1 |
James wrote: |
2 |
> Dale <rdalek1967 <at> gmail.com> writes: |
3 |
> |
4 |
> |
5 |
>>> Blueness has created a 'tin hat' [1] mini secure linux distro that runs |
6 |
>>> in all ram for the truely paranoid (or those with valid security features). |
7 |
>>> You can just boot up with tinhat or Pentoo and use the live version |
8 |
>>> for sensitive transactional types of events...... There is also, bluedragon |
9 |
>>> and lilblue, all excellent, reasonably secure systems to testdrive. |
10 |
>>> Also, you may want to see if 'www-client/xombrero' meets your needs. |
11 |
>>> I have not had time to implement it, so it's on my todo list to evaluate. |
12 |
>>> [1] http://opensource.dyc.edu/tinhat |
13 |
>> Only thing is, I access my bank pretty much daily. To use that would |
14 |
>> require a reboot and booting from USB/DVD etc. I rarely reboot. |
15 |
>> Generally, I reboot when I lose power and have to shutdown. So far, I |
16 |
>> haven't rebooted in 182 days. In a little over a week, I'll have a new |
17 |
>> record. Well, documented record for this rig anyway. |
18 |
> |
19 |
> |
20 |
> OK, then the solution, which is not in my current expertise, is to run |
21 |
> something secure in a VM or a container from your workstation. Since tinhat |
22 |
> is an "in-ram' solution that would work. I sure there are secure, |
23 |
> gentoo-hardeded images for a VM or container, just look around. One of the |
24 |
> gentoo security/container/vm channels may provide faster expertise on this |
25 |
> route. |
26 |
> |
27 |
> Or get an embedded board (should be less than $50) with hdmi, usb |
28 |
> (mouse/keyboard) and ethernet, that has a secure distro avalilable for it. |
29 |
> Perhaps some of Rasp. Pi3 or this one [1]. With gentoo-hardened, I'd cobble |
30 |
> together a second system, before munging up your current gentoo workstation. |
31 |
> Be sure that the secure OS you want to run, is already well supported before |
32 |
> you choose an embedded board. Apline linux shines here too, as it uses musl |
33 |
> (libc) and is security oriented. |
34 |
> |
35 |
> |
36 |
> Did you read up on Xombrero? There are many choices, finding the least |
37 |
> time-consuming option that meets your needs requires lots of time. |
38 |
> ;-) |
39 |
> |
40 |
> |
41 |
> hth, |
42 |
> James |
43 |
> |
44 |
> |
45 |
> [1] |
46 |
> http://www.cnx-software.com/2016/02/29/odroid-c2-64-bit-arm-development-board-is-now-available-for-purchase-for-40/ |
47 |
> |
48 |
> |
49 |
> |
50 |
|
51 |
|
52 |
My biggest curiosity at the start of this was if using VPN would help. |
53 |
Given that so much of the security stuff has been hacked by Govt types, |
54 |
and no telling who else, I was just curious on what VPN would offer. |
55 |
I'm not really looking into USB/DVD rebooting and such. My hope was |
56 |
that places such as my bank and other financial sites would benefit from |
57 |
this. Since none of them are likely to use this anyway, I'll just have |
58 |
to hope they are doing enough. Plus, if someone hacks in, it's on them |
59 |
anyway. My bank has that no frills warranty. |
60 |
|
61 |
I might add, I've never used anything but Linux since 2003 when I built |
62 |
my first puter. So far, I've yet to have anything hacked. I haven't |
63 |
even had the likes of Facebook or anything hacked. I've heard of lots |
64 |
of other folks having theirs hacked but I've never had it happen to me. |
65 |
I use pretty good passwords and started using Lastpass which means even |
66 |
stronger passwords. So far, it's working. |
67 |
|
68 |
Running a VM is not my expertise either. I read about them sometimes |
69 |
but never used or even seen one. It does make me curious tho. To me, |
70 |
it sounds like a install on top of a install but the one on the inside |
71 |
can't touch the main one. Something like that anyway. If I had to |
72 |
describe it to someone familiar with Gentoo, sort of like a chroot type |
73 |
thing with some extras built in. |
74 |
|
75 |
Still, using Linux is likely the biggest bonus. ;-) |
76 |
|
77 |
Dale |
78 |
|
79 |
:-) :-) |