5 ms·
"no big deal" A stolen laptop is usually not considered "no big deal" basically everywhere I worked.
by debt 6y ago
"no big deal"
A stolen laptop is usually not considered "no big deal" basically everywhere I worked.
- jerkstate 6y agoReally? Every place I have worked with more than about 50 employees has used full drive encryption, so a laptop being stolen is not an infosec risk at all.
- jandrese 6y agoFDE only works if the machine is powered off. If a machine is stolen while it is still running there's a risk the user account could be compromised. Depending how sophisticated your adversary is they could potentially completely compromise the machine and extract all of the data. When you have physical access and no time pressure the options are vast.
- ChrisMarshallNY 6y ago> Depending how sophisticated your adversary is The videos I saw don't inspire much dread, there, but they may give the laptop to someone that can do digital forensics. Lots of LEOs in that lot. They would be smart enough to stay out of the building, but might have been waiting for someone to come out with something like that. But, as someone pointed out, a lot of the folks wouldn't bother trying to read anything. They'd probably try to plant their own fantasies onto it, and send it to Rudy The Hair Dye Man.
- jandrese 6y agoThey'll probably give it to that computer repair guy in Deleware so he can pull off all of the emails from March of 2021 and somehow lose them in the mail when he tries to send them to Fox News.
- reaperducer 6y agoTime to update your internet boogeymen memes. Fox News and Trump are enemies. He's into Newsmax now.
- jandrese 6y agoI was making an allusion to the actual Hunter Biden laptop story. https://www.independent.co.uk/news/world/americas/us-election-2020/fox-news-tucker-carlson-hunter-biden-evidence-deep-state-b1412878.html https://www.independent.co.uk/news/world/americas/us-electio...
- bJGVygG7MQVF8c 6y agoyou're neck deep in propaganda my friend
- knorker 6y agoAre you sure? Most of the rioters seem like herpa-derpers, but some came there on a mission, like this guy: https://www.thesun.co.uk/news/13690389/us-capitol-rioters-zip-ties-plan-take-hostages/ https://www.thesun.co.uk/news/13690389/us-capitol-rioters-zi... (those are not regular zipties, but the "taking hostages" kind)
- ChrisMarshallNY 6y agoI also notice he’s masked. That was unusual for that lot. There were definitely some folks there with mayhem in mind.
- throwaway201103 6y agoYes it would be really interesting to find out who those guys were, were they Proud Boys, Antifa, foreign agents, undercover domestic agents, etc?
- jandrese 6y agoThere have been several arrests already. Thus far it seems to be right wing extremists. For example, the lady who was shot trying to enter the VP bunker has a social media profile with extensive Qanon related postings. Another was a Republican member of the House of Representatives. He was caught because he livestreamed himself breaking the law, as all genius criminals do. The story about Antifa being in the riots was made up out of whole cloth by the Washington Times. The company they cited put out a press release saying that they had done no such thing and the whole story was a fabrication.
- ChrisMarshallNY 6y agoOn another note, the same publication (a redtop, so the language is rather "pithy") has this story[0], in which the "Fine People on All Sides" smeared feces around the place. They have a photo of a guy on his hands and knees, cleaning the place. He's a congressman.[1] [0] https://www.the-sun.com/news/2105149/trump-supporters-smeared-poo-capitol-building/ https://www.the-sun.com/news/2105149/trump-supporters-smeare... [1] https://www.cnn.com/2021/01/08/us/congressman-capitol-trash-trnd/index.html https://www.cnn.com/2021/01/08/us/congressman-capitol-trash-...
- asdff 6y agoWho is to say that a few opportunistic spies weren't in that push looking for anything of interest? Historically, this has been the case during these sorts of events. When the Stasi HQ was overwhelmed by protestors, Western intelligence agents were the first in the building securing lots of information.
- jlokier 6y agoFDE could be made to protect the data when the machine is out of range of its secure home network too. Leaving it on, the machine would detect loss of home network fairly quickly and lock itself. The FDE key would depend on a key server on the home network, so it could not be rebooted and unlocked just with the physical on-board devices. If some parts of the FDE were handled on the storage itself and required a periodic end-to-end refresh with the home network key server, then even freezing main RAM (literally) to extract keys later would not work. More generally, the FDE key could be split over a number of components on the machine, all of them requiring end-to-end periodic refresh from the home network key server, making it extremely difficult to freeze all on-board devices effectively enough to extract the whole key and decrypt the storage contents. Add RAM encryption to complete the job.
- jerzyt 6y agoReally? When I worked at one of the Big Four a stolen/lost laptop was DefCon 4, despite all of the security precautions. We were actually required to notify a partner in the firm before contacting law enforcement.
- polka_haunts_us 6y agoNot to detract from the point you're trying to make with meaningless pedantry, but minimum DEFCON is 5, current is 4, we spend most of our time swapping between the two. I assume what you mean is 2.
- jerzyt 6y agoThanks for the correction. I just used the DefCon as a catchphrase.
- chasd00 6y agome too, i have a special "corporate 911" card that i've been informed during onboarding is the "real" 911. No matter the emergency, lost/stolen passports, lost/stolen corp computer, place crash, car crash, anywhere in the world the company does business, i've been told to call it first before doing anythign else.
- tehbeard 6y agoOf all the cyberpunk trappings, a Trauma Team card was not what I expected to exist in real life.
- johnrgrace 6y agoI"ve used the number, they'll bail you out of anything.
- aksss 6y agoUh.. I think it's standard security policy in most enterprises to discuss matters internally before getting law enforcement involved. That's just prudent. If I walked into a company where the policy was "let IT staff talk to LE first, then notify chief counsel" I'd change that on day 1.
- vengefulduck 6y agoFull disk encryption is only as good as the TPM and I’d imagine that nation states have plenty of exploits they could use to bypass them. Not to mention cold boot attacks if the laptop was still running.
- jacquesm 6y agoAnd this is the one situation where the 'nationstate adversary' is pretty much the expected thing and not the exception.
- freeone3000 6y agoIf they have the laptop, they also have the TPM. It doesn't prevent decryption if you have the TPM.
- plif 6y agoYeah, me too. If they don't have this in 2021 their IT staff should be fired.