16-07-2020, 01:14 PM
(16-07-2020, 09:33 AM)Mike Watterson Wrote: ...
Don't use the so called "Cloud" to store ANYTHING private or important, only for collaboration.
...
That's a sweeping and frankly IMHO a FUD (*) statement akin to "don't use banks - people will rob them and steal your money" - authoritative references please. There are plenty of cloud systems that are secure - you need, as in everything, to make choices about the services you use and what you use them for - read the Ts & Cs, do your own research.
Major businesses and governments happily use cloud facilities for highly confidential and business-critical data and, speaking from experience, they have extremely good people continually evaluating and testing these environments. The Information Commissioners Office (ICO) Guidence on the use of cloud computing and their general Guide to Data Protection plus the Federal Information Processing Standards (FIPS) publication 199 are good reads for those interested in this stuff - the ICO's documents are easy reading and "accessible" (even though the 'GDPR as it applies to the UK' explanation section alone is 183 pages long whereas the actual GDPR regulations, EU 2016/679, are only 88 pages long...).
There's a lot of subtlety in usage of the internet in general, specifically in how metadata is gathered and used but if you're sensible, there's no need to be concerned.
One item I really take issue with is the usage of a notepad to write down passwords and accounts. Really? That is a genuine major risk - try recommending that at a RANT, Infosec or similar professional security forum and you'd be laughed off stage. No-one I know of has actually written down passwords for many years (it's sooo last century), and in all the companies I've worked in (some multi$B), writing down passwords is a disciplinary offence. Admittedly, in some of those companies I was the CTO and wrote the rules... but no ITSEC professional would ever condone keeping passwords in plain text anywhere. To paraphrase the late great Douglas Adams, not even in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard'.
One thing I would recommend is turning on Multi-Factor Authentication (MFA) on critical accounts, e.g. banking. MFA is where you don't just need a password - you need something you know (account & password) plus something you have (e.g. a one-time code from SMS or a phone app such as the Google/Microsoft Authenticator) and/or something you are (e.g. a fingerprint or other biometric identifier).
If you use MFA plus multi-word-concatenated passwords for the critical accounts they are easy for you to remember and NEVER write down (**). You can then use a password manager to generate unique passwords for each non-critical site. Decent password managers, e.g. LastPass, automatically erase the clipboard (should you use it for a password) after a few seconds.
It's not complex and it demonstrably works. I have several hundred different passwords, literally 99% of which I don't (and never want to) know - the password manager deals with all that.
Lastly, if you are genuinely worried that Google is homing in on you, consider using the SRWare Iron browser or the Epic browser which are both built from the open-source Chrome/Chromium sources, but don't send anything back to Google. You might also consider using DuckDuckGo as your default search engine - it uses Google's search APIs, so is much the same as searching from Google UK, but it completely anonymises all your traffic and it's source. Both are highly regarded in INFOSEC circles - don't trust me, do your own research!
(*) FUD = Fear, Uncertainty & Doubt
(**) Please, PLEASE just don't go there
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
ʞɔıu







