<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>epicblog &#187; Security</title> <atom:link href="http://www.rickwargo.com/category/security/feed/" rel="self" type="application/rss+xml" /><link>http://www.rickwargo.com</link> <description>Acquiring information, one day at a time.</description> <lastBuildDate>Fri, 14 Oct 2011 01:23:12 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>Configuring DKIM and Sendmail on Fedora 13</title><link>http://www.rickwargo.com/2010/11/19/configuring-dkim-and-sendmail-on-fedora-13/</link> <comments>http://www.rickwargo.com/2010/11/19/configuring-dkim-and-sendmail-on-fedora-13/#comments</comments> <pubDate>Fri, 19 Nov 2010 18:55:51 +0000</pubDate> <dc:creator>Rick Wargo</dc:creator> <category><![CDATA[E-mail]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[WILT]]></category> <guid
isPermaLink="false">http://www.rickwargo.com/?p=492</guid> <description><![CDATA[With all the movement with DomainKeys and the updated DomainKeys Identified Mail (better known as DKIM), much has changed in the &#8220;standards&#8221; and it is difficult gathering the correct steps to do when integrating with sendmail on Fedora. Following these simple steps, you should be able to get it configured and running with little headache. [...]]]></description> <content:encoded><![CDATA[<p>With all the movement with DomainKeys and the updated DomainKeys Identified Mail (better known as <a
href="http://www.dkim.org" target="_blank">DKIM</a>), much has changed in the &#8220;standards&#8221; and it is difficult gathering the correct steps to do when integrating with sendmail on Fedora.</p><p>Following these simple steps, you should be able to get it configured and running with little headache. Note there are a lot of moving pieces and a misstep on one will cause failure. Check and re-check each step before moving on.</p><ol><li>Install the DKIM package using yum</li><li>Generate the public and private keys</li><li>Create the DNS records<ol><li>Public DomainKey Selector</li><li>Author Domain Signing Practices</li></ol></li><li>Modify the configuration files<ol><li>Private keys</li><li>Milter configuration</li><li>KeyList</li><li>Internal hosts</li></ol></li><li>Start the dkim-milter service</li><li>Integrate with sendmail</li><li>Test</li><li>Caveats</li></ol><h2><span
id="more-492"></span>Install DKIM using yum</h2><p>From the command line, issue the following command to install the DKIM sendmail milter on your system. I am assuming sendmail is correctly configured and running at this point.</p><p><code>$ sudo yum install dkim-milter</code></p><p>This package provides the dkim-filter sendmail plugin, and a default configuration. It also creates a dkim-milter user and group. As of this post, the current 64-bit, Fedora 13 version is dkim-milter-2.8.3-5.fc13.x86_64.</p><h2>Generate the public and private keys</h2><p>DKIM needs a key pair to sign the message headers to guarantee the specified headers have not been altered. By making the public key available in a DNS TXT record in the sender&#8217;s domain, and assuming the account that manages the DNS records has not been compromised, this can verify the message has actually come from the stated domain (or the message&#8217;s origin).</p><p>The dkim-milter package comes with a utility to generate the key pair for you, dkim-genkey (located in /usr/sbin). This makes it exceedingly simple &#8211; just pass the domain name and selector on the command line and it will generate a 1024 bit (by default) private and public key pair.</p><p>Naming of the selector is not without significance, especially during the testing phase. The selector designates the DNS TXT record to retrieve; it will be in the form &lt;selector&gt;._domainkey. If changes are made to that entry, you may have to wait about an hour for the DNS system to flush. By generating a new selector name, you can bypass this, without having to wait for the time to live (TTL) period to expire.</p><p>The private key needs to be located such that it can be specified correctly in the milter configuration file, specifically the KeyList item; more on this later. To accommodate multiple domains, even if you have no plans on doing so now, I strongly suggest the following naming convention. Under a directory called keys within your dkim-milter folder, create a directory based on your domain name, for this example, it would be example.com. If you choose to keep the dkim-milter directory under your sendmail directory (/etc/mail), the newly created path is as follows:</p><p><code>/etc/mail/dkim-milter/keys/example.com/</code></p><p>Prior to generating the key pair, create the directory and cd into it to save the output from the dkim-genkey command.