Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Firefox and VPN, plus security in generla
Date: Wed, 15 Jun 2016 21:25:20
Message-Id: loom.20160615T232409-175@post.gmane.org
In Reply to: Re: [gentoo-user] Re: Firefox and VPN, plus security in generla by Dale
1 Dale <rdalek1967 <at> gmail.com> writes:
2
3
4 > > Blueness has created a 'tin hat' [1] mini secure linux distro that runs
5 > > in all ram for the truely paranoid (or those with valid security features).
6 > > You can just boot up with tinhat or Pentoo and use the live version
7 > > for sensitive transactional types of events...... There is also, bluedragon
8 > > and lilblue, all excellent, reasonably secure systems to testdrive.
9
10 > > Also, you may want to see if 'www-client/xombrero' meets your needs.
11 > > I have not had time to implement it, so it's on my todo list to evaluate.
12
13 > > [1] http://opensource.dyc.edu/tinhat
14
15 > Only thing is, I access my bank pretty much daily. To use that would
16 > require a reboot and booting from USB/DVD etc. I rarely reboot.
17 > Generally, I reboot when I lose power and have to shutdown. So far, I
18 > haven't rebooted in 182 days. In a little over a week, I'll have a new
19 > record. Well, documented record for this rig anyway.
20
21
22
23 OK, then the solution, which is not in my current expertise, is to run
24 something secure in a VM or a container from your workstation. Since tinhat
25 is an "in-ram' solution that would work. I sure there are secure,
26 gentoo-hardeded images for a VM or container, just look around. One of the
27 gentoo security/container/vm channels may provide faster expertise on this
28 route.
29
30 Or get an embedded board (should be less than $50) with hdmi, usb
31 (mouse/keyboard) and ethernet, that has a secure distro avalilable for it.
32 Perhaps some of Rasp. Pi3 or this one [1]. With gentoo-hardened, I'd cobble
33 together a second system, before munging up your current gentoo workstation.
34 Be sure that the secure OS you want to run, is already well supported before
35 you choose an embedded board. Apline linux shines here too, as it uses musl
36 (libc) and is security oriented.
37
38
39 Did you read up on Xombrero? There are many choices, finding the least
40 time-consuming option that meets your needs requires lots of time.
41 ;-)
42
43
44 hth,
45 James
46
47
48 [1]
49 http://www.cnx-software.com/2016/02/29/odroid-c2-64-bit-arm-development-board-is-now-available-for-purchase-for-40/

Replies

Subject Author
Re: [gentoo-user] Re: Firefox and VPN, plus security in generla Dale <rdalek1967@×××××.com>