This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

H9. Avoid unnecessary risks

From OWASP
Jump to: navigation, search


Description: Avoiding dark alleys at night in the rough part of town when you’re alone and have no business being there is generally a wise decision. Any possible reward isn’t worth the risk. Just as there are safer places in your town or neighborhood, there are safer places to be on the Internet and some less reputable places. Be aware of where those places might be and avoid them if necessary. If it isn’t, take proper precautions to protect yourself.

Threats: Accessing unsafe or disreputable sites increase the possibility of attacks, being harassed, becoming a target of criminal or government interests, or the revelation of private information.

Impact: Damage to your reputation by being associated with certain sites, the disclosure of visits in browsing history, or being targeted in ads on pages. Theft of personal and financial data.

Recommendations:

Consumers should focus on:

1. Avoid malicious/underground websites
2. Avoid creating accounts for “shady”  and sites you do not use regularly
3. Do not do important tasks (pay bills, trade stocks, etc) on unprotected networks

Tech-savvy users should also:

1. Use non-persistent virtual machines for riskier sites
2. When creating DNS domains, use a privacy service to hide your home address if you have an unlisted telephone number
3. Understand the risks of unsigned and side-loaded applications. Do not use them on your primary phone or system

Example: Having your email associated with an adult website and having the data breached. Having embarrassing bookmarks on your browser or in sites in your browser history when someone uses your computer.