</p><p>There seem to be a number of different camps on how the selector should be named; in this example, I chose a date-based selector name: nov2010. Assuming the domain of example.com (you will need to substitute your own domain name), issue the following command to generate the key pair:</p><p><code>$ dkim-genkey -s nov2010 -d example.com</code></p><p>This will create two files in the current directory, one for the private key and one for the public. The private key will be named in the format &lt;selector&gt;.private, so in this example, it will be called nov2010.private. The public key will be named &lt;selector&gt;.txt, and in this example it will be called nov2010.txt. The public key file has the benefit of being formatted for your zone file (if running bind or other DNS server); otherwise, you can just add it using your DNS manager software on your ISP.</p><h3>The generated public key</h3><p>The public key file generated from the dkim-genkey command will contain something similar to the following, with the selector you have chosen replacing nov2010 and a new public key value replacing the one following the p= key.</p><p><code>nov2010._domainkey IN TXT "v=DKIM1; g=*; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD0g8Ac4gbYhHA3cuSL4kLcgDTE1iyTmugK1mzvhckCP959pavuuSZ5TyA7wLYhv9VTx9QXVwj0WxYqNyRYEGOKXb+gDy16OIdRYy2h4bw5F9Y+rUpvayPSlUmJsrkEm3wuMFoybUGCOQesSeKGPSaxdc+6ENpM6YRvwc+pCh4FjQIDAQAB" ; ----- DKIM nov2010 for example.com</code></p><h3>The generated private key</h3><p>This file needs no modification. It will appear as a block of text between two comments lines, similar to the following:</p><p><code>-----BEGIN RSA PRIVATE KEY-----<br
/> uvap959CPkchvzm1gKumyTi1TEgDckL4SLuc3HAhbYg4c8Ag0QDgKBAAIBwCXIIM<br
/> vprU+9Y5Fwb4h2yRYdOI61ygD+bKXGOYEyRqNxY0WjwXV9QxVT9vhLYw7yA5TSZu<br
/> ABAQIDjQ4FhpC+cwvYR6pMEN6+cdxaPSKGesSeOQGCbUyoMFuw3mkErsmJlUPSya<br
/> ao4Z40oOODFIpuWzNnceu7KjUjmnSyI41VFXKoCraBIezgS8C5m2MpH5KNSBAoGA<br
/> 934kMTe9lvYmoopK3+gDuqhR49/i9/p+JZwSV2vaQ8znYsXoqv/aRW94Vmy2Qmld<br
/> e6UlnElbe0A/EAkBAg/EA8UlANGz3LL+iAmm3DVaCRJxULCGRlvXY3FsjkK10Roa<br
/> GEyvqfjhZf0zzynr9qxb5RlZnZfznO7qoey+/tym3Ft78lim7tPPBPG61f/r3tbX<br
/> wWjDTMpn1QRdi7XHQSJpVQIBrrxNsomNcoMlwfGQnjDGr6Hj7PUBAQJw4FHcNklk<br
/> BBgTmV24Vg4YNn8F5J7Q43b7nQDCQ08kjOBrrnlIRUoem84rasnbVi7gsY9+iPTD<br
/> EAkBA3o8PR8+Yq9IkMz+jeMgNlecDcMG4HD7vKxnj+tubUWVh+7WBfQMxa+NpNwt<br
/> 6OMaxm+Z23zHlbDi0T3hbE5CITvymj5YcI780F44ZtOhdovd0mZXNklFwgs8mTOy<br
/> LNabV8fk/nTnHP5WscBaBfXV1ADn9Wdvs6YbH3AOJB+QdgVSq+DKpBTB87U6KTyH<br
/> =4kz3ri/shYab326OcDPLuwLqtGMSyy0gAP+bTz2h3aLXbUZ=<br
/> -----END RSA PRIVATE KEY-----</code></p><p>Note this key is not a pair for the public key so do not use it; it has been mangled and is for demonstration purpose only.</p><h2>Create the DNS records</h2><p>Having successfully created a private/public key pair, the next step is to publish the public key, and optionally the Author Domain Signing Practice, to your DNS server. This will result in the addition of one or two TXT records to your DNS server.</p><h3>Public DomainKey Selector</h3><p>If you run your own DNS server, just add the public key file generated from the dkim-genkey command to your zone file. In this example, that would be the information from the nov2010.txt file. If you are updating DNS through your ISP, create a new TXT record and assign the Host value &lt;selector&gt;._domainkey, so in this example, it would be nov2010._domainkey. The value for the TXT record will be what is enclosed in quotes within the public key file, again in this example, nov2010.txt. The value will start with v=DKIM1 and end in the public key. This collection of key/value pairs compromises the DomainKey. The keys for v= and g= are optional; and either do not exist in the original DomainKey specification or are different. The values specified in the file are the default and will be assumed if omitted. You can choose to omit them when entering them in the DNS system; it may help make it compatible with DomainKey MTAs, although I have not tested this.</p><h3>Author Domain Signing Practices</h3><p>This is an optional DNS TXT record that describes the policy if emails are signed using DKIM. Not creating this record assumes a default of dkim=unknown, which signifies that the domain may sign some, none, most, or all email. During the testing phase, I would suggest not creating this record, or at least using the default of <em>unknown</em>. Once the server is verified to work correctly, updating this record to state <em>all</em> or <em>discardable</em>.</p><p>The host for this record is _adsp._domainkey and the value is &#8220;dkim=unknown&#8221;. Again, <em>all</em> and <em>discardable</em> may replace <em>unknown</em> once the system is completely functional. The zone record is as follows:</p><p><code>_adsp._domainkey IN TXT "dkim=unknown"</code></p><h2>Modify the configuration files</h2><p>Once the public keys are in place and the DNS TXT records configured correctly, the configuration files need updating. The private keys need to be stored safely and the milter configuration needs to be tweaked.</p><h3>Private keys</h3><p>Assuming you created the domain directory under /etc/mail/dkim-milter/keys, the private key file will exist but will have the extension .private. The file can be renamed to remove the .private extension such that it matches the name of the selector. This is important as the keyfile item in the milter configuration is fashioned to find the private key using the selector name as the last item in the path. If the file does not exist, it will search for the file with a .pem extension and if that doesn&#8217;t exist, will look for it with a .private extension. I prefer no extension so that it matches the selector and the keyfile record matches the full path.</p><p>This private key must be kept secure and access only given to the user needing it &#8211; dkim-milter (remember it was created as part of the yum package installation). It is important to change the owner (and optionally the group) to this user as the milter will be running under this user id. This is accomplished with the chown command; for the example it would be the following:</p><p><code>$ sudo chown dkim-milter:dkim-milter nov2010 # recall the file has been renamed from nov2010.private to nov2010</code></p><p>The public key will also exist in this directory as a result of the dkim-genkey command issued earlier. It is helpful to keep this file in case something happens to the DNS record.</p><h3>Milter configuration</h3><p>Installation of the yum package will create a generic configuration file that needs tweaking. The comments contained within the file are useful in determining what each option means. I have documented below only the options that are changed to get this to work. These are listed in alphabetical order, the same order as listed in the configuration file.</p><p>Note in other web pages, you will find references to a sysconfig file (/etc/sysconfig/dkim-milter). It is unnecessary to create and maintain this file for the Sendmail/DKIM integration to work.</p><p>The following is a list of options that must be set for the milter to work successfully. Much information about these options is also available in the <a
href="http://manpages.ubuntu.com/manpages/maverick/man5/dkim-filter.conf.5.html" target="_blank">dkim-filter.conf(5) man page</a>.</p><h4>Domain</h4><p>If a KeyList is used (as it is in this example), is not necessary to be specify this option; the signing-domain entries in the KeyList file infer the domains.</p><p>If you plan on only a single domain, set the value of this option to the name of the domain and omit the KeyList parameter.</p><h4>InternalHosts</h4><p>This option specifies hosts (typcially on the local network) whose emails should be signed rather than verified. If an MTA is sitting behind this copy of sendmail (for example an Exchange server), that has this sendmail configured as its smart host, then those hosts need to be listed in this file. The localhost (127.0.0.1) should always be listed in this file.</p><p>Again, I recommend setting it to a file under the dkim-milter directory, such as /etc/mail/dkim-milter/internalhosts and remember to set the appropriate permissions.</p><h4>KeyList</h4><p>The KeyList option specifies where to find the list of private keys for all the domains whose emails are to be signed. I recommend using /etc/mail/dkim-milter/keys/keylist and setting the permissions appropriately. Refer to the following section for the contents of this file.</p><p>If only a single domain is to be used, this option can be omitted and the Domain and Selector options used in its place.</p><h4>MTA</h4><p>Other sites have specified setting this value to MSA; I have left it alone. This limits which emails to sign based on the specified MTA; I choose to not limit signing based on the MTA.</p><h4>Selector</h4><p>If a KeyList is used (as it is in this example), is not necessary to be specify this option; the keypath entries in the KeyList file infer the selector per domain.</p><p>If you plan on only a single domain, set the value of this option to the name of the selector and omit the KeyList parameter. In this example, the selector should be set to nov2010.</p><h4>Socket</h4><p>Many of the examples listed on various web pages specify a TCP port to use for communication. I have chosen to use a <a
