27 ms·
BusKill: A kill cord for your laptop
- vgaldikas 7y agoSilkRoad guy would of loved this :D
- nkrisc 7y agoRoss Ulbricht, who was apprehended at a public library while logged in to various accounts. As I recall a plain clothes agent distracted him while others then tackled him. ("would've", not "would of")
- thechao 7y agoOther English speakers I know complain about our orthography: bought, caught, draught, etc. But, yet, here we are with a “word” pronounced “of” and spelled “‘ve”! Now that’s awful orthography!
- iherbig 7y agoIn case you're serious and unaware: it's a contraction of "would have," hence the apostrophe. It's not a single word spelled weirdly.
- overcast 7y agoIt's not pronounced "of", it's more like "ev", exactly like the contraction of words it's made up of. Would have.
- chefandy 7y agoəv
- geocrasher 7y agoIn my household I'm the English nerd, although I have no degree behind it. I'd correct my wife when she wrote "would of" but then I listened closer when she talked: She wasn't saying "would've" she was saying "would of". That's when I gave up. There are a million other reasons to love my wife, and her proper use of 'would've' wasn't one of them to begin with :)
- deleted 7y ago[deleted]
- mikeryan 7y agoDoes your wife actually pronounce these differently? Small sample size but as far as I can tell I pronounce these identically. (CA - native speaker)
- geocrasher 7y agoShe does not. They are the same to her. We're also native speakers from the Reno NV area, which is heavily influenced by Sacramento and San Francisco language.
- Buge 7y agoTo me "would of" and "would've" are pronounced exactly the same. If I said "would ev" that would sound weird. It would sound very similar to "whatev": https://www.urbandictionary.com/define.php?term=whatev https://www.urbandictionary.com/define.php?term=whatev
- UnFleshedOne 7y agoWell, nothing else in english is pronounced like it is written, so I don't think this is a good reason to misspell things.
- merlyn 7y agoThe word should be pronounced the way the contraction actually is would (ha)ve. But people are lazy. And words like caramel get blurred over. Or the one that bugs me the most of saying ‘ta’ instead of to. My favorite is the Futurama universe where the word ask is official changed to ax instead.
- masukomi 7y agoothers have covered the correct full form, but to the issue of the pronunciation, it's not pronounced "would of" it's MISpronounced "would of". You can make any weird confusing pronunciation you want out of anything if you're willing to say it "wrong". The correct pronunciation of the contraction, as another hinted at is basically "would have" without the h and the a becoming an sound "uh" instead of an "ah" sound.
- bart_spoon 7y agoAccording to the book "American Kingpin", they had worked their way into the administration staff for the Silk Road, and used the site admin IM chat to ensure that he was using his laptop and actually signed into his account before rushing him in the library.
- refurb 7y agoYup. Simple approach that was very effective.
- artursapek 7y agoThat's pretty impressive.
- mattm 7y agoThis article goes into pretty good detail of his takedown https://www.wired.com/2015/04/silk-road-1/ https://www.wired.com/2015/04/silk-road-1/
- jkrltifk 7y agoOnce he was identified he was gone anyway.
- Grazester 7y agoAfter that incident I basically wrote this program in java that monitors a usb port for a device with a given ID. If it does not find it then it locks the computer.
- Reventlov 7y agoArchive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/ http://web.archive.org/web/20200102140351/https://tech.micha... I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.
- Piskvorrr 7y agoShared medium (i.e. wireless spectrum) means anybody can do that, without being too conspicuous. A wire is significantly harder to DoS ;) (Plus I tried several solutions to do this; BT is not really well suited for proximity detection, teeming with false positives and false negatives)
- k_sze 7y agoIf you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 (https://www.xkcd.com/538/ https://www.xkcd.com/538/) still applies.
- tyingq 7y agoI'm surprised there isn't a "ready to go" solution with a duress passphrase that boots a plausible, but "clean" system.
- rahuldottech 7y agoNot really ready-to-go, but can be set up in entirety in like half an hour with VeraCrypt
- tyingq 7y agoWell, you would probably want some stealth that doesn't provide that makes it less obvious. Like maybe the duress passphrase decrypts everything except a docker container you use for sensitive work, replacing it with a vanilla docker image. Edit: Ahh, read up a but. I wasn't aware "veracrypt hidden volumes" are already pretty stealthy. Would probably require some work to make it plausible though...like recent faked web browsing history.
