Live data from Hacker News

BusKill: A kill cord for your laptop

tech.michaelaltfield.net

51–60 of 272 posts

Re: BusKill: A kill cord for your laptop

#51
I will sometimes go to the university library to do some work and I'm always amazed at people who will go to the restroom or something and leave their laptop sitting there without a lock or even logged out.

I always use a kensington lock and lock my screen whenever I have to leave my laptop. If I had a macbook I would be taking it with me. I know the locks won't stop someone who really wants to steal it but with so many unattended laptops sitting around it makes it less likely they will go for mine.

Re: BusKill: A kill cord for your laptop

#52
post #49

> You could just have a usb thumb drive on a retractable lanyard (think RFID badges or DoD Common Access Cards), but what if that thin retractable cord just snaps–leaving the USB drive snugly in-place in the laptop? You could also just use a thicker cord. The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment. > As of yesterday, that’s [stolen laptop] a hard attack to d…

2FA doesn't matter if you're already logged in.

Re: BusKill: A kill cord for your laptop

#54
post #16

Earlier quoted context omitted.

If you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 ( https://www.xkcd.com/538/ ) still applies.

In theory an adversary could deep-freeze the computer the moment the kill cord activates. Sufficiently cold RAM doesn't loose data immediately when it loses power, allowing the adversary to make a copy and read the decryption keys from RAM. Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibr…

How long does it take RAM to lose that data though? Most laptops take far more time to remove the ram than a PC and it's soldered down in a lot of cases.

Re: BusKill: A kill cord for your laptop

#55
post #41

Earlier quoted context omitted.

Not really ready-to-go, but can be set up in entirety in like half an hour with VeraCrypt

Well, you would probably want some stealth that doesn't provide that makes it less obvious. Like maybe the duress passphrase decrypts everything except a docker container you use for sensitive work, replacing it with a vanilla docker image. Edit: Ahh, read up a but. I wasn't aware "veracrypt hidden volumes" are already pretty stealthy. Would probably require some work to make it plausible though...like recent faked w…

The VeraCrypt guide recommends "You should use the decoy operating system as frequently as you use your computer. Ideally, you should use it for all activities that do not involve sensitive data." You don't need to fake it per se, but section off what needs to be in the hidden operating system (rather than a standard VeraCrypt partition). You are therefore revealing real, thus plausible, information, but not the actual subset you want to hide.

Re: BusKill: A kill cord for your laptop

#56

What if someone plugs in a rubber ducky or some other kind of sophisticated USB while you turn your head for just a second? There are USB devices that are so small, you can barely even see them in the port when plugged in. Perhaps a hard-to-remove USB plug? (like child-proof plugs you might see in an electrical outlet)

There are udev rules to defeat this kind of thing, law enforcement use USB mouse jigglers to keep computers awake for example, these can be filtered out and ignored.

Re: BusKill: A kill cord for your laptop

#57
post #49

> You could just have a usb thumb drive on a retractable lanyard (think RFID badges or DoD Common Access Cards), but what if that thin retractable cord just snaps–leaving the USB drive snugly in-place in the laptop? You could also just use a thicker cord. The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment. > As of yesterday, that’s [stolen laptop] a hard attack to d…

2FA doesn't matter if you're already logged in.

> extra PSA: if you’re worried about this but somehow haven’t already required 2FA...

I’m aware - I’m pointing out that it’s extremely likely you already have a physical device you can attach to a cord/chain/braided-steel-cable and use for the “snatch and grab” scenario. And that a snatch and grab is just so unlikely compared to any other security threat imo.

Re: BusKill: A kill cord for your laptop

#58
post #5

Earlier quoted context omitted.

Other English speakers I know complain about our orthography: bought, caught, draught, etc. But, yet, here we are with a “word” pronounced “of” and spelled “‘ve”! Now that’s awful orthography!

It's not pronounced "of", it's more like "ev", exactly like the contraction of words it's made up of. Would have.

əv

Re: BusKill: A kill cord for your laptop

#59
post #50
post #44

Earlier quoted context omitted.

The heart rate of your examples are somewhat different compared to an active threat for most people I assume from being in a situation when a crime is taking place. Although, I would be curious to view trials of each situation showing the heart rate measurement with the statistical average result.

Many other potential variables as well. When experiencing this event, how long does it take your heart rate to reach a point it can be identified as worthy of triggering the switch? Is the laptop still in range of your smart watch at that point? Then there's the reliability of the wireless connection and the watches ability to accurately read your heart rate (make sure it's seated correctly). If this is a situation y…

I assume you would want the computer to be locked if the watch signal dropped and being concerned enough to desire the feature in question. I'm doubtful one's heart rate isn't increasing in an event of theft and where it wouldn't lock a person out in time before for a person significantly uses the device. There are multiple variables but I can also see the wired approach being futile in situations where a person is pinned down by multiple people.

Re: BusKill: A kill cord for your laptop

#60
post #48

Earlier quoted context omitted.

Cases like this in countries that do not have due process laws makes the use-case even more compelling.

If they don’t have due process laws they can throw you in jail until you produce the decryption password, and if they turn on the computer and it’s wiped they’ll throw away the key. If there is no due process, all bets are off and your best defense is to be uninteresting to authorities.

Things are not always black and / or white. The rule of law, in reality, is rather a continuous variable then a binary one.

And even if: A kill switch can simply hide / erase some things and present some weak evidence..

Post reply on HN