href="http://en.wikipedia.org/wiki/Unix_domain_socket" target="_blank">Unix domain socket</a> that is created when the milter is started. By default the socket is created at /var/run/dkim-milter/dkim-milter.sock so the the value for this option is local:/var/run/dkim-milter/dkim-milter.sock. Again, note this dkim-filter daemon is not listening to requests on a TCP port in this example.</p><h4>Syslog</h4><p>Make sure to set this to yes so that you can verify it is working. You may also choose to set the LogWhy parameter to yes to see more debugging information.</p><h4>SyslogSuccess</h4><p>Again, set this to yes to confirm the process has performed successfully. It is very useful in determining what has occurred. The output of the messages from the daemon will b written to the tail end of the /var/log/maillog file.</p><h4>UserID</h4><p>Set this to the user that was created during the package installation: dkim-milter. This will ensure the dkim-filter daemon runs as that user and has limited access to other system files.</p><h4>ADSP*</h4><p>The following two options are used to make the MTA accountable to the ADSP TXT records. These are optional and can be left alone.</p><ul><li>ADSPDiscard yes</li><li>ADSPNoSuchDomain yes</li></ul><h3>KeyList</h3><p>This file specifies the domain or domains that will be signed, the selector for each domain, and the path to the private key used to sign the message. The file is in the format:</p><p><code>sender-pattern:signing-domain:keypath</code></p><p>where,</p><ol><li> <em>sender-pattern</em> is a &#8220;globbed&#8221; string matching the sender&#8217;s mail address to be signed. You may use &#8220;*&#8221; to match zero or more characters in the address for this entry part.</li><li><em>signing-domain</em> is the name of the domain that will have emails signed.</li><li><em>keypath</em> is the full path to the private key file, without an extension. The file must be the name of the selector, as the last part of the keypath must be the selector name. If the file is named with a .pem or .private extension, this should not be specified here.</li></ol><p>To sign all emails from the domain example.com with the selector nov2010, the following entry can be specified:</p><p><code>*:example.com:/etc/mail/dkim-milter/keys/example.com/nov2010</code></p><p>The keypath matches what has been described in this post.</p><h3>Internal hosts</h3><p>Listed as one host per line, this file describes the hosts that send mail on behalf of this domain and need to have the email signed by this milter. It is important to also list the localhost or the computer will not be able to send any signed mail.</p><p>This file is recommended to be created at /etc/mail/dkim-milter/internalhosts with an owner and group of dkim-milter. Refer to the <a
href="http://manpages.ubuntu.com/manpages/maverick/man5/dkim-filter.conf.5.html" target="_blank">dkim-filter.conf(5) man page</a> under the <em>PeerList</em> option for the format for this file.</p><h2>Start the dkim-milter service</h2><p>The package installation created a service but did not configure it to start upon boot. To do this, use the chkconfig command to enable it at run-levels 3, 4, &amp; 5 (or whatever is appropriate for your organization). This is simply accomplished by issuing the following:</p><p><code>$ sudo chkconfig --levels 345 dkim-milter on</code></p><p>To start the service without reboot, issue:</p><p><code>$ sudo service dkim-milter start</code></p><p>If all goes well, it should output the following:</p><p>Starting DomainKeys Identified Mail Milter (dkim-filter):  [  OK  ]</p><p>If it says [FAILED], you must go back and double-check your configuration and access to the files and attempt to start the service again.