Apps, etc. » 2021-02-02 13:18:18

You want to use stuff that you need to use and still be private. This is quite a challenge because Microsoft, Adobe and to an extent, Apple does not care about your privacy. It is still quite doable.

First, do consider a Linux host system for your desktop to virtualize the Windows and Hackintosh. The reason to do this is to do image backups (via something like ZFS or maybe BTRFS). Windows has this tendency to commit suicide so having the capability to completely rollback changes to the OS at the VM level is good to have. You need a computer with lots of cores to achieve similar enough speed in your renders. You can offload the Handbrake, VLC and torrent software to the host Linux OS itself.

For the iphone, I would suggest:

Use a VPN software (that uses the IKEv2 protocol)
Install Lockdown 9 to block the tracking and telemetry.
Use Firefox for browsing instead of Safari and use it to browse the FB, Whatsapp and Youtube instead of using the app version.
Install cryptomator to encrypt contents in DropBox and Google Drive/Google One. Consider using something like Nextcloud 2 as replacement especially if you do not have a lot of online storage requirements. Maybe check out the enterprise version if it is worth it for you.
Your banking app stays because it might trigger some weird fraud protection scheme if you do something weird with it.
Consider moving on to a better email providers instead of remaining on GMail. Just transfer all your online accounts to whatever you choose. There is no need to totally delete Google for now (Google already has your personal data and there is no verifiable way for you to know if you they can actually delete your personal data).
Consider making an Android VM to your pc (via Androidx86) to access Instagram (which cannot be accessed via a desktop computer).
The iPad should probably stay as is and also install Firefox, Lockdown and another VPN provider as well. Also remove the Youtube app and just watch straight from the browser.

Finally, also consider using the following devices:

A new smartphone instead of iPhone. Google Pixel with Graphene OS 1. I havent used this myself though but I will try to remigrate my device once my old Lineage phone dies.
Raspberry Pi 4 + PiHole 1 - Use these to provide local network-wide DNS blocking for trackers and telemetry in all your devices. This is like what lockdown is, but for desktop. Previously you could edit the host file in microsoft but they have since then blocked modifications to it that pertains to telemetry.

#59 Re: Off Topic » Spywares and Privacy Mantra » 2021-01-27 11:56:31

I hadn't heard of it either, but I do see what it does. CCleaner is free and seems to do the same - but more. Not to mention the fact that we've heard of it and it's used by many. It's in the "Free Cleaning Programs" section.

#60 Re: Off Topic » How to permanently delete browsing history? » 2021-01-27 11:53:28

That's not browsing history, exactly, it's just a list of domains that have been resolved. It will likely include plenty of sites you never explicitly visited along with those you did. I would also presume that the /flushdns option to ipconfig would clear that out, since it's designed to clear the DNS cache, which is what you would be displaying.

Of course that only takes care of records on YOUR computer. There are still plenty of records existing on every other server your system has ever communicated with. The Internet was not designed to be anonymous or even all that secure, despite its military origins. The only real way to be truly anonymous on the Internet is to not be on the Internet.

#61 Off Topic » How to isolate a home server from the local network? » 2021-01-26 08:46:49

Drassen
Replies: 8

Hi, I have a reasonably simple home network set up - see dia below.

I have a Raspberry Pi3 (RPi3) set up as a web/chat server in the DMZ. The rest of the machines are connected - either wired or wireless - to a switch that is running DD-WRT - dia.

I would like to set things up so that the RPi3 home web/chat server is completely isolated from the rest of my home network, so that if it is compromised it can't be used as a gateway to gain access the other machines on the network.

Though I would still like to be able to access the home web server to perform maintenance tasks via SSH.

Can anyone give me advice me how to approach setting things up to allow for an internet available heme server, while maintaining the security of my home network?

Thanks

#62 Re: General Discussion » Why do you use Utopia as a best privacy tool? » 2021-01-21 12:07:53

Unstressed;177 wrote:

We need to move forward, test newcomers, and Utopia is exactly the newcomer in which I was not disappointed!
I didn't find any negative feedback from users. A decent ecosystem in our time, which is not a shame to advise someone)

And what do you think about the negative army of those, who hate that soft because of the closed source and tell everyone it's a scam not even trying?

#63 Re: Off Topic » Why It’s Dangerous to Share Your Birthday Online? » 2021-01-21 12:01:41

John_Sward28;173 wrote:

You're not paranoid, you're absolutely right. And you should be especially careful with entering personal dates in the social network.
And it is even better to use 2-step verification, so that you are already sure!

But 2 step verification requires a phone number, what I also don't really like and I think it can be dangerous also. Moreover, if my sim card will be lost, I couldn't enter the page anymore. I already faced such problems and prefer not to use it.

#64 Re: Off Topic » Tips for Keeping Your Data Private Online » 2021-01-21 11:59:53

Dr-Hack;161 wrote:

I wrote a blog, few years ago which explains how you can delete your cyber footprint by doing some easy steps like :
Step 1 – Recalling Emails
Step 2 – Deleting Ghost Accounts
Step 3 – Check if Hacked
Step 4 – Ask Google to Forget You
Step 5 – Disable Google Tracking
Step 6 – Delete Old E-Mails
Step 7 – Securing Accounts
Step 8 – Protect Your Internet
Step 9 – Disposable Accounts
Step 10 – Deleting Internet Content

just some small little steps !!!

complete article is accessible on utopia : https://blog.drhack.net/how-to-delete-y … footprint/ smile

Wow! You're a real expert in that field as I can see! Thanks for sharing, I'll follow your blog from now.
Keep going

#65 General Discussion » Why do you use Utopia as a best privacy tool? » 2021-01-16 12:31:33

Drassen
Replies: 70

As I've mentioned more and more new users are coming to Utopia every day. So I've came to a question Why do people trust it?

I've read lots of articles about best privacy tools and for every niche there is a separate list. As for me, having all in one place, based on its own blockchain with a highest encryption level, is a good choice. But still it's just words and without a whitepaper not many people still believe in it.

Why have you chosen it and why do you believe that Utopia can be a best privacy tool?

#66 Re: Off Topic » VPN Free Trial No Credit Card Services » 2021-01-16 08:37:29

Repeating once again, they differ in price and the countries list they provide. So you have to choose the one with a concrete country if needed, then choose the best price for you and then check whether it wasn't mentioned in any data leak scandals. That's it.

#67 Re: Off Topic » Tips for Keeping Your Data Private Online » 2021-01-16 08:35:03

Yep, for those who want to remain safe and anonymous online, it can be easier to refuse from such popular services as all the Google stuff and popular social media. But I still believe that such a radical steps are only for hackers or other online scammers. In other case, the data collected there will not do any harm to you, I guess.

#68 Re: Off Topic » VPN Free Trial No Credit Card Services » 2021-01-15 08:39:59

lolapolooza;140 wrote:

In general, today almost any service can be called reliable. I agree with the previous user that the services differ only in price and in the number of countries. On my own I can recommend TunnelBear - a good VPN service that guarantees the proper level of security.

I think we can simply check the list, choose the one we like most and then check the news dedicated to the service. As if it faced real ip leaks, then it's better not to try. I always check the reviews and latest news while choosing any service.

#69 Re: Off Topic » Why It’s Dangerous to Share Your Birthday Online? » 2021-01-15 08:33:55

lolapolooza;138 wrote:

Hmm, I want to note that you are not paranoid  big_smile Indeed, such seemingly non-obvious things are very good clues for cybercriminals or just stalkers. Therefore, I believe that every user should be aware that any personal data on the Internet deprives users of their privacy. cool

And I wonder what else similar things we have to mention. Like it's not so obvious and we have to be more careful about anything shared. Like pet name or photo views.. On the whole, looks like we have to forget about sharing anything at all. It will be so sad.

#70 Re: Off Topic » VPN Free Trial No Credit Card Services » 2021-01-14 13:59:47

You know what I'll tell you, I think that most of the VPNs have a free trial. But you'd better choose by different options. Like price, how much supported countries do you want, etc. I use Hide me and I'm fully satisfied with it. But it doesn't have a wide range of supported countries. If you don't need any exact ones and just want to hide your ip - it will be okay for you.

#71 Off Topic » Why It’s Dangerous to Share Your Birthday Online? » 2021-01-14 12:38:52

Drassen
Replies: 10

Hello, Utopians!

Look what I've thought about. Of course all of us share photos from our Birthday party and also there are many who make their Birthday date public in social media. On the one hand, we simply want more people to congratulate us, but on the other hand, it can be even dangerous.

Many of you will ask why, right? The answer is simple:

1. Our birth date is often used as a security question.
2. Still there are some sillies that use the combination of birth date as a password.
3. Being a USA citizen, your social security number can be guessed.

So what do you think, am I paranoid about it? I know that many people here care about their security more than usual internet users. But still that question seems important for me.

Board footer

Powered by FluxBB