Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.arch.embedded > #13975
| From | Don Y <this@isnotme.com> |
|---|---|
| Newsgroups | comp.arch.embedded |
| Subject | Re: OT: Inhibiting persistent changes to a workstation |
| Date | 2013-09-29 09:15 -0700 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <l29jnc$8ln$1@speranza.aioe.org> (permalink) |
| References | <l25gll$vdb$1@speranza.aioe.org> <Mox1u.1296$zx5.1094@fx27.am4> <l27odq$nbk$1@speranza.aioe.org> <l28ppi$u53$1@speranza.aioe.org> |
Hi Herbert, On 9/29/2013 1:50 AM, Herbert Kleebauer wrote: > On 29.09.2013 01:23, Don Y wrote: > >>>> So, I'm looking for something that will "discard" any changes >>>> made to a system (W7) after a login session terminates. >>> >>> Run their session in a virtual machine? Either without >>> write access, or so the VM files are re-created after >>> logout? >> >> I think that would be harder to set up and maintain. >> >> I figure there is (must be?) a market for the sort of >> "sandbox the session" products. > > I would like to see a hardware solution because no software > is bug free. So, even the "hardware solution" could contain no software? Even if parts of it were *designed* using "non-bug free" software *tools*? [EXPECT software to contain bugs and it *will* contain bugs!] > And because you think you are save, you are > more careless and then you maybe are more unsafe than without > the software solution. Would be happy to pay the extra > money for a "secure system disk". > > A "secure hard disk" is a disk which installs with only > half of it's physical size. In normal mode this first > half can be use like a normal disk. In save mode, read is > done from the first half (even heads) but writes goes to the > second half (odd heads). If a sector is written in the second > half, further reads of this sector are done from the second > half instead of the first half (until the next power up, > which resets the tag RAM). This way a virus never could infect > the system disk (but only data disks, which isn't a big problem), > everything it does is gone after then next power up. > > The only additional hardware needed within the disk would be > a tag ram (128 Mbyte for a 1000 Gbyte disk) and a connector for > an external button to enter "normal mode" when pressed during > power on. Anything else would just be a firmware modification. > > From the PC hardware/software side the disk works like any normal > hard disk. You can use it for the swap file, write to the registry and > anything else. There is no way to find out from the PC side, > that there is a "secure hard disk" attached instead of a normal disk. > But after a new power on, any changes are lost and the disk is > reset to it's frozen state. This happens only with a power on > and not a reset, because Windows must be able to restart without > loosing the modifications done to the hard disk. And if you need > to make persistent changes, disconnect from the net, power on > the PC with the hard disk in normal mode, make your changes (new > software, Windows update, ...) and then restart the system in > secure mode. You should be able to do this as a stand-alone box that sits *between* a disk and its controller. That should allow you to test if the idea really *can* work. (because such a disk would not want to *rely* on a particular OS being in use) How do you handle the disk cache that is invariably present in the OS? > The only penalty of such a secure hard disk is, that you > only get half of the size for your money. But I'm sure most > of the PC users wouldn't care to have only a 500 Gbyte system > disk instead of 1000 Gbyte disk when in the return they get > an absolutely save system which no virus or trojan can infect. > And there is also a big advantage for the disk manufacturer, > because then there are always two disks in a PC, the secure > system disk and an additional data disk.
Back to comp.arch.embedded | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 19:59 -0700
Re: OT: Inhibiting persistent changes to a workstation Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2013-09-27 21:46 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 23:01 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 02:25 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:21 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:31 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:21 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-29 01:47 -0500
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:33 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:27 -0700
Re: OT: Inhibiting persistent changes to a workstation Tom Gardner <spamjunk@blueyonder.co.uk> - 2013-09-28 10:34 +0100
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:23 -0700
Re: OT: Inhibiting persistent changes to a workstation Herbert Kleebauer <klee@unibwm.de> - 2013-09-29 10:50 +0200
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 09:15 -0700
Re: OT: Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 04:00 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:29 -0700
Re: OT: Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 13:15 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:20 -0700
Re: OT: Inhibiting persistent changes to a workstation Paul <paul@pcserviceselectronics.co.uk> - 2013-09-28 23:07 +0100
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 15:41 -0700
Re: OT: Inhibiting persistent changes to a workstation Rich Webb <webb.ra@example.net> - 2013-09-28 09:56 -0400
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:32 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:58 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:35 -0700
Re: OT: Inhibiting persistent changes to a workstation Spehro Pefhany <speffSNIP@interlogDOTyou.knowwhat> - 2013-09-28 20:12 -0400
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:09 -0700
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-29 11:24 -0400
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-30 10:24 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-30 12:11 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-10-01 00:12 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-10-01 17:37 -0700
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-10-02 15:32 -0400
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-30 19:39 -0400
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:33 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:37 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:38 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:30 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:39 -0700
Re: OT: Inhibiting persistent changes to a workstation David Brown <david.brown@removethis.hesbynett.no> - 2013-09-29 23:13 +0200
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 15:43 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <This.is@not.Me> - 2013-11-17 01:06 -0700
csiph-web