Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Advice Please; How to "Quarantine" Hard Drives

0 views
Skip to first unread message

Darren Harris

unread,
Aug 8, 2004, 12:38:35 PM8/8/04
to
Is it really possible to "Quarantine" three system hard drives from a
single hard drive when that hard drive is used for internet related
purposes?(The idea is to keep them from from viruses, hacking, ect.).

Thanks a lot.

Darren Harris
Staten Island, New York.

Message has been deleted

Tod

unread,
Aug 8, 2004, 9:21:00 PM8/8/04
to
I believe in the past I have seen hard drives with a jumper that write
protects a hard drive (SCSI drives ?)
Maybe you could go into the bios at startup and disable the IDE controller
the drives are connected to.
Or put the drives into an external USB case and leave the drive disconnected
when not in use.

"Darren Harris" <Sear...@mail.con2.com> wrote in message
news:9437a27c.04080...@posting.google.com...

CJT

unread,
Aug 8, 2004, 9:22:36 PM8/8/04
to
Darren Harris wrote:

On Linux, you mean?

--
The e-mail address in our reply-to line is reversed in an attempt to
minimize spam. Our true address is of the form che...@prodigy.net.

Darren Harris

unread,
Aug 9, 2004, 1:50:47 AM8/9/04
to
I'll be using Windows XP. All four drives will be in a single case.
And I really need to be able to access any of the drives on a dime,
but will be spending most of the time using drive "C".

Basically, what I'm looking for is something simular in principle to
the way the "Recycle Bin" works. Data/apps in there cannot be changed.
One would have to restore them first.

Since those "brains" over at Microsoft will never come up with a
secure OS, you'd think that a simple "Quarantine" function would be
incorporated into their products.

Thanks a lot.

Darren Harris
Staten ISland, New York.

Darren Harris

unread,
Aug 9, 2004, 1:52:01 AM8/9/04
to

Thanks a lot.

Darren Harris
Staten ISland, New York.

Christopher Pollard

unread,
Aug 9, 2004, 2:18:11 AM8/9/04
to
On 8 Aug 2004 22:52:01 -0700, Sear...@mail.con2.com (Darren Harris) wrote:

>Basically, what I'm looking for is something simular in principle to
>the way the "Recycle Bin" works. Data/apps in there cannot be changed.
>One would have to restore them first.

Could you not create a zip file on each drive, which XP will then treat as a
folder. Then password protect it?
Although my experience of XP's handling of zip files is that it sucks...

Just a thought.

Chris Pollard

--
CG Internet café, Tagum City, Philippines
http://www.cginternet.net

Jim Wilson

unread,
Aug 9, 2004, 7:49:13 AM8/9/04
to
I have not personally done what you are trying to do. That said
simply typed in
" password protect hard drive " on Google and got a ton of hits.
This one looks promising...... http://www.softstack.com/hidedrv.html

Hide and Protect Drives will apparently password protect hard drives,
floppy drives...... even CD and DVD drives. ( BTW....It's $29.95 )

Let us know if you find something better. Good luck!

====================================================================
Sear...@mail.con2.com (Darren Harris) wrote in message news:<9437a27c.04080...@posting.google.com>...

J. Clarke

unread,
Aug 9, 2004, 9:01:41 AM8/9/04
to
Darren Harris wrote:

Such a "quarantine" function would be no more reliable than the security of
the OS. While you can't call up a file from the recycle bin and edit it
with Word someone who knows what he's about should be able to alter the
contents regardless--those files aren't really protected in any special
manner.

If you're running 2K/XP I believe you can set policies on the drives that
deny writing to specific users--I know you can do that if you have a domain
going just don't recall if it's possible to do it with workstation working
standalone. That's fairly robust.

_Safest_ bet is to put the files you want to protect on a server that has no
Internet access and then use the security features of the OS on that server
to prevent writing. That way security is handled independently of anything
that happens on your working machine. You can use Linux or BSD on the
server if you can't afford Windows Server or if you feel like doing a
little "sweet talking" you can probably get a 5 user copy of Netware for
Small Business (or whatever they're calling it this week) out of your local
Novell authorized reseller--the 5 user is officially free but available
only through resellers.


>
> Thanks a lot.
>
> Darren Harris
> Staten ISland, New York.

--
--John
Reply to jclarke at ae tee tee global dot net
(was jclarke at eye bee em dot net)

Alexander Grigoriev

unread,
Aug 9, 2004, 10:11:58 AM8/9/04
to
Format the drives as NTFS, set the security permissions "Read" for everybody
and "modify" for Administrators.
Then, to copy files there, you'll need to be logged as an administrator. Any
account will be able to read those files.

To make sure the malware won't be able to install on your computer: never
work as an administrator or a member of Administrators group. Make your user
account "limited user". Then, even some security hole or your own fault will
allow some malware install to run, it won't be able to copy anything to the
system folders and register itself in the OS.

"Darren Harris" <Sear...@mail.con2.com> wrote in message
news:9437a27c.04080...@posting.google.com...

Darren Harris

unread,
Aug 11, 2004, 3:02:06 AM8/11/04
to
I just need a *simple* way to protect 3 out of 4 drives when not in
use, and save to them quickly when I have to. So having to create Zip
drives or getting a server to store my files is not an option. And
paying $30 for an unproven app(wiht very little comments about it on
the net) that *might* protect my drives from hacking and viruses
doesn't seem plausible. And I don't know how it is possible to get 3
out of four drives to recognize me as an "Administrator" with the one
single drive allowing full access.

I guess a firewall should be my first line of defense, but shouldn't I
be able to set up a SCSI system to spin down 3 out of 4 drives until I
access them?

(I guess if there was an easy way to do this, it would be widely
know).

Thanks.

Darren Harris
Staten Island, New York.

*******************************************************************************
"Alexander Grigoriev" <al...@earthlink.net> wrote in message news:<OCLRc.14188$cK.1...@newsread2.news.pas.earthlink.net>...

David Maynard

unread,
Aug 11, 2004, 3:15:20 AM8/11/04
to
Darren Harris wrote:
> I just need a *simple* way to protect 3 out of 4 drives when not in
> use, and save to them quickly when I have to. So having to create Zip
> drives or getting a server to store my files is not an option. And
> paying $30 for an unproven app(wiht very little comments about it on
> the net) that *might* protect my drives from hacking and viruses
> doesn't seem plausible.

> And I don't know how it is possible to get 3
> out of four drives to recognize me as an "Administrator" with the one
> single drive allowing full access.

You don't. He's telling you how do operate the machine so ALL 'drives' are
as protected as they can be. You should not normally be logged on as an
administrator so that any malicious code you run across then has full
administrator rights to run through the system at will.

Then you can change write rights on the 'protected' drives, or anything
else you want 'protected', so that nothing but an administrator has write
rights and since you will not be logged on as administrator no malicious
code can use your rights to alter them.

CJT

unread,
Aug 11, 2004, 3:15:10 AM8/11/04
to
Darren Harris wrote:

> I just need a *simple* way to protect 3 out of 4 drives when not in

> use, and save to them quickly when I have to. <snip>

You may not want to hear this, but it's a trivial task in Linux.

Via Samba, you can integrate that with Windows.

lordy

unread,
Aug 11, 2004, 5:04:09 AM8/11/04
to
Sear...@mail.con2.com (Darren Harris) wrote in
news:9437a27c.04081...@posting.google.com:

> I just need a *simple* way to protect 3 out of 4 drives when not in
> use, and save to them quickly when I have to.

How quick is quickly? How about USB2/Firewire enclosures - and pull the
plug to protect??

Why is a server not an option? speed?

Under Linux just umount them :)


--
Lordy

patrick

unread,
Aug 11, 2004, 10:48:29 AM8/11/04
to
Don Taylor wrote:

> Sear...@mail.con2.com (Darren Harris) writes:
>
>>Is it really possible to "Quarantine" three system hard drives from a
>>single hard drive when that hard drive is used for internet related
>>purposes?(The idea is to keep them from from viruses, hacking, ect.).
>
>
> There was a retail product called "Hard Drive Sherrif" that might help you.
>
> I always thought a nice product would be a big red switch and a
> modification of defrag. You decide, with some assistance from the
> software, which files you don't want changed, probably forever.
> The software moves all those to one side of "the fence." Things
> that you are expecting to change are kept on the other side of "the
> fence." When it is finished moving files it asks you to flip the
> switch. Then any attempt to write on the wrong side of the fence
> results in a disk write error and it doesn't do the write. No
> software can then flip that switch, and that is the essential part
> of providing that security. (It actually wouldn't be too difficult
> for a company to build such a product)
>
> It would seem to me that a substantial fraction of your hard drive
> is stuff that you likely very very rarely want to change, and if
> something does try to change that then it is almost certainly a
> bug or a virus. (Now if Microsoft just didn't need to patch their
> code every week we would be set!)
Gee, that is how the more than 260+ FREE, Open Source, Operating
Systems, and, MAC OSX, all work, NOW! The /ROOT system can ONLY be
changed by the Sys.Admin.! (Unlike XP, which can be cracked, via a
floppy, usb drive, or, through remote access!).

Here ar 190+ LiveCDs to play with!
http://www.frozentech.com/content/livecd.php

Folkert Rienstra

unread,
Aug 11, 2004, 8:50:53 AM8/11/04
to

"Darren Harris" <Sear...@mail.con2.com> wrote in message news:9437a27c.04081...@posting.google.com...

> I just need a *simple* way to protect 3 out of 4 drives when not in
> use, and save to them quickly when I have to. So having to create Zip
> drives or getting a server to store my files is not an option. And
> paying $30 for an unproven app(wiht very little comments about it
> on the net) that *might* protect my drives from hacking and viruses
> doesn't seem plausible. And I don't know how it is possible to get 3
> out of four drives to recognize me as an "Administrator" with the one
> single drive allowing full access.
>
> I guess a firewall should be my first line of defense, but shouldn't I
> be able to set up a SCSI system to spin down 3 out of 4 drives until I
> access them?

Uhuh, and when exactly did you inform this group that your drives are SCSI?

>
> (I guess if there was an easy way to do this, it would be widely know).

It is, but for you to accept anything and not moan about it, that is the problem.
Or maybe your uncanny ability to misunderstand what you read.

Darren Harris

unread,
Aug 11, 2004, 7:09:04 PM8/11/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10hjhs9...@corp.supernews.com>...

> Darren Harris wrote:
> > I just need a *simple* way to protect 3 out of 4 drives when not in
> > use, and save to them quickly when I have to. So having to create Zip
> > drives or getting a server to store my files is not an option. And
> > paying $30 for an unproven app(wiht very little comments about it on
> > the net) that *might* protect my drives from hacking and viruses
> > doesn't seem plausible.
>
> > And I don't know how it is possible to get 3
> > out of four drives to recognize me as an "Administrator" with the one
> > single drive allowing full access.
>
> You don't. He's telling you how do operate the machine so ALL 'drives' are
> as protected as they can be. You should not normally be logged on as an
> administrator so that any malicious code you run across then has full
> administrator rights to run through the system at will.

But since as I said, I'll be working with my "C" drive(and will only
occasionally need to copy to the other three), it seems that I won't
have the freemdom I need with that drive until I login in as an
"Administrator", which of course opens up the other drives to
malicious code.

It seems that you're talking about an all-or-nothing solution, and I
need complete freedom with *one* drive while protecting the others. Or
is there sommething I'm not being told?

> Then you can change write rights on the 'protected' drives, or anything
> else you want 'protected', so that nothing but an administrator has write
> rights and since you will not be logged on as administrator no malicious
> code can use your rights to alter them.

Basically, I'd need for the "C" drive to "see" me as an
"Administrator", but not the other three drives. IS that possible?

Darren Harris

unread,
Aug 11, 2004, 7:10:13 PM8/11/04
to
CJT <abuj...@prodigy.net> wrote in message news:<4119C77E...@prodigy.net>...

> Darren Harris wrote:
>
> > I just need a *simple* way to protect 3 out of 4 drives when not in
> > use, and save to them quickly when I have to. <snip>
>
> You may not want to hear this, but it's a trivial task in Linux.
>
> Via Samba, you can integrate that with Windows.

Unfortunately, Linux is not an option.

Darren Harris

unread,
Aug 11, 2004, 7:17:17 PM8/11/04
to
lordy <spam...@gmx.net> wrote in message news:<Xns9542666E2559...@130.133.1.4>...

> Sear...@mail.con2.com (Darren Harris) wrote in
> news:9437a27c.04081...@posting.google.com:
>
> > I just need a *simple* way to protect 3 out of 4 drives when not in
> > use, and save to them quickly when I have to.
>
> How quick is quickly? How about USB2/Firewire enclosures - and pull the
> plug to protect??

I assume that you mentioned USB and Firewire because they are
hot-swappable? I'm building a single self-contained system.(Hardware
and software manufacturesers have made it extremely difficult to own a
simple system with multiple drives without having to buy a whole lot
of crap to protect it).

> Why is a server not an option? speed?

As well as cost, space, complexity...

> Under Linux just umount them :)

:-)

Darren Harris

unread,
Aug 11, 2004, 7:25:24 PM8/11/04
to
> > I guess a firewall should be my first line of defense, but shouldn't I
> > be able to set up a SCSI system to spin down 3 out of 4 drives until I
> > access them?
>
> Uhuh, and when exactly did you inform this group that your drives are SCSI?

2004-08-11 00:02:07 PST

Nevertheless, the system doesn't exist yet. I want to build two with
one of them being SCSI. I haven't decided if the one to be connected
to the internet is to be that one.

What's your point?



> >
> > (I guess if there was an easy way to do this, it would be widely know).
>
> It is, but for you to accept anything and not moan about it, that is the problem.
> Or maybe your uncanny ability to misunderstand what you read.

I understand that you are a troll looking for someone to harass. Find
someone else to start with. There are a lot of other threads.

David Maynard

unread,
Aug 11, 2004, 8:30:00 PM8/11/04
to
Darren Harris wrote:
> David Maynard <dNOT...@ev1.net> wrote in message news:<10hjhs9...@corp.supernews.com>...
>
>>Darren Harris wrote:
>>
>>>I just need a *simple* way to protect 3 out of 4 drives when not in
>>>use, and save to them quickly when I have to. So having to create Zip
>>>drives or getting a server to store my files is not an option. And
>>>paying $30 for an unproven app(wiht very little comments about it on
>>>the net) that *might* protect my drives from hacking and viruses
>>>doesn't seem plausible.
>>
>>
>> > And I don't know how it is possible to get 3
>>
>>>out of four drives to recognize me as an "Administrator" with the one
>>>single drive allowing full access.
>>
>>You don't. He's telling you how do operate the machine so ALL 'drives' are
>>as protected as they can be. You should not normally be logged on as an
>>administrator so that any malicious code you run across then has full
>>administrator rights to run through the system at will.
>
>
> But since as I said, I'll be working with my "C" drive

And what does 'working with' the C drive mean?

>(and will only
> occasionally need to copy to the other three), it seems that I won't
> have the freemdom I need with that drive until I login in as an
> "Administrator", which of course opens up the other drives to
> malicious code.

Your 'plan' opens them to malicious code by leaving your C: drive
completely unprotected, so that it can become infected, and then it infects
the other drives the instant you 'spin them up'.

> It seems that you're talking about an all-or-nothing solution, and I
> need complete freedom with *one* drive while protecting the others. Or
> is there sommething I'm not being told?

You're asking for 'complete freedom', why I don't know, for the drive on
which an infection is most likely since every targeted vulnerability
resides on it, and the one where it matter most, yet want to be
'protected'. Just ain't going to happen.


>>Then you can change write rights on the 'protected' drives, or anything
>>else you want 'protected', so that nothing but an administrator has write
>>rights and since you will not be logged on as administrator no malicious
>>code can use your rights to alter them.
>
>
> Basically, I'd need for the "C" drive to "see" me as an
> "Administrator", but not the other three drives. IS that possible?

Yes. Format them NTFS and then mount/dismount them when needed. Or buy
'removable' drives and 'unplug' them when not needed. Doesn't really matter
because whatever vulnerability you're protecting them from will simply
infect them the moment you activate them.

kony

unread,
Aug 11, 2004, 8:35:05 PM8/11/04
to
On 11 Aug 2004 16:09:04 -0700, Sear...@mail.con2.com (Darren
Harris) wrote:


>It seems that you're talking about an all-or-nothing solution, and I
>need complete freedom with *one* drive while protecting the others. Or
>is there sommething I'm not being told?

That you're trying to reinvent the wheel to a certain extent,
that having protected data is the whole purpose behind removable
media and/or disconnected backup storage?

The moment you are in a position to access those other drive(s),
so is any virus/etc. If it were simply a matter of "denial" of
access to drives, would viri exist at all? Could we not simply
assign all file transfers to a ramdrive and deny all traditional
physical storage rights?

WinXP should be able to pick up a drive connected to a SCSI IDE
controller if it is powered on, from being off, while system
stays running, providing your SCSI controller also supports this.
In other words, you'd be closing power circuit to drive to use
it, then opening circuit again when done. If you can settle for
manually flipping a switch, it is relatively easy, or you could
go a more complicated route and have software commands to cause a
port to drive a relay to do it.

Message has been deleted

J. Clarke

unread,
Aug 11, 2004, 10:31:45 PM8/11/04
to
Darren Harris wrote:

I'm going to give you a rather extreme suggestion that is quite workable and
about as secure as you're going to get with a single machine, but not
particularly simple or cheap. Run your Windows under VirtualPC for OS/2
with Netware 4.1 for OS/2, accessing your additional drives via Netware.
All runs on one box, quite reliable, performance is acceptable on modern
hardware, primary Internet exposure is OS/2 which if not bulletproof (and
OS/2 fans, I didn't say it wasn't bulletproof, just that even if it isn't)
is at least uncommon enough to be below the radar for crackers, you have
Novell's very robust and fine-grained security, you can do your
administration from a separate Windows session that is set up under IPX/SPX
and has no Internet access, so you can turn on and off privilege for your
working session as required, and your working Windows session is isolated
in the VirtualPC sandbox.

Less extreme, you could run your Windows session under VMWare on a Linux
box, with your additional drives accessed via SAMBA. Security is not as
fine-grained as Netware but should be plenty for what you want to do, you
can enable write access when desired from the Linux console without closing
Windows or unplugging anything, again Windows is isolated in a
virtual-machine sandbox, and primary internet exposure is Linux, which
while not below the radar doesn't have a whole heck of a lot of known
exploits extant.

Could also do this with VMware or VirtualPC under Windows, running
"dangerous" activities in the virtual session--this would be more secure
than running it in your console session but Windows would be exposed on the
Net, and there are known exploits that require only exposure. Again you'd
enable or disable write access from the console session.

> Thanks.
>
> Darren Harris
> Staten Island, New York.

--

CJT

unread,
Aug 11, 2004, 11:28:49 PM8/11/04
to
Don Taylor wrote:

> Sear...@mail.con2.com (Darren Harris) writes:
>
>>David Maynard <dNOT...@ev1.net> wrote in message news:<10hjhs9...@corp.supernews.com>...
>>
>>>Darren Harris wrote:
>>>
>>>>I just need a *simple* way to protect 3 out of 4 drives when not in
>>>>use, and save to them quickly when I have to.
>

> ...


>
>>Basically, I'd need for the "C" drive to "see" me as an
>>"Administrator", but not the other three drives. IS that possible?
>
>

> So, asking a question here, what would it take in terms of hardware
> between the IDE cable and the drive to make a (non-boot) drive
> read-only? Or maybe non-existant? Back in the old ST506/MFM days
> I imagine that a switch to disconnect the write signal to the drive
> would have done it. The same might be possible with (non-boot) IDE
> drives.
>
> And you might be able to accomplish the same with SCSI drives.
>
> Then you don't need any suspicious software to pay for, you don't
> need another operating system to use, any attempt to write to the
> drive would likely just get an error reported by your OS, and on
> the rare occasions you want to write to the drive you close the
> switch.

As I recall, to read an IDE drive you have to write to its registers.

Message has been deleted

CJT

unread,
Aug 12, 2004, 12:58:45 AM8/12/04
to
Don Taylor wrote:

> CJT <abuj...@prodigy.net> writes:


>
>>Don Taylor wrote:
>>
>>>So, asking a question here, what would it take in terms of hardware
>>>between the IDE cable and the drive to make a (non-boot) drive
>>>read-only? Or maybe non-existant? Back in the old ST506/MFM days
>>>I imagine that a switch to disconnect the write signal to the drive
>>>would have done it. The same might be possible with (non-boot) IDE
>>>drives.
>
>

>>As I recall, to read an IDE drive you have to write to its registers.
>
>

> I believe that is true, something like 8 registers make up IDE. You
> fill some of those with the block number on the drive and then fill
> a command register with a read command. But I've never found any
> info on someone trying to protect drives with this, or do other
> silly things like display the current block number on the front of
> the case, the way some wierd off-brand pc did fifteen years ago.
>
> thanks

The point is that the logic needed is more significant than simply
pulling down a write signal.

Darren Harris

unread,
Aug 12, 2004, 5:23:06 AM8/12/04
to
kony <sp...@spam.com> wrote in message news:<reelh095egpsvo4dq...@4ax.com>...

> On 11 Aug 2004 16:09:04 -0700, Sear...@mail.con2.com (Darren
> Harris) wrote:
>
>
> >It seems that you're talking about an all-or-nothing solution, and I
> >need complete freedom with *one* drive while protecting the others. Or
> >is there sommething I'm not being told?
>
> That you're trying to reinvent the wheel to a certain extent,
> that having protected data is the whole purpose behind removable
> media and/or disconnected backup storage?

But I'm talking about the option of keeping all my data in one
place(case) and protecting it.

I'm not trying to reinvent the wheel. The wheel is inherently faulty.
:-)

> The moment you are in a position to access those other drive(s),
> so is any virus/etc. If it were simply a matter of "denial" of
> access to drives, would viri exist at all? Could we not simply
> assign all file transfers to a ramdrive and deny all traditional
> physical storage rights?

There is no great technological hurdle in hardware manufacturers
making systems that give the user total control over the writing
between drives(without having to power them down), but they will not
do it.

> WinXP should be able to pick up a drive connected to a SCSI IDE
> controller if it is powered on, from being off, while system
> stays running, providing your SCSI controller also supports this.
> In other words, you'd be closing power circuit to drive to use
> it, then opening circuit again when done. If you can settle for
> manually flipping a switch, it is relatively easy, or you could
> go a more complicated route and have software commands to cause a
> port to drive a relay to do it.

Perhaps in the future one will have the option of "flipping a switch"
to quarantine specific drives, keeping them from being written to.

Darren Harris

unread,
Aug 12, 2004, 5:23:28 AM8/12/04
to
> Yes. Format them NTFS and then mount/dismount them when needed. Or buy
> 'removable' drives and 'unplug' them when not needed. Doesn't really matter
> because whatever vulnerability you're protecting them from will simply
> infect them the moment you activate them.

Not if I can shut down the "C" drive first. :-)

Nevertheless, if I have a system multiple drives inside it's case, I
shouldn't have to get "removable drives" in order to quarantine,
but...

The bottom line is that something that should be simple isn't because
there is too much money to be made using paid for solutions from that
hardware and software manufacturers.(Not to mention ITs). :-)

David Maynard

unread,
Aug 12, 2004, 5:46:48 AM8/12/04
to
Darren Harris wrote:

>>Yes. Format them NTFS and then mount/dismount them when needed. Or buy
>>'removable' drives and 'unplug' them when not needed. Doesn't really matter
>>because whatever vulnerability you're protecting them from will simply
>>infect them the moment you activate them.
>
>
> Not if I can shut down the "C" drive first. :-)

And just how are you going to automagically, and instantly, transfer the
operating system to something else so it runs when you 'shutdown' the C:
drive? Not to mention, where are you going to find uninfected OS files if
the C: drive is corrupted: the reason you're shutting it down?

If you're going to operate it as if it were 'two' machines, one with the
'internet' infected files that never talk to the 'safe' drives, and the
'safe' drives that never talk to the nasty infected one, then simply dual
boot the thing with the opposing drives dismounted and removed from the other.

> Nevertheless, if I have a system multiple drives inside it's case, I
> shouldn't have to get "removable drives" in order to quarantine,
> but...

And why not? Because you don't like the 'name'?

You presume there is some useful purpose to 'quarantining' hard drives but
there isn't; which answers your question of why they don't already do it.

>
> The bottom line is that something that should be simple isn't because
> there is too much money to be made using paid for solutions from that
> hardware and software manufacturers.(Not to mention ITs). :-)

No, the bottom line is that your proposed 'solution' does not solve the
problem you base it on any better than the solutions already available.

Mike Redrobe

unread,
Aug 12, 2004, 8:56:09 AM8/12/04
to
Darren Harris wrote:
>> Yes. Format them NTFS and then mount/dismount them when needed. Or
>> buy 'removable' drives and 'unplug' them when not needed. Doesn't
>> really matter because whatever vulnerability you're protecting them
>> from will simply infect them the moment you activate them.
>
> Nevertheless, if I have a system multiple drives inside it's case, I
> shouldn't have to get "removable drives" in order to quarantine,
> but...
>
> The bottom line is that something that should be simple isn't because
> there is too much money to be made using paid for solutions from that
> hardware and software manufacturers.(Not to mention ITs). :-)

If you *really* want hardware level write-protection of hard drives
you have to look to the forensics industry - see links below...

This stuff isn't cheap though:

"This special Write-Protect version of the ARS7720UW disables the ability to
write to the
connected IDE drive. For auditability of forensic data this is an essential
product."
http://www.verbatim.com.au/products.cfm?productID=ARS7720WP

"SCSIBLOCK is a 68 Pin SCSI-3 to IDE conversion device that provides full
hardware
write protection to IDE devices while permitting direct connection to any
SCSI-3 bus."
http://www.digitalintel.com/scsiblock.htm

http://www.logicubeforensics.com/products/accessories/desktopwriteprotect.asp

http://www.forensicpc.com/products.asp?cat=19

http://www.memstore.se/LEVEL2/PRODUKTER/LEVEL3/FORENSIC/LEVEL2/DriveLock.htm

There are older IDE drives which had a write-protect jumper (I have an
ancient fujitsu
500Mb drive with one), it is/was much more common on SCSI drives though.

IIRC I'm sure I`ve seen this option in the BIOS of a SCSI adaptor as well.

It isn't as simple as cutting a wire on the ribbon....

--
Mike


J. Clarke

unread,
Aug 12, 2004, 10:00:34 AM8/12/04
to
Darren Harris wrote:

> kony <sp...@spam.com> wrote in message
> news:<reelh095egpsvo4dq...@4ax.com>...
>> On 11 Aug 2004 16:09:04 -0700, Sear...@mail.con2.com (Darren
>> Harris) wrote:
>>
>>
>> >It seems that you're talking about an all-or-nothing solution, and I
>> >need complete freedom with *one* drive while protecting the others. Or
>> >is there sommething I'm not being told?
>>
>> That you're trying to reinvent the wheel to a certain extent,
>> that having protected data is the whole purpose behind removable
>> media and/or disconnected backup storage?
>
> But I'm talking about the option of keeping all my data in one
> place(case) and protecting it.
>
> I'm not trying to reinvent the wheel. The wheel is inherently faulty.
> :-)
>
>> The moment you are in a position to access those other drive(s),
>> so is any virus/etc. If it were simply a matter of "denial" of
>> access to drives, would viri exist at all? Could we not simply
>> assign all file transfers to a ramdrive and deny all traditional
>> physical storage rights?
>
> There is no great technological hurdle in hardware manufacturers
> making systems that give the user total control over the writing
> between drives(without having to power them down), but they will not
> do it.

Perhaps there is no demand for this feature?

>> WinXP should be able to pick up a drive connected to a SCSI IDE
>> controller if it is powered on, from being off, while system
>> stays running, providing your SCSI controller also supports this.
>> In other words, you'd be closing power circuit to drive to use
>> it, then opening circuit again when done. If you can settle for
>> manually flipping a switch, it is relatively easy, or you could
>> go a more complicated route and have software commands to cause a
>> port to drive a relay to do it.
>
> Perhaps in the future one will have the option of "flipping a switch"
> to quarantine specific drives, keeping them from being written to.

Perhaps. Personally I would rate the probability of it occurring on par
with the probability that Santa Claus and the Easter Bunny will have a
boxing match in Madison Square Garden. For the two people in the universe
who percieve this need there are ways to accomplish that objective with
software. If you aren't willing to do what you have to to get there then
you don't have a _need_, you have an idle whim.

> Darren Harris
> Staten Island, New York.

--

Alexander Grigoriev

unread,
Aug 12, 2004, 11:23:06 AM8/12/04
to
Another variant of isolating internet-connected system with Vmware:

If you use PPPoE access with an ADSL modem configured as RFC1483 bridge
(assumes that a PPpoE client driver runs on the host), you can bridge those
PPPoE packets to the VM and run RASPPPOE there. Only VM will have Internet
access. Any packets going through the physical host will be benign PPPoE
packets, not able to do anything with the host.

"J. Clarke" <jcl...@nospam.invalid> wrote in message
news:cfemf...@news4.newsguy.com...

Darren Harris

unread,
Aug 12, 2004, 1:59:55 PM8/12/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10hmf42...@corp.supernews.com>...

> Darren Harris wrote:
>
> >>Yes. Format them NTFS and then mount/dismount them when needed. Or buy
> >>'removable' drives and 'unplug' them when not needed. Doesn't really matter
> >>because whatever vulnerability you're protecting them from will simply
> >>infect them the moment you activate them.
> >
> >
> > Not if I can shut down the "C" drive first. :-)
>
> And just how are you going to automagically, and instantly, transfer the
> operating system to something else so it runs when you 'shutdown' the C:
> drive? Not to mention, where are you going to find uninfected OS files if
> the C: drive is corrupted: the reason you're shutting it down?

No that wouldn't be the reason I'm shutting it down. You're missing
the whole point. I'm conveying inherent software(OS) limitations that
shouldn't exist. My first system had the OS on all three drives. But
thanks to the way software is written, if my "C" drive went down, I
still wouldn't be able to use my other drives without major changes to
my system first.

> If you're going to operate it as if it were 'two' machines, one with the
> 'internet' infected files that never talk to the 'safe' drives, and the
> 'safe' drives that never talk to the nasty infected one, then simply dual
> boot the thing with the opposing drives dismounted and removed from the other.

Again, you are missing the point. Re-read the above posts. You're
repeating what has already been said. And it's not in line with my
goal.(Achievable or not).

> > Nevertheless, if I have a system multiple drives inside it's case, I
> > shouldn't have to get "removable drives" in order to quarantine,
> > but...
>
> And why not? Because you don't like the 'name'?

That made no sense whatsoever. Again, re-read the above posts. I
already gave the reasons why that wasn't an option.

> You presume there is some useful purpose to 'quarantining' hard drives but
> there isn't; which answers your question of why they don't already do it.

You are incorrect. The reasons are amazingly obvious, and have already
been mentioned here.

> > The bottom line is that something that should be simple isn't because
> > there is too much money to be made using paid for solutions from that
> > hardware and software manufacturers.(Not to mention ITs). :-)
>
> No, the bottom line is that your proposed 'solution' does not solve the
> problem you base it on any better than the solutions already available.

Sigh... Wrong. THis isn't about a "proposed solution". I indicated
what I wanted to do and why.(Re-read the post that started this
thread). The posters in this thread only had to say it is *not*
possible.

ie: "One cannot "quarantine" three drives from a fourth, or change
write options on the fly." I've come to this conclusion myself based
on what was said.

Darren Harris

unread,
Aug 12, 2004, 2:39:11 PM8/12/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10hleg7...@corp.supernews.com>...

> Darren Harris wrote:
> > David Maynard <dNOT...@ev1.net> wrote in message news:<10hjhs9...@corp.supernews.com>...
> >
> >>Darren Harris wrote:
> >>
> >>>I just need a *simple* way to protect 3 out of 4 drives when not in
> >>>use, and save to them quickly when I have to. So having to create Zip
> >>>drives or getting a server to store my files is not an option. And
> >>>paying $30 for an unproven app(wiht very little comments about it on
> >>>the net) that *might* protect my drives from hacking and viruses
> >>>doesn't seem plausible.
> >>
> >>
> >> > And I don't know how it is possible to get 3
>
> >>>out of four drives to recognize me as an "Administrator" with the one
> >>>single drive allowing full access.
> >>
> >>You don't. He's telling you how do operate the machine so ALL 'drives' are
> >>as protected as they can be. You should not normally be logged on as an
> >>administrator so that any malicious code you run across then has full
> >>administrator rights to run through the system at will.
> >
> >
> > But since as I said, I'll be working with my "C" drive
>
> And what does 'working with' the C drive mean?

?!? I assume you don't understand that the "C" drive is the drive that
I want to isolate the other three from or that it is the one that will
be used when connected to the internet, correct?

> >(and will only
> > occasionally need to copy to the other three), it seems that I won't
> > have the freemdom I need with that drive until I login in as an
> > "Administrator", which of course opens up the other drives to
> > malicious code.
>
> Your 'plan' opens them to malicious code by leaving your C: drive
> completely unprotected, so that it can become infected, and then it infects
> the other drives the instant you 'spin them up'.

How is the "C" drive "completely unprotected", when there are
anti-virus and firewall utilities?

> > It seems that you're talking about an all-or-nothing solution, and I
> > need complete freedom with *one* drive while protecting the others. Or
> > is there sommething I'm not being told?
>
> You're asking for 'complete freedom', why I don't know, for the drive on
> which an infection is most likely since every targeted vulnerability
> resides on it, and the one where it matter most, yet want to be
> 'protected'. Just ain't going to happen.

See my last paragraph.

> >>Then you can change write rights on the 'protected' drives, or anything
> >>else you want 'protected', so that nothing but an administrator has write
> >>rights and since you will not be logged on as administrator no malicious
> >>code can use your rights to alter them.
> >
> >
> > Basically, I'd need for the "C" drive to "see" me as an
> > "Administrator", but not the other three drives. IS that possible?
>
> Yes. Format them NTFS and then mount/dismount them when needed. Or buy
> 'removable' drives and 'unplug' them when not needed. Doesn't really matter
> because whatever vulnerability you're protecting them from will simply
> infect them the moment you activate them.

We've been through this already...

Darren Harris

unread,
Aug 12, 2004, 2:51:19 PM8/12/04
to
> >> The moment you are in a position to access those other drive(s),
> >> so is any virus/etc. If it were simply a matter of "denial" of
> >> access to drives, would viri exist at all? Could we not simply
> >> assign all file transfers to a ramdrive and deny all traditional
> >> physical storage rights?
> >
> > There is no great technological hurdle in hardware manufacturers
> > making systems that give the user total control over the writing
> > between drives(without having to power them down), but they will not
> > do it.
>
> Perhaps there is no demand for this feature?

?!? There would be if it were an option.

> >> WinXP should be able to pick up a drive connected to a SCSI IDE
> >> controller if it is powered on, from being off, while system
> >> stays running, providing your SCSI controller also supports this.
> >> In other words, you'd be closing power circuit to drive to use
> >> it, then opening circuit again when done. If you can settle for
> >> manually flipping a switch, it is relatively easy, or you could
> >> go a more complicated route and have software commands to cause a
> >> port to drive a relay to do it.
> >
> > Perhaps in the future one will have the option of "flipping a switch"
> > to quarantine specific drives, keeping them from being written to.
>
> Perhaps. Personally I would rate the probability of it occurring on par
> with the probability that Santa Claus and the Easter Bunny will have a
> boxing match in Madison Square Garden. For the two people in the universe
> who percieve this need there are ways to accomplish that objective with
> software. If you aren't willing to do what you have to to get there then
> you don't have a _need_, you have an idle whim.

The inability to understand what I've written by *some* of the posters
in this thread is astounding.

I saw a problem. I asked if there a particular solution was possible.
And if so, how to do it. The common concensus *seems* to be that it is
*not* possible. Just because I find certain solutions given to be
impractical for me doesn't mean that I am "willing to do what (I) have
to to get there". It has become obvious that it isn't possible to have
the options I want, and I conveyed that it should be, and gave the
reasons. And I gave the reasons why the "proposed" solutions would not
work for me. That's all.