- sysbin 7y agoMaybe a smartwatch reading the heart rate of the owner and noticing stimulation could trigger the same functionality as well.
- k_sze 7y agoThe connection between the smartwatch and the computer would, in practice, be wireless, which is something the author wants to avoid because it's easier to hack without the victim noticing.
- sysbin 7y agoI'm sure with encryption there shouldn't be much worry. I think currently apple watches allow users to unlock their computers when returning.
- nkrisc 7y agoSure, but is that really useful? Just better not read something exciting or notice an attractive person while working.
- sysbin 7y agoThe heart rate of your examples are somewhat different compared to an active threat for most people I assume from being in a situation when a crime is taking place. Although, I would be curious to view trials of each situation showing the heart rate measurement with the statistical average result.
- nkrisc 7y agoMany other potential variables as well. When experiencing this event, how long does it take your heart rate to reach a point it can be identified as worthy of triggering the switch? Is the laptop still in range of your smart watch at that point? Then there's the reliability of the wireless connection and the watches ability to accurately read your heart rate (make sure it's seated correctly). If this is a situation you're actually concerned about, the approach in the article seems simpler and more foolproof.
- brianbreslin 7y agoCan someone explain to me in laymen's terms what this does? It renders the motherboard inoperable? Kills the display? How do you recover from this if you ACCIDENTALLY unplug it?
- mpalme 7y ago> [...] rule that will trigger xscreensaver to lock the screen every time any USB drive is removed
- arm 7y agoIt can do whatever you want it to do. The examples in the article were: • whenever any USB drive is removed, trigger xscreensaver to lock the screen: > ACTION=="remove", SUBSYSTEM=="usb", RUN+="DISPLAY=:0 xscreensaver-command -lock" • whenever a specific USB drive is removed, shut down the computer: > ACTION=="remove", SUBSYSTEM=="usb", ENV{ID_MODEL}=="Micromax_A74", RUN+="shutdown -h now"
- oefrha 7y agoNitpick, it can do whatever you want it to do that’s possible in software. You’ll be disappointed if you want to have it drill a hole in your hard drive ;)
- somebodythere 7y agoJust build a USB-powered hard-drive drill, duh.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- Etheryte 7y agoThe article shows two different configurations, one that simply triggers the screensaver with a lock screen, the other to fully shut the machine down. Recovery from both of those is fairly straightforward.
- RandomBacon 7y agoWhat if someone plugs in a rubber ducky or some other kind of sophisticated USB while you turn your head for just a second? There are USB devices that are so small, you can barely even see them in the port when plugged in. Perhaps a hard-to-remove USB plug? (like child-proof plugs you might see in an electrical outlet)
- amiga-workbench 7y agoThere are udev rules to defeat this kind of thing, law enforcement use USB mouse jigglers to keep computers awake for example, these can be filtered out and ignored.
- Zenst 7y agoSaw a demo 20 years ago at Infosec(UK) of a company selling a dongle which with corresponding pass, acted as a proximity authentication and locking when you walked away. Today, most laptops have cameras which can offer the same level of proximity detection if you away from the laptop. That would make this type of solution doable via software that way, albeit a bit more of a software load overhead. But for some killcord, I'd also have an alarm.
- krilly 7y agoEr, why not just attach the laptop itself to your body? Low tech > high tech
- dangus 7y agoThis is a really neat project but it’s also not really a solution to anything. First, it doesn’t solve for the scenario of person pointing a gun at you and telling you to access your top secret files for them. That will defeat most forms of security and so if physical access is a concern you probably shouldn’t be logging in at your local coffee shop. Second, a thief who wants your computer for its monetary value isn’t interested in its contents. Your normal drive encryption and screen timeout restrictions have you covered there. They’re gonna wipe your computer, sell it, and move on. Institutionally purchased hardware is often equipped with zero-touch provisioning (such as Apple Device Enrollment). These products can be bricked at the hardware level they moment they touch the Internet. They’ll need a new logic board, i.e. new soldered on storage, i.e. they’re not even necessarily worth stealing. Third, the idea of a magnetic connector’s removal locking or bricking your computer seems awfully inconvenient. That’s gonna be constant false positives without a gain in security. If you’ve got someone who is after you to obtain your secret company info and knows enough to cause mayhem, you’ve got much bigger problems than whether or not your screen is going to lock. They’re also probably going to use social engineering, targeted malware and spyware, not brute force physical access.
