- This topic has 1 reply, 2 voices, and was last updated Aug 11-4:41 pm by anticapitalista.
Viewing 2 posts - 1 through 2 (of 2 total)
Viewing 2 posts - 1 through 2 (of 2 total)
- You must be logged in to reply to this topic.
Forum for users of antiX Linux. Mean and Lean and Proudly anti-fascist.
Forum › Forums › New users › New Users and General Questions › Aren't those static persistence plus no-password-asked combination insecure?
Tagged: home persistence, password, static
(Reworded from an earlier version of this post)
When using LiveUSB, if using Persist Root static mode, or using Persist Home which is always in static mode, all your browser sessions would be persisted on the USB disk. And each time you boot from this USB, antiX does NOT require you to type your account password. That would mean if you happen to lost your usb disk, and someone finds it, they can boot into your desktop and resume all your browser signed-in sessions (Gmail, online-shopping, online-banking, etc.), all without ever needing to try your password!
I personally stick with root persistence without saving changes most of the time, so I would be fine. (FWIW, previously I was using TENS Linux for similar LiveUSB usage pattern, but I gave it up due to it was designed to be fully locked down so there was absolutely no way to customize it.)
I figure this might be a potential security risk that worth fixing or at the very least worth mentioning in the GUI when setting up home persistence, before new users notice it too late.
My $0.02
Regards,
Ray
User can always choose to set up an encrypted live usb for more security.
Philosophers have interpreted the world in many ways; the point is to change it.
antiX with runit - leaner and meaner.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |