Hacking 101: Protecting Sites & Visitors

Notes from Computers in Libraries 2013 Workshop

Quick Wins

Update everything
If you carry it, put a password in it
Don’t trust anything
Backup
Use second factor of authentication (Example: Google)
Own the email, own the person
Good passphrases

Browser

Use two updated browsers
Know your setting
Plugins/Ad-ons
Limit JavaScript
Block Ads
Block Java, Flash, Acrobat

WordPress

WP Scan
Keep it update
File permission
ModSecurity