# Linux LiveCD for online transactions: How does it work?

**URL:** <https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083>\
**Category:** Factual Questions\
**Created:** [April 7, 2013, 4:36pm UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083 "2013-04-07T16:36:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![LynnM](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@LynnM](https://boards.straightdope.com/u/LynnM)\
**Post date:** [April 7, 2013, 4:36pm UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083/1 "2013-04-07T16:36:51Z")

</div>

Does using an Ubuntu or Mint LiveCD for online transactions, like banking or buying stuff, make the transaction safer?

If so, how does this work, and why is it safer?

I understand booting from the CD, but what about establishing the internet connection? And since data is being transmitted, I don’t get how/why this might be safer?

Info appreciated!

---

<div class="post-metadata">

**Author:** ![jz78817](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jz78817/32/1028_2.png) [@jz78817](https://boards.straightdope.com/u/jz78817)\
**Post date:** [April 7, 2013, 4:44pm UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083/2 "2013-04-07T16:44:04Z")

</div>

> [@LynnM](#):
>
> Does using an Ubuntu or Mint LiveCD for online transactions, like banking or buying stuff, make the transaction safer?
> 
> If so, how does this work, and why is it safer?
> 
> I understand booting from the CD, but what about establishing the internet connection? And since data is being transmitted, I don’t get how/why this might be safer?
> 
> Info appreciated!

a few things I can see:

1. booting to a known-safe live CD (Ubuntu and similar) pretty much guarantees there’s no malware running which could be logging your keystrokes (and stealing your usernames, passwords, account #s, etc.)

2. live CDs have no persistent storage so once you restart the system all cookies and other web tracking things are gone.

3. as for the internet connection, if you have a wired connection (ethernet) then as long as your network card is supported by the Linux distro it’ll automatically detect. if it’s WiFi, then (as long as it’s supported by the distro) it’ll detect the card and you’ll have to find your network and put in the security key.

I guess this would be marginally safer, but it’s starting to edge into paranoia IMO…

---

<div class="post-metadata">

**Author:** ![BorgHunter](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@BorgHunter](https://boards.straightdope.com/u/BorgHunter)\
**Post date:** [April 7, 2013, 5:45pm UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083/3 "2013-04-07T17:45:28Z")

</div>

> [@jz78817](#):
>
> 1. booting to a known-safe live CD (Ubuntu and similar) pretty much guarantees there’s no malware running which could be logging your keystrokes (and stealing your usernames, passwords, account #s, etc.)

Absent a hardware keylogger or the like, yes. But I’ve gotta say, booting to a live CD just to check your bank account balance is some serious overkill. It’s much easier (and, overall, far preferable) to just prevent the malware from getting on your computer in the first place.

I see one thing which makes live CDs **less** secure, though: They’re, to some degree, out of date. If you used an Ubuntu 12.10 live CD, for example, that’s an ISO approaching six months old. You’d be running a version of Firefox with known security vulnerabilities. That’s an actual, known attack vector (albeit one unlikely to be exploited by simply browsing to your bank’s website), rather than the very fuzzy and dubious “there might be malware on my computer!” vector. Now, if you _know_ there’s malware on your computer, yeah, don’t be typing in credit card numbers until you’ve cleared it away. If you _suspect_ there’s malware on your computer, you need to prove or disprove this before you log into your bank’s website. But on a healthy computer, using a live CD for this purpose is, at best, useless.

---

<div class="post-metadata">

**Author:** ![LynnM](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@LynnM](https://boards.straightdope.com/u/LynnM)\
**Post date:** [April 8, 2013, 9:52am UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083/4 "2013-04-08T09:52:03Z")

</div>

Thanks for info.

Might a LiveCD be a good idea if using someone else’s PC–esp a “public” one like at a library?

When using a LiveCD, is that PC’s hard drive completely protected against any downloads, from anything being saved on the hard drive?

Is the LiveCD “writable”?–How do cookies get saved? Or are the cookies saved only in memory?

---

<div class="post-metadata">

**Author:** ![BorgHunter](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@BorgHunter](https://boards.straightdope.com/u/BorgHunter)\
**Post date:** [April 8, 2013, 12:31pm UTC](https://boards.straightdope.com/t/linux-livecd-for-online-transactions-how-does-it-work/655083/5 "2013-04-08T12:31:31Z")

</div>

> [@LynnM](#):
>
> Might a LiveCD be a good idea if using someone else’s PC–esp a “public” one like at a library?

Do you trust the computer owner to not be malicious, and to be competent enough not to allow malware on their machines? If “no”, then yes, using a live CD might be preferable, but it’s also risky in that you might get booted off the computers entirely by the supervisor there. Also, you’re not going to be able to do this on any competently run library computer, which you’ll either not be afforded physical access to, or they’ll have the boot order set to hard drive first with the BIOS settings behind a password.

> [@LynnM](#):
>
> When using a LiveCD, is that PC’s hard drive completely protected against any downloads, from anything being saved on the hard drive?

Not “completely”. You can mount and write to physical drives from a live CD. Generally, though, you would have to go out of your way to do this.

> [@LynnM](#):
>
> Is the LiveCD “writable”?–How do cookies get saved? Or are the cookies saved only in memory?

The live CD is not writeable, as optical discs are generally “write-once”. Cookies are stored in the RAM drive and are not persisted when you reboot the machine.
