Live data from Hacker News

Usbkill – anti-forensic tool to halt computer when new USB device is connected

github.com

141–150 of 195 posts

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#141
post #89
post #86

Earlier quoted context omitted.

This is a somewhat pessimistic outlook on humanity, first off I would say that those who are most commonly at risk are those with trade secrets. Patented tech and investment intel for example. As for the dissenters, I’m sure they would appreciate their co-conspirators remain secret.

> This is a somewhat pessimistic outlook on humanity, first off I would say that those who are most commonly at risk are those with trade secrets. Patented tech and investment intel for example. Can you provide any evidence at all of police or "thugs" (or anyone, really) kicking down doors to get at trade secrets being a common problem? Because there are countless news articles of police raids seizing computers to st…

That is a dangerously naive viewpoint - trusting that the only instances are the ones they proudly brag about? When they have been caught not even allocating all of the funds for Child Pornography prevention they have been allocated while using "the children" as an excuse to undermine cryptography?

It is doubly foolish to believe that the police are the only users of forensic software when there is credit card theft and multmillion dollar ransomware rings out there. Robbing a bank by force or by heist is foregone jail but snatching a laptop from a banker? Far more petty in risk and disguised as mere property theft as opposed to the data theft.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#142

Earlier quoted context omitted.

Can we please stop endlessly repeating this? Life is much more complex than that. A small laptop, a phone or a tablet can be stolen from you while powered on and unlocked by a simple thief that has no intention, nor ability, to capture and torture you. The thief could then quickly hand the device to other people that flash it and sell it in a different country. But first they might extract any valuable data.

> Life is much more complex than that. > [...] a simple thief that has no intention, nor ability, to capture and torture you By your comment I assume you live in a developed country and/or are not within a regularly oppressed minority, which of course, is a nice privilege. Sadly not everyone is that lucky and torture over something simple as $1 online transactions is pretty real.

That isn't priveledge but a matter of the threat model to protect against - stop with the irrelevant pseudomoralist privledge shaming shit.

If they wanted protection against that they would recommended a gun or several mercenary bodyguards. Which would require money and connections. But the topic isn't "How to quickly kill or incapacitate three or more men with only your barehands while having legal cover".

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#143

Earlier quoted context omitted.

Hidden operating system is the way to go. Usbkill turns the machine off, when asked you supply the public password.

Investigators will say "you sent this email to your dad at 09:29 on Tuesday, yet it wasn't sent from your phone or laptop according to device logs. You either have another device you haven't given us, or you haven't decrypted the right partition".

Bootdrives with no cache are the perfect answer to this through a lawywe."USB boot drive. There are no logs kept to it. I'm not hiding anything, it is just good sense to use a computer which doesn't persist any state limiting any malware to session only in the very worst case."

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#144

Earlier quoted context omitted.

This is fairly straightforward with udev, a couple lines of config should be sufficient.

any directions?

This guide is pretty good: http://reactivated.net/writing_udev_rules.html

Some ten-odd years ago, I wrote how to create udev rules to execute a command after connecting a particular USB device:

https://www.vankuik.nl/2008-12-19_Linux_USB_device_handling

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#145

From going through the discussion I'm getting the impression that the only feasible attack vector provided by USB is by emulating a keyboard like a USB Rubber Ducky. Is this really the case? For instance, if my laptop is locked (with a proper[0][1] lock screen like xscreensaver) and that lock screen is capturing all keyboard input and magic SysRq keys[2] are disabled, too, is there really no way an attacker could use…

> [0] https://www.jwz.org/blog/2015/04/i-told-you-so-again/

Sorry for the digression, but WTF is this guy doing? Looks like he redirects all requests that have HN as the referrer to a picture of a testicle. Copy-pasting the link (i.e., dropping the referrer) seems to work, though.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#146
post #26

Earlier quoted context omitted.

Here's details of this attack for people who want more details https://citp.princeton.edu/our-work/memory/ If memory serves correctly they achieved the best results by using a can of compressed air to freeze the ram in place before removal. //Small edit to wording

Many of the measures that provide effective physical security also make a device really unsuited for personal usage. Look at HSMs for an example of this. And even they rely on being stored in a physically secure room and protected from theft. It's a matter of being more determined than your attacker. Imagine a device that will irretrievably brick itself if tilted more than a certain angle, if left unpowered for more…

> And even they rely on being stored in a physically secure room and protected from theft.

