Earlier quoted context omitted.
Sounds like a good way to hit the 10k usb-c lifespan
Lets see. Say you work 5 days a week. That's about 260 days a year (without vacations etc). Say you unlock your device 4 times a day when you work. That is 1040 times a year. Does your device even last 9-10 years? Well, if it is a MacBook, Apple ditched support for all <= 2012 MBPs. Not sure when they did, but this was true at start of last year for sure.
BusKill: A kill cord for your laptop
251–260 of 272 posts
Re: BusKill: A kill cord for your laptop
#252Earlier quoted context omitted.
Have you ever remembered something that you left in a home directory on someone else's server but only after you no longer had access to it? It wasn't sensitive but then, it wasn't something you'd leave in a public place like foo.com/~name, either. You can't convince yourself they had the inclination to just delete all your trash. You know of at least one person who might have gained access (you don't know whether )…
Yeah, it's fine to have stuff you want to hide for a lot of reasons. The problem I have with what the parent posted is that the specifically invoke "FBI" as what they're afraid of. That suggests to me that they aren't just hiding embarrassing or private information, but specifically something illegal. Now, as other posters have mentioned, parent could be an activist or something, but frankly I doubt that everyone I'v…
Re: BusKill: A kill cord for your laptop
#253Earlier quoted context omitted.
> It's as simple as that. Nothing is ever as simple as that. Not only is it a foolish, immoral and illegal, you've also just communicated murderous intent. Have fun spending 20-to-life in a cell because you thought ultraviolence would be a good way to do your part towards society. I've had more than my fair share of violent confrontations, and I assure you, no matter how well you think you are prepared, once the meta…
> you've also just communicated murderous intent. No I have not. It's your bias that colored it that way. Reread my comment. I never said I want kill a thief for stealing. I simply stated that I will take back what is mine. If, and only if, the thief tries to kill me will I respond in kind. Again, it has nothing to do with grandeur and everything to d with doing what is right. I will take back what is mine, and threa…
Re: BusKill: A kill cord for your laptop
#254I used to have my laptop setup to require my specific Yubikey to be inserted to allow waking from sleep and booting, and when you pulled it out it locked the machine, logged you out, suspended, or shutdown depending on which modifier key you were holding down when you removed it. Worked pretty well as a "kill switch" when getting up from my desk. I probably have the udev scripts laying around somewhere.
I'm using a similar setup on macOS, except mine does not use modifier keys; it just logs me out. YubiCo even provides the documentation to set it up via OpenSC. I guess you can also set macOS up to hibernate and destroy the FileVault key. (My adversary is not government etc (who can execute a cold boot attack anyway), it is thieves while I'm in transit, and clients around the office.)
macOS Logon Tool Configuration Guide https://support.yubico.com/support/solutions/articles/150000...
Unfortunately, it's not currently compatible with Catalina.
Here are a few more resources for macOS users:
Simple Daemon for lock and unlock macOS with Yubikey https://podtynnyi.com/2017/03/07/simple-daemon-for-lock-and-...
Locking macOS to a Yubikey 4 with PIV and PAM https://www.richard-purves.com/2017/02/13/locking-macos-with...
HOW to lock and unlock screen upon removal and insertion of Yubikey on macOS https://confluence.panio.info/display/PUBL/HOW+to+lock+and+u...
Re: BusKill: A kill cord for your laptop
#255There was a story not long ago about an old man who rigged up his front door to trigger a gun of some sort on unexpected entry, and ended up getting killed by it. This really just sounds like a way to inadvertently brick your computer 999 times out of 1000. Seems like something to secure it to your person would be mostly adequate.
This specific implementation doesn't brick it. It just locks the screen (or you could make it shutdown).
"As of today, we have BusKill. The BusKill solution described in this article can trigger your laptop to self-destruct if it’s physically separated from you."
Re: BusKill: A kill cord for your laptop
#256Earlier quoted context omitted.
I'm using a similar setup on macOS, except mine does not use modifier keys; it just logs me out. YubiCo even provides the documentation to set it up via OpenSC. I guess you can also set macOS up to hibernate and destroy the FileVault key. (My adversary is not government etc (who can execute a cold boot attack anyway), it is thieves while I'm in transit, and clients around the office.)
Just curious; is this the Yubico guide you're referring to? macOS Logon Tool Configuration Guide https://support.yubico.com/support/solutions/articles/150000... Unfortunately, it's not currently compatible with Catalina. Here are a few more resources for macOS users: Simple Daemon for lock and unlock macOS with Yubikey https://podtynnyi.com/2017/03/07/simple-daemon-for-lock-and-... Locking macOS to a Yubikey 4 with P…
[1] https://support.yubico.com/support/solutions/articles/150000...
Re: BusKill: A kill cord for your laptop
#257A gentle warning: different Linux distros handle UDEV "remove" differently, and incompatibly, so few people actually use this message it's not well tested (try shipping code for a device that DOES need it!). Debian was a particular problem until they switched to SystemD (which I think is possibly the only udevdaemon that gets it right) - even so some distros (Ubuntu I'm looking at you) screwed up starting the udevdae…
BTW - a clue for budding writers of UDEV scripts - you can't run daemons directly (udevdaemon will kill them when the scripts that started them exit) - you can use "at now" (after you install at of course) to start a secondary script that will be allowed to start your daemon for you (that way you can write code that works with all init systems, largely by avoiding them)
Source for startup: https://gitlab.com/chinstrap/startup
Example of the udev events in action: https://gitlab.com/chinstrap/pinebook-pro/blob/master/etc/st...
Re: BusKill: A kill cord for your laptop
#258Earlier quoted context omitted.
Just curious; is this the Yubico guide you're referring to? macOS Logon Tool Configuration Guide https://support.yubico.com/support/solutions/articles/150000... Unfortunately, it's not currently compatible with Catalina. Here are a few more resources for macOS users: Simple Daemon for lock and unlock macOS with Yubikey https://podtynnyi.com/2017/03/07/simple-daemon-for-lock-and-... Locking macOS to a Yubikey 4 with P…
No, that guide uses PAM and OTP. This [1] is the guide. It uses OpenSC and the smartcard feature of the YubiKey (not all support this but my YubiKey Neo (3rd gen) and YubiKey Nano 4 both do). Neither of them supports FIDO2 though; other than that they are feature rich. [1] https://support.yubico.com/support/solutions/articles/150000...
Does that approach allow instantly locking the screen if the YubiKey is removed? It's not mentioned in the guide, so I just want to be sure.
Re: BusKill: A kill cord for your laptop
#259Earlier quoted context omitted.
I have a Macbook Air 2012 which is still supported by Apple (I get new OSes and OS updates every year).
Try to get the screen or battery replaced. To be fair, they're easier user serviceable than newer MB(A/P)s. For example, me with my MBP 2015 will have a harder time to service it once it gets EOL (hardware-wise) than you have now with your MBA 2012.
I might want to replace the battery again in the next 3-4 years if I still have this laptop, and you might be right in that this might not be possible, but at least today it is.
Re: BusKill: A kill cord for your laptop
#260Smart. Author should productize and sell this. Small market, but almost no competition so far.
Main difference is that you don't need to configure anything with mine :P