LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-24-2010, 06:12 PM   #1
lugoteehalt
Senior Member
 
Registered: Sep 2003
Location: UK
Distribution: Debian
Posts: 1,215
Blog Entries: 2

Rep: Reputation: 49
Is a live CD the safest thing for doing b*nking?


Want to know if using a live CD, say Knoppix, gives a good level of protection when moving money about? I am very unsophisticated on the subject of security.

This question has been addressed before on this site
Code:
if you have enough RAM you can ignore your local disks all together, and avoid the security risk of a swap file
How you do that then?

Perhaps it would be better to use an operating system inside the software computer, virtual box, that only ever gets used for this b*nking purpose?

Thanks any help. I'm not the greatest intellectual on the planet - this security stuff is a bit over-awing.
 
Old 06-24-2010, 06:35 PM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
Why are you censoring "banking"?
 
Old 06-24-2010, 06:39 PM   #3
lugoteehalt
Senior Member
 
Registered: Sep 2003
Location: UK
Distribution: Debian
Posts: 1,215

Original Poster
Blog Entries: 2

Rep: Reputation: 49
Quote:
Originally Posted by AlucardZero View Post
Why are you censoring "banking"?
I'm paranoid, I thought some scum bag (or douche bag - incidentally, if you are an American, what is a "douche bag"?) might search up banking and target me.
 
Old 06-24-2010, 06:44 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by lugoteehalt View Post
if you are an American, what is a "douche bag"?
Just google it, please. No need to get into that here. Thanks.
 
Old 06-24-2010, 07:00 PM   #5
lugoteehalt
Senior Member
 
Registered: Sep 2003
Location: UK
Distribution: Debian
Posts: 1,215

Original Poster
Blog Entries: 2

Rep: Reputation: 49
Quote:
Originally Posted by win32sux View Post
Just google it, please. No need to get into that here. Thanks.
Quote:
Device used to administer a douche
So that's solved then. Let's get back on topic.
 
Old 06-25-2010, 12:30 PM   #6
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by lugoteehalt
I'm paranoid, I thought some scum bag... might search up banking and target me.
This seems unlikely. If you're of the financial means to attract this level of attention, I recommend that you physically sit down with your bank manager and come up with a solution that you're comfortable with. It may mean disabling all online bank account access, telephone system access, etc.

Last edited by anomie; 06-25-2010 at 12:32 PM.
 
Old 06-25-2010, 08:16 PM   #7
lugoteehalt
Senior Member
 
Registered: Sep 2003
Location: UK
Distribution: Debian
Posts: 1,215

Original Poster
Blog Entries: 2

Rep: Reputation: 49
Quote:
Originally Posted by anomie View Post
This seems unlikely. If you're of the financial means to attract this level of attention, I recommend that you physically sit down with your bank manager and come up with a solution that you're comfortable with. It may mean disabling all online bank account access, telephone system access, etc.
Thanks. I do not have great financial means but, very probably foolishly, most of them are on line. This gets me nervous.

Might a solution be to put them off line. Then using a Knoppix live CD put them on line. Do the transaction. Then take them off line again. All under the live Knoppix CD. ??

I know bugger all about this stuff, thought someone might know.
 
Old 06-27-2010, 07:04 AM   #8
lupusarcanus
Senior Member
 
Registered: Mar 2009
Location: USA
Distribution: Arch
Posts: 1,022
Blog Entries: 19

Rep: Reputation: 146Reputation: 146
NO.

A live CD CANNOT get valuable security updates to the browser or the kernel or anything. Your stuck with whats on the CD and if a key security exploit is discovered you are in trouble.
 
1 members found this post helpful.
Old 06-28-2010, 11:16 AM   #9
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by lugoteehalt
Might a solution be to put them off line. Then using a Knoppix live CD put them on line. Do the transaction. Then take them off line again. All under the live Knoppix CD. ??
I'm not sure your banking institution would be amenable to that level of overhead.

