Live data from Hacker News

BusKill: A kill cord for your laptop

tech.michaelaltfield.net

231–240 of 272 posts

Re: BusKill: A kill cord for your laptop

#232

Earlier quoted context omitted.

I'd definitely give chase. To me, it is worth dying for. Not because of the laptop, but out of principle for vigorously fighting these ridiculous crimes. We all need to collectively fight back against crime or it will be normal (as it is now).

That'll be a lonely hill to die on. We in California collectively decided that theft under $950 is not a big deal and should be fought less vigorously: https://en.wikipedia.org/wiki/2014_California_Proposition_47

Rather than outsourcing the pros and cons of a bill to professionals you employ with time to research it (politicians), you ask millions of uninformed people vote on passing “The Safe Neighborhoods and Schools Act ”?

Re: BusKill: A kill cord for your laptop

#234
post #205

I used to have my laptop setup to require my specific Yubikey to be inserted to allow waking from sleep and booting, and when you pulled it out it locked the machine, logged you out, suspended, or shutdown depending on which modifier key you were holding down when you removed it. Worked pretty well as a "kill switch" when getting up from my desk. I probably have the udev scripts laying around somewhere.

Sounds like a good way to hit the 10k usb-c lifespan

Lets see. Say you work 5 days a week. That's about 260 days a year (without vacations etc). Say you unlock your device 4 times a day when you work. That is 1040 times a year. Does your device even last 9-10 years? Well, if it is a MacBook, Apple ditched support for all <= 2012 MBPs. Not sure when they did, but this was true at start of last year for sure.

Re: BusKill: A kill cord for your laptop

#235

I used to have my laptop setup to require my specific Yubikey to be inserted to allow waking from sleep and booting, and when you pulled it out it locked the machine, logged you out, suspended, or shutdown depending on which modifier key you were holding down when you removed it. Worked pretty well as a "kill switch" when getting up from my desk. I probably have the udev scripts laying around somewhere.

I'm using a similar setup on macOS, except mine does not use modifier keys; it just logs me out.

YubiCo even provides the documentation to set it up via OpenSC. I guess you can also set macOS up to hibernate and destroy the FileVault key.

(My adversary is not government etc (who can execute a cold boot attack anyway), it is thieves while I'm in transit, and clients around the office.)

Re: BusKill: A kill cord for your laptop

#236
I'd like to see a more practical solution for removing disk encryption keys from RAM.

For example, wipe the disk encryption key from RAM, but then pause all disk IO and present some kind of UI to re-enter the encryption key to continue using the system.

Encrypting all of system RAM can also quickly be done - perhaps a kernel module which in the case of a panic encrypts all of system ram with a key derived from your disk encryption key would be handy. Then when the key is available again, ram can be decrypted and processes resumed.

Re: BusKill: A kill cord for your laptop

#237
post #234
post #205

Earlier quoted context omitted.

Sounds like a good way to hit the 10k usb-c lifespan

Lets see. Say you work 5 days a week. That's about 260 days a year (without vacations etc). Say you unlock your device 4 times a day when you work. That is 1040 times a year. Does your device even last 9-10 years? Well, if it is a MacBook, Apple ditched support for all <= 2012 MBPs. Not sure when they did, but this was true at start of last year for sure.

I have a Macbook Air 2012 which is still supported by Apple (I get new OSes and OS updates every year).

Re: BusKill: A kill cord for your laptop

#238
post #234

Earlier quoted context omitted.

Lets see. Say you work 5 days a week. That's about 260 days a year (without vacations etc). Say you unlock your device 4 times a day when you work. That is 1040 times a year. Does your device even last 9-10 years? Well, if it is a MacBook, Apple ditched support for all <= 2012 MBPs. Not sure when they did, but this was true at start of last year for sure.

I have a Macbook Air 2012 which is still supported by Apple (I get new OSes and OS updates every year).

Try to get the screen or battery replaced. To be fair, they're easier user serviceable than newer MB(A/P)s. For example, me with my MBP 2015 will have a harder time to service it once it gets EOL (hardware-wise) than you have now with your MBA 2012.

Re: BusKill: A kill cord for your laptop

#239

Ross Ulbricht had his laptop snatched by an undercover FBI agent while he was using it. This kill cord might have saved him some grief.

Indeed. Better, perhaps, would be to trigger wiping the LUKS header and deleting the boot partition.

If your /boot is on a USB drive and you set up with detached header then the disk can already be 100% random data. On the down side, that USB drive is not very deniable and the system can't be set to destroy it since you probably don't keep it connected. Still, you could boot the machine at home, put it to sleep, leave /boot at home, and wake it up whenever you've reattached this kill cord. If you absolutely need to be able to reboot, use kexec (in theory).

Re: BusKill: A kill cord for your laptop

#240
post #87

Earlier quoted context omitted.

To me "would of" and "would've" are pronounced exactly the same. If I said "would ev" that would sound weird. It would sound very similar to "whatev": https://www.urbandictionary.com/define.php?term=whatev

Well, nothing else in english is pronounced like it is written, so I don't think this is a good reason to misspell things.

Reminds me of https://en.m.wikipedia.org/wiki/Ghoti
Post reply on HN