Ubuntu 'trusted client' secures Windows and Citrix

 

Even from a malware-infected PC.

Trusted Client, an Ubuntu-based encrypted clean boot utility, has received its Common Criteria certification and been included in the Defence Signals Directorate Evaluated Product List.

The device is designed to allow secure and safe access to a corporate or government network - even if the host machine is infected with malware.

Developed by UK-based encryption specialist Becrypt, Trusted Client is a hardened version of Ubuntu 9.04 that has been cut down to its bare components - about 500mb - and then bundled with Windows deployment tools. This is all wrapped in a layer of encryption and deployed on a standard USB drive.

David Jones, senior product consultant at Becrypt explained that in order to bypass any malware on an untrusted PC, users just boot from the Trusted Client memory stick. The PC then requests a username and password before loading Ubuntu.

The potentially infected hard drive is completely ignored.

"We boot the machine from the USB stick so you come from a known clean starting point. We never allow users to see the hard drive, we never touch it - we assume it is dirty. Instead we use the available RAM on the machine as our work area.

"You can then use the machine to connect with a VPN, use Firefox, Citrix or whatever you want. When you are finished, you shut it down and we do a secure wipe of the RAM," Jones told iTnews.

When questioned about Becrypt's decision to choose Ubuntu, Jones said the popular Linux distribution worked well with a diverse range of hardware.

"One reason we chose Ubuntu is because it is a very powerful OS and is very up to date - it has got lots and lots of drivers," he said.

Administrators can assign a portion of the Trusted Client USB stick to store documents or applications. Alternatively, if internet connectivity is guaranteed, everything can be stored in the cloud.

Housing the Trusted Client in a standard off-the-shelf USB drive means the product is not easily recognisable as a security tool. In addition, if the device falls into the wrong hands, when it is inserted into a computer, the machine will not be able to read the contents and usually advise the user to format it.

The product has a list price of $125.

Becrypt claims ASX-listed Caltex, a major fuel supplier and convenience retailer, is one of the first companies in Australia to deploy Trusted Client.

No Apple Mac support

Trusted Client will not work on Apple Mac systems because, according to Jones, they do not allow users to boot from a USB. The ideal system to run Trusted Client is an x86 PC that is less than four years old.


Ubuntu 'trusted client' secures Windows and Citrix
"@graeme.speak "GoPC.net does this, FREE." The website shows costs, not high, but costs nevertheless."
By kenrob
 
 
 
Comments: 7
Graeme Harrison (prof at-symbol post.harvard.edu)
Mar 18, 2010 4:08 PM
Very good and clever use of Ubuntu.
It should silence those who claim Open Source equates to poor security.

Indeed, I've wondered for the 15 years that the internet has been pervasive, why Microsoft (or say HP) never worked within XP to offer a daily check of your Windows system, to 'sync' it back to an exact copy of a standard/safe system. If it was HP, they could have included all HP drivers, all HP printer drivers etc, and grow a list of 'trusted apps'. That could have overcome the issue of having every individual home user (other options are there for corporate users) supposedly looking after security on their own system. Possibly 90% of users could have lived within that limited application list (open office, Firefox etc).

But now that thumb-drive Linux versions will be available, it is possibly a moot point. With competition, these might drop to 'cheap' options, for home users. The normal Ubuntu (or booting off your Ubuntu CD-R) gives you access to your hard drive files, yet 'quite good' security. Though for corporate use there will always be a market for excellent security, like this device.
graeme.speak
Mar 18, 2010 10:09 PM
GoPC.net does this, FREE. A Linux workstation created out of a diskless or corrupted PC, but they include an online "cloud platform" hosting dozens of desktop apps, storage, security, etc. The cloud has no dependence on physical hardware.

Downloads to your USB or a CDROM and boots on any PC hardware so you can recyle hardware or recover files.

Best of all, this company is Australian and exporting to the world.
neddludd
Mar 19, 2010 6:55 AM
This is good, particularly after so many articles telling business to not use windows for internet banking.

However, wont puppylinux,knoppix,slitaz, or similar do much the same thing at no cost? I realise you dont get as solid support with those distros.
mkotadia
Mar 19, 2010 7:20 AM
Thanks for your comments.

There are numerous free methods of creating a clean boot and Puppy Linux has been highlighted as one of the easiest by NSW Police.

This product's encryption abilities - and the secure RAM wipe feature - make it stand out.
Sams
Mar 19, 2010 9:39 AM
"However, wont puppylinux,knoppix,slitaz, or similar do much the same thing at no cost? I realise you dont get as solid support with those distros."

Yeah, but businesses like to pay for something so they know they can get a refund if it doesn't work. :-) I'm just being facetious, but really some businesses do act that way.
cjc1959au
Mar 19, 2010 12:51 PM
"Trusted Client will not work on Apple Mac systems because, according to Jones, they do not allow users to boot from a USB"

Gees, I wonder what I have been booting off my USB sticks on my Macbook Pro? Let's see: Windows, Ubuntu, Mac OS X, Puppy Linux, wow even DOS. All boot fine.

Maybe the lack of Mac Support is much more to do with a lack of testing.

But then Mac OS X doesn't need this "Trusted Client". Mac OS X is a lot safer in standard form, simply because it doesn't run or support Internet Explorer!


kenrob
Mar 22, 2010 10:36 AM
@graeme.speak
"GoPC.net does this, FREE." The website shows costs, not high, but costs nevertheless.
Comments have been disabled for this article.
 
 
 
Top Stories
Vito Forte: A CIO for tough times
Fortescue Metals CIO talks vendor management and innovation.
 
Tech staff spared in ANZ's 1000 job cuts
Cost cutting hits middle management.
 
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  83%
 
No
  17%
TOTAL VOTES: 245

Vote