What's is so difficult to understand?

It's a good thing that inovative minds are not on "lock-down" like
that minds of many here.

Darren Harris
Staten ISland, New York.

Darren Harris

unread,
Aug 12, 2004, 2:53:49 PM8/12/04
to
"J. Clarke" <jcl...@nospam.invalid> wrote in message news:<cfemf...@news4.newsguy.com>...

The cost, learning curve, and relative support make all of this
impractical as far as what I'd like to do.

Alexander Grigoriev

unread,
Aug 12, 2004, 4:35:07 PM8/12/04
to
OK, here is a procedure for you:

1. Assume your drives you want to protect are formatted as NTFS. The example
goes for a drive E:
2. Create an user account, for example "PowerfulMe". It can be a limited
user, too. Set a password on it.
3. Run the following (while logged as an administrator):

cacls E: /g Everyone:r Administrators:f SYSTEM:f PowerfulMe:c
OWNER_CREATOR:f

4. When you want to copy files to E: (while logged as a regular user),
right-click on blue IE icon, select RunAs, enter PowerfulMe and its
password. Enter e:\ in the address line. Click on [Folders] button. Copy the
source files to the drive. It's assumed that you gave PowerfulMe
read-permissions to the source files. When you're done copying, close the
Explorer window, which runs as PowerfulMe. You can also run copy with a
command-line script, if you open a command console with Run As.

You can have a separate account with write privileges for each drive, if you
like.

"Darren Harris" <Sear...@mail.con2.com> wrote in message
news:9437a27c.04081...@posting.google.com...

J. Clarke

unread,
Aug 12, 2004, 5:19:53 PM8/12/04
to
Darren Harris wrote:

The cost and learning curve might be an issue. The "relative support" is
minor--once you have OS/2 and Novell up and running they don't need much in
the way of support, they just kind of sit there and work.

Are you looking for a solution for a personal machine or for some other
purpose? If some other purpose if you gave some details someone might be
able to propose a workable solution.

> Thanks.
>
> Darren Harris
> Staten Island, New York.

--

J. Clarke

unread,
Aug 12, 2004, 5:23:38 PM8/12/04
to
Darren Harris wrote:

>> >> The moment you are in a position to access those other drive(s),
>> >> so is any virus/etc. If it were simply a matter of "denial" of
>> >> access to drives, would viri exist at all? Could we not simply
>> >> assign all file transfers to a ramdrive and deny all traditional
>> >> physical storage rights?
>> >
>> > There is no great technological hurdle in hardware manufacturers
>> > making systems that give the user total control over the writing
>> > between drives(without having to power them down), but they will not
>> > do it.
>>
>> Perhaps there is no demand for this feature?
>
> ?!? There would be if it were an option.

It was on some drives. The market apparently gave a great big yawn and the
drive manufacturers decided that they had wasted the 2 cents or whatever it
is that the header for the jumper costs and quit providing such a feature.

>> >> WinXP should be able to pick up a drive connected to a SCSI IDE
>> >> controller if it is powered on, from being off, while system
>> >> stays running, providing your SCSI controller also supports this.
>> >> In other words, you'd be closing power circuit to drive to use
>> >> it, then opening circuit again when done. If you can settle for
>> >> manually flipping a switch, it is relatively easy, or you could
>> >> go a more complicated route and have software commands to cause a
>> >> port to drive a relay to do it.
>> >
>> > Perhaps in the future one will have the option of "flipping a switch"
>> > to quarantine specific drives, keeping them from being written to.
>>
>> Perhaps. Personally I would rate the probability of it occurring on par
>> with the probability that Santa Claus and the Easter Bunny will have a
>> boxing match in Madison Square Garden. For the two people in the
>> universe who percieve this need there are ways to accomplish that
>> objective with
>> software. If you aren't willing to do what you have to to get there then
>> you don't have a _need_, you have an idle whim.
>
> The inability to understand what I've written by *some* of the posters
> in this thread is astounding.
>
> I saw a problem. I asked if there a particular solution was possible.
> And if so, how to do it. The common concensus *seems* to be that it is
> *not* possible. Just because I find certain solutions given to be
> impractical for me doesn't mean that I am "willing to do what (I) have
> to to get there".

Of course it doesn't. If you _were_ willing then you would go with one of
the solutions that does not require custom drive firmware.

> It has become obvious that it isn't possible to have
> the options I want, and I conveyed that it should be, and gave the
> reasons. And I gave the reasons why the "proposed" solutions would not
> work for me. That's all.
>
> What's is so difficult to understand?
>
> It's a good thing that inovative minds are not on "lock-down" like
> that minds of many here.

The fact that someone disagrees with you does not mean that his "mind is on
lock-down". It may mean that he has seen the feature you want come and go
in the market without anybody to speak of wanting it.

> Darren Harris
> Staten ISland, New York.

--

David Maynard

unread,
Aug 13, 2004, 4:14:02 AM8/13/04
to
Darren Harris wrote:

> David Maynard <dNOT...@ev1.net> wrote in message news:<10hmf42...@corp.supernews.com>...
>
>>Darren Harris wrote:
>>
>>
>>>>Yes. Format them NTFS and then mount/dismount them when needed. Or buy
>>>>'removable' drives and 'unplug' them when not needed. Doesn't really matter
>>>>because whatever vulnerability you're protecting them from will simply
>>>>infect them the moment you activate them.
>>>
>>>
>>>Not if I can shut down the "C" drive first. :-)
>>
>>And just how are you going to automagically, and instantly, transfer the
>>operating system to something else so it runs when you 'shutdown' the C:
>>drive? Not to mention, where are you going to find uninfected OS files if
>>the C: drive is corrupted: the reason you're shutting it down?
>
>
> No that wouldn't be the reason I'm shutting it down. You're missing
> the whole point. I'm conveying inherent software(OS) limitations that
> shouldn't exist. My first system had the OS on all three drives. But
> thanks to the way software is written, if my "C" drive went down, I
> still wouldn't be able to use my other drives without major changes to
> my system first.

I have no idea what you mean by 'unable' to 'use' your 'other drives' but
if you mean the system not operating with a third of the OS missing from,
as you put it, the C: drive going down then that is a big "well, Duh." Not
to mention I can't figure out what the heck that has to do with
'quarantining' drives.

I did read your originals and don't recall this new 'criteria' about the OS
spread over three drives, which would make 'quarantining' them rather
unworkable to begin with.

Frankly, I think you just want to 'complain' that operating systems aren't
made the way you think they should be and are artificially manufacturing
'requirements' to suit your preconceived 'solution' rather than seeking
workable ones. But since you've decided 'it' is, whatever 'it' is now,
impossible I'll leave it at that.

David Maynard

unread,
Aug 13, 2004, 4:18:24 AM8/13/04
to
Darren Harris wrote:

Yes. And since you're obviously not interested in a workable solution but
merely complaining that operating systems don't natively support your
'idea' then there's not really any need to go on about it.

Darren Harris

unread,
Aug 13, 2004, 5:52:46 AM8/13/04
to
"Alexander Grigoriev" <al...@earthlink.net> wrote in message news:<%vQSc.18826$9Y6....@newsread1.news.pas.earthlink.net>...

> OK, here is a procedure for you:
>
> 1. Assume your drives you want to protect are formatted as NTFS. The example
> goes for a drive E:
> 2. Create an user account, for example "PowerfulMe". It can be a limited
> user, too. Set a password on it.
> 3. Run the following (while logged as an administrator):
>
> cacls E: /g Everyone:r Administrators:f SYSTEM:f PowerfulMe:c
> OWNER_CREATOR:f
>
> 4. When you want to copy files to E: (while logged as a regular user),
> right-click on blue IE icon, select RunAs, enter PowerfulMe and its
> password. Enter e:\ in the address line. Click on [Folders] button. Copy the
> source files to the drive. It's assumed that you gave PowerfulMe
> read-permissions to the source files. When you're done copying, close the
> Explorer window, which runs as PowerfulMe. You can also run copy with a
> command-line script, if you open a command console with Run As.
>
> You can have a separate account with write privileges for each drive, if you
> like.

Since "NTSF", "user accounts", and "command lines" are things I'm not
familiar with, I'll have to do some research. :-)

Thanks.

Darren Harris

unread,
Aug 13, 2004, 5:58:33 AM8/13/04
to
"J. Clarke" <jcl...@nospam.invalid> wrote in message news:<cfgnh...@news1.newsguy.com>...

> Darren Harris wrote:
>
> >> >> The moment you are in a position to access those other drive(s),
> >> >> so is any virus/etc. If it were simply a matter of "denial" of
> >> >> access to drives, would viri exist at all? Could we not simply
> >> >> assign all file transfers to a ramdrive and deny all traditional
> >> >> physical storage rights?
> >> >
> >> > There is no great technological hurdle in hardware manufacturers
> >> > making systems that give the user total control over the writing
> >> > between drives(without having to power them down), but they will not
> >> > do it.
> >>
> >> Perhaps there is no demand for this feature?
> >
> > ?!? There would be if it were an option.
>
> It was on some drives. The market apparently gave a great big yawn and the
> drive manufacturers decided that they had wasted the 2 cents or whatever it
> is that the header for the jumper costs and quit providing such a feature.

If this is true, then having toopen ones case and navigate to a drive
to manipulate those jumpers would have been a stupid idea anyway.

If I were willing.

> > It has become obvious that it isn't possible to have
> > the options I want, and I conveyed that it should be, and gave the
> > reasons. And I gave the reasons why the "proposed" solutions would not
> > work for me. That's all.
> >
> > What's is so difficult to understand?
> >
> > It's a good thing that inovative minds are not on "lock-down" like
> > that minds of many here.
>
> The fact that someone disagrees with you does not mean that his "mind is on
> lock-down". It may mean that he has seen the feature you want come and go
> in the market without anybody to speak of wanting it.

It has nothing to do with disagreeing with me. It is the inability to
see the obvious facets of what I'm talking about. And what I'm
referring to was definitely never an option in the market place.

Darren Harris
Staten Island New York.

Darren Harris

unread,
Aug 13, 2004, 6:02:46 AM8/13/04
to
"J. Clarke" <jcl...@nospam.invalid> wrote in message news:<cfgnh...@news1.newsguy.com>...


Well, it would be my personal machine.

I'd like too point out that I'd be frequently erasing and
re-installing the OS(along with basic software) from one of the
quarantine drives back to the "C" drive.(This would be sort of a
cleansing operation).

J. Clarke

unread,
Aug 13, 2004, 10:32:35 AM8/13/04
to
Darren Harris wrote:

If you aren't willing to do what you have to do to achieve an objective then
you don't _need_ to achieve that objective.

>> > It has become obvious that it isn't possible to have
>> > the options I want, and I conveyed that it should be, and gave the
>> > reasons. And I gave the reasons why the "proposed" solutions would not
>> > work for me. That's all.
>> >
>> > What's is so difficult to understand?
>> >
>> > It's a good thing that inovative minds are not on "lock-down" like
>> > that minds of many here.
>>
>> The fact that someone disagrees with you does not mean that his "mind is
>> on
>> lock-down". It may mean that he has seen the feature you want come and
>> go in the market without anybody to speak of wanting it.
>
> It has nothing to do with disagreeing with me. It is the inability to
> see the obvious facets of what I'm talking about. And what I'm
> referring to was definitely never an option in the market place.

OK, let me try to explain this clearly.

You want to be able to write-protect disks.

There are two ways to do this--you can do it in such a manner that it is
hardware-controlled or software-controlled.

If you make it hardware-controlled, that means a switch or jumper on the
drive to turn write-enable on or off. Such a feature used to be common on
drives and no longer is due to lack of interest. There are expensive
solutions that achieve the same objective today aimed at the forensics
market, which is a niche too small to make it worthwhile for the drive
manufacturers to re-implement this feature in their drives.

If you make it software controlled, any attack that circumvents your OS
security can also write-enable the drive, unless you put some kind of
elaborate security system in the drive firmware. Absent a clear demand for
a large quantity of drives with such a security system, that's not going to
happen.

All current major operating systems except Windows 9x/ME provide some
mechanism for controlling write-access to the drives. If an exploit
manages to circumvent this mechanism then it will also be able to
circumvent any software-controlled write-enable mechanism on the drives
unless that mechanism has its own independent security enforced by the
drive firmware. So by using the mechanisms in the OS you're going to be
able to protect the drives from unauthorized writes as securely as could be
done with any reasonably simple software-controllable mechanism built into
the drive.

> Darren Harris
> Staten Island New York.

--

Darren Harris

unread,
Aug 13, 2004, 7:33:22 PM8/13/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10hou24...@corp.supernews.com>...

> Darren Harris wrote:
>
> > David Maynard <dNOT...@ev1.net> wrote in message news:<10hmf42...@corp.supernews.com>...
> >
> >>Darren Harris wrote:
> >>
> >>
> >>>>Yes. Format them NTFS and then mount/dismount them when needed. Or buy
> >>>>'removable' drives and 'unplug' them when not needed. Doesn't really matter
> >>>>because whatever vulnerability you're protecting them from will simply
> >>>>infect them the moment you activate them.
> >>>
> >>>
> >>>Not if I can shut down the "C" drive first. :-)
> >>
> >>And just how are you going to automagically, and instantly, transfer the
> >>operating system to something else so it runs when you 'shutdown' the C:
> >>drive? Not to mention, where are you going to find uninfected OS files if
> >>the C: drive is corrupted: the reason you're shutting it down?
> >
> >
> > No that wouldn't be the reason I'm shutting it down. You're missing
> > the whole point. I'm conveying inherent software(OS) limitations that
> > shouldn't exist. My first system had the OS on all three drives. But
> > thanks to the way software is written, if my "C" drive went down, I
> > still wouldn't be able to use my other drives without major changes to
> > my system first.
>
> I have no idea what you mean by 'unable' to 'use' your 'other drives' but
> if you mean the system not operating with a third of the OS missing from,
> as you put it, the C: drive going down then that is a big "well, Duh." Not
> to mention I can't figure out what the heck that has to do with
> 'quarantining' drives.

Me either. I never said anything about "a third of the OS missing"
from the "C" drive.

Again, I never said anything about the "OS spread over three drives.

> Frankly, I think you just want to 'complain' that operating systems aren't
> made the way you think they should be and are artificially manufacturing
> 'requirements' to suit your preconceived 'solution' rather than seeking
> workable ones. But since you've decided 'it' is, whatever 'it' is now,
> impossible I'll leave it at that.

I hope so. Since you have completely failed to understand what I've
said.

Darren Harris

unread,
Aug 13, 2004, 7:55:31 PM8/13/04
to
> > If I were willing.
>
> If you aren't willing to do what you have to do to achieve an objective then
> you don't _need_ to achieve that objective.

Well since you don't understand the "objective", you cannot say that.

> OK, let me try to explain this clearly.
>
> You want to be able to write-protect disks.

I want to protect my three disks from malicious code that would come
from my "C" disk which of course would be the "doorway" since it would
have whatever software needed for surfing the internet. I'm told in
this thread that the only way to protect the three disks is to
write-protect them.



> There are two ways to do this--you can do it in such a manner that it is
> hardware-controlled or software-controlled.

I know that.

> If you make it hardware-controlled, that means a switch or jumper on the
> drive to turn write-enable on or off. Such a feature used to be common on
> drives and no longer is due to lack of interest. There are expensive
> solutions that achieve the same objective today aimed at the forensics
> market, which is a niche too small to make it worthwhile for the drive
> manufacturers to re-implement this feature in their drives.

Again, if that was done, then it it obvious why such a feature
wouldn't be popular. Who would want to have to unscrew their case and
navigate to their drives to manipulate a tiny jumper everytime they
had to save something to any of their disks?

> If you make it software controlled, any attack that circumvents your OS
> security can also write-enable the drive, unless you put some kind of
> elaborate security system in the drive firmware. Absent a clear demand for
> a large quantity of drives with such a security system, that's not going to
> happen.

Obviously. And certain people seem to have a problem with me conveying
that the developers/manufacturers have the technology to impliment
something as simple as what I said, but refuse to. To say they are
incapable of doing it, is to say they are extremely stupid.

> All current major operating systems except Windows 9x/ME provide some
> mechanism for controlling write-access to the drives. If an exploit
> manages to circumvent this mechanism then it will also be able to
> circumvent any software-controlled write-enable mechanism on the drives
> unless that mechanism has its own independent security enforced by the
> drive firmware. So by using the mechanisms in the OS you're going to be
> able to protect the drives from unauthorized writes as securely as could be
> done with any reasonably simple software-controllable mechanism built into
> the drive.

And you do't think that an easily accessable switch on the outside of
one's case to control writes to individual drives would be a good idea
if implimented?

As far as controlling drive write via the OS, I was looking for a way
to *easily* and *quickly* turn off/on the write to any of the other
three drives, but again, going by what is said in this thread it
cannot be done. And obviously from what I'm told here powering down
the three drives *easily* and *quickly* to prevent writing to the
drives also cannot be done.

That's it.

David Maynard

unread,
Aug 13, 2004, 10:31:03 PM8/13/04
to
Darren Harris wrote:

Neither did I.

You said "the OS on all three drives" followed by "if my "C" drive went
down." If 'the OS' is "on all three drives" and one of them goes down, you
said the "C" drive, then that portion of the OS is now 'missing' because
the damn drive it's located on isn't operating.

Like I said, you're not interested in solving any 'problem' but in just
complaining.

The exact quote from your own text, still up there, is "the OS on all three
drives."

I suppose that's another example of how 'clearly' you've explained everything.

>
>
>>Frankly, I think you just want to 'complain' that operating systems aren't
>>made the way you think they should be and are artificially manufacturing
>>'requirements' to suit your preconceived 'solution' rather than seeking
>>workable ones. But since you've decided 'it' is, whatever 'it' is now,
>>impossible I'll leave it at that.
>
>
> I hope so. Since you have completely failed to understand what I've
> said.

No, it's because you failed to explain anything with any clarity; instead
using such 'clear as mud' generalities as "work with" and "the OS on three
drives."

J. Clarke

unread,
Aug 14, 2004, 2:24:38 AM8/14/04
to
Darren Harris wrote:

I believe that I pointed out earlier that it is very easy to attach a switch
to the pins on which the jumper is normally installed and put that switch
outside the computer case. If not, then I am pointing this out again.

>> If you make it software controlled, any attack that circumvents your OS
>> security can also write-enable the drive, unless you put some kind of
>> elaborate security system in the drive firmware. Absent a clear demand
>> for a large quantity of drives with such a security system, that's not
>> going to happen.
>
> Obviously. And certain people seem to have a problem with me conveying
> that the developers/manufacturers have the technology to impliment
> something as simple as what I said, but refuse to. To say they are
> incapable of doing it, is to say they are extremely stupid.

If in fact they have that technology please be kind enough to describe it in
detail.

>> All current major operating systems except Windows 9x/ME provide some
>> mechanism for controlling write-access to the drives. If an exploit
>> manages to circumvent this mechanism then it will also be able to
>> circumvent any software-controlled write-enable mechanism on the drives
>> unless that mechanism has its own independent security enforced by the
>> drive firmware. So by using the mechanisms in the OS you're going to be
>> able to protect the drives from unauthorized writes as securely as could
>> be done with any reasonably simple software-controllable mechanism built
>> into the drive.
>
> And you do't think that an easily accessable switch on the outside of
> one's case to control writes to individual drives would be a good idea
> if implimented?

Again, that feature _was_ implemented and nobody wanted it.

> As far as controlling drive write via the OS, I was looking for a way
> to *easily* and *quickly* turn off/on the write to any of the other
> three drives, but again, going by what is said in this thread it
> cannot be done. And obviously from what I'm told here powering down
> the three drives *easily* and *quickly* to prevent writing to the
> drives also cannot be done.
>
> That's it.
>
> Darren Harris
> Staten ISland, New York.

--

Darren Harris

unread,
Aug 14, 2004, 5:50:49 AM8/14/04
to
> > Me either. I never said anything about "a third of the OS missing"
> > from the "C" drive.
>
> Neither did I.

Yes you did. Anyone can look and see that that is your exact quote. In
fact here is the entire paragraph:


"I have no idea what you mean by 'unable' to 'use' your 'other drives'
but
if you mean the system not operating with a third of the OS missing
from,
as you put it, the C: drive going down then that is a big "well, Duh."
Not
to mention I can't figure out what the heck that has to do with
'quarantining' drives."

> You said "the OS on all three drives" followed by "if my "C" drive went

> down." If 'the OS' is "on all three drives" and one of them goes down, you
> said the "C" drive, then that portion of the OS is now 'missing' because
> the damn drive it's located on isn't operating.

Your massive incomprehension is unbelieveable. *You* asked, "And just


how are you going to automagically, and instantly, transfer the
operating system to something else so it runs when you 'shutdown' the
C: drive?"

And I attempted to convey that *my first system* had the OS on all
three drives. So obviously the idea is that there would be a complete
copy of the OS on each of the four hard drives in the *new* system I
want to build. Now why would anyone want to stripe an OS across
multiple hard drives? I went on to say, "But thanks to the way


software is written, if my "C" drive went down, I still wouldn't be
able to use my other drives without major changes to my system first."

Which means that an entire copy of the OS on *each* of the drives
still wouldn't help me.

Now why is this so difficult for you to understand???

> Like I said, you're not interested in solving any 'problem' but in just
> complaining.

I've come to the conclusion that what I want to do cannot be done. It
is you who are instigating.

How can you possible believe you can get away with false info when the
evidence is up there as you say. Anyone can read the posts. The key
word is "spread", which *you* said. Not me. And again I was referring
to a previous system("my first system") I had, and a copy of the OS on
each of it's three drives. But of course that could not have possibly
occurred to you, because it was logical.

> >>Frankly, I think you just want to 'complain' that operating systems aren't
> >>made the way you think they should be and are artificially manufacturing
> >>'requirements' to suit your preconceived 'solution' rather than seeking
> >>workable ones. But since you've decided 'it' is, whatever 'it' is now,
> >>impossible I'll leave it at that.
> >
> >
> > I hope so. Since you have completely failed to understand what I've
> > said.
>
> No, it's because you failed to explain anything with any clarity; instead
> using such 'clear as mud' generalities as "work with" and "the OS on three
> drives."

The problem is your inability to comprehend what everyone else can.

David Maynard

unread,
Aug 14, 2004, 8:05:20 AM8/14/04
to
Darren Harris wrote:

>>>Me either. I never said anything about "a third of the OS missing"
>>>from the "C" drive.
>>
>>Neither did I.
>
> Yes you did. Anyone can look and see that that is your exact quote. In
> fact here is the entire paragraph:
> "I have no idea what you mean by 'unable' to 'use' your 'other drives'
> but
> if you mean the system not operating with a third of the OS missing
> from,
> as you put it, the C: drive going down then that is a big "well, Duh."
> Not
> to mention I can't figure out what the heck that has to do with
> 'quarantining' drives."

Reading comprehension isn't your strong suit, I see.

I said "a third of the OS missing from, as you put it,"
----> "the C: drive going down" <----
NOT "the C: drive" as you claimed.

>>You said "the OS on all three drives" followed by "if my "C" drive went
>>down." If 'the OS' is "on all three drives" and one of them goes down, you
>>said the "C" drive, then that portion of the OS is now 'missing' because
>>the damn drive it's located on isn't operating.
>
>
> Your massive incomprehension is unbelieveable. *You* asked, "And just
> how are you going to automagically, and instantly, transfer the
> operating system to something else so it runs when you 'shutdown' the
> C: drive?"

Not a surprising 'opinion' coming from someone who can't read nor type with
any clarity.

> And I attempted to convey that *my first system* had the OS on all
> three drives.

Yes. And the word "the" is singular, as in one: I.E. "the O.S." The first
impression for "the O.S." 'on three drives' is "the O.S." 'spread' across
them, not 3 bloody COPIES of the silly thing as you now seem to indicate.
Why anyone would want 3 COPIES on three drives is another mystery you leave
unanswered.

> So obviously the idea is that there would be a complete
> copy of the OS on each of the four hard drives in the *new* system I
> want to build.

And what is so 'obvious' about someone being nutty enough to want 4
"complete" COPIES of their OS on 4 drives?

> Now why would anyone want to stripe an OS across
> multiple hard drives?

You apparently don't know about RAID. Why? Speed, fault tolerance. Depends
on how much of each you want and how much you're willing to spend to get it.

And it's a hell of a lot more common that someone keeping '3 copies on 3
hard drives'.

> I went on to say, "But thanks to the way
> software is written, if my "C" drive went down, I still wouldn't be
> able to use my other drives without major changes to my system first."
> Which means that an entire copy of the OS on *each* of the drives
> still wouldn't help me.

Well, it might if it were installed on each; you could simply boot from the
alternate. But then no one knows what the heck YOU mean by a 'copy' ('copy'
of the CD? Copy of just the install files? a 'copy' of the files as
installed on C:? an INSTALLED to THAT drive 'copy'?), nor why you had 3
copies on 3 drives in your previous system, nor what the heck you mean by
(would or wouldn't) 'help me' (do WHAT? boot? clean C:? repair C:? recover
data from C:? or lord knows.).

> Now why is this so difficult for you to understand???

Because you talk in generic riddles, adding information only when you want
to shoot down something (and you've shot down every suggestion from every
poster in the group who was trying to help you) and, even then, not
explaining enough of it to know what the hell you're trying to do or why.

>>Like I said, you're not interested in solving any 'problem' but in just
>>complaining.
>
>
> I've come to the conclusion that what I want to do cannot be done. It
> is you who are instigating.

The case is that your proposed 'solution' for whatever it is you're
actually trying to accomplish but which, for some bizarre reason, you seem
compelled to keep as friggin secret and unexplained as possible, is not
commonly available.

Whether what you're actually "trying to do," whatever the hell it is, could
be done or not is an unanswerable question given the current lack of any
sensible information about it.

It didn't occur to me because it's nonsensical.

>>>>Frankly, I think you just want to 'complain' that operating systems aren't
>>>>made the way you think they should be and are artificially manufacturing
>>>>'requirements' to suit your preconceived 'solution' rather than seeking
>>>>workable ones. But since you've decided 'it' is, whatever 'it' is now,
>>>>impossible I'll leave it at that.
>>>
>>>
>>>I hope so. Since you have completely failed to understand what I've
>>>said.
>>
>>No, it's because you failed to explain anything with any clarity; instead
>>using such 'clear as mud' generalities as "work with" and "the OS on three
>>drives."
>
>
> The problem is your inability to comprehend what everyone else can.

<chuckle> Yes, I've read the 'understanding' of the others and they've all
given up trying to make sense of what you're posting too.

Darren Harris

unread,
Aug 14, 2004, 8:38:36 AM8/14/04
to
> Yes. And since you're obviously not interested in a workable solution but
> merely complaining that operating systems don't natively support your
> 'idea' then there's not really any need to go on about it.

I'm the one who decides what is or isn't a "workable solution" for me. Not you.
Who are you to get angry and rant just because I will not use any idea that
*you* consider "workable"? If you want to do it that way, then fine. That is
your perogative. I also merely pointed out thatwhat I envision can be done if
the manufacturers really wanted to do it. And If you want to disagree with that
too, then fine.

Darren Harris

unread,
Aug 14, 2004, 8:44:51 AM8/14/04
to
> > Again, if that was done, then it it obvious why such a feature
> > wouldn't be popular. Who would want to have to unscrew their case and
> > navigate to their drives to manipulate a tiny jumper everytime they
> > had to save something to any of their disks?
>
> I believe that I pointed out earlier that it is very easy to attach a switch
> to the pins on which the jumper is normally installed and put that switch
> outside the computer case. If not, then I am pointing this out again.

No, you didn't say that before.

> >> If you make it software controlled, any attack that circumvents your OS
> >> security can also write-enable the drive, unless you put some kind of
> >> elaborate security system in the drive firmware. Absent a clear demand
> >> for a large quantity of drives with such a security system, that's not
> >> going to happen.
> >
> > Obviously. And certain people seem to have a problem with me conveying
> > that the developers/manufacturers have the technology to impliment
> > something as simple as what I said, but refuse to. To say they are
> > incapable of doing it, is to say they are extremely stupid.
>
> If in fact they have that technology please be kind enough to describe it in
> detail.

That would only give cause to continue a useless argument. But
obviously in involves present day technology. I already said that
there are no technological hurdles to overcome. Nevertheless, you
already said that it was done, so why ask?

> >> All current major operating systems except Windows 9x/ME provide some
> >> mechanism for controlling write-access to the drives. If an exploit
> >> manages to circumvent this mechanism then it will also be able to
> >> circumvent any software-controlled write-enable mechanism on the drives
> >> unless that mechanism has its own independent security enforced by the
> >> drive firmware. So by using the mechanisms in the OS you're going to be
> >> able to protect the drives from unauthorized writes as securely as could
> >> be done with any reasonably simple software-controllable mechanism built
> >> into the drive.
> >
> > And you do't think that an easily accessable switch on the outside of
> > one's case to control writes to individual drives would be a good idea
> > if implimented?
>
> Again, that feature _was_ implemented and nobody wanted it.

Again, there would be no readon for me to describe it then. But since
you said it was implemented, would you be kind enough to describe that
technology in detail? Hmmmmm?

J. Clarke

unread,
Aug 14, 2004, 10:30:14 AM8/14/04
to
Darren Harris wrote:

Set the jumper, the write line is disconnected. Or set the jumper, the
onboard processor ignores any write commands. I suspect that both
approaches were used at different times.

It's easy to say "the industry knows how to do this". That doesn't get the
job done. In 1940 the statement that "American scientists know how to make
an atomic bomb" was true. But getting from theory to product took one of
the largest engineering development programs in history. In 1960 the
statement that "American scientists know how to put a man on the Moon" was
true. Getting from theory to footprints was another huge engineering
program.

Write protecting drives is not so difficult an engineering challenge, but if
you don't have any idea how it would be accomplished then you should not
expect claims such as "the developers/manufacturers have the technology to
impliment something as simple as what I said, but refuse to" to go
unchallenged.

But getting back to the original point, there is not enough market for this
to make it worthwhile for the drive manufacturers to continue to implement
it, so it's not going to happen.

You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to be of
interest. Given the price of those devices, if there is a real mass-market
for this capability, seems to me that you could make yourself rich by
coming out with a hardware write blocker for, say, $50 instead of $500.


>
> Darren Harris
> Staten Island, New York.

--

Arno Wagner

unread,
Aug 14, 2004, 12:27:11 PM8/14/04
to
In comp.sys.ibm.pc.hardware.storage J. Clarke <jcl...@nospam.invalid> wrote:
> Darren Harris wrote:

[...]


>>> Again, that feature _was_ implemented and nobody wanted it.
>>
>> Again, there would be no readon for me to describe it then. But since
>> you said it was implemented, would you be kind enough to describe that
>> technology in detail? Hmmmmm?

> Set the jumper, the write line is disconnected. Or set the jumper, the
> onboard processor ignores any write commands. I suspect that both
> approaches were used at different times.

There was an other optin in MFM/RLL times, simply fixate the
RD/WR-line to the RD signal level in the cable. I once did that
for somebody with hardware cost maybe $10.

> It's easy to say "the industry knows how to do this". That doesn't get the
> job done. In 1940 the statement that "American scientists know how to make
> an atomic bomb" was true. But getting from theory to product took one of
> the largest engineering development programs in history. In 1960 the
> statement that "American scientists know how to put a man on the Moon" was
> true. Getting from theory to footprints was another huge engineering
> program.

> Write protecting drives is not so difficult an engineering challenge, but if
> you don't have any idea how it would be accomplished then you should not
> expect claims such as "the developers/manufacturers have the technology to
> impliment something as simple as what I said, but refuse to" to go
> unchallenged.

Implementing write protection for HDDs is pretty trivial, as long as
you do not have to protect against people trying to hack the HDD
firmware (which would be pretty advanced hacking, IMO).

> But getting back to the original point, there is not enough market for this
> to make it worthwhile for the drive manufacturers to continue to implement
> it, so it's not going to happen.

Yes, that is the core problem. Not enough people want it. For most
applications that need this type of protection, it is solved at the
OS level (not talking toys like products out of Redmont here). I myself
use a read-only nfs-export and dedicated fileserver for such a thing
in one instance. An other powerful option is to mount partitions as
read-only, as for example Knoppix does as default. Unless somebody
gets root permissions, this is completely secure. Still another
option would be to block all modifying commands for specific devices
at the driver level.

> You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to be of
> interest. Given the price of those devices, if there is a real mass-market
> for this capability, seems to me that you could make yourself rich by
> coming out with a hardware write blocker for, say, $50 instead of $500.

If there were a mass-market for these, the HDDs would have this
feature. $500 is a pretty low price for a special-purpose device
like this. On the other hand, I personally believe that from a legal
point of view mounting read-only should be as good, since some changes
are made to the disk, simply by powering it up. The power-on hours
SMART field, e.g., may well be stored on disk. So does the start-stop
counter and other values. Garanted, this is not in the user data area,
but the user data area is only protected by software. So why not accept
a comparable protection at the OS driver level?

Regards,
Arno
--
For email address: lastname AT tik DOT ee DOT ethz DOT ch
GnuPG: ID:1E25338F FP:0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F
"The more corrupt the state, the more numerous the laws" - Tacitus


Mike Redrobe

unread,
Aug 14, 2004, 12:40:37 PM8/14/04
to
J. Clarke wrote:

> You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to
> be of interest. Given the price of those devices, if there is a real
> mass-market for this capability, seems to me that you could make
> yourself rich by coming out with a hardware write blocker for, say,
> $50 instead of $500.

how about $25 on top of the device cost?

normal SCSI-IDE converter $74
http://www.mars-tech.com/aec-7720uw.htm

write-protected SCSI-IDE converter (same model): $99
http://www.mars-tech.com/aec-7720wp.htm

I haven't seen any which can be changed from ReadOnly
to ReadWrite "with the flick of a (hardware) switch"

There are hotswap caddy based systems with seperate
ReadWrite and ReadOnly bays.

--
Mike


Arno Wagner

unread,
Aug 14, 2004, 12:46:22 PM8/14/04
to
In comp.sys.ibm.pc.hardware.storage J. Clarke <jcl...@nospam.invalid> wrote:
> Darren Harris wrote:

[...]

> You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to be of


> interest. Given the price of those devices, if there is a real mass-market
> for this capability, seems to me that you could make yourself rich by
> coming out with a hardware write blocker for, say, $50 instead of $500.

Here are some nice solution starting at $150:

http://www.digitalintel.com/ultrablock.htm

Obviously there is a marjet for these things, but it seems to
be relatively small.

Alexander Grigoriev

unread,
Aug 14, 2004, 6:16:56 PM8/14/04
to
This thread deserves to die.
If a OS-provided file security is not adequate for OP, let him find another
workable solution and enlighten us about it.


"J. Clarke" <jcl...@nospam.invalid> wrote in message

news:cfl7m...@news3.newsguy.com...
> Darren Harris wrote:


David Maynard

unread,
Aug 14, 2004, 8:12:57 PM8/14/04
to

I did not claim to 'decide' what 'idea' is, or is not, a workable solution
"for you." What I said was it's clear you're not seeking one because you go
out of your way to NOT explain what you're trying to accomplish and,
instead, insist that your 'solution' is not only the 'right way' but the
'only way' of accomplishing whatever the hell the 'job' is and that 'the
industry' is stupid, or conspiratorial, for not providing the 'solution'
you've dreamed up.

The fact of the matter is, based on what meager hints you've provided as to
the nature of the supposed 'problem', your 'solution' does not solve it and
'the industry' does not provide such a thing, except for perhaps
specialized applications unrelated to your situation, because there are
superior solutions already available.

But you have shown to not be interested in hearing the flaws in it,
alternate solutions, or anything else; instead insisting the only issue is
"can it [your idea] be done," which is why I say you are apparently not
really interested in a 'solution' to 'the problem'.

