View Single Post
  #3 (permalink)  
Old 02-11-2008, 10:44 AM
Ertugrul =?UTF-8?B?U8O2eWxlbWV6?=
Guest
 
Posts: n/a
Default Re: Techniques to prevent Key-loggers

On Mon, 11 Feb 2008 02:46:53 -0800 (PST)
Hakako <1001webs@gmail.com> wrote:

> >> You didn't seem to mention hardware loggers. These are small, hard
> >> to notice, and hard to protect against, but they require physical
> >> access to the machine. You only need a few moments to unplug a
> >> keyboard and connect the doo-hickey.

> >
> > This is particularly a problem at my workplace. I cannot trust
> > anyone here. Unfortunately there are no useful counter-measures
> > other than using key files on a USB stick, from which you boot,
> > which isn't quite easy to handle (backups and such), and not quite
> > secure. A smartcard-based solution would be nice.

>
> I was going to reply to the other poster that I was talking about
> remote key-logging, since it's your responsibility to physically
> protect your computer.
> But obviously, if there are dozens of computers at your office that
> would be Mission Impossible.


Exactly.


> As far as I know there are PC & Notebook Security Combination Cable
> Locks, which are literally bolted-into your computer's VGA or Serial
> port.
> It protects your computer with 2 steel bolts that cannot be accessed,
> together with a 6'6" steel cable sheathed in black PVC and a included
> security plate, that gives you the option of securing the cable to an
> area without a convenient attachment point.
>
> Here you can see the specs:
> http://gadgetofficeinspector.blogspo...able-lock.html


Still the cable can be cut apart to install a logger right inbetween, or
a camera could be installed to intercept my typing. Connected USB
storages may be intercepted through hardware. Or even the entire
Machine could be replaced, while I'm at home sleeping.

So the "security cable lock" is just an anti-lamer measure, just like
unconfigured firewalls are. Someone really interested in my data will
easily get around it.


Regards,
Ertugrul Söylemez.


Reply With Quote