Security Basics mailing list archives

Re: Secure Internet Browsing


From: "Liam Jewell" <ljjewell () gmail com>
Date: Thu, 17 Jan 2008 10:28:52 -0500

While Anonym.OS hasn't been maintained for a while now, it still works.

Additionally if you were looking for an option that was Windows
compliant and didn't require a live cd, I wrote an article about
browsing anonymously the other day:
http://www.liamjewell.com/wordpress/?p=90

Cheers!
Liam

On Jan 10, 2008 2:01 PM, Shamanovsky, Victor (x2035)
<vshamanovsky () pbwt com> wrote:
Check out - http://en.wikipedia.org/wiki/Anonym.OS



-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Orlin Gueorguiev
Sent: Wednesday, January 09, 2008 11:38 AM
To: security-basics () securityfocus com
Subject: Re: Secure Internet Browsing

If you need a computer for only browzing, you can just use a live cd(whitout
mounting a hdd). This will however mean, that you will be unable to save any
information on the hard disk. However you can save it on an online storage or
better: usb. If you use an encrypted file system on this device and not
allowed executing files from the usb, more of your problems should be out.
Every restart of the system will trow you to a secure enviroment.
The first Live CD was Knoppix, not a bad distro. Almoast every Linux distro
has a live cd... check what programs (and versions) come on those cds and if
not setisfied, try this:
http://gentoo-wiki.com/HOWTO_Gentoo_LiveCD_and_LiveUSB

Regards,
Orlin

На Wednesday 26 December 2007 17:08:04 Rodrigo Blanco написа:
Hello list,

these days I have been taking a look at the solution for secure
Internet browsing based on VMWare player + Browser Appliance (Ubuntu
virtual image running firefox). I especially like three things of it:
apprently more resistant to virus / spyware / malware, browser does
not run with admin / root privileges and the auto-revert feature, that
will automatically revert the machine to its original state, no matter
what visited sites have added (cookies, malware...) to the client.

I had already heard of other solutions, more suitable for corporate
environments, such as a Citrix-based IE browser, on a machine that is
re-built everyday (maybe through some virtualization solution) so that
any infection is automatically eliminated daily.

While these solutions will help prevent against spyware, malware and
viruses, I still have the feeling they still would be vulnerable to
keyloggers or resident programs able to capture mouse / GUI events.
I.e. if the machine running the VMPlayer has a keylogger running, it
would still be able to capture keystrokes sent to the Browser
Appliance virtual machine.

What is your opinion? Do you know of solutions that will provide a
"reasonably complete" security for browsing? Are they suitable for
both home and corporate environments?

Thanks for any comments and kind regards,
Rodrigo.




----------------------------------------------
Privileged/Confidential Information may be contained in this message.  If you are not
the addressee indicated in this message (or responsible for delivery of the message to
such person), you may not copy or deliver this message to anyone.  In such case, you
should destroy this message and kindly notify the sender by reply email.  Please advise
immediately if you or your employer do not consent to Internet email for messages of this
kind.

----------------------------------------------

IRS Circular 230 disclosure:  Any tax advice contained in this communication (including
any attachments or enclosures) was not intended or written to be used, and cannot be
used, for the purpose of (i) avoiding penalties under the Internal Revenue Code or (ii)
promoting, marketing or recommending to another party any transaction or matter addressed
in this communication.  (The foregoing disclaimer has been affixed pursuant to U.S.
Treasury regulations governing tax practitioners.)

==============================================================================

Current thread: