This is a discussion on hdd copy protection within the Linux Security forums, part of the System Security and Security Related category; Hi, I have setup a software in linux ...and want to give the server to the client . But the problem ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Hi,
I have setup a software in linux ...and want to give the server to the client . But the problem is that ...if the client copy my hdd ...then i will lose a large amount of money . It is not in php so i cannot encode it :( It has some conf files that can be read by any editors(ie,vim). I want a way so that ...even if they copy my hdd they cant read or change the configuration. Is there any other solution ? and wat is the best software(opensource) that can do the job . My os is debian4/centos4.5/5. Please help. Thanks . |
|
|||
|
I demand that learnq may or may not have written...
> I have setup a software in linux ...and want to give the server to the > client . But the problem is that ...if the client copy my hdd ...then i > will lose a large amount of money . It is not in php so i cannot encode it > :( Yet another Google-using multiposting idiot... [snip] -- | Darren Salt | linux or ds at | nr. Ashington, | Toon | RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland | Army | + Output less CO2 => avoid boiling weather. TIME IS RUNNING OUT *FAST*. If you really want to know, you won't ask me. |
|
|||
|
On Aug 26, 11:02 pm, Darren Salt
<n...@youmustbejoking.demon.cu.invalid> wrote: > I demand thatlearnqmay or may not have written... > > > I have setup a software in linux ...and want to give the server to the > > client . But the problem is that ...if the client copy my hdd ...then i > > will lose a large amount of money . It is not in php so i cannot encode it > > :( > > Yet another Google-using multiposting idiot... > > [snip] > -- > | Darren Salt | linux or ds at | nr. Ashington, | Toon > | RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland | Army > | + Output less CO2 => avoid boiling weather. TIME IS RUNNING OUT *FAST*. > > If you really want to know, you won't ask me. "idiot..."!!!! ...i just post it another grope to get some more reply ...on my topic. |
|
|||
|
I demand that learnq may or may not have written...
> On Aug 26, 11:02 pm, Darren Salt > <n...@youmustbejoking.demon.cu.invalid> wrote: >> I demand thatlearnqmay or may not have written... >>> I have setup a software in linux ...and want to give the server to the >>> client. But the problem is that ...if the client copy my hdd ...then i >>> will lose a large amount of money. [...] >> Yet another Google-using multiposting idiot... [snip my .sig] > "idiot..."!!!! ...i just post it another grope to get some more reply ...on > my topic. It looks like you need to read http://en.wikipedia.org/wiki/Crossposting and at least one of the pages listed in the "external links" section. -- | Darren Salt | linux or ds at | nr. Ashington, | Toon | RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland | Army | + Buy less and make it last longer. INDUSTRY CAUSES GLOBAL WARMING. Man who fall in vat of molten optical glass make spectacle of self. |
|
|||
|
learnq wrote:
> On Aug 26, 11:02 pm, Darren Salt > <n...@youmustbejoking.demon.cu.invalid> wrote: >> I demand thatlearnqmay or may not have written... >> >>> I have setup a software in linux ...and want to give the server to the >>> client . But the problem is that ...if the client copy my hdd ...then i >>> will lose a large amount of money . It is not in php so i cannot encode it >>> :( >> Yet another Google-using multiposting idiot... >> >> [snip] >> -- >> | Darren Salt | linux or ds at | nr. Ashington, | Toon >> | RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland | Army >> | + Output less CO2 => avoid boiling weather. TIME IS RUNNING OUT *FAST*. >> >> If you really want to know, you won't ask me. > > "idiot..."!!!! ...i just post it another grope to get some more > reply ...on my topic. Multiposting != crossposting. If you can't trust your client, change your client. You're not going to do that, are you? OK, make the HDD the only boot device in BIOS, set a strong password on the BIOS, make sure the BIOS has no backdoor password and fit an extremely strong padlock on the case. It's not foolproof, but it's not bad. Alternatively, set up some decent HDD encryption and insist that you are present whenever the server is booted up. I doubt your client allow this. Now, is this where you start playing the 'yes but....' game? Boggy. |
|
|||
|
learnq wrote:
> Hi, > I have setup a software in linux ...and want to give the server to > the client . > But the problem is that ...if the client copy my hdd ...then i will > lose a large amount of money . > It is not in php so i cannot encode it :( > > It has some conf files that can be read by any editors(ie,vim). > I want a way so that ...even if they copy my hdd they cant read or > change the configuration. > Is there any other solution ? and wat is the best software(opensource) > that can do the job . > > My os is debian4/centos4.5/5. > > Please help. Thanks . > You can't give your client the physical media, the decryption key so s/he can use the data on it, and expect him/her not to have access to the data.... See AACS, CSS, DRM.... If you can figure out how to do that, I'm sure **AA and Micro$oft will give you $millions. --Yan |
|
|||
|
On Sat, 25 Aug 2007 20:56:41 -0700, learnq wrote:
> Hi, > I have setup a software in linux ...and want to give the server to the > client . > But the problem is that ...if the client copy my hdd ...then i will lose > a large amount of money . > It is not in php so i cannot encode it :( > > It has some conf files that can be read by any editors(ie,vim). I want a > way so that ...even if they copy my hdd they cant read or change the > configuration. > Is there any other solution ? and wat is the best software(opensource) > that can do the job . > > My os is debian4/centos4.5/5. > > Please help. Thanks . That's what contracts are for. This isn't a technical issue it's a legal one. The contract spells out the client can do with your software and what they have to pay you. |
|
|||
|
On 26 Aug, 14:02, Darren Salt <n...@youmustbejoking.demon.cu.invalid>
wrote: > I demand that learnq may or may not have written... > > > I have setup a software in linux ...and want to give the server to the > > client . But the problem is that ...if the client copy my hdd ...then i > > will lose a large amount of money . It is not in php so i cannot encode it > > :( > > Yet another Google-using multiposting idiot... You're not helping. *Explain* Netiquette before whinging about some new person's lack: English is probably not his first language. Friend, it's unclear what you mean by "hdd". Are you trying to give your client some data from your server, and provide it securely without copying the whole hard drive? Or allow them to read output without reading the source data from a database? Or what? |
|
|||
|
On 29 Aug, 01:43, General Schvantzkoph <schvantzk...@yahoo.com> wrote:
> On Sat, 25 Aug 2007 20:56:41 -0700, learnq wrote: > > Hi, > > I have setup a software in linux ...and want to give the server to the > > client . > > But the problem is that ...if the client copy my hdd ...then i will lose > > a large amount of money . > > It is not in php so i cannot encode it :( > > > It has some conf files that can be read by any editors(ie,vim). I want a > > way so that ...even if they copy my hdd they cant read or change the > > configuration. > > Is there any other solution ? and wat is the best software(opensource) > > that can do the job . > > > My os is debian4/centos4.5/5. > > > Please help. Thanks . > > That's what contracts are for. This isn't a technical issue it's a legal > one. The contract spells out the client can do with your software and > what they have to pay you.- Hide quoted text - > > - Show quoted text - Well, it becomes a "Digital Rights Management" issue. If the data is in a database on a secured server, in a box owned and administered by learnq, and the client only needs web or client access to the data when they request it, then the original data can be pretty protected. Mind you, a lot of us on groups like this have deliberately broken such security, or various security by keeping the data in S00p3r s3kr3t F0rmatz (badly built, super secret formats). I've certainly done so to debug what was broken and restore a broken system where the vendor would have taken too long to go through 4 levels of off-shore helpdesk and let us talk to the engineer who wrote it (and who, it turned out, no longer worked there.) |