Not exactly. You don't want someone sneaking in and misappropriating the HSM to authorize something bad. And if you set the system up for unattended recovery from a power failure, then in all likelihood someone walking off with the server the HSM is in can use those keys indefinitely. But there are options.

Some HSMs have self-destruct mechanisms that attempt to prevent physical access to the private key (ie by lapping the chip). Some vendors (nCipher, IIRC) have a smart card (a second HSM) that is required to authorize certain activities, like signing, or key recovery. In fact they had a byzantine generals solution that either had the key or a password for the key split between n cards. In the latter case you needed one of the original HSMs in order to clone the key, so a movie plot where you kidnap the entire team at a conference doesn't work. During initial setup the cert would be generated on the first HSM and copied to the others, having never seen daylight.

That system was quite difficult to explain to users, and I had to document it just so I wouldn't get confused and trigger a reset of the evaluation hardware (at which point all of our test artifacts have to be rebuilt).

It might be more complicated to start WWIII than to protect a signing certificate, but only just.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#147

Interesting project, I'm sure this is useful for people at risk. Somewhat related, I'm wondering about the physical security of computers. There is an attack where they open your PC, take out the ram, and freeze it immediately so the bits don't decay and they can extract your encryption keys. All BIOSes have an option for cassis intrusion detection, but I've never seen a case that has the necessary cable. Has anybody…

Back in the BBS days, there were textfile describing how to wire your beige box to either turn on strong magnets or ignite termite if a case was detected. ... I don’t know of anyone actually implementing this though :)

It's funny when I think back, I was a teen in the 90s and did plenty of questionable stuff online and w/ local BBS scene (Kevin Mitnick was busted in Raleigh and many rumors existed about his presence in the BBS scene, obviously fantasy though!).

Nobody I know who got arrested ever managed to destroy anything. When I think about it, we all assumed the cops would storm in when we were in the act of doing something bad, probably like in the movies lol, when in practice, they tend to pick you up when you are really off guard, duh.

Very few people had automatic protections because like, our parents would probably get mad if we burned down the house :)

When it came to me, the FBI did knock on my front door, and I managed to dd if=/dev/random of=/dev/hda

I lost my entire BBS, all the custom code and ANSI I had for it, among other ancient treasures that I'd probably still have with my napster mp3s :)

Of course they didn't come for me, there had been a flasher in the neighborhood on halloween...

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#148

Earlier quoted context omitted.

Back in the BBS days, there were textfile describing how to wire your beige box to either turn on strong magnets or ignite termite if a case was detected. ... I don’t know of anyone actually implementing this though :)

It's funny when I think back, I was a teen in the 90s and did plenty of questionable stuff online and w/ local BBS scene (Kevin Mitnick was busted in Raleigh and many rumors existed about his presence in the BBS scene, obviously fantasy though!). Nobody I know who got arrested ever managed to destroy anything. When I think about it, we all assumed the cops would storm in when we were in the act of doing something bad…

The FBI was investigating a flasher?

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#149

Earlier quoted context omitted.

I would imagine that's thermite and not termite ;) If the latter, the server would probably be okay, and it would take a very long time for the termites to damage the surrounding room enough to be a security deterrent.

Probably just a debugging technique.

Well, it certainly complicates debugging.

Re: Usbkill – anti-forensic tool to halt computer when new USB device is connected

#150

Earlier quoted context omitted.

It's funny when I think back, I was a teen in the 90s and did plenty of questionable stuff online and w/ local BBS scene (Kevin Mitnick was busted in Raleigh and many rumors existed about his presence in the BBS scene, obviously fantasy though!). Nobody I know who got arrested ever managed to destroy anything. When I think about it, we all assumed the cops would storm in when we were in the act of doing something bad…

The FBI was investigating a flasher?

I could be remembering incorrectly, but it may have been reoccurring or not even really the FBI, but state police or something and my parents said it was the FBI.

I only saw people in suits with a black car outside knocking on the door, also this was like 30 years ago so don't twist my arm :)

Post reply on HN