Secure portable Win 10 VM


Recommended Posts

I'm looking to create a secure portable VM (a bit like Windows To Go but as a VM) that I can use at home, work and on the go on. All the machines have VMware Workstation Pro on, my idea is to run the VM off my portable SSD. If I encrypted the SSD with BitLocker (256bit just to be sure), then encrypted the machine with VMware on top of that.... Would that give adequete protection that if lost, I could comfortably leave things like Outlook, Dashlane and browser sessions signed in? Or perhaps somebody could recommend a different way to achieve this?

Link to comment
https://www.neowin.net/forum/topic/1401740-secure-portable-win-10-vm/
Share on other sites

As an alternative you could SSH into your home network, forward a port over the tunnel and Remote Desktop to your main computer at home. Nothing to carry about and potentially loose then.


A portable hard drive / VM encrypted BitLocker should be secure enough though, presuming you trust all the machines you will unlock this drive on.

4 minutes ago, InsaneNutter said:

As an alternative you could SSH into your home network, forward a port over the tunnel and Remote Desktop to your main computer at home. Nothing to carry about and potentially loose then.


A portable hard drive / VM encrypted BitLocker should be secure enough though, presuming you trust all the machines you will unlock this drive on.

That's not a bad idea actually. I haven't used SSH much beyond basic Linux admin but I will look into this. A small, low powered mini PC might be ideal for this.

52 minutes ago, SouthSider said:

That's not a bad idea actually. I haven't used SSH much beyond basic Linux admin but I will look into this. A small, low powered mini PC might be ideal for this.

Something like an Intel NUC would be ideal for that, you could even run SSH on that if your router is not capable of doing so. Routers with custom firmware installed such as DD-WRT or Tomato can run an SSH server by clicking a few options in the web ui, running SSH on port 443 should even allow you to connect from behind pretty restrictive firewalls too.

 

From what you've said you likely already know how to establish an SSH session with Putty, so its just a case of setting a tunnel up once you do. Essentially select the destination on your home network you wish to tunnel to and the source port on the local machine you will make the connection from.

 

So for example when I type localhost:1111 in to Remote Desktop, that will go though my SSH tunnel to my machine at home with the ip 192.168.1.3 on my home network:

 

image.thumb.png.320361d93e8dd3bb80bf39cf3486bdd8.png

  • Like 2
  • 2 weeks later...

the only problem with a mobile VM is windows activation, it will detect it's changed environments even if it's VMware to VMware and ask to activate again, i have the same problem in VirtualBox, even on the same machine it will prompt for re-activation. 

 

I think the other options of a NUC, Laptop or remote SSH / RDP session might be easier?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Wow, throwback.  VERY VERY briefly - but realised that it wasn't the language I needed for the tasks I was taking on.
    • Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack by Hamid Ganji Image via Depositphotos.com Tata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies. The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.” The ransomware group reportedly sent a ransom demand to Tata Electronics, while Apple has launched an investigation into the incident. World Leaks claims it stole more than 200,000 files totaling over 630GB from Tata Electronics. Some database files on the ransomware group’s website are titled "com.apple.factorydata," which could refer to Apple’s iPhone production operations in India. Moreover, some documents reportedly contain material specifications and quality inspection standards for iPhone circuit board components. However, Apple is not the only affected company. A folder found in the World Leaks database is titled "NV36 Chargeport Controller - North America," which may refer to Tesla Model Y components. Additionally, other files in the database reportedly contain drawings related to Tesla’s Project Highland, the internal codename for the EV maker’s updated Model 3 sedan. To support the authenticity of the stolen files, World Leaks has published documents containing footers that read: "This document contains proprietary and confidential information of Apple Inc." and "information contained herein is deemed confidential, proprietary, and a trade secret of Tesla Inc." Cybersecurity researcher Rajshekhar Rajaharia told Reuters that the database also contains emails, event logs spanning several years, and passport copies of employees, including foreign nationals. Both Tesla and Apple have declined to comment on the scale of the incident.
    • Last time I used Pascal was in college about 40 yrs ago, programmed an inventory database for my exam.
    • If they don't sell enough of the 1st gen then there won't be a 2nd gen
    • Epic fail, should've added an eSata port on the back, also if the memory/NVME are soldered then they're hardly gonna sell any, first thing most people do with their Steamdeck is, or used to be, replacing the NVME with a 2TB one. At that price they should, possibly for the first time, offer an installments option, say 24 months, they may sell a lot if they do. I'm sure they would have no shortage of credit companies willing to partner.
  • Recent Achievements

    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      487
    2. 2
      +Edouard
      204
    3. 3
      PsYcHoKiLLa
      95
    4. 4
      Michael Scrip
      91
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!