- jefftk 7y ago> it’s also not really a solution to anything It's a solution to situations like https://en.wikipedia.org/wiki/Ross_Ulbricht#Silk_Road,_arrest_and_trial https://en.wikipedia.org/wiki/Ross_Ulbricht#Silk_Road,_arres... , where the laptop is taken by people who (a) can legally seize it, (b) can legally search it, but (c) probably can't legally compel you to produce passwords. (Not endorsing this usage!)
- koheripbal 7y agoCases like this in countries that do not have due process laws makes the use-case even more compelling.
- dangus 7y agoIf they don’t have due process laws they can throw you in jail until you produce the decryption password, and if they turn on the computer and it’s wiped they’ll throw away the key. If there is no due process, all bets are off and your best defense is to be uninteresting to authorities.
- henvic 7y ago> In less than 60 seconds and with the help of a rubber ducky, the thief could literally cause millions of dollars in damages to your organization. Kudos for the imagination, but in real life for most developers not vendorizing and auditing their dependencies (+ downloading them all from production) is most likely to cause such havoc (regardless if dozen thousands or millions of damage)... I imagine this might likely happen in places like security and programming language conferences, especially when you leave your belongings around unattended for a minute or two. The ideal scenario IMHO would be to have to authorize/reject devices from connecting to your machine (and limiting the scope). I don't know much about USB-C and know it is hard, but I see Apple coming up with something like this in the future (maybe along with Apple Watch detection for quick logout - you can already use it for logging in).
- jotm 7y agoI guess I'll share in this thread. ---1--- I have a OnePlus 6T with the stock ROM exclusively for my British phone number. On the 25th of December, someone from Canada logged into the GMail account used on that phone, from a OnePlus 3T. The password was one randomly generated in KeePass (all of them are except for useless websites). They managed to change the password to the account, but seemingly nothing else, so that's just weird. I received the notification on my other email, and recovered the account, reset the password, replaced with a new one. ---2--- Last week, I opened up a laptop I use for storage (3 drives fit inside, perfect for backups) and noticed a network drive with a Chinese name. It disappeared when I clicked on it. The laptop is always on connected to my router and to a VPN server. Now I need to completely wipe the phone, root and use a custom ROM, as well as wipe the laptop (and two other computers?), upgrade OpenWRT on the router and change all of the passwords I guess. Yes, I still haven't done it heh. --- ----------->I am curious about your comments on this.<----------- --- Never had anything really suspicious like this actually happen to me. I don't even have anything good/useful on my devices, except a Keepass database with passwords to all bank accounts/emails/etc. If that's been opened, I'm a bit fucked, but I'd be receiving notifications on my phone and other emails.
- therealmocker 7y agoSounds like maybe a SIM swap attack? In addition to password changes I would look into Google's advanced protection program (https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/) and get U2F or FIDO2 setup on your account.
- ColanR 7y agoI would assume that whoever that was now has a copy of your keepass database. However, it may be that your computer was simply added to a botnet, in which case the harm done to you personally may be minimal.
- whatactuallywat 7y agoWhy are you under the impression that accessing your KP database is guaranteed to alert you. I can't imagine how that could possibly be true without the master key being stored in some service running somewhere and you're notified when it's used. Which, well, would explain how your key was compromised. Otherwise it seems highly misleading to assume that no email = no compromise. Doesn't really matter though, it would've been mitigated by not keeping the KP database decrypted at rest or by using 2FA. Both of which are SOP for hardware token users. For real, at this point if you don't have a yubi/nitrokey on your keychain, I assume you just don't care about actual account security.
- MonkZ 7y agoOn systemd enabled systems, try "loginctl lock-sessions" as udev cmd. It should work on common desktop environments. If you have something custom try xss-lock to react on the lock-sessions signal.
- 0kl 7y ago> You could just have a usb thumb drive on a retractable lanyard (think RFID badges or DoD Common Access Cards), but what if that thin retractable cord just snaps–leaving the USB drive snugly in-place in the laptop? You could also just use a thicker cord. The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment. > As of yesterday, that’s [stolen laptop] a hard attack to defend against. Which is just wrong; the author did not invent anything here - anyone I’ve known that’s ever been worried about this scenario has implemented it already with <yubikey/access card/arbitrary usb>. * extra PSA: if you’re worried about this but somehow haven’t already required 2FA for all your accounts and admin access on your laptop, then you should re-evaluate your threat scenarios.
