6 ms·
10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves. There I met two secu
by dosshell 4y ago
10 years ago i was working at in a shared office where companies could hire a room. We all had a common lunch place and shared microwaves.
There I met two security nerds. They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security.
They spoke with passion about security fixes they made in the vpn client that no other had.
They got many requests regularly from others that they should add there server as an endpoint - and they sad always no. All endpoints must be 100% secure by their knowledge. Never trust anyone.
If they had to leave a laptop they used some old coffee paper trick so that one could not open the lid without visible marks.
I was super impressed by them and have never met any like them. I guess they have grown out of their tiny office now, Mullvad.
- Rastonbury 4y agoWhat is the coffee paper trick?
- LanternLight83 4y agoIt must be attached such it tears when opened, tamper-evident- similar techniques are common fro doors, either across the frame or more stealthily near the hinge. You want it to be a little stealth because an informed adversary could break the seal, remove it, and be prepared to replace/recreate it when they're done (like faking a new wax seal)
- oceanplexian 4y agoI would think you'd do the exact opposite. If you leave a computer running anyone (Well "anyone" being a skilled adversary) can simply pull out the RAM and grab encryption keys in clear text. Law enforcement does this so often, it's practically routine. The only "safe" system is one that has been long powered off and is using tried and true cryptography, ideally open-source FDE that's been fully audited.
- WhitneyLand 4y agoIt’s practically routine for law enforcement to extract encryption keys from RAM, since when? I’ve only heard of it being done by researchers and/or special situations. Is this just speculation?
- gzer0 4y agoMullvad is fully open source, with the source code provided here [1], which has also undergone multiple rounds of audits with the reports available to the public [2][3]. [1] https://github.com/mullvad https://github.com/mullvad [2] https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leaks-found-cure53s-infrastructure-audit/ https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak... [3] https://cure53.de/pentest-report_mullvad_2021_v1.pdf https://cure53.de/pentest-report_mullvad_2021_v1.pdf
- OJFord 4y agoIt's a shame the API isn't open though. I maintain a Terraform provider for it, but it has to come with a fat warning that it can break due to (reversed) API changes, and that fixing it may require breaking changes or even not be feasible etc.
- Kototama 4y agoFDE is not enough against physical access, see the evil maid attack.
- oceanplexian 4y agoWell obviously, FDE also doesn't protect you if someone is standing over your shoulder reading you type the password. The point is that leaving a machine turned on, while not in your physical possession puts all of your data at risk. My company would freak if I did this and I don't even work in the security space.
- deleted 4y ago[deleted]
- gavinray 4y ago> "They never shutdown their computers and if it happened, they did a full format and reinstalled the os - because if security." I don't get it
- deleted 4y ago[deleted]
- dosshell 4y agoI don't recall why, it was so long time ago. But my best guess is that they wanted to guarantee that they know what has been booted?
- brobinson 4y agoThe sibling comment already mentioned evil maid attacks (not as much of an issue nowadays thanks to SecureBoot and TPMs), but there's also DMA attacks through physical ports: https://en.wikipedia.org/wiki/DMA_attack https://en.wikipedia.org/wiki/DMA_attack
- justsomehnguy 4y agoOffline attack aka Evil Maid
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]