from a security and privacy point

and not surface stuff like “whats my ip” “whats my fingerprint” (someone said the fingerprint checking sites are useless idk) or “is tor connected”

i have no clue what im doing and i want to know where the security/privacy holes are

  • MonaySimpson@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    3 days ago

    Its kind of like asking how do I check if my home is secure and private.

    First off YOU need to decide what safe and private feels like. Secure from who? Private form who? Most people have locks and blinds. Others might live in areas and feel they need a chain latch or roller shutters.

    This is called a threat modle and is designed by YOUR requirements. Most people need a password manager and 2FA. Others report on hostile countries and need systems that are locked down further.

    YOU design a setup for YOU by researching tools that meet your threat model.

    For the home some people might look into security cameras, alarms or gaurd dogs.

    For IT you might need your own email domain, maybe your model means hosting the email service yourself.

    What I’m saying is there isn’t really one setup. So there isn’t one tool to test it.

    Once you learn about what your trying to achieve you should have a good idea about pros and cons of the setup you’ve chosen, and if it’s secure for your needs.

    If your looking to install locks on your house you might get a deadbolt. If looking for a VPN you might want outside of 5Eyes.

    Weaknesses can come from anywhere. Maybe your setup is storing your passwords on “Dave’s Legot Password Storage Site For N00bs”. No tool will find that.

    What WOULD capture those types of things and more is paying for a pen test to hack into your stuff, but I don’t really think that’s an option for you. A pen test is where a cyber expert breaks into your stuff.

    If that sounds like what you ecnetually need, start lole they did. Learn some about privacy and security. There’s some privacy guide websites that explain some basics. Look into hack the box and learn about cyber security in general. Somone mentioned Kali and its hundreds of tools, but if you don’t know these to begin with they’ll be useless to you. I’m sure there are other video training series to do aswell.

    Then, in a few years, come back with specifically what is your threat model. What device, app, service or setup are you trying to secure, how is it configured. Etc.

    Then you’ll get some more specifics.