- tylerhou 7y ago2FA doesn't matter if you're already logged in.
- 0kl 7y ago> extra PSA: if you’re worried about this but somehow haven’t already required 2FA... I’m aware - I’m pointing out that it’s extremely likely you already have a physical device you can attach to a cord/chain/braided-steel-cable and use for the “snatch and grab” scenario. And that a snatch and grab is just so unlikely compared to any other security threat imo.
- jccalhoun 7y agoI will sometimes go to the university library to do some work and I'm always amazed at people who will go to the restroom or something and leave their laptop sitting there without a lock or even logged out. I always use a kensington lock and lock my screen whenever I have to leave my laptop. If I had a macbook I would be taking it with me. I know the locks won't stop someone who really wants to steal it but with so many unattended laptops sitting around it makes it less likely they will go for mine.
- CaptainMarvel 7y agoWhat do you attach the other end of the kensington lock to?
- SmellyGeekBoy 7y agoThe desk?
- savingGrace 7y agoAnother solution would be to just remove the battery and plug the laptop in. While this removes the portability, it is still an alternative solution.
- Accujack 7y agoYep. Same effect, really, and in fact this is more likely to be secure because there's a chance that pulling power will damage something or scramble data on disk. The article's solution is amusing and "cool" but not really secure at all. If you're worried about physical security of devices, don't take them to coffee shops.
- ShakataGaNai 7y agoMaybe a decade or so ago this would be a good answer. But unless you're one of those ThinkPad people who are still pulling for the X220 to make a come back.... A majority of modern laptops don't have user removable batteries. Yes, they could still be removed in some cases, but its often not for the feint of heart and not something many people would want to undertake.
- AnIdiotOnTheNet 7y ago> A majority of modern laptops don't have user removable batteries. Yet another major regression in the state of computing since the 90s.
- war1025 7y agoIs it really the majority? Or just on macbooks and the high end lines like that? I didn't think my laptops were that old (3-5 years) and they all have removable batteries.
- perl4ever 7y agoI hadn't thought about it, but I have a newish business class Dell and I don't think it does have a removable battery. On the other hand, I have a Dell laptop from circa 2011 and it does; in fact I got the extra large one that sticks out awkwardly.
- ropiwqefjnpoa 7y agoThe article keeps saying "self-destruct" but that's not what happens. But if your hard drive is encrypted, this is a pretty good solution for most people. Maybe if you can get BusKill to activate a mini thermite explosive under your hard drive.
- nowahe 7y agoI remember watching a Defcon conference where they tested different methods for destroying a hard drive in place. And they found that thermite actually doesn't damage the platters (well at least not enough for data to be unrecoverable). Hard drive platters are surprisingly heat/chemical resistant. I think they found that the best method was to physically destroy the platters.
- ropiwqefjnpoa 7y agoDid they test SSDs?
- dwyerm 7y agoHighly recommended by me, too: Zoz at DefCon 23, entitled "And That's How I Lost My Other Eye...Explorations in Data Destruction" https://www.youtube.com/watch?v=-bpX8YvNg6Y https://www.youtube.com/watch?v=-bpX8YvNg6Y
- dlgeek 7y agoI remember watching that talk years ago. I was disappointed in the lack of rigor of their conclusions. The whole point of thermite-based HDD destruction is to get the platens over the Curie temperature so the magnetic field is gone, not to physically destroy them. They point this out in the start, but then never talk about whether this was achieved or not in their experiment (assumably so they could go on to the actual explosives). It was entertainment, and I'd take any results with a grain of salt.
- namibj 7y agoThe guy worked on it further. He eventually solved the original challenge.
- crankylinuxuser 7y agoIt reminds me of USBkill https://github.com/hephaest0s/usbkill https://github.com/hephaest0s/usbkill Its primary use is to thwart machine fuzzing and debugging using USB devices. The moment there's a change in USB state, down the machine goes.
- jonnycomputer 7y agoThere was a story not long ago about an old man who rigged up his front door to trigger a gun of some sort on unexpected entry, and ended up getting killed by it. This really just sounds like a way to inadvertently brick your computer 999 times out of 1000. Seems like something to secure it to your person would be mostly adequate.
- Buge 7y agoThis specific implementation doesn't brick it. It just locks the screen (or you could make it shutdown).
- jonnycomputer 7y agoor, if you actually read the article: "As of today, we have BusKill. The BusKill solution described in this article can trigger your laptop to self-destruct if it’s physically separated from you."
