Industry guru Dave Taylor answers free tech support questions about a wide variety of business and technical topics, including blogging, Google AdSense, MySpace, Sony PSP, Apple iPod, Mp3 players, management, Linux, SEO, Mac OS X, Facebook, Twitter, LinkedIn and Microsoft Windows.

Can hackers read everything on my computer?

My local newspaper's computer guru recently said that it was possible for a hacker to read what you have just copied into memory. The example he used was copying your password from a text file into a password box on a website. Is this true?


Dave's Answer:

Weeelllll.....

I don't want to disagree with your local computer guru, but I think he or she might be speaking a bit imprecisely based on what you're saying.

It is true that if a hacker has your computer they can probably dig up things you'd prefer to keep private, including a file that contains your passwords (which seems like a dangerous strategy, btw, unless you at least keep that file password protected) but without explicit access and without the aid of a virus that's already running on your computer that they control, it's hard for me to envision exactly how they could see what's in your computer's memory.

On the other hand, it is quite possible - and disturbingly easy, actually! - for even a neophyte hacker to be sniffing login account and password information from a wireless network, whether it's public or private. (A private, password-protected network protects you from people who aren't on the network, but if you're at a cafe, say, where they have the password posted on the cash register, then everyone who is online is "trusted". Dangerous!)

As a scary experiment, go to Google and search for something like "wireless password sniffer" or "wifi packet sniffer" or similar and you'll find that there are applications that are easily downloaded - and free - that will let anyone start monitoring the wireless network traffic around them.

This is the tip of a much bigger topic, of course, and there are a variety of best practices you should learn so you can stay secure on wireless networks, but I'll just start by saying that you should never log in to a Web site that isn't protected by SSL (that is, its URL is "https://" rather than "http://"). More importantly, you can also use a secure SSL connection to communicate with your mail server: call your ISP to get details of how to switch to that.

Hope that clears things up. If you are the "computer guru" who wrote this original note, by the way, please do explain what you were thinking!



Help others find this article at Del.icio.us, Digg, Netscape, Reddit, and Simpy.

Subscribe!

Never miss another useful Q&A article again! Subscribe to AskDaveTaylor with Google Reader.

Comments

Is it possible said "Guru" was referring to the recently discovered fact that DRAM chips are not as volatile as was previously thought. For a short time after power-off, it is possible to recover information from the computer's physical RAM, using some technique or other, which I don't pretend to know or understand, lol.
By freezing the chips before powering down, the degradation of the data in RAM is slowed, allowing someone to remove the computer from a property before getting to work on it.

Certainly nothing for the likes of you and I to be concerned with on a day to day basis. It's more a worry for people who REALLY have something to hide - enough that the FBI have just seized their PC, that is.

Posted by: Slippy Lane at February 27, 2008 12:51 PM

Yeah, if I've hacked a computer and have good enough access to peruse it's memory, then I wouldn't bother with that. If I'm looking at a memory dump, I'm gonna see what you typed into the field, regardless of whether or not the clipboard was used. The guru could have been referring specifically to accessing the clipboard, but, once again, if I can do that on the PC, I'd have already hacked the password file and gotten that info. Fear sells, tho.

Posted by: Steve at February 28, 2008 9:21 AM

I have suddenly started receiving emails from so-called Russian women looking for men. Same letter, same pic but different names. Obviously a dating scam but I have never subscribed to any dating agencies, how have they got my email address?

Posted by: Irene Lane at April 17, 2008 7:23 AM

I want to create a search engine for my website. So, that it searches only my site contents. Also, I want to see my site name on each page. So, that it looks that my search is going under my site only. I don't want Google search (of entire web search) to view on my site. Is there any solution? Please help me.!!

Posted by: James at April 29, 2008 5:18 PM

I have a lot to say, but ...
Starbucks coffee cup I have a lot to say, and questions of my own for that matter, but most of all I'd like to say thank you for all your efforts on this Web site by buying you a chai!

I do have a comment, now that you mention it!









Remember personal info?


Please note that I will never send you any unsolicited commercial email. Ever.

While I'm at it, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site.









Search
Find just the answers you seek from among our 1700+ free tech support articles by using our Lijit search engine.


Help!





Subscribe to
Ask Dave Taylor!

Add to Google Reader
Add to My Yahoo!
Subscribe in NewsGator Online

RDF   XML

Free Updates!
Sign up and get free weekly updates and special offers on books, seminars, workshops and more.


Recent Entries
Join the List!
Join my author info mailing list, where you'll learn about my upcoming books, speaking gigs, and more!


Book Links
© 2002 - 2008 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site.

[whiteboard marker tray]