</p><p>Any time the configuration is modified, restart the service with the following:</p><p><code>$ sudo service dkim-milter restart</code></p><h2>Integrate with sendmail</h2><p>Adding another milter to the sendmail configuration is simple, all that is necessary is the addition of the following line to the sendmail.mc file, rebuild the sendmail.cf file, and restart sendmail. Remembering we chose to communicate through a Unix socket, add this line near the end of the sendmail.mc file (in /etc/mail):</p><p><code>INPUT_MAIL_FILTER(`dkim-filter', `S=local:/var/run/dkim-milter/dkim-milter.sock')</code></p><p>To rebuild the sendmail configuration file, enter the following command:</p><p><code>$ sudo make</code></p><p>If all goes well and you see no output, restart sendmail to use the new milter. This is done by issuing:</p><p><code>$ sudo make restart</code></p><p>or</p><p><code>$ sudo server sendmail restart</code></p><p>If everything has gone well up to this point, the DKIM milter is successfully installed and configured to work with sendmail. You are now ready to test signed email messages.</p><h2>Test</h2><p>There are a number of sites on the web that can test your DKIM configuration. You can perform a DKIM test by sending an email to one of the following addresses:</p><ul><li><a
href="mailto:check-auth@verifier.port25.com">autorespond+dkim@dk.elandsys.com</a></li><li><a
href="mailto:sa-test@sendmail.net">sa-test@sendmail.net</a></li><li><a
href="mailto:check-auth@verifier.port25.com">check-auth@verifier.port25.com</a></li></ul><p>Their email server will respond to the sender with a response indicating the success of the test.</p><p>In testing, I having a running tail of the mail log:</p><p><code>$ sudo tail -f /var/log/maillog</code></p><p>and watch the log as I send the message. If the setup is correct, the sendmail milter will sign the outgoing message and produce a log entry similar to:</p><p><code>dkim-filter[22234]: oAJEplSN026556 "DKIM-Signature" header added</code></p><p>For verification, the log will display messages such as:</p><p><code>dkim-filter[8206]: oAHIoXFJ008437 DKIM verification successful</code></p><p>or</p><p><code>dkim-filter[7882]: oAHIhIXU007949: no signature data</code></p><p>if the sender&#8217;s domain does not publish DKIM information.</p><p>To view the DNS records, use the <strong>dig</strong> command (<strong>host</strong> also works equally well). The following will view the public key information for the nov2010 selector of the example.com domain.</p><p><code>$ dig -t TXT nov2010._domainkey.example.com</code></p><p>And this will view the corresponding ADSP record:</p><p><code>$ dig -t TXT _adsp._domainkey.example.com</code></p><h2>Caveats</h2><p>I have had issues sending to an email account that has the mail forwarded back to the original senders account. For example, if I sent a test message to my gmail account, which in turn automatically forwards it back to me, the message will get lost in limbo, with the dkim-filter complaining that the <em>key retrieval failed</em>. I have yet to figure out the solution, but a work-around is to not sign emails going to those addresses. This is accomplished by setting a comma-separated list of addresses for the value of the <em>DontSignMailTo</em> option in the dkim-milter.conf file.</p><p>I have also had issues using the DNS managers for different ISPs, especially pertaining to quotes. Some of the tools strip the quotes and other keep them. Check the TXT value using the dig command to ensure it looks right. If there is a double-quote in the value escaped with a backslash, then there will be a syntax error with the record and you may seen a message similar to the following in your log.</p><p><code>dkim-filter[6813]: oAI5kwwB012942 ADSP query: syntax error in policy data</code></p> ]]></content:encoded> <wfw:commentRss>http://www.rickwargo.com/2010/11/19/configuring-dkim-and-sendmail-on-fedora-13/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Understanding Your Information with respect to the Microsoft Outlook Social Connector Provider for Facebook</title><link>http://www.rickwargo.com/2010/07/13/understanding-your-information-with-respect-to-the-microsoft-outlook-social-connector-provider-for-facebook/</link> <comments>http://www.rickwargo.com/2010/07/13/understanding-your-information-with-respect-to-the-microsoft-outlook-social-connector-provider-for-facebook/#comments</comments> <pubDate>Tue, 13 Jul 2010 16:41:29 +0000</pubDate> <dc:creator>Rick Wargo</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[WILT]]></category> <guid
isPermaLink="false">http://www.rickwargo.com/?p=399</guid> <description><![CDATA[The Outlook Social Connector for Facebook is now available for download. This connector pumps Facebook wall feeds into Outlook for the sender of the selected email message and also within their Contact page. It&#8217;s usefulness is apparent as relevant and timely information is presented with the contact. It only displays the information which it authorized [...]]]></description> <content:encoded><![CDATA[<p>The <a
