Live data from Hacker News

BusKill: A kill cord for your laptop

tech.michaelaltfield.net

101–110 of 272 posts

Re: BusKill: A kill cord for your laptop

#101

Earlier quoted context omitted.

Making it self-destruct is the easy part, just change "DISPLAY=:0 xscreensaver-command -lock" to "sudo rm -rf /" or whatever you like. It's understandable that the author didn't want to put a destructive command in his example configuration.

A drive wipe might take too long though, especially if they grab the laptop and shut if off. After a simple shutdown or lock, disk encryption really is the primary protection here.

Change encryption key to random value, discard random value.

Re: BusKill: A kill cord for your laptop

#102
post #69

The article keeps saying "self-destruct" but that's not what happens. But if your hard drive is encrypted, this is a pretty good solution for most people. Maybe if you can get BusKill to activate a mini thermite explosive under your hard drive.

I remember watching a Defcon conference where they tested different methods for destroying a hard drive in place. And they found that thermite actually doesn't damage the platters (well at least not enough for data to be unrecoverable). Hard drive platters are surprisingly heat/chemical resistant. I think they found that the best method was to physically destroy the platters.

I remember watching that talk years ago. I was disappointed in the lack of rigor of their conclusions.

The whole point of thermite-based HDD destruction is to get the platens over the Curie temperature so the magnetic field is gone, not to physically destroy them. They point this out in the start, but then never talk about whether this was achieved or not in their experiment (assumably so they could go on to the actual explosives).

It was entertainment, and I'd take any results with a grain of salt.

Re: BusKill: A kill cord for your laptop

#103
post #32
post #29

This is a really neat project but it’s also not really a solution to anything. First, it doesn’t solve for the scenario of person pointing a gun at you and telling you to access your top secret files for them. That will defeat most forms of security and so if physical access is a concern you probably shouldn’t be logging in at your local coffee shop. Second, a thief who wants your computer for its monetary value isn’…

> it’s also not really a solution to anything It's a solution to situations like https://en.wikipedia.org/wiki/Ross_Ulbricht#Silk_Road,_arres... , where the laptop is taken by people who (a) can legally seize it, (b) can legally search it, but (c) probably can't legally compel you to produce passwords. (Not endorsing this usage!)

Absolutely agreed.

I've read that LEO in the USA specifically try to grab laptops / phones while they are unlocked.

This seems to be designed as a defense against that threat model.

Re: BusKill: A kill cord for your laptop

#104
post #33

Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.micha... I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.

I suppose if the drive is encrypted and requires a passphrase at boot, it's effective for FBI raids, etc.

Ross Ulbricht would like to have a word with you.

Re: BusKill: A kill cord for your laptop

#105
post #3

Earlier quoted context omitted.

Ross Ulbricht, who was apprehended at a public library while logged in to various accounts. As I recall a plain clothes agent distracted him while others then tackled him. ("would've", not "would of")

According to the book "American Kingpin", they had worked their way into the administration staff for the Silk Road, and used the site admin IM chat to ensure that he was using his laptop and actually signed into his account before rushing him in the library.

Yup. Simple approach that was very effective.

Re: BusKill: A kill cord for your laptop

#106
post #16

Earlier quoted context omitted.

If you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 ( https://www.xkcd.com/538/ ) still applies.

Are there any known cases of western police forces beating people with wrenches until they gave up passwords?

That would be far too direct and brutal. Put them in prison until they talk and let the inmates know that they are refusing to decrypt their PC. The inmates will soon enough make their own assumptions why and do the beating themselves. Of course protective custody would be an option, but that is just even further isolation and mental torture.

Re: BusKill: A kill cord for your laptop

#107
post #33

Earlier quoted context omitted.

I suppose if the drive is encrypted and requires a passphrase at boot, it's effective for FBI raids, etc.

Whenever I read stuff like this I am forced to wonder just what the fuck people are doing that they feel such a pressing need to hide their data from law enforcement. I mean, I have plenty of things to hide just like any other reasonably interesting person, but none of it is outright criminal.

If you happen to have an opinion that is not shared by the current powers-that-be, law enforcement will be happy to look at your data under any pretense it can cook up.

And they'll be equally fine with - ooops! accidentally, of course! - leaking info that you'd like to stay hidden, even if it's not anything criminal.

Re: BusKill: A kill cord for your laptop

#109
post #86
post #29

This is a really neat project but it’s also not really a solution to anything. First, it doesn’t solve for the scenario of person pointing a gun at you and telling you to access your top secret files for them. That will defeat most forms of security and so if physical access is a concern you probably shouldn’t be logging in at your local coffee shop. Second, a thief who wants your computer for its monetary value isn’…

> This is a really neat project but it’s also not really a solution to anything. Knowing your encrypted data is inaccessible to a thief is a huge relief, and may have saved this man's life: A man working at Starbucks had his laptop stolen. He was killed when he chased down the thief. https://www.cnn.com/2020/01/01/us/oakland-laptop-thief-starb...

Some faith in the Oakland PD to actually work property theft cases might have saved his life
Post reply on HN