5 ms·
D*mmit. Guess I finally should break down and burn a linux bootdisk for banking.
by ccarter84 13y ago
D*mmit.
Guess I finally should break down and burn a linux bootdisk for banking.
- lifeguard 13y agoAhhh, but what system can you trust to burn the linux boot CD on?
- al1x 13y agoNot to mention by the time you burned it it would be well out of date (security patches). If you're going to go that route you'd be better off buying a USB stick with a write-lock (Kanguru sells some).
- lifeguard 13y agoThe usual move is to argue but I have seen un-patched Windows servers rooted in under 30 min on the public Internet. I made several recommendations to modify their SOP...
- akama 13y agoKanguru has some really nice thumb drives. I own two and would recommend them to anyone. Keep in mind, you can also store private keys on them.
- jlgaddis 13y ago> you can also store private keys on them As regular files (e.g. `cp ~/.gnupg/secring.gpg /media/kanguru/`) or can you somehow import them such as with a smart card? I carry multiple devices at the moment but it would be nice to consolidate.
- akama 13y agoOnly as regular files, but with the write lock you can be sure that they don't get deleted.
- Wingman4l7 13y agoAre you saying this software can inject malicious code into a disk image and/or falsify the integrity report if you look at the md5 checksum of said image?
- lifeguard 13y agoNo. But it is also hard to trust a frozen OS. How often should one refresh the ISO?
- AJ007 13y agoEven if your OS is out of date: 1 - Malware should be purged on shut down 2 - Only specific sites are accessed, e.g. banking domains, minimizing the risk of picking something up through e-mail or careless browsing. 3 - Obviously you shouldn't be running a server. 4 - You should still practice safe browsing, being aware of packet injection via public WiFi. If you are being specifically targeted, that is another issue.
- Asterick6 13y agoAlso, you shouldn't even be using md5 anyways. It's essentially broken and has serious vulnerabilities. Use sha2 or sha3.
- Wingman4l7 13y agoThat's what I get for being specific. >.< My point was that it's unlikely that you're dealing with malware so sophisticated that it can successfully corrupt any given OS disk image and/or fake-out a checksum verification on same -- and if it can, you're probably screwed anyway.
- jlgaddis 13y ago> That's what I get for being specific. That's one little thing about HN -- most people are so literal, completely missing the point. I'm sure that it's not (yet) possible to do that, although that would be a huge breakthrough. Imagine malware that could detect what (OS) is on the ISO image and inject itself into the files inside the ISO stealthily... all at run-time when you click the "burn this ISO to this CD" button. Yeah, we'd just be screwed at that point.
- dinkumthinkum 13y agoYeah but if you go this far, how could you ever trust the bank's security?
- SmokyBorbon 13y agoA Linux boot CD would be secure but I think it's awkward to have to reboot your computer all the time. I use Linux but I have stopped using my computer for anything like banking. Instead, I use my bank's app on my iPhone or iPad neither of which are jailbroken.
- gcb0 13y agoJust hope you never open the wrong PDF... Or hope that the app is using SSL correct.... Or, nah, forget it. too much hope goes on in using a closed source from a company that does not disclose nothing. thank you.
- al1x 13y agoOr break down and invest in a VMWare license, and run everything (_everything_) in a virtual machine.
- spindritf 13y agoYou can get that for free and designed for security: http://qubes-os.org/trac http://qubes-os.org/trac
- unimpressive 13y agoI tried to find an article about an attack against virtualization that used some CPU trickery to spy on everything the host computer was doing. (Including other virtual machines on the same host.) Sadly I couldn't. So here are all the tabs I opened during my search instead. http://www.kb.cert.org/vuls/id/649219 http://www.kb.cert.org/vuls/id/649219 https://www.scmagazineus.com/Altor-Networks-Altor-VF/Review/3009/ https://www.scmagazineus.com/Altor-Networks-Altor-VF/Review/... https://www.juniper.net/us/en/products-services/software/security/vgw-series/ https://www.juniper.net/us/en/products-services/software/sec... http://news.cnet.com/8301-13846_3-10395695-62.html?tag=mncol;title http://news.cnet.com/8301-13846_3-10395695-62.html?tag=mncol... http://www.itworld.com/security/80289/securing-your-virtual-environment http://www.itworld.com/security/80289/securing-your-virtual-... http://www.symantec.com/connect/blogs/infographic-what-small-businesses-should-know-about-virtualization-security http://www.symantec.com/connect/blogs/infographic-what-small... A quick look at these shows them to be wholly not what I'm looking for. (And wholly unfit for HN I might add, which is where I got them.) If anyone out there has a link to the vulnerability I'm thinking of (it was on HN at one point), or useful information on securing virtual machines against breakout malware, that would be awesome.
- socillion 13y agoThis one? http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-privilege-escalation/ http://blog.xen.org/index.php/2012/06/13/the-intel-sysret-pr... http://www.vupen.com/blog/20120904.Advanced_Exploitation_of_Xen_Sysret_VM_Escape_CVE-2012-0217.php http://www.vupen.com/blog/20120904.Advanced_Exploitation_of_... Exploits are developed to break VMs, just like everything else, and are promptly patched once revealed. Apart from general intrusion detection tools, I think you would be hard pressed to find anything to guard against them. Maybe run a VM inside another VM ;)
- reeses 13y agoMake sure the media don't come with a little surprise. :-)