title="Microsoft blog posting about the Social Connector Release" href="http://blogs.msdn.com/b/outlook/archive/2010/07/13/use-the-outlook-social-connector-with-facebook-linkedin-myspace-and-windows-live.aspx" target="_blank">Outlook Social Connector for Facebook</a> is now <a
href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=ce8b7517-234c-48a1-a655-324a88893b02" target="_blank">available for download</a>. This connector pumps Facebook wall feeds into Outlook for the sender of the selected email message and also within their Contact page. It&#8217;s usefulness is apparent as relevant and timely information is presented with the contact. It only displays the information which it authorized to view.</p><p>Similarly, the Outlook Social Connector for Windows Live Messenger is also <a
title="Outlook Social Connector for Windows Live Messenger" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=ce8b7517-234c-48a1-a655-324a88893b02" target="_blank">available for download</a>. This presents Windows Live feeds into Outlook for the selected contact.</p><p>Note when installing any of the Outlook Connectors you&#8217;ll need to match the architecture of Outlook with the architecture of the plug-in. For example, if you have 64-bit Outlook installed, then you&#8217;ll need the 64-bit version of the connectors installed, otherwise they will not work. At the time of this posting, the connectors for <a
title="LinkedIn Outlook Connector" href="http://www.linkedin.com/outlook" target="_blank">LinkedIn</a> and <a
title="MySpace Outlook Connector" href="http://www.myspace.com/msoutlook" target="_blank">MySpace</a> do not support the 64-bit platform of Outlook.</p><p>While adding these connectors to your Outlook is helpful for you, it also potentially exposes your information to others who have installed the connector. If you don&#8217;t want your Facebook wall appearing in the Outlook of others you email, you need to ensure that your privacy and email settings are secure. Even if you don&#8217;t use Outlook, there will be someone with whom you communicate with, directly or indirectly, that does use Outlook and thus it is imperative to monitor your Facebook privacy settings. I would safely assume other email readers will soon offer the same integration so I suggest that you follow these security practices below.</p><h3>Choose Your Privacy Settings</h3><p>In Facebook, under the <strong>Account </strong>menu, select <strong>Privacy Settings </strong>and click <strong>Friends Only </strong>under the <strong>Sharing on Facebook</strong> section. This will limit reading of your information to only those you have selected to be your friends. Click On <strong>Apply These Settings </strong>to make your changes permanent.</p><h3>Info accessible through your friends</h3><p>Now make sure that your friends are not sharing your information. On the same <strong>Privacy Settings </strong>page, under the section <strong>Applications and Websites</strong>, click on <strong>Edit your settings</strong>. Then, click on the <strong>Edit Settings </strong>button in the <strong>Info accessible through your friends</strong> section. This dialog will present a list of things you permit your friends to share about you. I would suggest ensuring nothing is selected. Click on <strong>Save Changes</strong> to enhance your security settings. I would also suggest <strong>disabling </strong><strong>instant personalization on partner websites </strong>under the <strong>Instant Personalization</strong> section.</p><h3>Email Security</h3><p>It appears that the Outlook Connector for Facebook searches all the email addresses you have for the selected contact to determine the Facebook account (or other Social Connector accounts). If you want to associate Facebook posts with your contacts, you will need to ensure one of the email addresses you have for that contact is associated to your Facebook friend. If not, even though your contact and you are connected on Facebook, you will not see that person&#8217;s wall feed in Outlook. <em>If you do add a new email address for a Contact to associate it with the Facebook friend, you will need to restart Outlook for the Connector to be aware of the new email address and display wall postings.</em></p><p>To secure your own information, I suggest using an email account for Facebook that is not the same as the one you typically use to correspond. And please do not use a work email address on Facebook; that will make it much too easy for your personal and professional lives to collide.</p><p>If you only have one email address, get another one from Gmail and set that to be the primary (and only) email account on Facebook. Then forward the email you received on the newly created Gmail account to your regular account so you won&#8217;t miss out on any Facebook updates.</p><p>Finally, if you don&#8217;t want any of your friends to get your feeds, hide the Facebook email address. People can still send a direct message to you in Facebook without knowing your email address. To hide your email from everyone, go to the <strong>Privacy Settings</strong> page, selected from the <strong>Account</strong> menu. Click on the tiny <strong>Customize settings</strong> link near the bottom of the main section. At the bottom of the <strong>Customize settings</strong> page, under <strong>Contact information</strong>, click on the drop down next to your email address and select <strong>Customize</strong>. In the drop down under <strong>Make this visible to</strong> <strong>These people</strong> select <strong>Only Me</strong>. This will hide your email address from all Facebook users and make it difficult for others to configure their Outlook Facebook Connector to integrate your posts with their email.</p><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=ce8b7517-234c-48a1-a655-324a88893b02Outtlook Social</div> ]]></content:encoded> <wfw:commentRss>http://www.rickwargo.com/2010/07/13/understanding-your-information-with-respect-to-the-microsoft-outlook-social-connector-provider-for-facebook/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Secure Your Windows Computer When Using Adobe Reader</title><link>http://www.rickwargo.com/2010/04/15/secure-your-windows-computer-when-using-adobe-reader/</link> <comments>http://www.rickwargo.com/2010/04/15/secure-your-windows-computer-when-using-adobe-reader/#comments</comments> <pubDate>Thu, 15 Apr 2010 18:43:55 +0000</pubDate> <dc:creator>Rick Wargo</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[WILT]]></category> <guid
isPermaLink="false">http://www.rickwargo.com/?p=229</guid> <description><![CDATA[Turns out there are some nasty security holes in Adobe Reader that are not bugs, just intended features. Unfortunately, these &#8220;features&#8221; should not be enabled by default, but they are. 1. JavaScript - there really is no reason to have JavaScript enabled in most PDF documents unless it is a form-based document that requires input [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://www.rickwargo.com/wp-content/uploads/2010/04/adobe-reader-javascript.png"><img
class="size-medium wp-image-230 alignright" title="Adobe Reader  JavaScript Preferences" src="http://www.rickwargo.com/wp-content/uploads/2010/04/adobe-reader-javascript-300x187.png" alt="" width="210" height="131" /></a>Turns out there are some nasty security holes in Adobe Reader that are not bugs, just intended features. Unfortunately, these &#8220;features&#8221; should not be enabled by default, but they are.</p><p>1. <strong>JavaScript </strong>- there really is no reason to have JavaScript enabled in most PDF documents unless it is a form-based document that requires input with validation. So, unless you use this type of document all the time, please disable JavaScript in the Preferences dialog (located under the Edit menu, or just press Ctrl-K). Click on the JavaScript category and uncheck Enable Acrobat JavaScript.</p><p><a
href="http://www.rickwargo.com/wp-content/uploads/2010/04/adobe-reader-trust-manager.png"><img
class="size-medium wp-image-232 alignleft" title="Adobe Reader Trust  Manager" src="http://www.rickwargo.com/wp-content/uploads/2010/04/adobe-reader-trust-manager-300x224.png" alt="" width="168" height="125" /></a>2. <strong>External Application Launching </strong>- Believe it or not, Reader can launch other application and have them display their content within the PDF viewer. This is enabled by default! Turns out there is a hack to change the contents of the warning dialog to use social engineering to deceive the user into allowing the application to launch and even launch arbitrary code to take over your computer. This is easily avoidable by disabling it &#8211; if you ever do need it, Adobe Reader will tell you that it is disabled and you can have the opportunity to re-enable it. To do so,go to the Preferences dialog and click on the Trust Manager category. Uncheck &#8220;Allow opening of non-PDF file attachments with external applications.&#8221; Please.</p> ]]></content:encoded> <wfw:commentRss>http://www.rickwargo.com/2010/04/15/secure-your-windows-computer-when-using-adobe-reader/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
