Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.arch.embedded > #13969
| From | Herbert Kleebauer <klee@unibwm.de> |
|---|---|
| Newsgroups | comp.arch.embedded |
| Subject | Re: OT: Inhibiting persistent changes to a workstation |
| Date | 2013-09-29 10:50 +0200 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <l28ppi$u53$1@speranza.aioe.org> (permalink) |
| References | <l25gll$vdb$1@speranza.aioe.org> <Mox1u.1296$zx5.1094@fx27.am4> <l27odq$nbk$1@speranza.aioe.org> |
On 29.09.2013 01:23, Don Y wrote: >>> So, I'm looking for something that will "discard" any changes >>> made to a system (W7) after a login session terminates. >> >> Run their session in a virtual machine? Either without >> write access, or so the VM files are re-created after >> logout? > > I think that would be harder to set up and maintain. > > I figure there is (must be?) a market for the sort of > "sandbox the session" products. I would like to see a hardware solution because no software is bug free. And because you think you are save, you are more careless and then you maybe are more unsafe than without the software solution. Would be happy to pay the extra money for a "secure system disk". A "secure hard disk" is a disk which installs with only half of it's physical size. In normal mode this first half can be use like a normal disk. In save mode, read is done from the first half (even heads) but writes goes to the second half (odd heads). If a sector is written in the second half, further reads of this sector are done from the second half instead of the first half (until the next power up, which resets the tag RAM). This way a virus never could infect the system disk (but only data disks, which isn't a big problem), everything it does is gone after then next power up. The only additional hardware needed within the disk would be a tag ram (128 Mbyte for a 1000 Gbyte disk) and a connector for an external button to enter "normal mode" when pressed during power on. Anything else would just be a firmware modification. From the PC hardware/software side the disk works like any normal hard disk. You can use it for the swap file, write to the registry and anything else. There is no way to find out from the PC side, that there is a "secure hard disk" attached instead of a normal disk. But after a new power on, any changes are lost and the disk is reset to it's frozen state. This happens only with a power on and not a reset, because Windows must be able to restart without loosing the modifications done to the hard disk. And if you need to make persistent changes, disconnect from the net, power on the PC with the hard disk in normal mode, make your changes (new software, Windows update, ...) and then restart the system in secure mode. The only penalty of such a secure hard disk is, that you only get half of the size for your money. But I'm sure most of the PC users wouldn't care to have only a 500 Gbyte system disk instead of 1000 Gbyte disk when in the return they get an absolutely save system which no virus or trojan can infect. And there is also a big advantage for the disk manufacturer, because then there are always two disks in a PC, the secure system disk and an additional data disk.
Back to comp.arch.embedded | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 19:59 -0700
Re: OT: Inhibiting persistent changes to a workstation Daniel Pitts <newsgroup.nospam@virtualinfinity.net> - 2013-09-27 21:46 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-27 23:01 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 02:25 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:21 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:31 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:21 -0700
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-29 01:47 -0500
Re: Inhibiting persistent changes to a workstation "Tim Williams" <tmoranwms@charter.net> - 2013-09-28 12:33 -0500
Re: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:27 -0700
Re: OT: Inhibiting persistent changes to a workstation Tom Gardner <spamjunk@blueyonder.co.uk> - 2013-09-28 10:34 +0100
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:23 -0700
Re: OT: Inhibiting persistent changes to a workstation Herbert Kleebauer <klee@unibwm.de> - 2013-09-29 10:50 +0200
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 09:15 -0700
Re: OT: Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 04:00 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:29 -0700
Re: OT: Inhibiting persistent changes to a workstation mike <ham789@netzero.net> - 2013-09-28 13:15 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 13:20 -0700
Re: OT: Inhibiting persistent changes to a workstation Paul <paul@pcserviceselectronics.co.uk> - 2013-09-28 23:07 +0100
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 15:41 -0700
Re: OT: Inhibiting persistent changes to a workstation Rich Webb <webb.ra@example.net> - 2013-09-28 09:56 -0400
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 09:32 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:58 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:35 -0700
Re: OT: Inhibiting persistent changes to a workstation Spehro Pefhany <speffSNIP@interlogDOTyou.knowwhat> - 2013-09-28 20:12 -0400
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:09 -0700
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-29 11:24 -0400
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-30 10:24 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-30 12:11 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-10-01 00:12 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-10-01 17:37 -0700
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-10-02 15:32 -0400
Re: OT: Inhibiting persistent changes to a workstation krw@attt.bizz - 2013-09-30 19:39 -0400
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:33 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 09:37 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 16:38 -0700
Re: OT: Inhibiting persistent changes to a workstation Jeff Liebermann <jeffl@cruzio.com> - 2013-09-28 18:30 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-28 18:39 -0700
Re: OT: Inhibiting persistent changes to a workstation David Brown <david.brown@removethis.hesbynett.no> - 2013-09-29 23:13 +0200
Re: OT: Inhibiting persistent changes to a workstation Don Y <this@isnotme.com> - 2013-09-29 15:43 -0700
Re: OT: Inhibiting persistent changes to a workstation Don Y <This.is@not.Me> - 2013-11-17 01:06 -0700
csiph-web