E-Mail:

Browsing The Web And Reading E-mail Safely As An Administrator

Summary: Michael Howard discusses how you can run as an administrator and access Internet data safely by dropping unnecessary administrative privileges when using any tool to access the Internet. (10 printed pages)

Download the DropMyRights.msi file.

I’ve said this many times, but I’ll say it again, “Running with an administrative account is dangerous to the health of your computer and your data.” So, whenever someone says they must operate their computers as administrators, I always try to persuade them it’s not the correct thing to do from a security perspective. That said, every once in a while I meet someone who has a valid reason. For example, I use one of the computers in my office to install the latest daily build of Windows, and I need to be an administrator to install the OS. However, and this is a big point, I do not read e-mail, browse the Web, or access the Internet in any form when running as an administrator on that machine. And I do not do so because the Web is the source of most of the nasty attacks today.

What if someone does want to browse the Web? Or read e-mail? Or do Instant Messaging and so on, and for some reason must run in an administrative context? If you look at the major threats to computers, they are from user interaction with the Web through tools like browsers and e-mail clients. Sure, there are non-user interaction attacks, such as Blaster and Lion, but that’s in part why we turned on the firewall in Windows XP SP2!

Note: For Best practices on running as a non-admin, I urge you to look over Aaron Margosis’ blog to glean tips on running as a non-admin in Windows.

What Do You Think?

 

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense hard-earned information back to the community, stake a claim on your very own Lockergnome blog today! You can write about anything - no matter the topic. Sign-up to start blogging!

Favorite - Oct 10, 2008

Scour

Download, Freeware - Oct 9, 2008

CurrPorts v1.51

Download, Freeware - Oct 6, 2008

AudioGrail v6.13.2.158

Download, Freeware - Oct 3, 2008

SniffPass v1.07

85 queries / 0.756 seconds.