Making Windows Live Messenger safer?

MichaelD

Lifer
Jan 16, 2001
31,528
3
76
I've traditionally eschewed IM-type programs due to the security risks they present to your network; too many open ports and things of that nature.

But now I have to use one. I'm using Windows Live Messenger v8.1.

Is there a way to make it "safer?" I.E. by locking down settings on my router or within my firewall program?

I use Symantec Client Firewall 7, if that helps.

Thanks for the assistance.
 

Zugzwang152

Lifer
Oct 30, 2001
12,134
1
0
Link to information about the Windows Live Messanger protocol KB:
http://support.microsoft.com/kb/903056/en-us

The obvious answers here are:

1. Do not allow external communication. Keep all traffic inside your network. Giving the Internet direct access to your PCs is always a bad idea. In addition to increased risk of attack, you don't want your confidential information being IM'd out over the Internet unencryped (see #3).
2. Unless they are needed, disable file transfer and audio/video capabilities. Note in the link that IM traffic goes through the Live Communications Server. The others are peer-to-peer. Disabling them limits connections between PCs, which limits your exposure in case one of them is compromised.
3. If you're going to allow people to discuss confidential information through IM (you might as well, because there's no good way to prevent people from doing it anyway), enable TLS encryption. Again, this is to minimize your risk incase your network is compromised and attackers start sniffing traffic.


Edit: These are best practices for any instant messaging applications, not specific to just Windows Live Messenger.
 

MichaelD

Lifer
Jan 16, 2001
31,528
3
76
Thanks very much, Zugzwang152. I really need to read up and do what I can.

*edit*

I read the article and now I'm confused. It mentions Microsoft Office Live Communications Server 2005; I'm not running a server and this isn't for work use (all IM programs are blocked/forbidden/WebSensed out) where I work.

This is for my home use. I use Symantec Client Firewall on my home PCs running unmanaged.

Does that change the situation any?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Also consider using a non-Admin user account to run the IM program. Don't hand over your ammunition along with the weapon; it's a lot less dangerous unloaded, right?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |