Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Firefox and VPN, plus security in generla
Date: Wed, 15 Jun 2016 22:17:01
Message-Id: 5761D3CB.60302@gmail.com
In Reply to: [gentoo-user] Re: Firefox and VPN, plus security in generla by James
1 James wrote:
2 > Dale <rdalek1967 <at> gmail.com> writes:
3 >
4 >
5 >>> Blueness has created a 'tin hat' [1] mini secure linux distro that runs
6 >>> in all ram for the truely paranoid (or those with valid security features).
7 >>> You can just boot up with tinhat or Pentoo and use the live version
8 >>> for sensitive transactional types of events...... There is also, bluedragon
9 >>> and lilblue, all excellent, reasonably secure systems to testdrive.
10 >>> Also, you may want to see if 'www-client/xombrero' meets your needs.
11 >>> I have not had time to implement it, so it's on my todo list to evaluate.
12 >>> [1] http://opensource.dyc.edu/tinhat
13 >> Only thing is, I access my bank pretty much daily. To use that would
14 >> require a reboot and booting from USB/DVD etc. I rarely reboot.
15 >> Generally, I reboot when I lose power and have to shutdown. So far, I
16 >> haven't rebooted in 182 days. In a little over a week, I'll have a new
17 >> record. Well, documented record for this rig anyway.
18 >
19 >
20 > OK, then the solution, which is not in my current expertise, is to run
21 > something secure in a VM or a container from your workstation. Since tinhat
22 > is an "in-ram' solution that would work. I sure there are secure,
23 > gentoo-hardeded images for a VM or container, just look around. One of the
24 > gentoo security/container/vm channels may provide faster expertise on this
25 > route.
26 >
27 > Or get an embedded board (should be less than $50) with hdmi, usb
28 > (mouse/keyboard) and ethernet, that has a secure distro avalilable for it.
29 > Perhaps some of Rasp. Pi3 or this one [1]. With gentoo-hardened, I'd cobble
30 > together a second system, before munging up your current gentoo workstation.
31 > Be sure that the secure OS you want to run, is already well supported before
32 > you choose an embedded board. Apline linux shines here too, as it uses musl
33 > (libc) and is security oriented.
34 >
35 >
36 > Did you read up on Xombrero? There are many choices, finding the least
37 > time-consuming option that meets your needs requires lots of time.
38 > ;-)
39 >
40 >
41 > hth,
42 > James
43 >
44 >
45 > [1]
46 > http://www.cnx-software.com/2016/02/29/odroid-c2-64-bit-arm-development-board-is-now-available-for-purchase-for-40/
47 >
48 >
49 >
50
51
52 My biggest curiosity at the start of this was if using VPN would help.
53 Given that so much of the security stuff has been hacked by Govt types,
54 and no telling who else, I was just curious on what VPN would offer.
55 I'm not really looking into USB/DVD rebooting and such. My hope was
56 that places such as my bank and other financial sites would benefit from
57 this. Since none of them are likely to use this anyway, I'll just have
58 to hope they are doing enough. Plus, if someone hacks in, it's on them
59 anyway. My bank has that no frills warranty.
60
61 I might add, I've never used anything but Linux since 2003 when I built
62 my first puter. So far, I've yet to have anything hacked. I haven't
63 even had the likes of Facebook or anything hacked. I've heard of lots
64 of other folks having theirs hacked but I've never had it happen to me.
65 I use pretty good passwords and started using Lastpass which means even
66 stronger passwords. So far, it's working.
67
68 Running a VM is not my expertise either. I read about them sometimes
69 but never used or even seen one. It does make me curious tho. To me,
70 it sounds like a install on top of a install but the one on the inside
71 can't touch the main one. Something like that anyway. If I had to
72 describe it to someone familiar with Gentoo, sort of like a chroot type
73 thing with some extras built in.
74
75 Still, using Linux is likely the biggest bonus. ;-)
76
77 Dale
78
79 :-) :-)

Replies

Subject Author
[gentoo-user] Re: Firefox and VPN, plus security in generla James <wireless@×××××××××××.com>