Earlier quoted context omitted.
Maybe this will change your mind: https://www.youtube.com/watch?t=20m04s&v=cJOgGsC0G9U
It's a real testament to the effectiveness of the BLM protests that the police took a good hard look at themselves and decided to use a light touch from here on out.
Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
231–240 of 747 posts
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#232Earlier quoted context omitted.
They turned down an offer from the Pentagon to supplement manpower, days before the protest. Why? A police department with an intelligence unit couldn't guess that things might get a little out of hand when 3 weeks before, the President publicly used Twitter to ask his followers[1] to attend a "wild" protest on January 6th? Not that an intelligence unit was required as the plans were in the open. I have great difficu…
They turned down an offer from the Pentagon to supplement manpower Hmm, why turn down an offer of assistance from a military whose commander-in-chief wants to overturn the election? I can think of a few reasons...
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#233Earlier quoted context omitted.
If it’s a shared machine for projecting notes, chances are it has nothing stored locally.
Optimistic thinking. Chances are it has many PDF and PowerPoint files scattered on it. And probably a shared user account where the files fill up a Windows desktop.
... realistic
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#234Earlier quoted context omitted.
Have a shit battery + full disk encryption + linux with broken hibernate support :D
Did Linux ever fix the hibernate stuff? I remember 5 years ago, it was a MUST to disable it, because the system would go to hibernate and never wake up again without a hard restart.
That's why the likes of System76 develop their own firmware.
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#235What is a good strategy for most convenience while securing private data on a laptop that could be stolen? Full disk encryption is good for when the machine is powered off. What about for the scenario when it gets swiped during the work day when I'm in the bathroom?
> What about for the scenario when it gets swiped during the work day when I'm in the bathroom? Can you help me understand what attacks you think can be done with a locked screen, powered on laptop ? (given Full disk encryption is on)
If the device has only USB, network, and display outputs, not a lot. Modern systems are pretty hardened with this config.
However, if it has Thunderbolt, ExpressCard, PCMCIA, or even FireWire, it's hosed.
This kind of attack has been highly researched by intelligence, for example the 'Sonic Screwdriver' attack revealed in 2017 [1] targeted Macs by tampering with boot parameters, and was installed over thunderbolt.
There have also been some PoC exploits for extracting BitLocker encryption keys out of memory using FireWire [2], though I'm not sure those have ever been widespread attack vectors.
Basically, the old adage still holds up - physical access is full access. The only thing you can really do is fill up any ports that could be used for DMA sidechannel attacks with epoxy, then hope nobody attacks your TCP stack or USB controller...
---
[1] https://arstechnica.com/information-technology/2017/03/new-w...
[2] https://support.microsoft.com/en-ca/help/2516445/blocking-th...
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#236Earlier quoted context omitted.
These folks don't trust one another with information, so it seems unlikely that they'd pass around a laptop loaded with one anothers presentations.
These folks are also among the most tech-unsavvy people on Earth...
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#237I'm surprised congressional office's laptops do not embed remotely detonated explosives/destruction devices triggered with sat or cellular comms.
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#238Earlier quoted context omitted.
Or everything from everybody. We just don't know.
presentation-2-Rewrite.pdf.bak.PPT presentation-BROKEN.PPT anotherpresentation.doc cantopen_presentaion-dontdelete,PPT MOMs_COOKIE_RECIPE.doc caterpillar french fry funny.bmp and so on...
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#239Earlier quoted context omitted.
Seems like it ought to be possible to have both, to some degree. I don't want the capitol to be a fortress, but they need to prevent stuff like this. I mean... the US spends massive amounts of money on the police and military. I think it should be kind of like a non-Newtonian fluid. Walk in slowly and peacefully and it's ok. Try and punch it, it solidifies quickly.
American history[1] shows this probably isn't a requirement - beyond a foreign military attacking, which is clearly out of scope of policing, the other attacks were acts carried out by isolated people. "Storming the gates" hasn't happened before now. I suspect the main reason that this hasn't happened before is that very large protests/gatherings are often met with a large show of police force to ensure the protestor…
There are hundreds of thousands of people behind the camera, going all the way to the Lincoln Memorial. You can see some security milling around, but no large show of police force.
Re: Laptop stolen from Pelosi's office during storming of U.S. Capitol, says aide
#240> belonged to a conference room and was used for presentations Yikes. My first though was - oh this should be no big deal chances are there are good policies in place for laptops that go home with people. Then I realized it is a shared/central machine which means it probably has the most effed up and relaxed security in the fleet, post-it notes with passwords taped to the palm rests, and god knows what else. IT depar…
The presentation machines at my workplace (in addition to being desktops in a locked cabinet, because why would they leave the room?) just allow you to remote desktop back to your real workstation or to a VM. They have nothing locally. I think that's a good solution to avoiding over-granting privileges.