Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Security Hardware

Increasing Computer Security through Hardware? 69

Audiostar asks: "I am interested in adding some security to several of my computers, but am unsure as to which product to go with. I would like to use some sort of external security measure, such as a pen drive token or something similar. I had considered custom building a key card and reader to install on all my machines, but once I started thinking about the cost and time of building a card reader for each of my computers it became rather impractical. Does anyone have any suggestions for external locking devices or software? I would prefer something that I could use on both my Windows and Linux machines, but protecting the Windows machines are the top priority. I don't need anything too fancy, just an added layer of protection from the multitude of various people who come in and out of my place of business everyday. I own a 128mb flash disk watch, so possibly using that as a token would be both easy and geek chic. Any suggestions on what to install?"
This discussion has been archived. No new comments can be posted.

Increasing Computer Security through Hardware?

Comments Filter:
  • Re:Smart Card (Score:2, Informative)

    by oO Peeping Tom Oo ( 750505 ) on Friday March 19, 2004 @01:24AM (#8607033)
    My apologies for double posting, but a far as commercial products go, this doesn't seem like a bad solution.... http://www.cyberflex.slb.com/ There is also a Linux SDK, if you want to go down that road......
  • by jargonCCNA ( 531779 ) on Friday March 19, 2004 @02:25AM (#8607307) Homepage Journal
    Check out the Securikey [thinkgeek.com] on ThinkGeek. I'm not sure if someone's written Linux drivers for it, but there's your hardware level -- and it's two-factor.
  • Re:Huh? (Score:3, Informative)

    by 0x0d0a ( 568518 ) on Friday March 19, 2004 @03:29AM (#8607530) Journal
    His complaint is legitimate, even if not for this particular case. "Locking" a Windows or Linux box does nothing for security if someone happens to have a rescue disc handy (well, other than let you possibly know that the machine has rebooted).
  • Re:Huh? (Score:3, Informative)

    by toast0 ( 63707 ) <slashdotinducedspam@enslaves.us> on Friday March 19, 2004 @05:43AM (#8607955)
    Lock down the bios*, so it only boots from the hard drive. Password protect your lilo.

    Yes, you can open the case, and fiddle with the lose bios settings jumper, but one hopes you'ld notice when they open the case.

    *Many bioses have a backdoor password, make sure yours doesn't, or at the least it's not a common one.

  • by jonadab ( 583620 ) on Friday March 19, 2004 @11:14AM (#8609819) Homepage Journal
    You didn't tell us -- are you protecting against vandalism (some clown messing
    up the settings, deleting stuff, whatever) or against information theft? The
    solution will be completely different.

    To protect against vandalism, nothing beats nightly offsite backups, nothing.

    To protect against information theft, how about storing the informationg in
    question on an external device that you keep on your person? Then when they
    go to steal it, it's not there. Hard to beat that.
  • Re:Er? Bad question! (Score:2, Informative)

    by DavidTC ( 10147 ) <slas45dxsvadiv.v ... m ['x.c' in gap]> on Friday March 19, 2004 @11:31AM (#8610016) Homepage
    NTFS encryption is exactly as good as Windows security.

    Haha. No, seriously, the concept behind NTFS encryption is great. It keeps keys with login creditials, and they're decrypted with your login password. I forget the algorythm, but it's not some snake oil crap, it's a real, heavy duty encryption thing. Linux could use something like it, it's so amazingly transparent and just works correctly.

    The problem, of course, is that administrator has all the keys, and administrator isn't anywhere near protected enough to be allowed that kind of power...a single spyware and all everyone's super secret files are free for the taking.

    Basically, NTFS encryption on Windows is about the same concept asking people their names before they board a plane, but doing a really good check on the name they gave, with absolutely no check to see if that's actually their name. They've bolted working security on a system with completely broken authentication. You can only get 'your own' files, but it's rather easy to be someone else, or even the administrator, so it's really goofy.

  • Abit SecureIDE (Score:4, Informative)

    by Asterisk ( 16357 ) on Friday March 19, 2004 @01:57PM (#8612006)
    Abit makes a product [abit-usa.com] that sits between the IDE port on your motherboard and the hard drive. It encrypts all of the data on-the-fly and requires a small dongle to be plugged in externally to work. Combine that with a good case lock, and you should be all set.
  • Re:Huh? (Score:2, Informative)

    by Audiostar ( 734627 ) on Friday March 19, 2004 @02:04PM (#8612100)
    Now, if you'd like to admit that you're business is being run out of your dorm room, and you only want something "cool" to lock out your buddies in the dorm, then maybe you'd get some better advice.

    That is truly +2 insightful. You got me. I want to protect my computer mostly from my annoying RA and frat buddies, not the freelance graphic designers I occasionally employ that aren't monitored constantly while they are working. I can only guess that you are making this assumption based on the fact that my email address on my slashdot profile is a University address, but this stems only from the fact that I have had this /. account since I my days in college. I will be sure to change it now to my current address.

    Its pretty amazing that someone can ask a simple question and a sarcastic and rude response can get +2 Insightful. Did it get +2 because of the Ctrl+alt+Del comment? Because I actually was already aware of that function, believe it or not. I know that as a college student it could be assumed that certain subtle nuances of computer usage could slip past you in all those hungover mornings from the previous night's sorority function, and you bringing this to my attention has been a great service to me. Flamebait.
  • ibutton.com (Score:1, Informative)

    by Anonymous Coward on Sunday March 21, 2004 @04:52PM (#8628927)
    ibutton.com

There are two ways to write error-free programs; only the third one works.

Working...