<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Wed Jun 19, 2013 5:19 pm by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Wed Jun 19, 2013 5:19 pm</pubDate>
  <lastBuildDate>Wed Jun 19, 2013 5:19 pm</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109719#109719</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=27343'&gt;Fíona&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Dec 17, 2012 11:07 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      I would agree that a banks view on security is sometimes surprising. I had problems with internet banking, apparently 3 atempts had been made to carry out transactions using my details. When I questioned the bank they assumed that the problem was on my computer and tried to tell me that I had windows virus's, trying to convince them that since I use linux I didn't believe that a windows virus would be the cause of the problem, was like talking to a brick wall.&lt;br /&gt;
If my bank were to compel me to use such software as the trusteer stuff, I would stop internet banking and go back to paper banking.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109719#109719</comments>
                                        <author>Fíona</author>
                                        <pubDate>Mon Dec 17, 2012 11:07 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109719#109719</guid>
                                      </item>
                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109715#109715</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=66408'&gt;pastychomper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Dec 17, 2012 8:51 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      I'd be inclined to point out that the standard Unix user &amp;amp; file permissions are designed to prevent virus and spyware infection, and are of course implemented in software, so any Linux system meets HSBC's requirements - at least, as long as it isn't run as root.&lt;br /&gt;
&lt;br /&gt;
If the bank didn't like that response I might consider using SELinux and/or a rootkit detector, but I doubt my current bank would care.  If they support &amp;quot;Verified by Visa&amp;quot; &lt;span style=&quot;font-style: italic&quot;&gt;and&lt;/span&gt; allow non-authenticated contactless payment, how security conscious can they be?</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109715#109715</comments>
                                        <author>pastychomper</author>
                                        <pubDate>Mon Dec 17, 2012 8:51 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109715#109715</guid>
                                      </item>
                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109705#109705</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=67227'&gt;Nuke&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sat Dec 15, 2012 12:27 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Ram wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;That's the same software my bank would like me to install - not much chance there.&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
All very well, but what if the bank make it a condition of the account?  In the HSBC General Terms and Conditions (April 2012 edition, Clause 9.2) it requires that you &amp;quot;keep your personal computer secure by using anti-virus and anti-spyware software&amp;quot;.  They do not specify which software, but it is a card that they could play if there were a dispute with your account.  I make no comment as to whether I meet the condition myself.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109705#109705</comments>
                                        <author>Nuke</author>
                                        <pubDate>Sat Dec 15, 2012 12:27 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109705#109705</guid>
                                      </item>
                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109685#109685</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=130'&gt;Ram&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Tue Dec 11, 2012 12:46 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      That's the same software my bank would like me to install - not much chance there.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109685#109685</comments>
                                        <author>Ram</author>
                                        <pubDate>Tue Dec 11, 2012 12:46 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109685#109685</guid>
                                      </item>
                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109682#109682</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=27343'&gt;Fíona&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Tue Dec 11, 2012 12:03 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Thanks for your answer and tip Nelz.&lt;br /&gt;
I use https everywhere, so hopefully that will help but I will certainly look into using the rootkit hunter as well. I have also seen another tool chkrootkit, I'll look at that too.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109682#109682</comments>
                                        <author>Fíona</author>
                                        <pubDate>Tue Dec 11, 2012 12:03 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109682#109682</guid>
                                      </item>
                                      <item>
                                        <title>Re: Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109680#109680</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=5'&gt;nelz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Tue Dec 11, 2012 11:55 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      HTTP uses plain text, so it is susceptible to interception regardless of the OS used. But your bank should be using HTTPS, which is both encrypted and certified, preventing man in the middle attacks.&lt;br /&gt;
&lt;br /&gt;
As for trojans, there are rootkits which can hide in the background and do nasty things. I run &lt;a href=&quot;http://rkhunter.sf.net/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Rootkit Hunter&lt;/a&gt; every day to make sure nothing has got onto my system.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109680#109680</comments>
                                        <author>nelz</author>
                                        <pubDate>Tue Dec 11, 2012 11:55 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109680#109680</guid>
                                      </item>
                                      <item>
                                        <title>Trusteer Rapport and preventing man in the middle attacks.</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=109676#109676</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=27343'&gt;Fíona&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Tue Dec 11, 2012 11:00 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      On my bank's website I noticed a suggestion to install Trusteer Rapport to protect my computer from trojans. Since I (obviously) use linux and there is no version for linux I have to pass on that piece of advice.&lt;br /&gt;
Browsing the net I discovered that this software appears to cause more problems than it solves and I wonder if it actually protects at all.&lt;br /&gt;
What is the position of linux and man in the middle malware? I know that the most of the malware/virus is designed to work on windows or mac platforms but don't understand how malware works and read that information can be hijacked during the http transmission. Is a linux system susceptable to this type of attack at the http level?&lt;br /&gt;
Interesting to see what you think!</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=109676#109676</comments>
                                        <author>Fíona</author>
                                        <pubDate>Tue Dec 11, 2012 11:00 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=109676#109676</guid>
                                      </item></channel></rss>