Following is the winning entry from our Fall 2007 security contest.
The winner is: Md. Sazzad Hossain.
- Do NOT save your website password when you use a public computer. When using library computers, working in computer labs, etc. - some browsers will prompt you whether you want to save your password. YOU MUST CHOOSE “NO”, otherwise the person using the computer after you can enter the site with your username and password.
- One of the most popular things students do when they have free time is to login to MSN or YAHOO chat and choose the option “sign in automatically.” Don’t do this using public computers. This is mostly likely the same information you use for your primary email account and signing in automatically leaves that information on the computer for everyone to use.
- Do not save your credit card, debit card, Social Security, or bank routing number in your email account.
- If you need to send any of your personal information (SSN, credit card, debit card, etc.) to someone else electronically, do it by encrypting it through a zip file.
- Always watch the address bar for https://. Don't give any credit card information to any site which shows http://.
- Avoid installing an ActiveX control or any .exe file when on the Internet. If you feel you must, do it only on a trusted site.
- Always watch the actual link that’s displayed in the toolbar when you are clicking on a link. It may say "www.yahoo.com" in the link in your mailbox but if you look at the toolbar it may display "www.hackers.com" (or something that is NOT what you want.)
- Always watch the last word of an internet site address. For example - "www.ebay.sus.com" and www."sus.ebay.com". The first one is NOT an eBay site, while the second one is the part of eBay. So don’t be fooled by "www.ebay.sus.com" thinking it's ebay. it's part of www.sus.com
- Install software that will warn you when the Registry file is going to be changed. This will prevent you from any changes that may be done unnoticed.