Darren Harris

unread,
Aug 14, 2004, 10:05:56 PM8/14/04
to
> >>>Me either. I never said anything about "a third of the OS missing"
> >>>from the "C" drive.
> >>
> >>Neither did I.
> >
> > Yes you did. Anyone can look and see that that is your exact quote. In
> > fact here is the entire paragraph:
> > "I have no idea what you mean by 'unable' to 'use' your 'other drives'
> > but
> > if you mean the system not operating with a third of the OS missing
> > from,
> > as you put it, the C: drive going down then that is a big "well, Duh."
> > Not
> > to mention I can't figure out what the heck that has to do with
> > 'quarantining' drives."
>
> Reading comprehension isn't your strong suit, I see.
>
> I said "a third of the OS missing from, as you put it,"
> ----> "the C: drive going down" <----
> NOT "the C: drive" as you claimed.

Are really that dense? I know what you said. I reposted that quote
didn't I? I'm looking at where you placed your quotation marks and I
have no idea what argument you are trying to conjure up this time in
your head. Are you on medication? I only quoted exactly what you said.
That means LOOK IN BETWEEN THE QUOTATION MARKS. Anything else would be
*my* words.



> >>You said "the OS on all three drives" followed by "if my "C" drive went
> >>down." If 'the OS' is "on all three drives" and one of them goes down, you
> >>said the "C" drive, then that portion of the OS is now 'missing' because
> >>the damn drive it's located on isn't operating.
> >
> >
> > Your massive incomprehension is unbelieveable. *You* asked, "And just
> > how are you going to automagically, and instantly, transfer the
> > operating system to something else so it runs when you 'shutdown' the
> > C: drive?"
>
> Not a surprising 'opinion' coming from someone who can't read nor type with
> any clarity.

Everyone else understands but you. So if it is not clear then
obviously you are the problem.

> > And I attempted to convey that *my first system* had the OS on all
> > three drives.
>
> Yes. And the word "the" is singular, as in one: I.E. "the O.S." The first
> impression for "the O.S." 'on three drives' is "the O.S." 'spread' across
> them, not 3 bloody COPIES of the silly thing as you now seem to indicate.
> Why anyone would want 3 COPIES on three drives is another mystery you leave
> unanswered.

That's right. Like you said "the O.S." means one operating system.
You're the only one who would be dense enough not to understand that
one operating system can be copied to three different drives. If I
said I had the O.S. on three computers you would still be dense enough
to find an issue, when everyone else would easy understand. Again,
*you* are the problem.Even I know that when an app is spread across
multiple drives, "spread across" and "stripping" are the phrases/terms
used. But I never used those words.

> > So obviously the idea is that there would be a complete
> > copy of the OS on each of the four hard drives in the *new* system I
> > want to build.
>
> And what is so 'obvious' about someone being nutty enough to want 4
> "complete" COPIES of their OS on 4 drives?

Honestly, this is like arguing with a mentally handicapped individual,
but since I have nothing else to do...

I'm sure it never occurred to you that if for some reason I wanted to
boot from a different drive, it would have to have an OS on it, right?
And an O.S. on all my drives would give me the option of booting from
any one of the three drives left if for example my "C" drive went
down, right? Now read that again several more times before you find
issue with it.



> > Now why would anyone want to stripe an OS across
> > multiple hard drives?
>
> You apparently don't know about RAID. Why? Speed, fault tolerance. Depends
> on how much of each you want and how much you're willing to spend to get it.

There are many apps one can stripe across hard drives for speed
reasons. But it is not a good idea to do that with an OS, for reason
anyone with half a brain can figure out. More importantly, you
yourself already gave the reason why stripping your OS across hard
drives is a bad idea? The follow are your words: "...but if you mean


the system not operating with a third of the OS missing from, as you
put it, the C: drive going down then that is a big "well, Duh.""

Duh, is right.

> And it's a hell of a lot more common that someone keeping '3 copies on 3
> hard drives'.

Sigh...



> > I went on to say, "But thanks to the way
> > software is written, if my "C" drive went down, I still wouldn't be
> > able to use my other drives without major changes to my system first."
> > Which means that an entire copy of the OS on *each* of the drives
> > still wouldn't help me.
>
> Well, it might if it were installed on each; you could simply boot from the
> alternate. But then no one knows what the heck YOU mean by a 'copy' ('copy'
> of the CD? Copy of just the install files? a 'copy' of the files as
> installed on C:? an INSTALLED to THAT drive 'copy'?), nor why you had 3
> copies on 3 drives in your previous system, nor what the heck you mean by
> (would or wouldn't) 'help me' (do WHAT? boot? clean C:? repair C:? recover
> data from C:? or lord knows.).

The sheer stupidity of everything you said in that paragraph is just
more proof that you just feel like finding issue with everything said,
but at this point you are starting to look extremely retarded.

> > Now why is this so difficult for you to understand???
>
> Because you talk in generic riddles, adding information only when you want
> to shoot down something (and you've shot down every suggestion from every
> poster in the group who was trying to help you) and, even then, not
> explaining enough of it to know what the hell you're trying to do or why.

You cannot comprehend what a novice would understand and then blame me
for not being clear enough for you. There is a reason that no one else
is asking the questions you are asking. They are probably laughing at
this point.

> >>Like I said, you're not interested in solving any 'problem' but in just
> >>complaining.
> >
> >
> > I've come to the conclusion that what I want to do cannot be done. It
> > is you who are instigating.
>
> The case is that your proposed 'solution' for whatever it is you're
> actually trying to accomplish but which, for some bizarre reason, you seem
> compelled to keep as friggin secret and unexplained as possible, is not
> commonly available.

How would you know when you can't comprehend what I'm trying to
accomplish?

> Whether what you're actually "trying to do," whatever the hell it is, could
> be done or not is an unanswerable question given the current lack of any
> sensible information about it.

I already have the answer. The rest of this thread is garbage.

> > How can you possible believe you can get away with false info when the
> > evidence is up there as you say. Anyone can read the posts. The key
> > word is "spread", which *you* said. Not me. And again I was referring
> > to a previous system("my first system") I had, and a copy of the OS on
> > each of it's three drives. But of course that could not have possibly
> > occurred to you, because it was logical.
>
> It didn't occur to me because it's nonsensical.

To you...

> > The problem is your inability to comprehend what everyone else can.
>
> <chuckle> Yes, I've read the 'understanding' of the others and they've all
> given up trying to make sense of what you're posting too.

Actually they have understood and posted their answers. You on the
other hand...

Darren Harris

unread,
Aug 14, 2004, 10:37:53 PM8/14/04
to
> >> > And you do't think that an easily accessable switch on the outside of
> >> > one's case to control writes to individual drives would be a good idea
> >> > if implimented?
> >>
> >> Again, that feature _was_ implemented and nobody wanted it.
> >
> > Again, there would be no readon for me to describe it then. But since
> > you said it was implemented, would you be kind enough to describe that
> > technology in detail? Hmmmmm?
>
> Set the jumper, the write line is disconnected. Or set the jumper, the
> onboard processor ignores any write commands. I suspect that both
> approaches were used at different times.

That isn't what I said. Can you tell me what era PCs had a switch on
the outside of the case that allowed one to turn off/on write?

> It's easy to say "the industry knows how to do this". That doesn't get the
> job done. In 1940 the statement that "American scientists know how to make
> an atomic bomb" was true. But getting from theory to product took one of
> the largest engineering development programs in history. In 1960 the
> statement that "American scientists know how to put a man on the Moon" was
> true. Getting from theory to footprints was another huge engineering
> program.

?!? In 1940 America did *not* know how to make an atomic bomb. In 1960
America did *not* know how to put a man on the moon. The basic
theories and procedures were known, but a lot of ground work still had
to be done.

> Write protecting drives is not so difficult an engineering challenge, but if
> you don't have any idea how it would be accomplished then you should not
> expect claims such as "the developers/manufacturers have the technology to
> impliment something as simple as what I said, but refuse to" to go
> unchallenged.

The basics are so well know that such a challenge would be weak. How
deeply would I need to explain the theory of turning off/on writes to
a drive and routing control of same to a switch bank that is easily
accessible *outside* of the PC case? There would be no oprning up of
the case or swapping drives between bays just to turn off the write.
I'm merely *attempting* to convey that it would take little for the
manufacturers to implement this.

> But getting back to the original point, there is not enough market for this
> to make it worthwhile for the drive manufacturers to continue to implement
> it, so it's not going to happen.

It's all about the bottom line. Malicious code makes a lot of money
for a lot of people in the software and hardware sectors. So why
promote an easier and cheaper way to fight viruses and hackers?

> You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to be of
> interest. Given the price of those devices, if there is a real mass-market
> for this capability, seems to me that you could make yourself rich by
> coming out with a hardware write blocker for, say, $50 instead of $500.

Would you buy a Grey Hound bus just to take yourself to work?

Darren Harris

unread,
Aug 14, 2004, 11:01:58 PM8/14/04
to
As I said there obviously are no solutions. So that issue is taken
care of.

As far as my idea goes. Windows is inherently faulty and always will
be. It's foundation will keep it that way. In fact, no software
solutions can be 100% trusted as far as I'm concerned. I really think
that this is best implemented in hardware. A hardwired line that one
can connect from the drives to switches on your PC case would be the
best way to go. Certain hard drive data info can be placed "outside
the loop" since there are dedicated sectors for this info.(But do
these disk-writes really benefit the average user?). It would be best
to make writes an impossibility using some sort of switch that
opens(or closes) the write circuit so that the write heads cannot
alter data on at least any part of the drive where user software is
installed. In fact three-position switches so as to include an
"Administrator only" write option also.

Anyway, that is my idea.

David Maynard

unread,
Aug 14, 2004, 11:26:09 PM8/14/04
to
Darren Harris wrote:

>>>>>Me either. I never said anything about "a third of the OS missing"
>>>>
>>>>>from the "C" drive.
>>>>
>>>>Neither did I.
>>>
>>>Yes you did. Anyone can look and see that that is your exact quote. In
>>>fact here is the entire paragraph:
>>>"I have no idea what you mean by 'unable' to 'use' your 'other drives'
>>>but
>>>if you mean the system not operating with a third of the OS missing
>>>from,
>>>as you put it, the C: drive going down then that is a big "well, Duh."
>>>Not
>>>to mention I can't figure out what the heck that has to do with
>>>'quarantining' drives."
>>
>>Reading comprehension isn't your strong suit, I see.
>>
>>I said "a third of the OS missing from, as you put it,"
>>----> "the C: drive going down" <----
>>NOT "the C: drive" as you claimed.
>
>
> Are really that dense? I know what you said.

Obviously not.

> I reposted that quote
> didn't I?

Yes, you did. And quite well too. Now, if you were only able to read and
comprehend it we'd have no problem.

> I'm looking at where you placed your quotation marks and I
> have no idea what argument you are trying to conjure up this time in
> your head. Are you on medication? I only quoted exactly what you said.
> That means LOOK IN BETWEEN THE QUOTATION MARKS. Anything else would be
> *my* words.

Listen very carefully. I said a third of the O.S. would be 'missing' (I.E.
not available, inaccessible.) since, if the C: drive isn't working (your
criteria of "the C: drive going down"), the files on the C: drive would not
be accessible. NOT that the files would be "missing from the C: drive."

That was based on your description of, somehow, having 'the O.S. on three
drives', and not RAIDed or else you'd have said RAIDed.

>>>>You said "the OS on all three drives" followed by "if my "C" drive went
>>>>down." If 'the OS' is "on all three drives" and one of them goes down, you
>>>>said the "C" drive, then that portion of the OS is now 'missing' because
>>>>the damn drive it's located on isn't operating.
>>>
>>>
>>>Your massive incomprehension is unbelieveable. *You* asked, "And just
>>>how are you going to automagically, and instantly, transfer the
>>>operating system to something else so it runs when you 'shutdown' the
>>>C: drive?"
>>
>>Not a surprising 'opinion' coming from someone who can't read nor type with
>>any clarity.
>
> Everyone else understands but you. So if it is not clear then
> obviously you are the problem.

I've seen their 'understanding' and it's essentially the same as mine.

>>>And I attempted to convey that *my first system* had the OS on all
>>>three drives.
>>
>>Yes. And the word "the" is singular, as in one: I.E. "the O.S." The first
>>impression for "the O.S." 'on three drives' is "the O.S." 'spread' across
>>them, not 3 bloody COPIES of the silly thing as you now seem to indicate.
>>Why anyone would want 3 COPIES on three drives is another mystery you leave
>>unanswered.
>
>
> That's right. Like you said "the O.S." means one operating system.
> You're the only one who would be dense enough not to understand that
> one operating system can be copied to three different drives.

A 'copy' is not 'the O.S.' It's a 'copy' of 'the O.S.'. And I can
understand copies just fine if you had the sense to simply SAY a freaking
copy instead of 'have the O.S. on three drives'.


> If I
> said I had the O.S. on three computers you would still be dense enough
> to find an issue, when everyone else would easy understand.

No, as imprecise as it would be to say you "have 'the O.S.' on three
computers" I'd know because any other interpretation is even more silly.

However, stripping 'the O.S.' across drives is quite normal for a RAID setup.

> Again,
> *you* are the problem.Even I know that when an app is spread across
> multiple drives, "spread across" and "stripping" are the phrases/terms
> used. But I never used those words.

You didn't use ANY descriptive words, not copy, not striping, not anything,
which is the problem.

I have LOTS of things on multiple drives. Care to 'guess' what the hell I
mean by that? Because that's what YOU expect when you say things like "have
the O.S. on three drives."

>>>So obviously the idea is that there would be a complete
>>>copy of the OS on each of the four hard drives in the *new* system I
>>>want to build.
>>
>>And what is so 'obvious' about someone being nutty enough to want 4
>>"complete" COPIES of their OS on 4 drives?
>
> Honestly, this is like arguing with a mentally handicapped individual,

I admit to not being a mind reader.

> but since I have nothing else to do...

That's apparent.

> I'm sure it never occurred to you that if for some reason I wanted to
> boot from a different drive, it would have to have an OS on it, right?

Of course it occurred to me. I even listed that as one of many
possibilities that occurred to me. What the hell YOU had in mind was an
unanswered question which, of course, you didn't bother to mention until
you felt it might be fun to throw more insults.

> And an O.S. on all my drives would give me the option of booting from
> any one of the three drives left if for example my "C" drive went
> down, right? Now read that again several more times before you find
> issue with it.

If you are concerned with 'drives going down' then you'd be better off with
a RAID5 array rather than separate bootable copies of the O.S. on each
drive. A three drive RAID5 uses less space, meaning more room for your
other data, and operates seamlessly even during a single drive failure
without even a 'boot' needed (except for drive replacement if you don't
have hot swap capability).

>>>Now why would anyone want to stripe an OS across
>>>multiple hard drives?
>>
>>You apparently don't know about RAID. Why? Speed, fault tolerance. Depends
>>on how much of each you want and how much you're willing to spend to get it.
>
> There are many apps one can stripe across hard drives for speed
> reasons. But it is not a good idea to do that with an OS, for reason
> anyone with half a brain can figure out.

Oh really? I guess that's why it's so commonly done, eh?

> More importantly, you
> yourself already gave the reason why stripping your OS across hard
> drives is a bad idea? The follow are your words: "...but if you mean
> the system not operating with a third of the OS missing from, as you
> put it, the C: drive going down then that is a big "well, Duh.""

I didn't say "striping" there. I was talking about your claim of "the O.S.
on three drives" with no explanation of what it means and that if you meant
RAID you'd have SAID RAID; an assumption I now freely admit was foolish in
your case.

>>And it's a hell of a lot more common that someone keeping '3 copies on 3
>>hard drives'.
>
> Sigh...

Which indicates you still don't know what RAID is.

>
>>>I went on to say, "But thanks to the way
>>>software is written, if my "C" drive went down, I still wouldn't be
>>>able to use my other drives without major changes to my system first."
>>>Which means that an entire copy of the OS on *each* of the drives
>>>still wouldn't help me.
>>
>>Well, it might if it were installed on each; you could simply boot from the
>>alternate. But then no one knows what the heck YOU mean by a 'copy' ('copy'
>>of the CD? Copy of just the install files? a 'copy' of the files as
>>installed on C:? an INSTALLED to THAT drive 'copy'?), nor why you had 3
>>copies on 3 drives in your previous system, nor what the heck you mean by
>>(would or wouldn't) 'help me' (do WHAT? boot? clean C:? repair C:? recover
>>data from C:? or lord knows.).
>
>
> The sheer stupidity of everything you said in that paragraph is just
> more proof that you just feel like finding issue with everything said,
> but at this point you are starting to look extremely retarded.

No one, not even I, can read your mind.

>>>Now why is this so difficult for you to understand???
>>
>>Because you talk in generic riddles, adding information only when you want
>>to shoot down something (and you've shot down every suggestion from every
>>poster in the group who was trying to help you) and, even then, not
>>explaining enough of it to know what the hell you're trying to do or why.
>
> You cannot comprehend what a novice would understand and then blame me
> for not being clear enough for you. There is a reason that no one else
> is asking the questions you are asking. They are probably laughing at
> this point.

The reason they're not asking is they've given up trying to help you.

>>>>Like I said, you're not interested in solving any 'problem' but in just
>>>>complaining.
>>>
>>>
>>>I've come to the conclusion that what I want to do cannot be done. It
>>>is you who are instigating.
>>
>>The case is that your proposed 'solution' for whatever it is you're
>>actually trying to accomplish but which, for some bizarre reason, you seem
>>compelled to keep as friggin secret and unexplained as possible, is not
>>commonly available.
>
> How would you know when you can't comprehend what I'm trying to
> accomplish?

No one, not even I, can 'comprehend' what you don't explain.

>>Whether what you're actually "trying to do," whatever the hell it is, could
>>be done or not is an unanswerable question given the current lack of any
>>sensible information about it.
>
>
> I already have the answer. The rest of this thread is garbage.

Be happy in your misery.


>>>How can you possible believe you can get away with false info when the
>>>evidence is up there as you say. Anyone can read the posts. The key
>>>word is "spread", which *you* said. Not me. And again I was referring
>>>to a previous system("my first system") I had, and a copy of the OS on
>>>each of it's three drives. But of course that could not have possibly
>>>occurred to you, because it was logical.
>>
>>It didn't occur to me because it's nonsensical.
>
> To you...

