1 |
Steve wrote: |
2 |
> In the context of online banking, where Windows of some flavour is the |
3 |
> desktop OS, I see a substantial risk arising through spyware and/or |
4 |
> viruses. I suspect that a neat way to mitigate this would be to run an |
5 |
> OS from a CD which offers nothing more fancy than a basic web-browser. |
6 |
> |
7 |
> Is there anything like this already available? |
8 |
> |
9 |
|
10 |
My preference is using a safe browser (Opera with plugins removed) on a |
11 |
QEMU/Hardened Gentoo VM - on a USB flash stick. It presents the user |
12 |
with a window in which the Linux OS boots up and in my case, presents a |
13 |
Fluxbox desktop. |
14 |
|
15 |
- The VM (actually, a qemu emulator in "virtual" mode) will start up |
16 |
without privilege - say, while on the road at a public library. |
17 |
|
18 |
- At the end of the session, there are no relics that I can find, except |
19 |
for a single, minor note in the windows registry. |
20 |
|
21 |
- The SSL connection is established within the Linux VM, so all the |
22 |
host sees is an encrypted connection to your bank. |
23 |
|
24 |
- IIUC, today's biggest banking concerns, besides pharming and phishing, |
25 |
are Trojan/Keyloggers. This kind of VM is -probably- immune from most |
26 |
kinds of spyware on the Windows host, though not hardware loggers on the |
27 |
keyboard or Terminal. Workaround is to have passwords handled |
28 |
automatically by the browser within the Linux OS - so that passwords are |
29 |
neither typed nor displayed. |
30 |
|
31 |
- Other banking concerns are pharming, DNS poisoning, and XSS attacks. |
32 |
So I go to my banking site with FireFox first, confirm that the DNS is |
33 |
correct (or do your own lookup at Sam Spade), and have NoScript confirm |
34 |
that everything is o.k. Then use Opera (safer browser) to consummate the |
35 |
transaction. |
36 |
|
37 |
- If you go this route, do a little research and get a fast and quick |
38 |
USB flash. |
39 |
|
40 |
HTH |
41 |
|
42 |
|
43 |
|
44 |
|
45 |
-- |
46 |
gentoo-user@l.g.o mailing list |