- miles 7y agoWindows users may want to try the built-in Bluetooth proximity locking feature: Lock your Windows 10 PC automatically when you step away from it https://support.microsoft.com/en-us/help/4028111/windows-lock-your-windows-10-pc-automatically-when-you-step-away-from https://support.microsoft.com/en-us/help/4028111/windows-loc... While macOS doesn't include such a feature out of the box, apps like Near Lock https://nearlock.me https://nearlock.me exist. EDIT: Just found Rohos Logon Key for Windows and macOS: https://www.rohos.com/products/rohos-logon-key-for-mac/ https://www.rohos.com/products/rohos-logon-key-for-mac/ It "converts any USB drive into a security token for your computer" and can "automatically lock your Mac screen when the key is unplugged".
- dbtx 7y agoecho o > /proc/sysrq-trigger (read linux/Documentation/admin-guide/sysrq.rst before you try this)
- s_gourichon 7y agoshutdown -h now or the more recent incantation (from memory) systemctl shutdown would be less violent. AFAIK it can't be stopped either, and at least it sync's and umount's filesystems properly.
- dbtx 7y agoViolent is the point-- shutdown might be prohibitively slow. Or it'll get stuck waiting to umount a network share. Or maybe, you want the DRAMs to go dark and start losing ASAP, I don't know. If you must, simply precede 'o' with some sequence of 's', 'e', 'u' so it'll go down hard and fast, but still a bit controlled. I find that 'u' succeeds more often if done after 'e'. FWIW, this is just what I do with the keyboard (but more slowly) when something went wrong enough that I can't even switch to a text VT and recover. Sometimes even 'b' won't hard reset it-- which indicates everything was already hosed, or maybe just the keyboard. Presumably the umount didn't work either, but I gave it a chance.
- dotBen 7y agoA man just died in Oakland today trying to recover his laptop that was snatched from him in a Starbucks. http://nypost.com/2020/01/02/man-dies-after-trying-to-stop-thief-who-stole-his-laptop-at-starbucks/ http://nypost.com/2020/01/02/man-dies-after-trying-to-stop-t... Definitely don't go running after your stolen laptop, let it go.
- abstractbarista 7y agoI'd definitely give chase. To me, it is worth dying for. Not because of the laptop, but out of principle for vigorously fighting these ridiculous crimes. We all need to collectively fight back against crime or it will be normal (as it is now).
- vorpalhex 7y agoDon't chase criminals because it's foolish. You are letting the opposition lead you into their plan where they control the setting. Be smart, be the one in control of the situation.
- lnanek2 7y agoOakland's a bit of a special place. I have friends living there who have been robbed at gun point, for example, and if you go into a Subway the workers are often behind bulletproof glass because they've been held up so often. Chasing a crook in Oakland is just going to get you dead, not change anything there. Not smart.
- Keverw 7y agoWow, sounds like not a hot tourist spot probably then. Not sure why people would want to live there when safer and cheaper places in the US.
- 0kl 7y agoI’m just assuming the above is not in good faith, but for anyone else that might be persuaded: You being killed by a criminal over an iPhone or laptop is not going to change anything. Fund your police, vote to change laws enough that they’re spending their time on things that are relevant, and if you’re honestly willing to die for the rule of law, become a police officer. Otherwise your body will be one more on the list of “people that died for no reason.” It’s not tough, righteous, or whatever else to die for no reason - and even if it were, if you’re going to make a stand and sacrifice your life, make it over something more than a laptop.
- chacha2 7y agoIf all the killcord does is turn off the machine, just use a laptop with no battery.
- kulahan 7y agoThat's somewhat less convenient, don't you think? This works if you're at the park typing a paper up, or at a Starbucks where all the outlets are in use, for instance.
- techaddict009 7y ago@OP sorry for lame question: Does the dis connection of USB formats the laptop or just shuts it down?
- fnord77 7y agoRoss Ulbricht had his laptop snatched by an undercover FBI agent while he was using it. This kill cord might have saved him some grief.
- mirimir 7y agoIndeed. Better, perhaps, would be to trigger wiping the LUKS header and deleting the boot partition.