If you need to perform banking transactions online, my recommendation would be to set up a Linux workstation / laptop for that purpose.
  • Keep it up to date.
  • Throw up a host-level firewall and deny all inbound traffic.
  • Bookmark your financial URLs.
  • Install Noscript, and allow only needed sites.
  • Pay attention to SSL warnings.
  • Don't use the banking box for anything but online banking.

IMO, that (along with common sense diligence) is sufficient for us middle-classers.

Last edited by anomie; 06-28-2010 at 11:17 AM.
 
1 members found this post helpful.
Old 07-13-2010, 11:01 PM   #10
kellyapproved
LQ Newbie
 
Registered: Jul 2010
Posts: 19

Rep: Reputation: 0
Quote:
Originally Posted by anomie View Post
If you need to perform banking transactions online, my recommendation would be to set up a Linux workstation / laptop for that purpose.
  • Keep it up to date.
  • Throw up a host-level firewall and deny all inbound traffic.
  • Bookmark your financial URLs.
  • Install Noscript, and allow only needed sites.
  • Pay attention to SSL warnings.
  • Don't use the banking box for anything but online banking.
I really don't understand this, I've posted similar questions about security and was under the impression that security is not an issue so long as you don't run root. Many replies also came back about people not using even a firewall.

That said, do you really need to go noscript and have a firewall?
 
Old 07-14-2010, 12:38 AM   #11
jtarin
Member
 
Registered: May 2010
Location: Vladivostok, Russia
Distribution: LinuxMint 17
Posts: 104

Rep: Reputation: 23
Quote:
Originally Posted by kellyapproved View Post
I really don't understand this, I've posted similar questions about security and was under the impression that security is not an issue so long as you don't run root. Many replies also came back about people not using even a firewall.

That said, do you really need to go noscript and have a firewall?
I believe he is trying to adjust your approach to your level of paranoia.You can do the level that makes you feel comfortable. My only concern about on-line banking is browser security and misleading websites.
 
Old 07-14-2010, 12:56 AM   #12
aeyeaws
LQ Newbie
 
Registered: May 2003
Location: south of Savannah Ga
Distribution: gentoo & the PARTITION DESTROYER FreeBsd
Posts: 6

Rep: Reputation: 0
dood , your only liable for pennies , your bank eats it as long as you notify them in a reasonable amount of time, same as credit card fraud..

Last edited by aeyeaws; 07-14-2010 at 01:01 AM.
 
Old 07-14-2010, 02:48 AM   #13
betula
Member
 
Registered: Aug 2008
Posts: 166

Rep: Reputation: 15
I believe that the OP is right to be concerned about online security. A friend of mine had his banking account raided and, although he eventually got his money back from the bank, it was a real hassle.

If I remember rightly, my friend had to show that his computer security was okay before the bank would do anything and in the interim he didn't have any money in his account to conduct his normal daily affairs.

It sounds to me that kellyapproved has the right idea though I must confess that I don't know what noscript is.
 
Old 07-14-2010, 05:03 AM   #14
rsciw
Member
 
Registered: Jan 2009
Location: Essex (UK)
Distribution: Home: Debian/Ubuntu, Work: Ubuntu
Posts: 206

Rep: Reputation: 44
http://noscript.net/

plugin for firefox to block javascript/flash, etc.
quite handy, and definitely recommended!
 
Old 07-14-2010, 09:42 AM   #15
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by kellyapproved
I really don't understand this, I've posted similar questions about security and was under the impression that security is not an issue so long as you don't run root.
Security "not an issue"? That's silly. Not running as root addresses numerous attack vectors, but there are plenty it does not.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Some thing wrong with downloaded live cd bhuvanbats Fedora 5 01-25-2010 12:21 AM
safest way to upgrade glibc? samengr Linux - Enterprise 9 03-03-2009 01:18 AM
Safest way for remote X access wild_oscar Linux - Security 2 03-19-2007 05:42 AM
safest way to run apache PennyroyalFrog Linux - Newbie 7 06-05-2004 10:57 AM
Best/Safest way to link folders in VSFTPD webnoelle Linux - Security 3 01-03-2004 06:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration