I always use a kensington lock and lock my screen whenever I have to leave my laptop. If I had a macbook I would be taking it with me. I know the locks won't stop someone who really wants to steal it but with so many unattended laptops sitting around it makes it less likely they will go for mine.
BusKill: A kill cord for your laptop
51–60 of 272 posts
Re: BusKill: A kill cord for your laptop
#52> You could just have a usb thumb drive on a retractable lanyard (think RFID badges or DoD Common Access Cards), but what if that thin retractable cord just snaps–leaving the USB drive snugly in-place in the laptop? You could also just use a thicker cord. The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment. > As of yesterday, that’s [stolen laptop] a hard attack to d…
Re: BusKill: A kill cord for your laptop
#53Re: BusKill: A kill cord for your laptop
#54Earlier quoted context omitted.
If you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 ( https://www.xkcd.com/538/ ) still applies.
In theory an adversary could deep-freeze the computer the moment the kill cord activates. Sufficiently cold RAM doesn't loose data immediately when it loses power, allowing the adversary to make a copy and read the decryption keys from RAM. Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibr…
Re: BusKill: A kill cord for your laptop
#55Earlier quoted context omitted.
Not really ready-to-go, but can be set up in entirety in like half an hour with VeraCrypt
Well, you would probably want some stealth that doesn't provide that makes it less obvious. Like maybe the duress passphrase decrypts everything except a docker container you use for sensitive work, replacing it with a vanilla docker image. Edit: Ahh, read up a but. I wasn't aware "veracrypt hidden volumes" are already pretty stealthy. Would probably require some work to make it plausible though...like recent faked w…
Re: BusKill: A kill cord for your laptop
#56What if someone plugs in a rubber ducky or some other kind of sophisticated USB while you turn your head for just a second? There are USB devices that are so small, you can barely even see them in the port when plugged in. Perhaps a hard-to-remove USB plug? (like child-proof plugs you might see in an electrical outlet)
Re: BusKill: A kill cord for your laptop
#57> You could just have a usb thumb drive on a retractable lanyard (think RFID badges or DoD Common Access Cards), but what if that thin retractable cord just snaps–leaving the USB drive snugly in-place in the laptop? You could also just use a thicker cord. The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment. > As of yesterday, that’s [stolen laptop] a hard attack to d…
2FA doesn't matter if you're already logged in.
I’m aware - I’m pointing out that it’s extremely likely you already have a physical device you can attach to a cord/chain/braided-steel-cable and use for the “snatch and grab” scenario. And that a snatch and grab is just so unlikely compared to any other security threat imo.
Re: BusKill: A kill cord for your laptop
#58Earlier quoted context omitted.
Other English speakers I know complain about our orthography: bought, caught, draught, etc. But, yet, here we are with a “word” pronounced “of” and spelled “‘ve”! Now that’s awful orthography!
It's not pronounced "of", it's more like "ev", exactly like the contraction of words it's made up of. Would have.
Re: BusKill: A kill cord for your laptop
#59Earlier quoted context omitted.
The heart rate of your examples are somewhat different compared to an active threat for most people I assume from being in a situation when a crime is taking place. Although, I would be curious to view trials of each situation showing the heart rate measurement with the statistical average result.
Many other potential variables as well. When experiencing this event, how long does it take your heart rate to reach a point it can be identified as worthy of triggering the switch? Is the laptop still in range of your smart watch at that point? Then there's the reliability of the wireless connection and the watches ability to accurately read your heart rate (make sure it's seated correctly). If this is a situation y…
Re: BusKill: A kill cord for your laptop
#60Earlier quoted context omitted.
Cases like this in countries that do not have due process laws makes the use-case even more compelling.
If they don’t have due process laws they can throw you in jail until you produce the decryption password, and if they turn on the computer and it’s wiped they’ll throw away the key. If there is no due process, all bets are off and your best defense is to be uninteresting to authorities.
And even if: A kill switch can simply hide / erase some things and present some weak evidence..