Why don't you take a poll of how many people keep three, soon to be 4 from
what you said, fully bootable, non-RAID, duplicate copies of their O.S. on
separate drives to see how much sense it makes.

>>>The problem is your inability to comprehend what everyone else can.
>>
>><chuckle> Yes, I've read the 'understanding' of the others and they've all
>>given up trying to make sense of what you're posting too.
>
> Actually they have understood and posted their answers. You on the
> other hand...

Enjoy the fantasy.

David Maynard

unread,
Aug 15, 2004, 12:33:52 AM8/15/04
to
Darren Harris wrote:

The problem is that the instant you flip the switch to write enable the
previously 'protected' drive any virus infection on the machine merrily
infects the now write enabled drive. Once on your machine, no 'Internet
connection' is required anymore.

The only way that has a chance of 'protecting' anything is if one routinely
does a full virus scan, and clean, of the exposed drive before write
enabling anything else (or if the drives never communicate with each other
as if they were in separate machines), but then that's a lot of work to do
each time one exposes the machine to the internet and a lot more work than,
say, not being 'admin' all the time and changing permissions.

However, you could simulate 'write protect' by having a small script, with
admin privileges, alter the whole drive permissions when you, as 'user',
wanted to. Although, altering whole drive permissions is probably
unnecessary as you likely only need write enabled to the 'user' files you
work with and if you are concerned with protecting them there are
techniques for doing so. Encryption is one example.


As for the 'admin' position on the switch, the hard drive controller has no
way of knowing who, or what, is sending write commands to it. Nor would it
help any to implement such a capability because, if a virus can spoof being
admin with the current security, it would simply spoof being admin when it
sent write commands to the 'admin enhanced' drive.

The closest things to a 'virus immune' system are the Linux 'live CDs'
where all code is reloaded on each boot from the read only CD media.


J. Clarke

unread,
Aug 15, 2004, 1:50:49 AM8/15/04
to
Darren Harris wrote:

>> >> > And you do't think that an easily accessable switch on the outside
>> >> > of one's case to control writes to individual drives would be a good
>> >> > idea if implimented?
>> >>
>> >> Again, that feature _was_ implemented and nobody wanted it.
>> >
>> > Again, there would be no readon for me to describe it then. But since
>> > you said it was implemented, would you be kind enough to describe that
>> > technology in detail? Hmmmmm?
>>
>> Set the jumper, the write line is disconnected. Or set the jumper, the
>> onboard processor ignores any write commands. I suspect that both
>> approaches were used at different times.
>
> That isn't what I said. Can you tell me what era PCs had a switch on
> the outside of the case that allowed one to turn off/on write?

Wiring this on machines which contained drives with a write-protect jumper
was trivial. Two pieces of wire and and a switch.



>> It's easy to say "the industry knows how to do this". That doesn't get
>> the
>> job done. In 1940 the statement that "American scientists know how to
>> make
>> an atomic bomb" was true. But getting from theory to product took one of
>> the largest engineering development programs in history. In 1960 the
>> statement that "American scientists know how to put a man on the Moon"
>> was
>> true. Getting from theory to footprints was another huge engineering
>> program.
>
> ?!? In 1940 America did *not* know how to make an atomic bomb.

Yes, America did. The physics had been worked out--it was reduced to an
engineering problem.

> In 1960
> America did *not* know how to put a man on the moon. The basic
> theories and procedures were known, but a lot of ground work still had
> to be done.

Well, actually, no, it didn't. It was a matter of designing and building
the spacecraft.

>> Write protecting drives is not so difficult an engineering challenge, but
>> if you don't have any idea how it would be accomplished then you should
>> not expect claims such as "the developers/manufacturers have the
>> technology to impliment something as simple as what I said, but refuse
>> to" to go unchallenged.
>
> The basics are so well know that such a challenge would be weak. How
> deeply would I need to explain the theory of turning off/on writes

Well, at least far enough to demonstrate that you actually understand the
issues involved.

> to
> a drive and routing control of same to a switch bank that is easily
> accessible *outside* of the PC case? There would be no oprning up of
> the case or swapping drives between bays just to turn off the write.
> I'm merely *attempting* to convey that it would take little for the
> manufacturers to implement this.

Look, if it's so all-fired important to you to have this capability, go
through the Seagate site, find the drives that had write-protect jumpers,
buy however many you need off of ebay, and install them with switches
outside the case wired to the headers. Or are you too stupid to figure out
how to solder two wires to a couple of pins and a switch?

>> But getting back to the original point, there is not enough market for
>> this to make it worthwhile for the drive manufacturers to continue to
>> implement it, so it's not going to happen.
>
> It's all about the bottom line. Malicious code makes a lot of money
> for a lot of people in the software and hardware sectors. So why
> promote an easier and cheaper way to fight viruses and hackers?

How does what you propose constitute "an easier and cheaper way to fight
viruses and hackers"?

>> You might find <http://www.ojp.usdoj.gov/nij/sciencetech/cftt.htm> to be
>> of
>> interest. Given the price of those devices, if there is a real
>> mass-market for this capability, seems to me that you could make yourself
>> rich by coming out with a hardware write blocker for, say, $50 instead of
>> $500.
>
> Would you buy a Grey Hound bus just to take yourself to work?

If it was the smallest and cheapest vehicle available, then I wouldn't have
much choice, now, would I.

> Darren Harris
> Staten Island, New York.

--

Darren Harris

unread,
Aug 15, 2004, 1:46:20 PM8/15/04
to
> > Are really that dense? I know what you said.
>
> Obviously not.
>
> > I reposted that quote
> > didn't I?

> Yes, you did. And quite well too. Now, if you were only able to read and
> comprehend it we'd have no problem.

Everything you said is already well known or just plan incorrect. So
there is nothing else to comprehend.

> Listen very carefully. I said a third of the O.S. would be 'missing' (I.E.
> not available, inaccessible.) since, if the C: drive isn't working (your
> criteria of "the C: drive going down"), the files on the C: drive would not
> be accessible. NOT that the files would be "missing from the C: drive."

Any dummy would have long ago understood one of the several times I've
had to convey that I'm *not* talking about spreading the O.S. over
three drives. How many more times do I have to repeat that?

> That was based on your description of, somehow, having 'the O.S. on three
> drives', and not RAIDed or else you'd have said RAIDed.

No it wasn't. It was based on your whatever is going on in your
imagination.

> > Everyone else understands but you. So if it is not clear then
> > obviously you are the problem.
>
> I've seen their 'understanding' and it's essentially the same as mine.

I'm sure they will appreciate that insult.

> A 'copy' is not 'the O.S.' It's a 'copy' of 'the O.S.'. And I can
> understand copies just fine if you had the sense to simply SAY a freaking
> copy instead of 'have the O.S. on three drives'.

It would not have made a difference, because you would have still
taken it to mean "spread" over three drives. And since you mentioned
it, everyone who has a an O.S. on their PC is said to have a "copy" of
the O.S. on their PC. Even the biggest moron would know that. So this
is further proof that you are just having a grand old time starting
arguments over nothing. Go harass someone else. I'm sure you can fin
plenty of threads to target.

> No, as imprecise as it would be to say you "have 'the O.S.' on three
> computers" I'd know because any other interpretation is even more silly.

"Know"? You obviously don't because you keep arguing the issue.

> However, stripping 'the O.S.' across drives is quite normal for a RAID setup.

Really?



> > Again,
> > *you* are the problem.Even I know that when an app is spread across
> > multiple drives, "spread across" and "stripping" are the phrases/terms
> > used. But I never used those words.
>
> You didn't use ANY descriptive words, not copy, not striping, not anything,
> which is the problem.

No, again you are the problem. I'm not going to draw you pictures
because you feel like you want to argue.

> I have LOTS of things on multiple drives. Care to 'guess' what the hell I
> mean by that? Because that's what YOU expect when you say things like "have
> the O.S. on three drives."

This thread was targeted toward intelligent people. Not you.

> I admit to not being a mind reader.

Which you would have to be in or to overcome your problem with
understanding what comes easily to others.



> > but since I have nothing else to do...
>
> That's apparent.

Obviously we'll be at this for the next 50 years.

> > I'm sure it never occurred to you that if for some reason I wanted to
> > boot from a different drive, it would have to have an OS on it, right?
>
> Of course it occurred to me. I even listed that as one of many
> possibilities that occurred to me. What the hell YOU had in mind was an
> unanswered question which, of course, you didn't bother to mention until
> you felt it might be fun to throw more insults.

If it occurred to you, then you did you ask, "And what is so 'obvious'


about someone being nutty enough to want 4 "complete" COPIES of their
OS on 4 drives?"

This is further proof that you are just trying your best to be a pest.

> > And an O.S. on all my drives would give me the option of booting from
> > any one of the three drives left if for example my "C" drive went
> > down, right? Now read that again several more times before you find
> > issue with it.
>
> If you are concerned with 'drives going down' then you'd be better off with
> a RAID5 array rather than separate bootable copies of the O.S. on each
> drive. A three drive RAID5 uses less space, meaning more room for your
> other data, and operates seamlessly even during a single drive failure
> without even a 'boot' needed (except for drive replacement if you don't
> have hot swap capability).

No. And I'm not going to bother telling you why "RAID5" is not an
option for me, because I knoiw it is just bait for you to start
another issue.



> >>>Now why would anyone want to stripe an OS across
> >>>multiple hard drives?
> >>
> >>You apparently don't know about RAID. Why? Speed, fault tolerance. Depends
> >>on how much of each you want and how much you're willing to spend to get it.
> >
> > There are many apps one can stripe across hard drives for speed
> > reasons. But it is not a good idea to do that with an OS, for reason
> > anyone with half a brain can figure out.
>
> Oh really? I guess that's why it's so commonly done, eh?

You're wrong again. It is *not* commonly done.



> > More importantly, you
> > yourself already gave the reason why stripping your OS across hard
> > drives is a bad idea? The follow are your words: "...but if you mean
> > the system not operating with a third of the OS missing from, as you
> > put it, the C: drive going down then that is a big "well, Duh.""
>
> I didn't say "striping" there. I was talking about your claim of "the O.S.
> on three drives" with no explanation of what it means and that if you meant
> RAID you'd have SAID RAID; an assumption I now freely admit was foolish in
> your case.

In the way you used the word "spreading", it is a term that is used in
place of, or means the same as "striping". (Duh)...

> Which indicates you still don't know what RAID is.

RAID has nothing to do with my goals, and I never mentioned that term.
So this is obviously your way of trying to start a new argument over
something that I didn't say.

> No one, not even I, can read your mind.

You can't understand simple concepts either.

> The reason they're not asking is they've given up trying to help you.

They are not asking because they already know the answers. And they've
already helped me come to my conclusions. You're just here trying to
be a pain.

> No one, not even I, can 'comprehend' what you don't explain.

Well, whatever I don't explain(or am not asked about)is not meant to
be comprehended.

> Be happy in your misery.

Is that what you are attempting to do? You need to take your hand off
of your johnson and get out more.

> Why don't you take a poll of how many people keep three, soon to be 4 from
> what you said, fully bootable, non-RAID, duplicate copies of their O.S. on
> separate drives to see how much sense it makes.

It's none of your business if I want to keep a copy of my O.S. on
*all* of my drives. I've alreaded stated my reason and it is a good
one. I'd rather take a poll of how many think you are a troll.

You asked the stupid question, "And just how are you going to


automagically, and instantly, transfer the operating system to
something else so it runs when you 'shutdown' the C: drive?"

I attempted to convey that it is possible to have an operating system
on multiple drives by saying that, "My first system had the OS on all
three drives." I did *not* say "spread" across three drives.

Since your (stupid)question involved how my system would work without
access to the "C" drive, it would be obvious to a normal person who
knows that the entire O.S. is needed for operation, that there would
be a "copy of the OS on each of the four hard drives in the *new*


system I want to build."

Even after I explained this in different words so many times, you kept
arguing the point and obviously will continue to do so. You've argued
over the word "copy", my intent to have the O.S on separate drives,
that I didn't explain myself to your satisfaction, "Spreading" vs.
"striping", and have now introduced RAID5 as an argument.

You sir are the biggest idiot I've ever come across on the newsgroups.

> Enjoy the fantasy.

Get a dose of reality.

Darren Harris

unread,
Aug 15, 2004, 1:55:31 PM8/15/04
to
> I did not claim to 'decide' what 'idea' is, or is not, a workable solution
> "for you." What I said was it's clear you're not seeking one because you go
> out of your way to NOT explain what you're trying to accomplish and,
> instead, insist that your 'solution' is not only the 'right way' but the
> 'only way' of accomplishing whatever the hell the 'job' is and that 'the
> industry' is stupid, or conspiratorial, for not providing the 'solution'
> you've dreamed up.

I've explained myself clearly(multiple times for you). And I've come
to the conclusion(without any help from you) that what I want to do is
not possible because hardware/sofware manufacturers don't have it
implemented.

> The fact of the matter is, based on what meager hints you've provided as to
> the nature of the supposed 'problem', your 'solution' does not solve it and
> 'the industry' does not provide such a thing, except for perhaps
> specialized applications unrelated to your situation, because there are
> superior solutions already available.

Incorrect. There are no superior solutions. My goal was stated. The
reasons for my goal were stated. The solutions were given. Those
soultions don't work for me. The reasons they don't work for me were
given. The end.

> But you have shown to not be interested in hearing the flaws in it,
> alternate solutions, or anything else; instead insisting the only issue is
> "can it [your idea] be done," which is why I say you are apparently not
> really interested in a 'solution' to 'the problem'.

Wrong. I'm not interested in *your* solution.

Darren Harris

unread,
Aug 15, 2004, 2:13:08 PM8/15/04
to
> The problem is that the instant you flip the switch to write enable the
> previously 'protected' drive any virus infection on the machine merrily
> infects the now write enabled drive. Once on your machine, no 'Internet
> connection' is required anymore.

Really? Now what makes you think that I wouldn't want to shut down,
"read-protect"(which may involve shutting down), or delete the
contents of the "C"(internet) drive before writing to any of the
others? It is the "C" drive that I will be erasing and mirroring to
from the other drives on a regular basis. That includes the OS. The
other three drive would in effect be source drives for "C", and when I
do need to copy to them or work with them individually, I will of
course take "C" out of the loop.

> The only way that has a chance of 'protecting' anything is if one routinely
> does a full virus scan, and clean, of the exposed drive before write
> enabling anything else (or if the drives never communicate with each other
> as if they were in separate machines), but then that's a lot of work to do
> each time one exposes the machine to the internet and a lot more work than,
> say, not being 'admin' all the time and changing permissions.

See my last paragraph.

> However, you could simulate 'write protect' by having a small script, with
> admin privileges, alter the whole drive permissions when you, as 'user',
> wanted to. Although, altering whole drive permissions is probably
> unnecessary as you likely only need write enabled to the 'user' files you
> work with and if you are concerned with protecting them there are
> techniques for doing so. Encryption is one example.

That's not a *quick* and "easy* workable solution for me. That is why
I stated my idea concerning what the manufactureres should be doing.

> As for the 'admin' position on the switch, the hard drive controller has no
> way of knowing who, or what, is sending write commands to it. Nor would it
> help any to implement such a capability because, if a virus can spoof being
> admin with the current security, it would simply spoof being admin when it
> sent write commands to the 'admin enhanced' drive.
>
> The closest things to a 'virus immune' system are the Linux 'live CDs'
> where all code is reloaded on each boot from the read only CD media.

Again. A simple option/solution like what I mentioned is much easier
and faster.

Darren Harris

unread,
Aug 15, 2004, 2:33:03 PM8/15/04
to
> > That isn't what I said. Can you tell me what era PCs had a switch on
> > the outside of the case that allowed one to turn off/on write?
>
> Wiring this on machines which contained drives with a write-protect jumper
> was trivial. Two pieces of wire and and a switch.

Once again. Since it was implemented already, can you tell me what era


PCs had a switch on the outside of the case that allowed one to turn

off/on writes to any of it's hard drives?

> > ?!? In 1940 America did *not* know how to make an atomic bomb.
>
> Yes, America did. The physics had been worked out--it was reduced to an
> engineering problem.

Incorrect. It would be a simple matter for me to tailor my basic game
playing techniques to allow me to score 3.3 million points on Pac-man,
but since I haven't done it I cannot claim that I can with any
credibilty. :-)



> > In 1960
> > America did *not* know how to put a man on the moon. The basic
> > theories and procedures were known, but a lot of ground work still had
> > to be done.
>
> Well, actually, no, it didn't. It was a matter of designing and building
> the spacecraft.

Wrong. "designing and building" a spacecraft has always entailed
unforseen problems and issues that the engineers had to come up with
solutions for.

> > The basics are so well know that such a challenge would be weak. How
> > deeply would I need to explain the theory of turning off/on writes
>
> Well, at least far enough to demonstrate that you actually understand the
> issues involved.

Um, Didn't you say "Wiring this on machines which contained drives
with a write-protect jumper was trivial."?

> Look, if it's so all-fired important to you to have this capability, go
> through the Seagate site, find the drives that had write-protect jumpers,
> buy however many you need off of ebay, and install them with switches
> outside the case wired to the headers. Or are you too stupid to figure out
> how to solder two wires to a couple of pins and a switch?

Hey moron. This doesn't involve my PC building project. All I did was
post an idea I had, and think that manufacurers should implement. That
was no excuse for you to attack me(again). If you disagree with it
then that is your perogative. But you need to correct your personal
problems before posting.

> > It's all about the bottom line. Malicious code makes a lot of money
> > for a lot of people in the software and hardware sectors. So why
> > promote an easier and cheaper way to fight viruses and hackers?
>
> How does what you propose constitute "an easier and cheaper way to fight
> viruses and hackers"?

?!? Where were you when write-protecting was discussed?

> > Would you buy a Grey Hound bus just to take yourself to work?
>
> If it was the smallest and cheapest vehicle available, then I wouldn't have
> much choice, now, would I.

That's the whole point. Everyone would be asking for smaller and
cheaper vehicles.

I had an idea like you did. I stated it. That's all.

J. Clarke

unread,
Aug 15, 2004, 3:16:26 PM8/15/04
to
Darren Harris wrote:

>> > That isn't what I said. Can you tell me what era PCs had a switch on
>> > the outside of the case that allowed one to turn off/on write?
>>
>> Wiring this on machines which contained drives with a write-protect
>> jumper
>> was trivial. Two pieces of wire and and a switch.
>
> Once again. Since it was implemented already, can you tell me what era
> PCs had a switch on the outside of the case that allowed one to turn
> off/on writes to any of it's hard drives?

About ten years back. If you wanted a switch on the outside you installed
it yourself.

>> > ?!? In 1940 America did *not* know how to make an atomic bomb.
>>
>> Yes, America did. The physics had been worked out--it was reduced to an
>> engineering problem.
>
> Incorrect. It would be a simple matter for me to tailor my basic game
> playing techniques to allow me to score 3.3 million points on Pac-man,
> but since I haven't done it I cannot claim that I can with any
> credibilty. :-)

Fine, believe what you want to.

>> > In 1960
>> > America did *not* know how to put a man on the moon. The basic
>> > theories and procedures were known, but a lot of ground work still had
>> > to be done.
>>
>> Well, actually, no, it didn't. It was a matter of designing and building
>> the spacecraft.
>
> Wrong. "designing and building" a spacecraft has always entailed
> unforseen problems and issues that the engineers had to come up with
> solutions for.

The same is true for an airliner, a large ship, or a tall building. So I
guess by your standards we don't know how to build airliners, large ships,
or tall buildings.

>> > The basics are so well know that such a challenge would be weak. How
>> > deeply would I need to explain the theory of turning off/on writes
>>
>> Well, at least far enough to demonstrate that you actually understand the
>> issues involved.
>
> Um, Didn't you say "Wiring this on machines which contained drives
> with a write-protect jumper was trivial."?

So what do you believe is the mechanism by which the write-protect jumper
prevents writes?

Knowing how to put the key in the ignition doesn't mean that you know how a
car operates.



>> Look, if it's so all-fired important to you to have this capability, go
>> through the Seagate site, find the drives that had write-protect jumpers,
>> buy however many you need off of ebay, and install them with switches
>> outside the case wired to the headers. Or are you too stupid to figure
>> out how to solder two wires to a couple of pins and a switch?
>
> Hey moron. This doesn't involve my PC building project. All I did was
> post an idea I had, and think that manufacurers should implement. That
> was no excuse for you to attack me(again). If you disagree with it
> then that is your perogative. But you need to correct your personal
> problems before posting.

I asked you a question. That was not an attack, that was an attempt to
determine whether any solution more complex than opening a cardboard box
and pulling out the contents was within your capabilities.

>> > It's all about the bottom line. Malicious code makes a lot of money
>> > for a lot of people in the software and hardware sectors. So why
>> > promote an easier and cheaper way to fight viruses and hackers?
>>
>> How does what you propose constitute "an easier and cheaper way to fight
>> viruses and hackers"?
>
> ?!? Where were you when write-protecting was discussed?

Right here and I saw no convincing case made that it was either easier or
cheaper than the alternatives.

>> > Would you buy a Grey Hound bus just to take yourself to work?
>>
>> If it was the smallest and cheapest vehicle available, then I wouldn't
>> have much choice, now, would I.
>
> That's the whole point. Everyone would be asking for smaller and
> cheaper vehicles.

And suppose everybody drives greyhound buses in preference to cars. Should
the car manufacturers continue to produce cars that nobody wants?

> I had an idea like you did. I stated it. That's all.

I'm sorry, but I do not recall introducing any "ideas" to this thread, only
techniques that will address the issues you raise. Since in point of fact
you don't seem to actually _want_ to protect your system and were instead
just trolling, that point is moot.

>
> Darren Harris
> Staten Island, New York.

--

David Maynard

unread,
Aug 15, 2004, 8:35:24 PM8/15/04
to
Darren Harris wrote:
>>I did not claim to 'decide' what 'idea' is, or is not, a workable solution
>>"for you." What I said was it's clear you're not seeking one because you go
>>out of your way to NOT explain what you're trying to accomplish and,
>>instead, insist that your 'solution' is not only the 'right way' but the
>>'only way' of accomplishing whatever the hell the 'job' is and that 'the
>>industry' is stupid, or conspiratorial, for not providing the 'solution'
>>you've dreamed up.
>
>
> I've explained myself clearly(multiple times for you). And I've come
> to the conclusion(without any help from you) that what I want to do is
> not possible because hardware/sofware manufacturers don't have it
> implemented.
>
>
>>The fact of the matter is, based on what meager hints you've provided as to
>>the nature of the supposed 'problem', your 'solution' does not solve it and
>>'the industry' does not provide such a thing, except for perhaps
>>specialized applications unrelated to your situation, because there are
>>superior solutions already available.
>
>
> Incorrect. There are no superior solutions. My goal was stated. The
> reasons for my goal were stated. The solutions were given. Those
> soultions don't work for me. The reasons they don't work for me were
> given. The end.

Your stated 'question' was whether you could 'quarantine' drives by a
hardware 'write protect' switch. That's not a goal; it's an already
proposed solution to 'whatever' the goal was. One you still keep as close
to the vest as possible; leaking out hints of what you intended to do with
it only when it suits your need to attack.

>>But you have shown to not be interested in hearing the flaws in it,
>>alternate solutions, or anything else; instead insisting the only issue is
>>"can it [your idea] be done," which is why I say you are apparently not
>>really interested in a 'solution' to 'the problem'.
>
>
> Wrong. I'm not interested in *your* solution.

I didn't give 'a' solution. I, and others, provided an entire panoply of
possible approaches yet, even after you admit to arriving at the conclusion
your 'solution' is "not possible," you still, not just reject but, ridicule
any alternatives. If your idea of seeking a solution is to reject
everything except an "impossible" one then I see where our difference of
opinion lies.

But, hey, have fun deleting and copying your O.S. all over the place. It's
no skin off my nose.

David Maynard

unread,
Aug 15, 2004, 9:22:47 PM8/15/04
to
Darren Harris wrote:

>>The problem is that the instant you flip the switch to write enable the
>>previously 'protected' drive any virus infection on the machine merrily
>>infects the now write enabled drive. Once on your machine, no 'Internet
>>connection' is required anymore.
>
>
> Really? Now what makes you think that I wouldn't want to shut down,
> "read-protect"(which may involve shutting down), or delete the
> contents of the "C"(internet) drive before writing to any of the
> others? It is the "C" drive that I will be erasing and mirroring to
> from the other drives on a regular basis. That includes the OS. The
> other three drive would in effect be source drives for "C", and when I
> do need to copy to them or work with them individually, I will of
> course take "C" out of the loop.

That an interesting new tidbit of information on how you envision it would
work. (If you'll notice, I was trying to cover the main possibilities here
and below, where I described that approach, because you had not said
anything about how you intended for it to work)

Erasing the C: drive would entail rebooting to another drive so you have
something to run on (obviously can't run from the drive you're planning to
erase), then replenishing the files on C: so you could then boot it for the
next 'exposure' to the internet, and the process repeated each time. So no,
after you vigorously complained that the simple act of changing user
permissions is so burdensome I would not have guessed you would think the
infinitely more complex and time consuming task of multiple reboots, and
BIOS setting to change boot drives, along with erasing and replenishing the
C: drive was 'easier'.


>>The only way that has a chance of 'protecting' anything is if one routinely
>>does a full virus scan, and clean, of the exposed drive before write
>>enabling anything else (or if the drives never communicate with each other
>>as if they were in separate machines), but then that's a lot of work to do
>>each time one exposes the machine to the internet and a lot more work than,
>>say, not being 'admin' all the time and changing permissions.
>
>
> See my last paragraph.

As a side note, even if this 'erase and replenish' would work for you it
would not work for the vast majority of users because it is only 'safe' if
the drive is erased, or removed, before the others are write enabled and
that means no data acquired from the internet could ever be moved to the
'protected' drives as it would expose them, at the least, to the very files
being saved.

Not to mention it's simply impractical for most people to segment 'internet
access' and their other work even if they were willing to go through this
reboot and restore procedure over and over.

>>However, you could simulate 'write protect' by having a small script, with
>>admin privileges, alter the whole drive permissions when you, as 'user',
>>wanted to. Although, altering whole drive permissions is probably
>>unnecessary as you likely only need write enabled to the 'user' files you
>>work with and if you are concerned with protecting them there are
>>techniques for doing so. Encryption is one example.
>
>
> That's not a *quick* and "easy* workable solution for me. That is why
> I stated my idea concerning what the manufactureres should be doing.

I really DO mean this as a helpful comment, which is maybe you should do
some investigating into how the O.S. works and what tools are available for
these kinds of problems before deciding the computer industry is remiss in
not implementing your solution, because it's just possible that the
hundreds of thousands of trained experts in the field actually know what
they're doing and that that's why your easy solution isn't readily available.

I know that may mean more work for you on the front end but it isn't
repetitive and, the most compelling reason of all, it's better than a
solution that's not available and most likely never will be.

>>As for the 'admin' position on the switch, the hard drive controller has no
>>way of knowing who, or what, is sending write commands to it. Nor would it
>>help any to implement such a capability because, if a virus can spoof being
>>admin with the current security, it would simply spoof being admin when it
>>sent write commands to the 'admin enhanced' drive.
>>
>>The closest things to a 'virus immune' system are the Linux 'live CDs'
>>where all code is reloaded on each boot from the read only CD media.
>
> Again. A simple option/solution like what I mentioned is much easier
> and faster.

Unfortunately, your solution isn't available. The good news is, if you
investigated the other solutions I think you'd find they're easier than you
think.

David Maynard

unread,
Aug 15, 2004, 10:00:05 PM8/15/04
to
Darren Harris wrote:

<snip>

>
> You sir are the biggest idiot I've ever come across on the newsgroups.


If, when this started, I had known you were such an ignorant ass so intent
on remaining an ignorant ass I wouldn't have tried to help. So I leave you
now with the impossible solution of your own design that you so richly deserve.

Have a nice day.

Darren Harris

unread,
Aug 16, 2004, 1:50:09 AM8/16/04
to
> > Once again. Since it was implemented already, can you tell me what era
> > PCs had a switch on the outside of the case tha
t allowed one to turn
> > off/on writes to any of it's hard drives?
>
> About ten years back. If you wanted a switch on the outside you installed
> it yourself.

Well my searches have found nothing to that effect.

> The same is true for an airliner, a large ship, or a tall building. So I
> guess by your standards we don't know how to build airliners, large ships,
> or tall buildings.

As usual you are incorrect. Many airliners, many large ships, and many
tall buildings have been built, which makes them bad examples when you
are comparing them to things that had not been done before at the
dates you menioned.(ie: atomic bomb(1940), and trip to the moon(1960).

> >> > The basics are so well know that such a challenge would be weak. How
> >> > deeply would I need to explain the theory of turning off/on writes
> >>
> >> Well, at least far enough to demonstrate that you actually understand the
> >> issues involved.
> >
> > Um, Didn't you say "Wiring this on machines which contained drives
> > with a write-protect jumper was trivial."?
>
> So what do you believe is the mechanism by which the write-protect jumper
> prevents writes?

What difference does it make? You said wiring the jumpers to a switch
was trivial. The bottom line is that if it can easily be done, then
what I said can easily be done.

> Knowing how to put the key in the ignition doesn't mean that you know how a
> car operates.

I fail to see what that has to do with anything.

> I asked you a question. That was not an attack, that was an attempt to
> determine whether any solution more complex than opening a cardboard box
> and pulling out the contents was within your capabilities.

And I guess using the word stupid helps you do that.

> >> How does what you propose constitute "an easier and cheaper way to fight
> >> viruses and hackers"?
> >
> > ?!? Where were you when write-protecting was discussed?
>
> Right here and I saw no convincing case made that it was either easier or
> cheaper than the alternatives.

What's new? You also gave no reasons why the alternatives you gave are
easier or cheaper than my idea.

> And suppose everybody drives greyhound buses in preference to cars. Should
> the car manufacturers continue to produce cars that nobody wants?

Another bad example, because everyone will never drive greyhound buses
in preference to cars.

> > I had an idea like you did. I stated it. That's all.


>
> I'm sorry, but I do not recall introducing any "ideas" to this thread, only
> techniques that will address the issues you raise. Since in point of fact
> you don't seem to actually _want_ to protect your system and were instead
> just trolling, that point is moot.

Wrong again. The following was your first idea...
"_Safest_ bet is to put the files you want to protect on a server that
has no
Internet access and then use the security features of the OS on that
server
to prevent writing."

And you need to learn what "facts" are. My intent not to use your idea
doesn't mean I don't want to protect my system.

J. Clarke

unread,
Aug 16, 2004, 8:28:46 AM8/16/04
to
Darren Harris wrote:

>> > Once again. Since it was implemented already, can you tell me what era
>> > PCs had a switch on the outside of the case tha
> t allowed one to turn
>> > off/on writes to any of it's hard drives?
>>
>> About ten years back. If you wanted a switch on the outside you
>> installed it yourself.
>
> Well my searches have found nothing to that effect.

So what? Contrary to popular belief there is much knowledge that is not on
or accessible from the Internet, and even when it is there constructing
searches that actually find it can be problematical.

>> The same is true for an airliner, a large ship, or a tall building. So I
>> guess by your standards we don't know how to build airliners, large
>> ships, or tall buildings.
>
> As usual you are incorrect. Many airliners, many large ships, and many
> tall buildings have been built, which makes them bad examples when you
> are comparing them to things that had not been done before at the
> dates you menioned.(ie: atomic bomb(1940), and trip to the moon(1960).

Believe what you want to. Every new one presents challenges.

Put it this way, if the United States wanted to build a faster-than-light
starship, could the US do it? Until you know how to do something you can't
plan a path to get from here to there.

>> >> > The basics are so well know that such a challenge would be weak. How
>> >> > deeply would I need to explain the theory of turning off/on writes
>> >>
>> >> Well, at least far enough to demonstrate that you actually understand
>> >> the issues involved.
>> >
>> > Um, Didn't you say "Wiring this on machines which contained drives
>> > with a write-protect jumper was trivial."?
>>
>> So what do you believe is the mechanism by which the write-protect jumper
>> prevents writes?
>
> What difference does it make? You said wiring the jumpers to a switch
> was trivial. The bottom line is that if it can easily be done, then
> what I said can easily be done.

Fine. It can "easily be done". So put a write protect header on a new
drive and then hook a switch to it since you're sure it's so easy.



>> Knowing how to put the key in the ignition doesn't mean that you know how
>> a car operates.
>
> I fail to see what that has to do with anything.

Figures.

>> I asked you a question. That was not an attack, that was an attempt to
>> determine whether any solution more complex than opening a cardboard box
>> and pulling out the contents was within your capabilities.
>
> And I guess using the word stupid helps you do that.

I asked you a question concerning your intelligence. You had the choice of
answering it "yes, I'm too stupid to do that" or "no, I'm smart enough to
do that". There's an old saying, "if the shoe fits, wear it". From your
general attitude one can guess how you answered the question to yourself.



>> >> How does what you propose constitute "an easier and cheaper way to
>> >> fight viruses and hackers"?
>> >
>> > ?!? Where were you when write-protecting was discussed?
>>
>> Right here and I saw no convincing case made that it was either easier or
>> cheaper than the alternatives.
>
> What's new? You also gave no reasons why the alternatives you gave are
> easier or cheaper than my idea.

So there was no convincing case made that any of the alternatives was easier
or cheaper. So what?

This is USENET. You claim that some technique is "easier or cheaper" then
it's up to you to prove it. Don't like it, find a venue that is more
tolerant of fuzzy reasoning.



>> And suppose everybody drives greyhound buses in preference to cars.
>> Should the car manufacturers continue to produce cars that nobody wants?
>
> Another bad example, because everyone will never drive greyhound buses
> in preference to cars.

It wasn't an "example", it was a "hypothetical".



>> > I had an idea like you did. I stated it. That's all.
>>
>> I'm sorry, but I do not recall introducing any "ideas" to this thread,
>> only
>> techniques that will address the issues you raise. Since in point of
>> fact you don't seem to actually _want_ to protect your system and were
>> instead just trolling, that point is moot.
>
> Wrong again. The following was your first idea...
> "_Safest_ bet is to put the files you want to protect on a server that
> has no
> Internet access and then use the security features of the OS on that
> server
> to prevent writing."

That's not an "idea", it's a proven technique that works well and reliably
in millions of installations around the world.

> And you need to learn what "facts" are. My intent not to use your idea
> doesn't mean I don't want to protect my system.

I'm sorry, but _my_ idea? You're the one who said that he wanted drives
that could be write protected by flipping a switch on the outside of the
case. I told you how to implement that. If you don't want to implement
_your_ idea when told how to do so then why are you wasting everyone's time
with this?


> Darren Harris
> Staten Island, New York.

--

Darren Harris

unread,
Aug 17, 2004, 1:08:05 AM8/17/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10i0590...@corp.supernews.com>...

You are/were incapable of helping me anyway. All you have done is
waste bandwidth in your attempt to have the last word. And you've been
wrong every time. Now be a jackass with someone else.

Darren Harris

unread,
Aug 17, 2004, 1:23:56 AM8/17/04
to
> > Incorrect. There are no superior solutions. My goal was stated. The
> > reasons for my goal were stated. The solutions were given. Those
> > soultions don't work for me. The reasons they don't work for me were
> > given. The end.
>
> Your stated 'question' was whether you could 'quarantine' drives by a
> hardware 'write protect' switch. That's not a goal; it's an already
> proposed solution to 'whatever' the goal was. One you still keep as close
> to the vest as possible; leaking out hints of what you intended to do with
> it only when it suits your need to attack.

A) The original question did *not* involve whether or not I could
quarantine drives by a hardware write protect switch. Write-protect
was proposed and discussed later.
B) I never said that write protect was a goal.
c) There were no hints to lead. I've spent most of this thread
responding to your attacks and stupidity.

