Showing posts with label Security Now!. Show all posts
Showing posts with label Security Now!. Show all posts

Thursday, April 7, 2016

Crunchbang++ Linux

Not so long ago, Steve Gibson in his Security Now podcast intimated that he was looking for small sized, contained browsing experience. Thanks to his shows, I had already switched to a full-fledged virtual machine and had been happily browsing with no problem at all. However, his requirements for something that would not be too onerous resource wise kept nagging at me. I knew that Linux could do the work within a virtual machine, but the problem was finding the right distro for it. Now, I think I have found it: Crunchbang plus plus and I think I am in love.

Here's how I finally settled on it:

Started, and as many others with Linux Mint. For myself, my biggest constraint was disk space. Although fine, and useful, it took well over 10 GB. Something slimmer, had to be out there.

Swinged far to the other side and got Tiny Core Linux working, but YouTube wouldn't play with the newer flash versions. Also the mouse pointer wasn't as smooth. Similar experience with Puppy Linux which didn't support the Virtual Box additions and had way too many preinstalled programs.

Bodhi Linux, seemed like it, and has a focus on being minimalistic, letting you install your own stuff, but the Enlightenment desktop was too alien for me. And still, I guessed something smaller could exist.

Dabbled with taking snapshots of live CDs of Porteus and Lubuntu and these did work, after a fashion and might serve for specific purposes, but still the sessions wouldn't allow installing additions and rebooting and keeping it chugging from RAM seemed like counter purpose going forward.

Antix was another contender, but even changing the screen resolution from the menus was not straightforward. Also, an inserted DVD would have to be searched for manually.

Trisquel Mini was also one that worked, but for my purposes it's philosophy was more of a hindrance.

Finally Crunchbang plus plus gave me these benefits:

  • Small footprint (2.5 GB with additions and chromium already added)
  • A beauty (glass!)
  • Based on Debian, whose terminal commands I'm more familiar with and is on a stable version
  • Upgradable
  • Alive and well and actively (so it would seem) developed
  • Very few preinstalled software (but with options to add Libreoffice and the like at install time)
  • Stats (Conky) on the desktop
  • Nice terminal
  • Additions work
As I see it, and the only way to make any more gains, and these minor, would be to 1) try the Debian netinstall (on my first attempt the installer crashed; will try again later on) ;or 2) get head on into Arch Linux. I will still check these out, but I think I have already hit bull's-eye.

Should plus plus go under there are at least two other Crunchbang "twins" that might be just as good: the one from Bunsenlabs & Monara.

Saturday, March 8, 2014

Is oneself the greatest threat to LastPass security?

I wrote this letter as a Q&A submission for the Security Now! podcast. It didn't make it into the show, but I thought about sharing it here. I think there's a valid point to my argument, but who knows? Am I right? Overly exaggerating? You tell us!


Dear Steve,

I'm currently moving away from a algorithm based password system. I have been testing out LastPass with some sites and have been more or less liking it. I'm already convinced that its technology can keep me safe from threats from without. However, I still have a cause for concern. As I see it, and as it currently stands, the greatest threat to a LastPass based security scheme is: *myself*.

Although I use good habits and have not had a problem for the last decade, I cannot completely trust myself not to bring malware to my system: I can be served a malicious banner on a trusted site, open a file from a contact that has been previously compromised, or click a link in an e-mail message while distracted ("so-and-so sent you a message!").

So, if I happen to get malware in my system, what is there to stop it from taking advantage from my LastPass sessions? As I see it, there are at least two ways in which it could harm me. The first one, taking advantage of an open LastPass session to look into my vault and grab whatever it can in one fell swoop; and secondly,  passively detecting the presence of LastPass and recording the unencrypted passwords on their way from LastPass to each webpage; key logging is surely not the only tool available for hackers. And, still a third one, if one wants to go over the top, what's to stop the malware from interacting concurrently with me on an open webpage? No doubt it can beat me on speed ("look! A banking site! Let's attempt a quick transaction").

The PPP option doesn't look as if it could help me here, because it would only protect the LastPass data when closed or from without, not when open and in use.

By the looks of it, LastPass is great with holding my passwords and populating fields quickly, but not much else. I still need some sort of second factor authentication for each site, preferably a global one.

Are these cause for concern or have the LastPass people have come with a solution for this too?