1 |
Dale <rdalek1967 <at> gmail.com> writes: |
2 |
|
3 |
|
4 |
> > Blueness has created a 'tin hat' [1] mini secure linux distro that runs |
5 |
> > in all ram for the truely paranoid (or those with valid security features). |
6 |
> > You can just boot up with tinhat or Pentoo and use the live version |
7 |
> > for sensitive transactional types of events...... There is also, bluedragon |
8 |
> > and lilblue, all excellent, reasonably secure systems to testdrive. |
9 |
|
10 |
> > Also, you may want to see if 'www-client/xombrero' meets your needs. |
11 |
> > I have not had time to implement it, so it's on my todo list to evaluate. |
12 |
|
13 |
> > [1] http://opensource.dyc.edu/tinhat |
14 |
|
15 |
> Only thing is, I access my bank pretty much daily. To use that would |
16 |
> require a reboot and booting from USB/DVD etc. I rarely reboot. |
17 |
> Generally, I reboot when I lose power and have to shutdown. So far, I |
18 |
> haven't rebooted in 182 days. In a little over a week, I'll have a new |
19 |
> record. Well, documented record for this rig anyway. |
20 |
|
21 |
|
22 |
|
23 |
OK, then the solution, which is not in my current expertise, is to run |
24 |
something secure in a VM or a container from your workstation. Since tinhat |
25 |
is an "in-ram' solution that would work. I sure there are secure, |
26 |
gentoo-hardeded images for a VM or container, just look around. One of the |
27 |
gentoo security/container/vm channels may provide faster expertise on this |
28 |
route. |
29 |
|
30 |
Or get an embedded board (should be less than $50) with hdmi, usb |
31 |
(mouse/keyboard) and ethernet, that has a secure distro avalilable for it. |
32 |
Perhaps some of Rasp. Pi3 or this one [1]. With gentoo-hardened, I'd cobble |
33 |
together a second system, before munging up your current gentoo workstation. |
34 |
Be sure that the secure OS you want to run, is already well supported before |
35 |
you choose an embedded board. Apline linux shines here too, as it uses musl |
36 |
(libc) and is security oriented. |
37 |
|
38 |
|
39 |
Did you read up on Xombrero? There are many choices, finding the least |
40 |
time-consuming option that meets your needs requires lots of time. |
41 |
;-) |
42 |
|
43 |
|
44 |
hth, |
45 |
James |
46 |
|
47 |
|
48 |
[1] |
49 |
http://www.cnx-software.com/2016/02/29/odroid-c2-64-bit-arm-development-board-is-now-available-for-purchase-for-40/ |