> >>But you have shown to not be interested in hearing the flaws in it,
> >>alternate solutions, or anything else; instead insisting the only issue is
> >>"can it [your idea] be done," which is why I say you are apparently not
> >>really interested in a 'solution' to 'the problem'.
> >
> >
> > Wrong. I'm not interested in *your* solution.
>
> I didn't give 'a' solution. I, and others, provided an entire panoply of
> possible approaches yet, even after you admit to arriving at the conclusion
> your 'solution' is "not possible," you still, not just reject but, ridicule
> any alternatives. If your idea of seeking a solution is to reject
> everything except an "impossible" one then I see where our difference of
> opinion lies.

A)Yes you did give (impractical)solutions. You can call them
approaches all you want.
B) I didn't arrive at the conclusion that my "solution" was "not
possible".
c) I did not "ridicule any alternatives".
D) And our difference in opinion is a moot point. You've failed to
understand my questions. So there was no way you could provide a
reasonable answer.

> But, hey, have fun deleting and copying your O.S. all over the place. It's
> no skin off my nose.

You certainly don't act like it.

Darren Harris

unread,
Aug 17, 2004, 1:47:07 AM8/17/04
to
> > Really? Now what makes you think that I wouldn't want to shut down,
> > "read-protect"(which may involve shutting down), or delete the
> > contents of the "C"(internet) drive before writing to any of the
> > others? It is the "C" drive that I will be erasing and mirroring to
> > from the other drives on a regular basis. That includes the OS. The
> > other three drive would in effect be source drives for "C", and when I
> > do need to copy to them or work with them individually, I will of
> > course take "C" out of the loop.
>
> That an interesting new tidbit of information on how you envision it would
> work. (If you'll notice, I was trying to cover the main possibilities here
> and below, where I described that approach, because you had not said
> anything about how you intended for it to work)

I didn't have to. The original question was simple.

> Erasing the C: drive would entail rebooting to another drive so you have
> something to run on (obviously can't run from the drive you're planning to
> erase), then replenishing the files on C: so you could then boot it for the
> next 'exposure' to the internet, and the process repeated each time. So no,
> after you vigorously complained that the simple act of changing user
> permissions is so burdensome I would not have guessed you would think the
> infinitely more complex and time consuming task of multiple reboots, and
> BIOS setting to change boot drives, along with erasing and replenishing the
> C: drive was 'easier'.

All this means nothing, because I still haven't given you all the
details. You're still dabbling in, assuming, and addressing things
that I haven't completely touch upon. I have four drives that are the
same size, model, and make. It should be a relatively simple matter to
erase my "C" drive and then mirror to it from my "D" drive. Stop
trying to guess what I want to do.

> As a side note, even if this 'erase and replenish' would work for you it
> would not work for the vast majority of users because it is only 'safe' if
> the drive is erased, or removed, before the others are write enabled and
> that means no data acquired from the internet could ever be moved to the
> 'protected' drives as it would expose them, at the least, to the very files
> being saved.

I fail to see your point. And it makes no difference to me that what I
want to do will not work for the majority of users.

> Not to mention it's simply impractical for most people to segment 'internet
> access' and their other work even if they were willing to go through this
> reboot and restore procedure over and over.

I'm not most people. And I never said how often I will erase and
restore. I'll have three source/back-up drives configured the way I
want with whatever apps I need. Whenever I erase "C", I'll have the
option of restoring from any of those drives

> > That's not a *quick* and "easy* workable solution for me. That is why
> > I stated my idea concerning what the manufactureres should be doing.
>
> I really DO mean this as a helpful comment, which is maybe you should do
> some investigating into how the O.S. works and what tools are available for
> these kinds of problems before deciding the computer industry is remiss in
> not implementing your solution, because it's just possible that the
> hundreds of thousands of trained experts in the field actually know what
> they're doing and that that's why your easy solution isn't readily available.

We're never going to agree on this, so why bother.

> I know that may mean more work for you on the front end but it isn't
> repetitive and, the most compelling reason of all, it's better than a
> solution that's not available and most likely never will be.

That is your opinion.

> Unfortunately, your solution isn't available. The good news is, if you
> investigated the other solutions I think you'd find they're easier than you
> think.

I've investigated enough, and have already stated my position.

Darren Harris

unread,
Aug 17, 2004, 2:00:13 AM8/17/04
to
> > Well my searches have found nothing to that effect.
>
> So what? Contrary to popular belief there is much knowledge that is not on
> or accessible from the Internet, and even when it is there constructing
> searches that actually find it can be problematical.

In that case. I won't believe it until I see it.

> Believe what you want to. Every new one presents challenges.
>
> Put it this way, if the United States wanted to build a faster-than-light
> starship, could the US do it? Until you know how to do something you can't
> plan a path to get from here to there.

I have no idea what your point is. And the laws of physics don't allow
for travel faster than light.

> > What difference does it make? You said wiring the jumpers to a switch
> > was trivial. The bottom line is that if it can easily be done, then
> > what I said can easily be done.
>
> Fine. It can "easily be done". So put a write protect header on a new
> drive and then hook a switch to it since you're sure it's so easy.

You said that was easy. My idea involves what the manufacturers can
do.

> >> Knowing how to put the key in the ignition doesn't mean that you know how
> >> a car operates.
> >
> > I fail to see what that has to do with anything.
>
> Figures.

Yes it does.

> I asked you a question concerning your intelligence. You had the choice of
> answering it "yes, I'm too stupid to do that" or "no, I'm smart enough to
> do that". There's an old saying, "if the shoe fits, wear it". From your
> general attitude one can guess how you answered the question to yourself.

I'd rather respond to insults with insults.

> >> Right here and I saw no convincing case made that it was either easier or
> >> cheaper than the alternatives.
> >
> > What's new? You also gave no reasons why the alternatives you gave are
> > easier or cheaper than my idea.
>
> So there was no convincing case made that any of the alternatives was easier
> or cheaper. So what?

So what?

> This is USENET. You claim that some technique is "easier or cheaper" then
> it's up to you to prove it. Don't like it, find a venue that is more
> tolerant of fuzzy reasoning.

You haven't proven anything. I'm still wating for what you said was
done already.

> >> And suppose everybody drives greyhound buses in preference to cars.
> >> Should the car manufacturers continue to produce cars that nobody wants?
> >
> > Another bad example, because everyone will never drive greyhound buses
> > in preference to cars.
>
> It wasn't an "example", it was a "hypothetical".

What difference does that make? It was a hypothetical example and it
was a bad one.

> > Wrong again. The following was your first idea...
> > "_Safest_ bet is to put the files you want to protect on a server that
> > has no
> > Internet access and then use the security features of the OS on that
> > server
> > to prevent writing."
>
> That's not an "idea", it's a proven technique that works well and reliably
> in millions of installations around the world.

It is still an idea...

> > And you need to learn what "facts" are. My intent not to use your idea
> > doesn't mean I don't want to protect my system.
>
> I'm sorry, but _my_ idea? You're the one who said that he wanted drives
> that could be write protected by flipping a switch on the outside of the
> case. I told you how to implement that. If you don't want to implement
> _your_ idea when told how to do so then why are you wasting everyone's time
> with this?

It is you who are wasting everyone's time. I'm not the one who said
that connecting a switch to the drives jumpers was trivial. I believe
that there are software a firmware changes that have to be made
inorder to make this plausible. And I believe the manufacturers have
the ability to do it. You can disagree all you want.

David Maynard

unread,
Aug 17, 2004, 2:28:29 AM8/17/04
to
Darren Harris wrote:

>>>Incorrect. There are no superior solutions. My goal was stated. The
>>>reasons for my goal were stated. The solutions were given. Those
>>>soultions don't work for me. The reasons they don't work for me were
>>>given. The end.
>>
>>Your stated 'question' was whether you could 'quarantine' drives by a
>>hardware 'write protect' switch. That's not a goal; it's an already
>>proposed solution to 'whatever' the goal was. One you still keep as close
>>to the vest as possible; leaking out hints of what you intended to do with
>>it only when it suits your need to attack.
>
>
> A) The original question did *not* involve whether or not I could
> quarantine drives by a hardware write protect switch. Write-protect
> was proposed and discussed later.
> B) I never said that write protect was a goal.
> c) There were no hints to lead. I've spent most of this thread
> responding to your attacks and stupidity.

Trying to find out what the hell you're talking about isn't an 'attack' nor
is pointing out flaws in your proposed hardware write protect methodology.
What constitutes an 'attack' is your perpetual hurling of insults simply
because people can't read your mind.

But, from now on, you can get your jollies banging your head against the
wall and hurling insults into the 'industry ethos' that doesn't make your
pet 'solution' for all I care because, as I said in the last one, I'm done
with you and simply closing out the remaining threads.

<snip>

David Maynard

unread,
Aug 17, 2004, 2:34:52 AM8/17/04
to
Darren Harris wrote:

<snip>


>
>
> All this means nothing, because I still haven't given you all the
> details.


Precisely. Which is what I said all along.

bye


<snip>

J. Clarke

unread,
Aug 17, 2004, 9:37:20 AM8/17/04
to
Darren Harris wrote:

>> > Well my searches have found nothing to that effect.
>>
>> So what? Contrary to popular belief there is much knowledge that is not
>> on or accessible from the Internet, and even when it is there
>> constructing searches that actually find it can be problematical.
>
> In that case. I won't believe it until I see it.

Fine.

>> Believe what you want to. Every new one presents challenges.
>>
>> Put it this way, if the United States wanted to build a faster-than-light
>> starship, could the US do it? Until you know how to do something you
>> can't plan a path to get from here to there.
>
> I have no idea what your point is. And the laws of physics don't allow
> for travel faster than light.

The laws that we _know_. See the point? In 1850 the laws of physics did
not allow nuclear weapons.

>> > What difference does it make? You said wiring the jumpers to a switch
>> > was trivial. The bottom line is that if it can easily be done, then
>> > what I said can easily be done.
>>
>> Fine. It can "easily be done". So put a write protect header on a new
>> drive and then hook a switch to it since you're sure it's so easy.
>
> You said that was easy. My idea involves what the manufacturers can
> do.

So try to figure out what manufacturers have to do to give you what you want
and maybe you'll understand why they don't bother.

>> >> Knowing how to put the key in the ignition doesn't mean that you know
>> >> how a car operates.
>> >
>> > I fail to see what that has to do with anything.
>>
>> Figures.
>
> Yes it does.
>
>> I asked you a question concerning your intelligence. You had the choice
>> of answering it "yes, I'm too stupid to do that" or "no, I'm smart enough
>> to
>> do that". There's an old saying, "if the shoe fits, wear it". From your
>> general attitude one can guess how you answered the question to yourself.
>
> I'd rather respond to insults with insults.

It would help if you first learned to recognize an insult.

>> >> Right here and I saw no convincing case made that it was either easier
>> >> or cheaper than the alternatives.
>> >
>> > What's new? You also gave no reasons why the alternatives you gave are
>> > easier or cheaper than my idea.
>>
>> So there was no convincing case made that any of the alternatives was
>> easier
>> or cheaper. So what?
>
> So what?
>
>> This is USENET. You claim that some technique is "easier or cheaper"
>> then
>> it's up to you to prove it. Don't like it, find a venue that is more
>> tolerant of fuzzy reasoning.
>
> You haven't proven anything. I'm still wating for what you said was
> done already.

Well, since you don't believe what people who have been there and done that
tell you, you're going to have a long wait.



>> >> And suppose everybody drives greyhound buses in preference to cars.
>> >> Should the car manufacturers continue to produce cars that nobody
>> >> wants?
>> >
>> > Another bad example, because everyone will never drive greyhound buses
>> > in preference to cars.
>>
>> It wasn't an "example", it was a "hypothetical".
>
> What difference does that make? It was a hypothetical example and it
> was a bad one.

Your opinion.

>> > Wrong again. The following was your first idea...
>> > "_Safest_ bet is to put the files you want to protect on a server that
>> > has no
>> > Internet access and then use the security features of the OS on that
>> > server
>> > to prevent writing."
>>
>> That's not an "idea", it's a proven technique that works well and
>> reliably in millions of installations around the world.
>
> It is still an idea...

If you choose to call it that.



>> > And you need to learn what "facts" are. My intent not to use your idea
>> > doesn't mean I don't want to protect my system.
>>
>> I'm sorry, but _my_ idea? You're the one who said that he wanted drives
>> that could be write protected by flipping a switch on the outside of the
>> case. I told you how to implement that. If you don't want to implement
>> _your_ idea when told how to do so then why are you wasting everyone's
>> time with this?
>
> It is you who are wasting everyone's time. I'm not the one who said
> that connecting a switch to the drives jumpers was trivial. I believe
> that there are software a firmware changes that have to be made
> inorder to make this plausible.

I see, you are illiterate. I said that putting a switch on a drive that had
a write-protect header was trivial. Since that fact is intuitively obvious
to the most casual observer it needs no proof. And I am surprised that in
the extensive research that you claim to have conducted you have not
encountered any of the many, many drives that were shipped with such a
header.

> And I believe the manufacturers have
> the ability to do it. You can disagree all you want.

Nobody has claimed that the manufacturers lack the ability. What has been
claimed is that they have no reason whatsoever to want to provide it.

Regardless, this is pointless--I don't know if your problem is illiteracy,
idiocy, or a bad attitude but I'm not wasting any more time on you.

<plonk>

Darren Harris

unread,
Aug 17, 2004, 2:56:32 PM8/17/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10i39c1...@corp.supernews.com>...

> Darren Harris wrote:
>
> >>>Incorrect. There are no superior solutions. My goal was stated. The
> >>>reasons for my goal were stated. The solutions were given. Those
> >>>soultions don't work for me. The reasons they don't work for me were
> >>>given. The end.
> >>
> >>Your stated 'question' was whether you could 'quarantine' drives by a
> >>hardware 'write protect' switch. That's not a goal; it's an already
> >>proposed solution to 'whatever' the goal was. One you still keep as close
> >>to the vest as possible; leaking out hints of what you intended to do with
> >>it only when it suits your need to attack.
> >
> >
> > A) The original question did *not* involve whether or not I could
> > quarantine drives by a hardware write protect switch. Write-protect
> > was proposed and discussed later.
> > B) I never said that write protect was a goal.
> > c) There were no hints to lead. I've spent most of this thread
> > responding to your attacks and stupidity.
>
> Trying to find out what the hell you're talking about isn't an 'attack' nor
> is pointing out flaws in your proposed hardware write protect methodology.
> What constitutes an 'attack' is your perpetual hurling of insults simply
> because people can't read your mind.

It's your perpetual lies and false assumptions that are the issue.
Anyone can see that you are just trolling and willnot stop. And you
comments about my reading comprehension, alleged inability to read or
type with any clarity, and inference that I am nutty because I want to
keep copies of my O.S. on all four of my drives that have prompted the
insults back.

> But, from now on, you can get your jollies banging your head against the
> wall and hurling insults into the 'industry ethos' that doesn't make your
> pet 'solution' for all I care because, as I said in the last one, I'm done
> with you and simply closing out the remaining threads.

I serious doubt it. You will continue to casue problems. That is why I
said we will be at this for the next 50 years.

Darren Harris

unread,
Aug 17, 2004, 3:07:01 PM8/17/04
to
David Maynard <dNOT...@ev1.net> wrote in message news:<10i39o0...@corp.supernews.com>...

And those details were unnecessary(for a normal person), because the
original question was simple. Any more info given throughout the
thread was only geared toward addressing points that I don't believe I
should ahve had to get into.

> bye

Promises, promises.

Darren Harris

unread,
Aug 17, 2004, 3:29:26 PM8/17/04
to
> > I have no idea what your point is. And the laws of physics don't allow
> > for travel faster than light.
>
> The laws that we _know_. See the point? In 1850 the laws of physics did
> not allow nuclear weapons.

In 1850 the laws of physics did very little to address this issue at
all. So this is all academic. And once they did, it was determined
that acheiving speeds faster than light is not possible. See the
point?

> > You said that was easy. My idea involves what the manufacturers can
> > do.
>
> So try to figure out what manufacturers have to do to give you what you want
> and maybe you'll understand why they don't bother.

I understand, and I've covered this already.

> > I'd rather respond to insults with insults.
>
> It would help if you first learned to recognize an insult.

I have and did.

> Well, since you don't believe what people who have been there and done that
> tell you, you're going to have a long wait.

When "people who have been there and done that" show up my wait will
have ended.

> >> It wasn't an "example", it was a "hypothetical".
> >
> > What difference does that make? It was a hypothetical example and it
> > was a bad one.
>
> Your opinion.

That is correct.

> > It is still an idea...
>
> If you choose to call it that.

I do, and have.

> >> > And you need to learn what "facts" are. My intent not to use your idea
> >> > doesn't mean I don't want to protect my system.
> >>
> >> I'm sorry, but _my_ idea? You're the one who said that he wanted drives
> >> that could be write protected by flipping a switch on the outside of the
> >> case. I told you how to implement that. If you don't want to implement
> >> _your_ idea when told how to do so then why are you wasting everyone's
> >> time with this?
> >
> > It is you who are wasting everyone's time. I'm not the one who said
> > that connecting a switch to the drives jumpers was trivial. I believe
> > that there are software a firmware changes that have to be made
> > inorder to make this plausible.
>
> I see, you are illiterate. I said that putting a switch on a drive that had
> a write-protect header was trivial. Since that fact is intuitively obvious
> to the most casual observer it needs no proof. And I am surprised that in
> the extensive research that you claim to have conducted you have not
> encountered any of the many, many drives that were shipped with such a
> header.

A moron calling me illiterate? I never said that proof was need that
it is possible to put a switch on a drive that had a write-protect
header. I was referring to proff that there were PCs for sale with
switches on the outside of their cases that would allow one to turn
on/off writing to individual drives.

Also, I never said that after "extensive research that (I) have
conducted (I) have not encountered any of the many, many drives that


were shipped with such a header."

> > And I believe the manufacturers have
> > the ability to do it. You can disagree all you want.
>
> Nobody has claimed that the manufacturers lack the ability. What has been
> claimed is that they have no reason whatsoever to want to provide it.

You need to re-read these posts.

> Regardless, this is pointless--I don't know if your problem is illiteracy,
> idiocy, or a bad attitude but I'm not wasting any more time on you.

Good riddance.

Darren Harris
Staten ISland, New York.

0 new messages