- segfaultbuserr 7y agoThe hard question is how to put an easy-to-use self-destruction mechanism in an existing machine (only the NSA can make a customized machine), and, at the same time, ensure the safety of the self-destruction mechanism. A self-destruction button is a safety risk if it can be triggered accidentally or maliciously, on the other hand, a secured self-destruction button is a safety risk if it's too hard to trigger. The NSA laptops have two buttons on one side of the machine, to destruct crypto keys, one needs to open a cover and press two buttons simultaneously. It's a pretty good self-destruction button. But you cannot find it in your laptops. Or perhaps you can design your kill switch like the Russian nuclear Dead Hand - the automatic nuclear retaliation mechanism is only armed if a safety switch has been explicitly switched on, in peacetime, the switch is turned off to avoid an accidental nuclear apocalypse. But remember to arm the switch every time you travel with your laptop became a question.
- dbtx 7y agoIf your /boot is on a USB drive and you set up with detached header then the disk can already be 100% random data. On the down side, that USB drive is not very deniable and the system can't be set to destroy it since you probably don't keep it connected. Still, you could boot the machine at home, put it to sleep, leave /boot at home, and wake it up whenever you've reattached this kill cord. If you absolutely need to be able to reboot, use kexec (in theory).
- 0kl 7y agoBetter opsec would have saved him some grief as well. Before even touching on his habitual use of coffee shops near his residence to run the Silk Road... > The connection was made by linking the username "altoid", used during Silk Road's early days to announce the website, and a forum post in which Ulbricht, posting under the nickname "altoid", asked for programming help and gave his email address, which contained his full name. By the time the FBI was watching him and had connected his name to I don’t think there’s a lot that he could have done to avoid arrest.
- wffurr 7y agoI was expecting something more like the Etherkiller: http://www.fiftythree.org/etherkiller/ http://www.fiftythree.org/etherkiller/
- brian_herman__ 7y agoOr this https://usbkill.com/ https://usbkill.com/
- pacomerh 7y agoIf you're using a macbook, isn't "Find my mac" enough to erase remotely?, I understand this is a faster disabling mechanism but also a bit inconvenient. I wish there was something even easier, like a tiny usb drive with a remote control
- Whatarethese 7y agoWith FindMy I can erase or mark as lost my Macbook in under 20 seconds from unlocking my iPhone if needed.
- daveidol 7y agoAssuming the laptop is still online / comes back online to receive the wipe command...
- andrey_utkin 7y ago... and you are conscious and have your hands free :)
- SmellyGeekBoy 7y agoWhere the hell do you people live!?
- andrey_utkin 7y agoUsed to live in Ukraine.
- rdc12 7y agoOr still be in possession of your phone, if eysomeone is trying to gain access to the data on your laptop, good chance they will be interested in your phone too
- fortran77 7y agoWould this have stopped the FBI getting the Silk Road laptop? I wonder if they're looking out for these things. I know when they take computers that are running, they keep them running and powered on with a portable power supply
- linuxhansl 7y agoCouldn't you just pair your computer with your phone (or something that you keep on you) via blue tooth, detect the loss of signal, and then trigger whatever action you'd like to trigger?
- tingletech 7y agoreminds me of a tragic death the other day where someone in a Starbucks was killed getting flung off a car while he was trying to save his laptop from robbers who grabbed his computer.
- tingletech 7y agohttps://asamnews.com/2020/01/03/victim-shuo-zeng-in-laptop-theft-died-on-34th-birthday/ https://asamnews.com/2020/01/03/victim-shuo-zeng-in-laptop-t...
- tingletech 7y agohttps://sanfrancisco.cbslocal.com/2020/01/03/suspects-in-fatal-laptop-theft-from-oakland-starbucks-face-murder-manslaughter-charges/ https://sanfrancisco.cbslocal.com/2020/01/03/suspects-in-fat...
- tyingq 7y agoIt appears breakaway mag USB-A connectors are pretty cheap: https://www.amazon.com/Griffin-Breaksafe-Magnetic-Breakaway-Disconnects/dp/B0759FKCK8 https://www.amazon.com/Griffin-Breaksafe-Magnetic-Breakaway-... From tidbits in this thread, it sounds like a Veracrypt hidden volume with a distress passphrase, plus a fairly simple dead-man script wouldn't be hard to set up. Something like: kill sensitive processes, drop caches, wipe memory, then panic the kernel.
- ColanR 7y agoI checked amazon earlier, and it looks like this thread may have put those things out of stock. Guess a lot of people like the idea!
- zelly 7y agoRoss Ulbricht needed this.
