ANTenna Blog -- Hardware & Software
A Quick And Easy Way To Minimize Online Banking Risks
Posted by Matthew McKenzie Tuesday, Oct 13, 2009, 02:30 PM ET
Even if your business runs Windows, it can still use Linux to avoid problems related to one of its most important -- and potentially most dangerous -- online activities: banking.
Online banking fraud isn't just a problem -- it's a full-blown plague. Many businesses understand the dangers of phishing scams; educated users know never to click on an email link that might transfer them to a phony login page, and they always double-check the URL when they visit an online banking site.
But the most insidious security threats to online banking still work under the hood on a compromised desktop PC. Malware, including Trojans and keystroke loggers, can intercept a user's login credentials and allow thieves to clean out an account. One notorious Trojan can even alter a victim's online bank statement to conceal the crime, buying additional time for the thieves to escape detection.
When security software fails to catch this malware, it can run unhindered almost indefinitely. And in a worst-case scenario, a company that discovers someone has pilfered its bank account will have few options for recovering the lost funds.
As long as consumers report suspected fraud promptly, federal banking regulations generally require banks to reimburse them for any losses. Those regulations, however, do not extend to business accounts; unless your bank explicitly extends such protection to business customers, then a business that falls prey to online fraud will have to absorb the loss -- if it can.
Solid antimalware protection can reduce this risk. Since the overwhelming majority of Trojans and keystroke loggers, however, attack only Windows PCs, the best way to minimize your company's exposure to online banking fraud is to minimize its use of Windows operating systems to access online accounts.
That's where a Linux Live CD can deliver enormous benefits. Companies that want or need to run Windows PCs for most daily tasks can still boot into a Live CD environment when an employee needs to log into an online bank account.
Washington Post computer security columnist Brian Krebs explains the process in an outstanding overview published this week. Live CDs, he explains,
are generally free, Linux-based operating systems that one can download and burn to a CD-Rom or DVD. The beauty of Live CDs is that they can be used to turn a Windows based PC into a provisional Linux computer, as Live CDs allow the user to boot into a Linux operating system without installing anything to the hard drive. Programs on a LiveCD are loaded into system memory, and any changes - such as browsing history or other activity -- are completely wiped away after the machine is shut down. To return to Windows, simply remove the CD from the drive and reboot.
More importantly, malware that is built to steal data from Windows-based systems simply won't load or work when the user is booting from LiveCD. Even if the Windows installation on the underlying hard drive is completely corrupted with a keystroke-logging virus or Trojan, the malware can't capture the victim's banking credentials if that user only transmits his user name and password after booting up into one of these Live CDs.
There are hundreds of LIve CD options available; most desktop Linux distros offer Live versions. Like Krebs, I recommend using the Ubuntu desktop Live CD. Ubuntu is user-friendly, it doesn't cost anything to use, and it is likely to work well with any standard PC hardware configuration. (Even if it doesn't, trying a different Live CD is an extremely simple matter, since this process doesn't involve actually installing anything on a desktop system.)
Live CDs, by the way, will also work just fine on portable USB sticks, if your PC supports booting from such a device.
Krebs has more details on using a Linux Live CD for online banking sessions, including a quick run-through of the setup process using the Ubuntu desktop Linux distro.
For some users, of course, even the prospect of having to reboot a system just to conduct online banking sounds like a hassle. Such an attitude frankly mystifies me: When an undetected bit of Windows malware could cripple your business in a matter of seconds, how could an extra minute or two possibly represent a burden?
Consider the prospect of explaining to your boss -- or your employees -- that a thief walked away with thousands of dollars because you didn't feel like waiting for your system to reboot. And it's worth saying this again: Consumers who fall prey to online banking fraud are protected. Most businesses are not.
Using a Linux Live CD for online banking sessions doesn't eliminate the risk entirely. A phishing scam, for example, is more an attack on a user's lack of sophistication than on a particular technology; a gullible Linux user can fall prey to such a scam just as easily as a gullible Windows user.
But IT security is not about eliminating risk. It is about minimizing risk. And based on that standard, I think that the benefits of using Linux to conduct online business banking transactions far outweigh the minimal time and effort required to find, learn about, and use a Linux Live CD.
Hardware & Software
Business & E-Business
| Company Size: 1-49
| Finance/Banking/Insurance
| How-To
| Internet/Web
| Security
| Windows
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
- Phone Systems Guide - What kind of phone system is right for your business
- Web Design Guide - What to look for in a Web designer
- Merchant Services Guide - Credit card processing and more
- Online Marketing Guide - Leverage the Net to market your business
- Alternative Financing Guide - How to find the cash your business needs
- View all guides
Explore ANTenna Blog
Most Recent Posts
- Twilight's Latest Hacking: Vampire Byte Scam Targets Stephanie Meyer Fans
- Quark Promote Enters Web-To-Print Market
- Yes, Virginia -- There IS A Google Phone
- Could Linux Fall Prey To Windows Malware?
- New Mini NAS Enclosure Targets Small-Biz Users
ANTenna Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 250-999
- Company Size: 50-249
- Company Size: 1-49
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- Hospitality
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Manufacturing/Mining
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Printers/Printing
- Professional/Creative Services
- Retail
- Unified Communications
- Sales/Marketing
- Start-Ups
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- The rANT
- Transportation
- Travel
- Windows
- Web 2.0
- Women in Business
ANTenna Bloggers
ANTenna Blog Roll
- ANTenna Archive
- Ars Technica
- Business Know-How
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- Mashable
- MonkeyBrains
- Network Computing Blog
- Scott Berkun
- Search Engine Land
- Search Engine Watch
- SmallBizResource
- SmallBizTechnology.com
- SmallBusinessHub
- Small Business Trends
- TechCrunch
- Technologizer
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
bMighty email newsletter!
Browse by Category
bMighty Tech
Term Of Day:
Boost your tech
vocabulary!
bMighty's SMB
TechEncyclopedia
defines more than
20,000 IT terms.
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
go



