Read-Only: Setting Hard Drives to Read-Only

Depending on the user's use case. Choose one.
- A) ISO users installing Kicksecure: Using the ISO just to install Kicksecure? This does not matter. The user can ignore any live mode related warnings. These are not applicable.
- B) Interested in live mode? See below.
When using live mode (grub-live or ISO live), no changes are made to the disk. For added security, consider setting your disk to read-only mode, if possible.
Sometimes it possible to optionally set the disks to read-only. This increases the security of live mode, because otherwise malware running as root could theoretically mount the image read-write and gain persistence in this way.
Contents
Introduction[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Introduction
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Introduction|Introduction]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Introduction)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Introduction)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Introduction]Introduction[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
The emphasis is on if possible.
This is platform specific.
Unfortunately, read-only mode is not easily available on all platforms.
VMs[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#VMs
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#VMs|VMs]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[VMs](https://www.kicksecure.com/wiki/Read-only?stableid=84569#VMs)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[VMs](https://www.kicksecure.com/wiki/Read-only?stableid=84569#VMs)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#VMs]VMs[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
VirtualBox[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#VirtualBox
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#VirtualBox|VirtualBox]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[VirtualBox](https://www.kicksecure.com/wiki/Read-only?stableid=84569#VirtualBox)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[VirtualBox](https://www.kicksecure.com/wiki/Read-only?stableid=84569#VirtualBox)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#VirtualBox]VirtualBox[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Step-by-step guide on implementing the Immutable Disk Method for Virtual Machine (VM) Live Mode in VirtualBox, focusing on secure, read-only VM configurations.
This option is the official method for setting VMs to read-only in VirtualBox. It will only work with the grub-live
package, which is installed by default. [1]
1. Make the VirtualBox disk immutable / read-only.
This step is crucial. Otherwise, contents might be recoverable from the host drive. [2]
Follow these steps:
- Power off the VM.
- In the VirtualBox main window, navigate to:
File
→Tools
→Virtual Media Manager
.
- Select the disk to write protect and release it.
- Then on
Type
→set it to Immutable
.
- In the VirtualBox main window, navigate to the settings of the VM.
- Under storage, select the top controller and add the existing hard disk there.
2. Launch live-mode.
Follow the documentation on the Live Mode wiki page.
3. Done.
The process of enabling read-only mode has been completed.
KVM[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#KVM
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#KVM|KVM]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[KVM](https://www.kicksecure.com/wiki/Read-only?stableid=84569#KVM)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[KVM](https://www.kicksecure.com/wiki/Read-only?stableid=84569#KVM)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#KVM]KVM[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
1. Set the VM disks to read-only.
Follow these steps:
- Power off the machine.
- Set the hard disk to read-only in the virt-manager GUI before booting into live mode.
2. Launch live-mode.
Follow the documentation on the Live Mode wiki page.
3. Optional: Revert the read-only change.
To boot into normal mode again, revert the change from step 1 and choose the normal boot option in the GRUB menu.
4. Done.
The process of enabling read-only mode has been completed.
Qubes[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Qubes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Qubes|Qubes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Qubes](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Qubes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Qubes](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Qubes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Qubes]Qubes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
grub-live
is currently unsupported on Qubes. [3] This issue is unspecific to Kicksecure. Qubes issue: implement live boot by porting grub-live to Qubes - amnesia / non-persistent boot / anti-forensics
In Qubes, Disposables are a suitable alternative.
Host Operating System[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Host_Operating_System
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Host_Operating_System|Host Operating System]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Host Operating System](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Host_Operating_System)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Host Operating System](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Host_Operating_System)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Host_Operating_System]Host Operating System[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
This would require a hard drive that comes with a physical read-only switch.
This is undocumented and unspecific to Kicksecure.
Comparison with Tails[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Comparison_with_Tails
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Comparison_with_Tails|Comparison with Tails]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Comparison with Tails](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Comparison_with_Tails)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Comparison with Tails](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Comparison_with_Tails)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Comparison_with_Tails]Comparison with Tails[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Comparison between grub-live and Tails
Alternative Configurations[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Alternative_Configurations
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Alternative_Configurations|Alternative Configurations]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Alternative Configurations](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Alternative_Configurations)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Alternative Configurations](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Alternative_Configurations)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Alternative_Configurations]Alternative Configurations[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- KVM: Skip this section if the KVM Live-mode
- VirtualBox: Skip this section if VirtualBox Live-mode configuration steps above have already been completed.
VirtualBox and KVM: VM Live Mode: Alternative ro-mode-init Configuration
Footnotes[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Read-only?stableid=84569#Footnotes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Read-only#Footnotes|Footnotes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Footnotes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Read-only?stableid=84569#Footnotes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Read-only?stableid=84569#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- ↑
This option will not work with the
ro-mode-init
package. - ↑ VirtualBox implements hard disk write protection differently. If an immutable virtual machine is booted, VirtualBox will always create a snapshot where data is written. After shutting down and booting the VM again (a soft reboot is inadequate), the old snapshot will be deleted and a new one created. Consequently, data will not persist in the VM, even if Live-mode is not selected. However, since the data is written to the hard disk of the host (instead of memory), it is easily recoverable. Therefore, selecting Live-mode is essential for safety. A snapshot file is still created, but it will not store any altered content from the VM.
- ↑
Nothing came out from forum discussion
.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!