"Clean boot" approaches to online banking sessions have been discussed in the blogosphere for several years. However, while one can easily find individuals describing how they themselves instituted such a project, typically using Linux, I could find no mention, by name, of any bank providing customers with bootable CD-ROMs for banking online (this despite several extended Google sessions and numerous reports that some banks were thinking of taking this approach).
Here's why banks have not rushed to this method: rebooting to do your online banking is inconvenient, whether the removable drive you boot from is a CD, a USB key or a removable hard drive. Suppose I am traveling on business, working in a hotel room in the evening, and I get an email from my wife asking me to transfer some money from my bank account to hers. Under current conditions, that takes just a few clicks. My browser and email program are already open. I can check my balance, confirm which transactions have cleared, complete the transfer, save the confirmation and email my wife to let her know.
Now consider the steps if the bank were to require me to access my account from a removable drive. I wouldhave to save all my work (which could be a dozen or more open documents). Then I would wait for the reboot to happen, the computer to connect to the Internet, and the browser to load. I'd complete the transfer, but where would I save the confirmation? Then I'd have to reboot, reconnect, load my email program to notify my wife, and then open up all the documents I was working on earlier.
If that weren't bad enough, consider how hard it would be for a bank to design a bootable CD that worked on all of its online customers' computers. Considering the technology involved, and the skill level required of the user, I think you'd be lucky if you had less than 1,000 support calls for every 100,000 customers. Banks are likely to find something cheaper and easier to improve the security of their online banking, like the one-time pad used by some European banks.
As for individuals taking this approach into their own hands, there could be, as the question suggests, licensing issues. However, if I felt compelled to make a bootable drive for my personal computer, which usually runs Windows XP, I would probably use something open source, like a live version of Linux running Firefox and OpenOffice (Ubuntu is good for this). I would not need to worry about my Windows antivirus software license. I would not be running it since the boot disc is read-only and thus immune.
For my money, your efforts are best directed at defending your computer through the usual measures, like antivirus and vigilance. After all, whether you bank via reboot or not, the rest of your data and applications still need protecting.
Dig Deeper on Data security strategies and governance
Related Q&A from Michael Cobb
Expert Michael Cobb details how to argue for a multistep secure code review process, like Microsoft SDL, and the pros of secure coding practices. Continue Reading
Researchers developed a tool to help prevent improper certificate pinning that causes security issues. Expert Michael Cobb reviews the issue and the ... Continue Reading
Google Project Zero discovered a WPAD attack that could target systems running Windows 10. Expert Michael Cobb explains how the attack works and how ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.