Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.arch.embedded > #13975

Re: OT: Inhibiting persistent changes to a workstation

From Don Y <this@isnotme.com>
Newsgroups comp.arch.embedded
Subject Re: OT: Inhibiting persistent changes to a workstation
Date 2013-09-29 09:15 -0700
Organization Aioe.org NNTP Server
Message-ID <l29jnc$8ln$1@speranza.aioe.org> (permalink)
References <l25gll$vdb$1@speranza.aioe.org> <Mox1u.1296$zx5.1094@fx27.am4> <l27odq$nbk$1@speranza.aioe.org> <l28ppi$u53$1@speranza.aioe.org>

Show all headers | View raw


Hi Herbert,

On 9/29/2013 1:50 AM, Herbert Kleebauer wrote:
> On 29.09.2013 01:23, Don Y wrote:
>
>>>> So, I'm looking for something that will "discard" any changes
>>>> made to a system (W7) after a login session terminates.
>>>
>>> Run their session in a virtual machine? Either without
>>> write access, or so the VM files are re-created after
>>> logout?
>>
>> I think that would be harder to set up and maintain.
>>
>> I figure there is (must be?) a market for the sort of
>> "sandbox the session" products.
>
> I would like to see a hardware solution because no software
> is bug free.

So, even the "hardware solution" could contain no software?
Even if parts of it were *designed* using "non-bug free"
software *tools*?

[EXPECT software to contain bugs and it *will* contain bugs!]

> And because you think you are save, you are
> more careless and then you maybe are more unsafe than without
> the software solution. Would be happy to pay the extra
> money for a "secure system disk".
>
> A "secure hard disk" is a disk which installs with only
> half of it's physical size. In normal mode this first
> half can be use like a normal disk. In save mode, read is
> done from the first half (even heads) but writes goes to the
> second half (odd heads). If a sector is written in the second
> half, further reads of this sector are done from the second
> half instead of the first half (until the next power up,
> which resets the tag RAM). This way a virus never could infect
> the system disk (but only data disks, which isn't a big problem),
> everything it does is gone after then next power up.
>
> The only additional hardware needed within the disk would be
> a tag ram (128 Mbyte for a 1000 Gbyte disk) and a connector for
> an external button to enter "normal mode" when pressed during
> power on. Anything else would just be a firmware modification.
>
> From the PC hardware/software side the disk works like any normal
> hard disk. You can use it for the swap file, write to the registry and
> anything else. There is no way to find out from the PC side,
> that there is a "secure hard disk" attached instead of a normal disk.
> But after a new power on, any changes are lost and the disk is
> reset to it's frozen state. This happens only with a power on
> and not a reset, because Windows must be able to restart without
> loosing the modifications done to the hard disk. And if you need
> to make persistent changes, disconnect from the net, power on
> the PC with the hard disk in normal mode, make your changes (new
> software, Windows update, ...) and then restart the system in
> secure mode.

You should be able to do this as a stand-alone box that sits *between*
a disk and its controller.  That should allow you to test if the
idea really *can* work.  (because such a disk would not want to
*rely* on a particular OS being in use)

How do you handle the disk cache that is invariably present in
the OS?

> The only penalty of such a secure hard disk is, that you
> only get half of the size for your money. But I'm sure most
> of the PC users wouldn't care to have only a 500 Gbyte system
> disk instead of 1000 Gbyte disk when in the return they get
> an absolutely save system which no virus or trojan can infect.
> And there is also a big advantage for the disk manufacturer,
> because then there are always two disks in a PC, the secure
> system disk and an additional data disk.

Back to comp.arch.embedded | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 19:59 -0700
  Re: OT:  Inhibiting persistent changes to a workstation Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2013-09-27 21:46 -0700
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 23:01 -0700
  Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 02:25 -0500
    Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:21 -0700
      Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:31 -0500
        Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:21 -0700
          Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-29 01:47 -0500
      Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:33 -0500
        Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:27 -0700
  Re: OT:  Inhibiting persistent changes to a workstation Tom Gardner <spamjunk@blueyonder.co.uk> - 2013-09-28 10:34 +0100
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:23 -0700
      Re: OT:  Inhibiting persistent changes to a workstation Herbert Kleebauer <klee@unibwm.de> - 2013-09-29 10:50 +0200
        Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 09:15 -0700
  Re: OT:  Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 04:00 -0700
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:29 -0700
      Re: OT:  Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 13:15 -0700
        Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:20 -0700
          Re: OT:  Inhibiting persistent changes to a workstation Paul <paul@pcserviceselectronics.co.uk> - 2013-09-28 23:07 +0100
            Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 15:41 -0700
  Re: OT:  Inhibiting persistent changes to a workstation Rich Webb <webb.ra@example.net> - 2013-09-28 09:56 -0400
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:32 -0700
      Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:58 -0700
        Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:35 -0700
        Re: OT:  Inhibiting persistent changes to a workstation Spehro Pefhany <speffSNIP@interlogDOTyou.knowwhat> - 2013-09-28 20:12 -0400
          Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:09 -0700
            Re: OT:  Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-29 11:24 -0400
              Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-30 10:24 -0700
                Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-30 12:11 -0700
                Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-10-01 00:12 -0700
                Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-10-01 17:37 -0700
                Re: OT:  Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-10-02 15:32 -0400
                Re: OT:  Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-30 19:39 -0400
          Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:33 -0700
  Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:37 -0700
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:38 -0700
      Re: OT:  Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:30 -0700
        Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:39 -0700
  Re: OT:  Inhibiting persistent changes to a workstation David Brown <david.brown@removethis.hesbynett.no> - 2013-09-29 23:13 +0200
    Re: OT:  Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 15:43 -0700
  Re: OT:  Inhibiting persistent changes to a workstation Don Y <This.is@not.Me> - 2013-11-17 01:06 -0700

csiph-web