Live data from Hacker News

BusKill – A USB kill cord for laptops

buskill.in

281–290 of 339 posts

Re: BusKill – A USB kill cord for laptops

#281

I’ve just been using a wristband made out of cheap headphones plugged into a 3.5mm jack, acpi event triggers the shutdown.

How does that work? Can you use udev to call a script on an acpi event? Is it cross-platform? Would love to see a write-up with more info on how to do this :)

acpid is probably the easiest way to accomplish this https://wiki.archlinux.org/title/acpid

Re: BusKill – A USB kill cord for laptops

#282

Earlier quoted context omitted.

You are assuming the signal is strong enough to be read at a distance. I just used the RSSI, and going away a few meters was enough. Moreover, since that was just a nicety in case I forgot to lock my computer during a corridor conversation, I could get away with a longer timeout. A more sophisticated implementation could be done if you can write software on the device. A PineTime would be perfect for this. I am not s…

I always carry my phone, even if moving to another room. I assumed that a similar behavior is why you got rid of your wristband.

No, I got rid of it for multiple other reasons: started using a mechanical watch again, got rid of all proprietary software on my phone (though I used gadgetbridge for a while), realized anybody could just track me as the band was broadcasting the same MAC address everywhere.

I also got multiple LG watch R, I'm probably going to fiddle a bit with them when I have time, hopefully mainlining them and porting postmarketos over. I'm open to trying again with those. In the end, I don't really have sensitive documents on a laptop (besides work-related confidential stuff), so I'm not sure I'd crank paranoia to 11.

As for my phone, I often pull it out of my pocket and leave it on my desk, or abandon it somewhere, charging or powered off -- I should probably be more careful with that, but people know to expect some latency when contacting me.

Re: BusKill – A USB kill cord for laptops

#283

Earlier quoted context omitted.

What about "pin his hands to the table" while the nerds exfiltrate the data?

Maybe there needs to be an accompanying/alternative device which can be worn in a shoe and detects toe movements. It would probably have to be wireless, which would introduce false positives or false negatives, (and part of it may need to be attached to the user's ankle, due to size constraints), but it would at least defend against an attacker who could physically restrain the user.

OMG, did you just invent Agent Smart's Shoe Phone? https://en.wikipedia.org/wiki/Shoe_phone

Re: BusKill – A USB kill cord for laptops

#284

There are mentions in this thread about false positives, risk of data loss, others. This made me think of Star Trek's use of a self destruct phrase. Obviously their method is too slow, but you could have a "duress" phrase and a "all clear" phrase. User-Defined Phrase: "Please dont kill me", activates "duress" mode. - A daemon listens in the background for a phrase of your choice. When detected, your laptop makes a so…

how would you account for :poker face: "please don't kill me" vs :in a stranglehold, bleeding internally from multiple stab wounds: "PLAYS DON--"

Re: BusKill – A USB kill cord for laptops

#285

Earlier quoted context omitted.

BusKill does not ship with destructive triggers. The current app is limited to locking your screen. Future releases will include soft/hard shutdown. We do have a "LUKS Header Shredder" trigger (which we call self-destruct as it renders all the data on the FDE disk useless), but we (intentionally) don't include it by default and raise the barrier of entry because of the risk of data loss. We'll be publishing a more de…

Does it support destroying keys in hardware tokens? Would be nice if plugging my yubikey into a specific USB port automatically destroyed all keys inside it.

You really want such devices - i.e. Devices with duress modes - to act normally, as much as possible when in those modes. If they clearly destroy themselves immediately you often place yourself in much greater danger. If anything log them into a sandbox or honeypot that is, as much as possible, indistinguishable from your normal environment but is less damaging for you for them to access.

Re: BusKill – A USB kill cord for laptops

#286
post #58

Earlier quoted context omitted.

Reminds me of a coworker who had their iPhone set to "wipe after 10 bad pins". Took about 2 days before their 5 year old happily typed the wrong pin 10 times and wiped it.

Blackberry required you to enter the word "Blackberry" after the fifth try, which would at least prevent butt-dialing from wiping the device. Some kids might figure that out too, but at that point I suppose you had the choice to use a condom and decided not to...

Here a story. I got BB RIM 850 when I was 15ish years old, it was my first communication pre-smartphone device. I stupidly set up to wipe my blackberry if input incorrectly after a few times, and I did this within minutes of first time using it. You can imagine what happened in the next 10 minutes... Yes, I forgot my complicated password and it got wiped. And that rendered my brand-new RIM 850 useless. So, I have to wait 10 days to get a new one.

Re: BusKill – A USB kill cord for laptops

#287
post #69

Earlier quoted context omitted.

I always thought that a lock screen with two passwords would be an interesting idea. Say the BusKill locks your system and sends a request to a server. If you don't enter the correct password to abort the script within a few seconds, it will run on your server, which sends a distress mail/call to emergency contacts, revoke all ssh keys/passwords etc. If however the distress password gets entered, the script still run…

Disclaimer: I know next to nothing about OS'es and login and so on. I had an idea once, would it be possible to set up two sets of passwords? One to properly unlock your device, and one to trigger either encryption or scrambling of the data when entered?

Lookup "duress passwords"

* https://en.wikipedia.org/wiki/Duress_code

The feature is more relevant in (full disk) encryption software than OSes.

Re: BusKill – A USB kill cord for laptops

#288
post #261

Earlier quoted context omitted.

> perfectly plausible deniability The paranoid dystopian counterpart is that you cannot prove you don't have a second partition either. Might get awkward if someone decided to compel the second password on less solid evidence. If you're not actually using the feature.

this is why you should actually have "signs of life" and something _slightly_ illegal on your plausible deniability partition. Just enough dirt to get you into trouble, but not too much trouble. If you're squeeky clean, you get the rubber hose cryptography treatment.

If you want those signs of life to be convincing, it should include all kinds of history without long gaps, such as:

- email, including recently received and sent emails

- web browser history

- system logs

- software updates

In practice, I think it’s impossible to do that. If the police discovers, for example, that your system logs show your machine was off for a week, but they also just saw you reset it, what do you tell them?

Re: BusKill – A USB kill cord for laptops

#289

I hate everything about this website. It uses all the tropes of a bad kickstarter campaign, and to sell you this item it preys on fear and misunderstanding. I absolutely do not trust that this company has my best interest at heart. It's so bad I wouldn't go near this product for any money.

Really? It seems like “here is what it does” kind if website to me

Re: BusKill – A USB kill cord for laptops

#290

Say I'm an investigative journalist, gathering information about some bad guy embezzling all politicians that matter in a small country and doing all kinds of criminal stuff, including murders. I'm careful. I'm using a laptop that has this kill switch. I only keep my work on this laptop, it's so sensitive. The bad guy gets a whiff I'm digging around him. He sends armed thugs to my lair. They enter, so I pop the kill…

In such a scenario, you're right that if the attacker will use physical violence against you, of course the device wouldn't save you from bodily harm. But what about your sources? In this situation (if you actually can't remember the anonymous email address of your source), it's not your life that's being saved -- it's the identity and the life of the whistleblower.

I’m pretty sure there are rules of informational hygiene for cases like this, and they mostly grate on instincts of any geek obsessed with having all the data neatly organized, cross-referenced, and persisted.

You can add any number of security layers, but you should always presume someone might get their hands onto whatever you’re working on at the moment in cleartext and you want any damage to be minimal.

Post reply on HN