11 ms·
Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-ma
by Reventlov 7y ago
Archive link because the website is down: http://web.archive.org/web/20200102140351/https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/ http://web.archive.org/web/20200102140351/https://tech.micha...
I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.
- Piskvorrr 7y agoShared medium (i.e. wireless spectrum) means anybody can do that, without being too conspicuous. A wire is significantly harder to DoS ;) (Plus I tried several solutions to do this; BT is not really well suited for proximity detection, teeming with false positives and false negatives)
- k_sze 7y agoIf you are doing proper OpSec, you would have whole disk encryption anyway, in which case destroying the computer is largely unnecessary, I think. That said, the caveat of XKCD 538 (https://www.xkcd.com/538/ https://www.xkcd.com/538/) still applies.
- tyingq 7y agoI'm surprised there isn't a "ready to go" solution with a duress passphrase that boots a plausible, but "clean" system.
- rahuldottech 7y agoNot really ready-to-go, but can be set up in entirety in like half an hour with VeraCrypt
- tyingq 7y agoWell, you would probably want some stealth that doesn't provide that makes it less obvious. Like maybe the duress passphrase decrypts everything except a docker container you use for sensitive work, replacing it with a vanilla docker image. Edit: Ahh, read up a but. I wasn't aware "veracrypt hidden volumes" are already pretty stealthy. Would probably require some work to make it plausible though...like recent faked web browsing history.
- stordoff 7y agoThe VeraCrypt guide recommends "You should use the decoy operating system as frequently as you use your computer. Ideally, you should use it for all activities that do not involve sensitive data." You don't need to fake it per se, but section off what needs to be in the hidden operating system (rather than a standard VeraCrypt partition). You are therefore revealing real, thus plausible, information, but not the actual subset you want to hide.
- D2187645 7y agoAre we going too overboard hiding our fetish video collections? My family members just leave thier dvds lying around, meanwhile Im encrypting every hd I can.
- stordoff 7y agoIt's not quite ready to go, but it's doable with TrueCrypt/VeraCrypt: https://www.veracrypt.fr/en/VeraCrypt%20Hidden%20Operating%20System.html https://www.veracrypt.fr/en/VeraCrypt%20Hidden%20Operating%2...
- hutzlibu 7y agoWhy is it not ready to go? I used truecrypt hidden systemvolume years ago? I do not anymore, but did it decreased?
- close04 7y agoDeniable encryption is part of a few encryption solutions (probably more than listed below). [0] [0] https://en.wikipedia.org/wiki/Deniable_encryption#Software https://en.wikipedia.org/wiki/Deniable_encryption#Software
- tyingq 7y agoThe "plausible" part is what seems not out of the box to me. Some easy way for the decoy image to show recent real looking activity, and an easy way to use the real image. Probably some integration with a VM or container.
- stordoff 7y agoI took ready to go to mean "run a command and it spins up a plausible fake system". The tech of TrueCrypt/VeraCrypt, AFAICT, seems sound, but maintaining the contents of the fake system (so it's not an obvious decoy/placeholder) takes more work.
- shakna 7y agoTrueCrypt shuttered in 2014, though an independent audit didn't find any significant issues in 2015. [0] VeraCrypt is one of the main forks that has picked up popularity, and has addressed some of the minor concerns of the audit. The hidden volume hasn't had a high degree of success when it comes to deniability [1]. Some leaks closed, probably not all. With the design, it may not actually be possible to close all the leaks. (Especially as "Stoned" can break the full-disk encryption). TrueCrypt doesn't use the TPM (and nor does VeraCrypt), because the authors didn't believe it added any security whatsoever (as it can't defend against a hardware keylogger, despite making coldboot attacks harder). TrueCrypt is vulnerable to coldboot, evil maid and the "Stoned" bootkit. Depending on your security concerns, that might be fine, it might not. Other solutions may be better when dealing with those attacks. [0] [PDF] https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_OCAP_final.pdf https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_O... [1] https://yro.slashdot.org/story/08/07/17/2043248/schneier-uw-team-show-flaw-in-truecrypt-deniability https://yro.slashdot.org/story/08/07/17/2043248/schneier-uw-...
- malka 7y agoyou'll still have to explain why there is a huge blob of seemingly random data on your hard drive if someone looks close enough.
- jbarberu 7y agoWith whole disk encryption the whole drive is seemingly random data, that's the point.
- captkos 7y agoLast i checked, you don't have to explain sh!t. Besides, I would just tell them i boot from a live cd only to prevent system compromise..
- brigandish 7y ago> Last i checked, you don't have to explain Exactly. One of my favourite vids is Don't Talk To The Police, it's the right thing to (not) do. https://www.youtube.com/watch?v=d-7o9xYp7eE https://www.youtube.com/watch?v=d-7o9xYp7eE
- mianos 7y agoThe common plausible explanation is you securely erased the disk or partition before. This would produce the same randomness signature.
- wongarsu 7y agoIn theory an adversary could deep-freeze the computer the moment the kill cord activates. Sufficiently cold RAM doesn't loose data immediately when it loses power, allowing the adversary to make a copy and read the decryption keys from RAM. Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibrations that are easily measured with a laser, or reconstructing screen content from reflections on a spoon.
- faceplanted 7y agoHow long does it take RAM to lose that data though? Most laptops take far more time to remove the ram than a PC and it's soldered down in a lot of cases.
