Forum › Forums › New users › New Users and General Questions › How to create isolated, underprevileged but standard user accounts? › Reply To: How to create isolated, underprevileged but standard user accounts?
I would like to create user accounts (for my different daily uses), which are; Underprivileged, isolated and standard.
By this I mean, when one is logged in to such an account, one cannot bring any systemic changes. The user can’t install software, can’t access the system except making subjective configurations for the desktop and application use. But one can access all the standard applications and not the system. The account is so isolated from other user accounts that even if a Trojan happens to get into one underprivileged account it cannot access anything or any data from other accounts and cannot access the system.
I am following this thread with great interest as this is something I was thinking of in the past. As originally described this would be great to have from theoretical perspective but IMHO appears to be quite challenging to accomplish in practice.
However from your later post I infer that the purpose of such distinction of entitlements is to actual use in practice rather than theoretical project, just to have dedicated setups for use such as work/banking/… etc., with their own security setups and entitlements, antiX is a unique OS that makes this easy to accomplish and to some degree I am actually using such concept in practice:
Namely:
Rather than looking at such task from a complicated and challenging setup of user entitlement, their lock-downs and application access, I have simply created separate Live USB keys:
– Separate keys for banking, system maintenance, multimedia, etc.
– Such keys are encrypted with their password. Separate passwords can be used e.g. for banking key than for multimedia, but in my case I am just one real user so I made the same password for all.
– Such separate live systems are configured to their requirements, so e.g. banking key has all the security configured to the max, such as firewall, browser security restrictions, etc.
– Once all applications and security/privacy setups are finalized for each USB key according to their requirements these USB keys are then set to have no persistence for banking key or to have some home persistence for typical work key. No persistence means no chance for rogue code or virus to make any permanent change. Should this unlikely happen during session – just reboot.
The reason I mentioned that antiX is a unique OS that make such task easy to accomplish in practice is that:
– antiX has all the needed tools already included and easy to use.
– Memory requirements are very low – USB keys can be used an any laptop
– Boots very fast from USB. Hard drives are optional.
– Mostly operates from memory so writes to USB are minimal
Just my two cents added to this interesting subject…
Live antiX Boot Options (Previously posted by Xecure):
http://antixlinuxfan.miraheze.org/wiki/Table_of_antiX_Boot_Parameters