- deleted 7y ago[deleted]
- im_down_w_otp 7y agoI used to have my laptop setup to require my specific Yubikey to be inserted to allow waking from sleep and booting, and when you pulled it out it locked the machine, logged you out, suspended, or shutdown depending on which modifier key you were holding down when you removed it. Worked pretty well as a "kill switch" when getting up from my desk. I probably have the udev scripts laying around somewhere.
- asia92 7y agoSounds like a good way to hit the 10k usb-c lifespan
- dancek 7y agoIsn't USB-C designed to wear out the cable (or dongle) and not the port? So if you used a Yubikey to log in and out ten times a day, you might need to replace it every three years. Of course you'll make the same amount of connections if you require it only for login, assuming you don't leave it connected.
- Fnoord 7y agoLets see. Say you work 5 days a week. That's about 260 days a year (without vacations etc). Say you unlock your device 4 times a day when you work. That is 1040 times a year. Does your device even last 9-10 years? Well, if it is a MacBook, Apple ditched support for all <= 2012 MBPs. Not sure when they did, but this was true at start of last year for sure.
- fluffything 7y agoI have a Macbook Air 2012 which is still supported by Apple (I get new OSes and OS updates every year).
- Fnoord 7y agoTry to get the screen or battery replaced. To be fair, they're easier user serviceable than newer MB(A/P)s. For example, me with my MBP 2015 will have a harder time to service it once it gets EOL (hardware-wise) than you have now with your MBA 2012.
- tylermenezes 7y agoFYI, you could also do this with your charger. (It sends udev events.) It's a lot less likely to get weird looks.
- sedatk 7y agoSo this project is already dead.
- Taniwha 7y agoA gentle warning: different Linux distros handle UDEV "remove" differently, and incompatibly, so few people actually use this message it's not well tested (try shipping code for a device that DOES need it!). Debian was a particular problem until they switched to SystemD (which I think is possibly the only udevdaemon that gets it right) - even so some distros (Ubuntu I'm looking at you) screwed up starting the udevdaemon before they mounted root writable meaning that scripts run from it couldn't really do anything useful Fortunately most distros are switching to SystemD so this will likely work in most places
- Taniwha 7y agoBTW - a clue for budding writers of UDEV scripts - you can't run daemons directly (udevdaemon will kill them when the scripts that started them exit) - you can use "at now" (after you install at of course) to start a secondary script that will be allowed to start your daemon for you (that way you can write code that works with all init systems, largely by avoiding them)
- CameronNemo 7y agoI maintain a fork of Upstart that I call startup. It integrates with udev (or busybox's uevent, or any other event source) so you can start daemons based on device events and then supervise those daemons. systemd has something similar where you can place a SYSTEMD_WANTS stanza in a udev rule and it will pull in a systemd unit, but I really dislike that model because it is hard to discover the policy that led to a unit being activated. With startup/Upstart, the policy is in the job configuration itself. Source for startup: https://gitlab.com/chinstrap/startup https://gitlab.com/chinstrap/startup Example of the udev events in action: https://gitlab.com/chinstrap/pinebook-pro/blob/master/etc/startup/setfont.conf https://gitlab.com/chinstrap/pinebook-pro/blob/master/etc/st...
- TedDoesntTalk 7y ago> We do what we can to increase our OpSec when using our laptops in public. But even then, there’s always a risk that someone could just steal your laptop..." Don't leave the house if you want to be safe.
- deleted 7y ago[deleted]
- bayesian_horse 7y agoI think it should be possible to program an MCU to bruteforce the USB ids. Or buy the same usb drive.
- sytelus 7y agoummm... ever heard of bit locker?
- simonebrunozzi 7y agoSmart. Author should productize and sell this. Small market, but almost no competition so far.
- alain_gilbert 7y agoI created the exact same thing 3 years ago. Main difference is that you don't need to configure anything with mine :P
- londons_explore 7y agoI'd like to see a more practical solution for removing disk encryption keys from RAM. For example, wipe the disk encryption key from RAM, but then pause all disk IO and present some kind of UI to re-enter the encryption key to continue using the system. Encrypting all of system RAM can also quickly be done - perhaps a kernel module which in the case of a panic encrypts all of system ram with a key derived from your disk encryption key would be handy. Then when the key is available again, ram can be decrypted and processes resumed.
- nickik 7y agoThat what systemd homed is supposed to enable
- hkai 7y agoWow, a solution for a problem we never have to worry about in Asia. Why can't your government just crack down on theft so that people can be allowed to use their laptop wherever they want without fear?