- jacquesm 7y agoSuprisingly long. I've played around with that a bit a while ago and sometimes up to minutes later you could still recover recognizable bitmaps. But definitely not something you should rely on if you want a bit perfect copy, the first bits start to flip immediately upon power loss, some of them take a lot longer and our brain is pretty good at such reconstruction from noisy data, especially if it knows what it is looking at. I guess the higher the RAM capacity the shorter it would be because of the decrease in physical cell size.
- beatgammit 7y agoIt doesn't need to be that long if you can plug in a bootable disk and copy the memory off.
- tyingq 7y agoThere's sdmem for Linux boxes. It has a -l and -ll option that makes it reasonably fast. So a combination of a duress encrypted volume, then killing only "sensitive processes", then clearing cache via /proc/sys/vm/drop_caches, then sdmem followed by halt might be reasonable protection. Your second point, though, makes sense. It won't always be someone physically grabbing your PC.
- austhrow743 7y agoAre there any known cases of western police forces beating people with wrenches until they gave up passwords?
- jlg23 7y agoA few months in prison for not revealing the password can be unpleasant, too.
- claudiawerner 7y agoOr, under the RIPA act in the UK, a maximum of five years.
- SkyBelow 7y agoThat would be far too direct and brutal. Put them in prison until they talk and let the inmates know that they are refusing to decrypt their PC. The inmates will soon enough make their own assumptions why and do the beating themselves. Of course protective custody would be an option, but that is just even further isolation and mental torture.
- jandrese 7y agoI think waterboarding is more common. For US citizens they're usually stuck with just solitary confinement, which is a working form of torture but is kind of slow.
- anigbrowl 7y agoSure, read up on Northern Ireland.
- panarky 7y agoGood opsec blends into the crowd. If the FBI traces illegal activity to a cafe / library / wework office, and you're the only one with a kill cord attached to your belt with a carabiner, guess who they're going to target first.
- penagwin 7y agoIt appears that it runs a script of your choosing, so you could make it more violent if you wanted (start trashing data, clear cache etc.). I'd be careful though, as you don't want any "misshaps". It's not likely worth going that far unless you're doing something very sensitive.
- michaelt 7y ago"Kill cord" is jargon from jetskis, powerboats and treadmills, which often have a cord you attach to your body that cuts power if you are thrown off. [1] On Linux there is blueproximity [2] that can lock (and if you like, unlock) your computer based on the proximity of a bluetooth device. My personal experience is that Bluetooth is frustratingly unreliable, and this package was no exception. But it's there if you'd like to try it! [1] https://www.rya.org.uk/knowledge-advice/safe-boating/look-after-yourself/Pages/kill-cord.aspx https://www.rya.org.uk/knowledge-advice/safe-boating/look-af... [2] http://www.daniloaz.com/en/automatically-lock-unlock-your-screen-by-bluetooth-device-proximity/ http://www.daniloaz.com/en/automatically-lock-unlock-your-sc...
- hutzlibu 7y agoIs it possible that the bluetooth unreliability was a driver issue and others work fine? In other words, did you test different bluetooth devices?
- michaelt 7y agoI only tested with my smartphone, as it's the only bluetooth device I reliably carry with me. I'm sure there are configurations that work - blueproximity probably worked well for its author, or they wouldn't have released it! And I gather Windows offers "Dynamic lock" which locks the screen based on bluetooth. However, having experienced bluetooth unreliability with Linux, Windows, Android and iPhone; and with mice, GPS receivers, cars, access control systems and sports watches; I am confident the unreliability was not unique to a single bluetooth device.
- Jamwinner 7y agoI used blueprox for years with no fuss. Might try a different bt dongle.
- Nextgrid 7y agoBluetooth on Linux is an unprecedented abomination. You’d think most of it would be similar to network interfaces, handled by the kernel with commands such as ip, iptables, etc to configure it? Wrong! Instead it’s mostly done in userspace and the tools to talk to it are using D-Bus which is an opaque, inconsistent, hard to understand mess which you can’t easily interact with programmatically. As horrible as BT itself is I’d give the protocol itself a break in this case and focus on the terrible implementation.
- tyingq 7y agoI suppose if the drive is encrypted and requires a passphrase at boot, it's effective for FBI raids, etc.
- AnIdiotOnTheNet 7y agoWhenever I read stuff like this I am forced to wonder just what the fuck people are doing that they feel such a pressing need to hide their data from law enforcement. I mean, I have plenty of things to hide just like any other reasonably interesting person, but none of it is outright criminal.
- tyingq 7y agoThere's no shortage of things someone might find morally acceptable themselves while still being potentially criminal. Or grey area stuff, like a business that sells marijuana in a state where it's legal, since the US federal government doesn't consider it legal. Or use cases like a crypto wallet. Where legality isn't the main concern.
- groby_b 7y agoIf you happen to have an opinion that is not shared by the current powers-that-be, law enforcement will be happy to look at your data under any pretense it can cook up. And they'll be equally fine with - ooops! accidentally, of course! - leaking info that you'd like to stay hidden, even if it's not anything criminal.
- AnIdiotOnTheNet 7y agoIn other words, it's just a bunch of self-important tech asshats deluding themselves into believing they are important enough to warrant FBI attention? Eh, believable, but I think it's more likely a lot of them are evading taxes or committing securities fraud.
- tyingq 7y agoI would probably look into it if I was already on some government agency's radar for whatever reason. You've probably broken a ton of obscure laws yourself without knowing it.
- piracy1 7y agoYou could get similar outcomes to that if you used FDE and had it power off the machine fully. But then also your cat might ruin your day with one step :purplegirlshrug: