Live data from Hacker News

BusKill: A kill cord for your laptop

tech.michaelaltfield.net

81–90 of 272 posts

Re: BusKill: A kill cord for your laptop

#81

Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.micha... I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.

"Kill cord" is jargon from jetskis, powerboats and treadmills, which often have a cord you attach to your body that cuts power if you are thrown off. [1] On Linux there is blueproximity [2] that can lock (and if you like, unlock) your computer based on the proximity of a bluetooth device. My personal experience is that Bluetooth is frustratingly unreliable, and this package was no exception. But it's there if you'd l…

Is it possible that the bluetooth unreliability was a driver issue and others work fine?

In other words, did you test different bluetooth devices?

Re: BusKill: A kill cord for your laptop

#82

Earlier quoted context omitted.

It's not pronounced "of", it's more like "ev", exactly like the contraction of words it's made up of. Would have.

In my household I'm the English nerd, although I have no degree behind it. I'd correct my wife when she wrote "would of" but then I listened closer when she talked: She wasn't saying "would've" she was saying "would of". That's when I gave up. There are a million other reasons to love my wife, and her proper use of 'would've' wasn't one of them to begin with :)

[deleted]

Re: BusKill: A kill cord for your laptop

#83
post #16

Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.micha... I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.

If you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 ( https://www.xkcd.com/538/ ) still applies.

Are there any known cases of western police forces beating people with wrenches until they gave up passwords?

Re: BusKill: A kill cord for your laptop

#84
post #34

Earlier quoted context omitted.

I'm surprised there isn't a "ready to go" solution with a duress passphrase that boots a plausible, but "clean" system.

It's not quite ready to go, but it's doable with TrueCrypt/VeraCrypt: https://www.veracrypt.fr/en/VeraCrypt%20Hidden%20Operating%2...

Why is it not ready to go? I used truecrypt hidden systemvolume years ago?

I do not anymore, but did it decreased?

Re: BusKill: A kill cord for your laptop

#85
post #39

I guess I'll share in this thread. ---1--- I have a OnePlus 6T with the stock ROM exclusively for my British phone number. On the 25th of December, someone from Canada logged into the GMail account used on that phone, from a OnePlus 3T. The password was one randomly generated in KeePass (all of them are except for useless websites). They managed to change the password to the account, but seemingly nothing else, so th…

I would assume that whoever that was now has a copy of your keepass database. However, it may be that your computer was simply added to a botnet, in which case the harm done to you personally may be minimal.

Re: BusKill: A kill cord for your laptop

#86
post #29

This is a really neat project but it’s also not really a solution to anything. First, it doesn’t solve for the scenario of person pointing a gun at you and telling you to access your top secret files for them. That will defeat most forms of security and so if physical access is a concern you probably shouldn’t be logging in at your local coffee shop. Second, a thief who wants your computer for its monetary value isn’…

> This is a really neat project but it’s also not really a solution to anything.

Knowing your encrypted data is inaccessible to a thief is a huge relief, and may have saved this man's life:

A man working at Starbucks had his laptop stolen. He was killed when he chased down the thief. https://www.cnn.com/2020/01/01/us/oakland-laptop-thief-starb...

Re: BusKill: A kill cord for your laptop

#87
post #5

Earlier quoted context omitted.

Other English speakers I know complain about our orthography: bought, caught, draught, etc. But, yet, here we are with a “word” pronounced “of” and spelled “‘ve”! Now that’s awful orthography!

It's not pronounced "of", it's more like "ev", exactly like the contraction of words it's made up of. Would have.

To me "would of" and "would've" are pronounced exactly the same.

If I said "would ev" that would sound weird. It would sound very similar to "whatev":

https://www.urbandictionary.com/define.php?term=whatev

Re: BusKill: A kill cord for your laptop

#88
post #79

Earlier quoted context omitted.

In theory an adversary could deep-freeze the computer the moment the kill cord activates. Sufficiently cold RAM doesn't loose data immediately when it loses power, allowing the adversary to make a copy and read the decryption keys from RAM. Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibr…

I've always heard that cold boot attacks like that require the ram to be frozen before the computer turns off (or the ram is removed).

In reality, RAM doesn't so much instantly lose its contents on power off anyway, the freezing just slows it down. IIRC there are cases of recovering significant portions of RAM a half hour or more after poweroff even without freezing.

Re: BusKill: A kill cord for your laptop

#89
post #16

Earlier quoted context omitted.

If you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 ( https://www.xkcd.com/538/ ) still applies.

In theory an adversary could deep-freeze the computer the moment the kill cord activates. Sufficiently cold RAM doesn't loose data immediately when it loses power, allowing the adversary to make a copy and read the decryption keys from RAM. Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibr…

I'd like to see a post demonstrating this attack.

Re: BusKill: A kill cord for your laptop

#90
post #33

Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.micha... I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.

I suppose if the drive is encrypted and requires a passphrase at boot, it's effective for FBI raids, etc.

Whenever I read stuff like this I am forced to wonder just what the fuck people are doing that they feel such a pressing need to hide their data from law enforcement.

I mean, I have plenty of things to hide just like any other reasonably interesting person, but none of it is outright criminal.

Post reply on HN