secure client-side platform

liudieyu_at_umbrella.name
Date: 08/31/05

  • Next message: security-alert_at_hp.com: "[security bulletin] SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege"
    To: <bugtraq@securityfocus.com>
    Date: Wed, 31 Aug 2005 12:53:47 -0000
    
    

    how to have a secure client-side platform for secret communication?
        ... transferring and storing secret messages, online banking, etc

    i got some fresh ideas in mind, and would like to share it here:
    0. watch network with sniffer, so be sure no byte is sent to weird destinations
    1. read-only operating system(knoppix, etc), so every boot is a fresh start
    2. get every secret processed in memory and stored as encrypted in remote server

    any suggesion or fresh idea on this topic is welcome

    this document for ordinary people on the street:
    http://umbrella.name/upid/trooseid

    bugtraq guys can directly go to the conclusion part:
    http://umbrella.name/computer/trooseid/trooseid_online/#conclusion

    have a nice day,

    Liu Die Yu


  • Next message: security-alert_at_hp.com: "[security bulletin] SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege"

    Relevant Pages