BusKill: A kill cord for your laptop
tech.michaelaltfield.net
tech.michaelaltfield.net
I was expecting a "kill switch" destroying the computer, but that's just a thing that switch off your laptop when unplugged. I guess you could also do this with bluetooth, for example.
(Plus I tried several solutions to do this; BT is not really well suited for proximity detection, teeming with false positives and false negatives)
That said, the caveat of XKCD 538 (https://www.xkcd.com/538/) still applies.
Edit: Ahh, read up a but. I wasn't aware "veracrypt hidden volumes" are already pretty stealthy. Would probably require some work to make it plausible though...like recent faked web browsing history.
I do not anymore, but did it decreased?
[0] https://en.wikipedia.org/wiki/Deniable_encryption#Software
VeraCrypt is one of the main forks that has picked up popularity, and has addressed some of the minor concerns of the audit.
The hidden volume hasn't had a high degree of success when it comes to deniability [1]. Some leaks closed, probably not all. With the design, it may not actually be possible to close all the leaks. (Especially as "Stoned" can break the full-disk encryption).
TrueCrypt doesn't use the TPM (and nor does VeraCrypt), because the authors didn't believe it added any security whatsoever (as it can't defend against a hardware keylogger, despite making coldboot attacks harder).
TrueCrypt is vulnerable to coldboot, evil maid and the "Stoned" bootkit. Depending on your security concerns, that might be fine, it might not. Other solutions may be better when dealing with those attacks.
[0] [PDF] https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_O...
[1] https://yro.slashdot.org/story/08/07/17/2043248/schneier-uw-...
Exactly. One of my favourite vids is Don't Talk To The Police, it's the right thing to (not) do.
Though if this is part of your threat model you should be much more concerned about a thousand more mundane problems, like adversaries reconstructing keystrokes from keyboard vibrations that are easily measured with a laser, or reconstructing screen content from reflections on a spoon.
I guess the higher the RAM capacity the shorter it would be because of the decrease in physical cell size.
The killcord would have been useful for Ross Ulbricht (Silk Road) who was busted by the FBI after using his laptop in public - they grabbed it while he had it unlocked and didn't have time to put it in suspend.
I’d really love a citation on this, especially since “quickly” seems to imply that they’d do this out in the field.
No idea how long you have to power it back on afterwards, tens of minutes to a couple of hours probably.
That said, the proper "kill switch" operation would be to explicitly wipe the key from memory before powering off (if you want to power off instead of just locking).
I wonder what their approach to a laptop with poor serviceability would be. I think it would take me more than a minute to get physical access to the ram of some modern computers.
RAM is still one of the most accessible parts for most laptops & desktops.
Tablets and phones on the other hand make it much much harder.
That’s pretty smart by the FBI agents to wait until it was unlocked and sneak up and take it. If instead they stormed in guns drawn, all Ross had to do was close the lid and bye bye evidence.
Drone strikes hit and kill hundreds of targets each year. Some on as little intelligence as an IP address used to click a link in a tweet.
For using reflections, there's this paper implementing reading screen content from various things like reading glasses, a can of coke or even the user's eye (including a discussion of limitations): http://gauss.ececs.uc.edu/Courses/c6055/extra/reflections.pd...
Right now I can't find something on reading keyboard vibrations with lasers, but here's one doing it acoustically and one doing it via acclerometer of a phone on the table:
https://security.stackexchange.com/questions/23322/keyboard-...
https://dl.packetstormsecurity.net/papers/general/traynor-cc...
And here's how to get the acoustics with a chip packet, or glass of water or pot plant: https://news.mit.edu/2014/algorithm-recovers-speech-from-vib...
I'm not sure if that's high fidelity enough to match to a keyboard, but I'm sure that if MIT can do it, someone else can do it better.
With this method, you would still be able to freeze the RAM, reboot the computer, dump the RAM, and disassemble the kernel memory, and discover where the disk encryption key was stored: in that location, you'd find all zeroes.
I read an article many years ago (I don't have a link but if you're interested google might find it) before ssd's were mainstream. They took a hdd and did one pass of overwriting it with /dev/zero.
Then they contacted some data recovery companies, told them they accidentally blanked the hdd with one pass, and ask for a quote to retrieve the data.
None of them had any interest in giving a quote or trying to recover the data even though in theory it could be recovered with a microscope or however they do it.
As you said, there are a 1000 more mundane ways that would be cheaper and more reliable than deep freeze.
If the FBI traces illegal activity to a cafe / library / wework office, and you're the only one with a kill cord attached to your belt with a carabiner, guess who they're going to target first.
I'd be careful though, as you don't want any "misshaps". It's not likely worth going that far unless you're doing something very sensitive.
On Linux there is blueproximity [2] that can lock (and if you like, unlock) your computer based on the proximity of a bluetooth device. My personal experience is that Bluetooth is frustratingly unreliable, and this package was no exception. But it's there if you'd like to try it!
[1] https://www.rya.org.uk/knowledge-advice/safe-boating/look-af... [2] http://www.daniloaz.com/en/automatically-lock-unlock-your-sc...
In other words, did you test different bluetooth devices?
I'm sure there are configurations that work - blueproximity probably worked well for its author, or they wouldn't have released it! And I gather Windows offers "Dynamic lock" which locks the screen based on bluetooth.
However, having experienced bluetooth unreliability with Linux, Windows, Android and iPhone; and with mice, GPS receivers, cars, access control systems and sports watches; I am confident the unreliability was not unique to a single bluetooth device.
You’d think most of it would be similar to network interfaces, handled by the kernel with commands such as ip, iptables, etc to configure it?
Wrong! Instead it’s mostly done in userspace and the tools to talk to it are using D-Bus which is an opaque, inconsistent, hard to understand mess which you can’t easily interact with programmatically.
As horrible as BT itself is I’d give the protocol itself a break in this case and focus on the terrible implementation.
Only in the sense that the bluetooth maintainers never completed the port to D-Bus. So, 25% of what you need to do with bluetooth needs to be done via kernel anyway.
Bluetooth on Linux is a prime example of how open source can fail.
It isn't shocking that the thing to talk to them isn't complete.
I mean, I have plenty of things to hide just like any other reasonably interesting person, but none of it is outright criminal.
Or use cases like a crypto wallet. Where legality isn't the main concern.
And they'll be equally fine with - ooops! accidentally, of course! - leaking info that you'd like to stay hidden, even if it's not anything criminal.
Eh, believable, but I think it's more likely a lot of them are evading taxes or committing securities fraud.
Or politics (see Watergate), or being a public defender, or environmental activism, or... the list goes on.
Did that feel good? Well, it was preventable. That's a kind of thing that a reasonably interesting person might want to prevent.
Anyway, this happened. Not that I'm, like, supposed to be reasonably interesting or anything. ;)
I don't think a mouse jiggler would help. A dead-man script would force a fast, ungraceful OS halt. Maybe after emptying some caches and wiping memory.
That sounds like exactly a good use case for this. Or maybe that's what you meant?
Worked pretty well as a "kill switch" when getting up from my desk.
I probably have the udev scripts laying around somewhere.
So if you used a Yubikey to log in and out ten times a day, you might need to replace it every three years. Of course you'll make the same amount of connections if you require it only for login, assuming you don't leave it connected.
I might want to replace the battery again in the next 3-4 years if I still have this laptop, and you might be right in that this might not be possible, but at least today it is.
YubiCo even provides the documentation to set it up via OpenSC. I guess you can also set macOS up to hibernate and destroy the FileVault key.
(My adversary is not government etc (who can execute a cold boot attack anyway), it is thieves while I'm in transit, and clients around the office.)
macOS Logon Tool Configuration Guide https://support.yubico.com/support/solutions/articles/150000...
Unfortunately, it's not currently compatible with Catalina.
Here are a few more resources for macOS users:
Simple Daemon for lock and unlock macOS with Yubikey https://podtynnyi.com/2017/03/07/simple-daemon-for-lock-and-...
Locking macOS to a Yubikey 4 with PIV and PAM https://www.richard-purves.com/2017/02/13/locking-macos-with...
HOW to lock and unlock screen upon removal and insertion of Yubikey on macOS https://confluence.panio.info/display/PUBL/HOW+to+lock+and+u...
[1] https://support.yubico.com/support/solutions/articles/150000...
Does that approach allow instantly locking the screen if the YubiKey is removed? It's not mentioned in the guide, so I just want to be sure.
Also, remember you only need to enter the PIN, which I'd argue is a good thing as I don't want to enter my password in public (I don't even know my password out of my head). If you boot up, you need a password of a username to unlock FileVault, but I use a different username for that (who does not have root, though for forensics this is an attack vector).
Lock your Windows 10 PC automatically when you step away from it https://support.microsoft.com/en-us/help/4028111/windows-loc...
While macOS doesn't include such a feature out of the box, apps like Near Lock https://nearlock.me exist.
EDIT: Just found Rohos Logon Key for Windows and macOS:
https://www.rohos.com/products/rohos-logon-key-for-mac/
It "converts any USB drive into a security token for your computer" and can "automatically lock your Mac screen when the key is unplugged".
This kill cord might have saved him some grief.
Better, perhaps, would be to trigger wiping the LUKS header and deleting the boot partition.
The NSA laptops have two buttons on one side of the machine, to destruct crypto keys, one needs to open a cover and press two buttons simultaneously. It's a pretty good self-destruction button. But you cannot find it in your laptops.
Or perhaps you can design your kill switch like the Russian nuclear Dead Hand - the automatic nuclear retaliation mechanism is only armed if a safety switch has been explicitly switched on, in peacetime, the switch is turned off to avoid an accidental nuclear apocalypse. But remember to arm the switch every time you travel with your laptop became a question.
Before even touching on his habitual use of coffee shops near his residence to run the Silk Road...
> The connection was made by linking the username "altoid", used during Silk Road's early days to announce the website, and a forum post in which Ulbricht, posting under the nickname "altoid", asked for programming help and gave his email address, which contained his full name.
By the time the FBI was watching him and had connected his name to I don’t think there’s a lot that he could have done to avoid arrest.
But if your hard drive is encrypted, this is a pretty good solution for most people.
Maybe if you can get BusKill to activate a mini thermite explosive under your hard drive.
Hard drive platters are surprisingly heat/chemical resistant. I think they found that the best method was to physically destroy the platters.
The whole point of thermite-based HDD destruction is to get the platens over the Curie temperature so the magnetic field is gone, not to physically destroy them. They point this out in the start, but then never talk about whether this was achieved or not in their experiment (assumably so they could go on to the actual explosives).
It was entertainment, and I'd take any results with a grain of salt.
At that point, the better option would be (IMO) to simply blow away the first 2 MB or so of your disk (where the LUKS master key is stored), run a "sync", and execute an immediate "reboot -f" (along with, perhaps, the other options that skip spitting out the warning message, writing an entry to utmp/wtmp or whatever, and so on).
There wouldn't be a real need to actually zero/wipe the entire drive (which would take a bit, even at SSD speeds).
I always use a kensington lock and lock my screen whenever I have to leave my laptop. If I had a macbook I would be taking it with me. I know the locks won't stop someone who really wants to steal it but with so many unattended laptops sitting around it makes it less likely they will go for mine.
From tidbits in this thread, it sounds like a Veracrypt hidden volume with a distress passphrase, plus a fairly simple dead-man script wouldn't be hard to set up. Something like: kill sensitive processes, drop caches, wipe memory, then panic the kernel.
http://nypost.com/2020/01/02/man-dies-after-trying-to-stop-t...
Definitely don't go running after your stolen laptop, let it go.
Be smart, be the one in control of the situation.
You being killed by a criminal over an iPhone or laptop is not going to change anything. Fund your police, vote to change laws enough that they’re spending their time on things that are relevant, and if you’re honestly willing to die for the rule of law, become a police officer.
Otherwise your body will be one more on the list of “people that died for no reason.” It’s not tough, righteous, or whatever else to die for no reason - and even if it were, if you’re going to make a stand and sacrifice your life, make it over something more than a laptop.
Not GP, but your assumption is wrong.
It's not about the laptop. It's about standing up for yourself and doing your part towards society. You obviously don't agree with this stance and that's fine, but it's not your place to dictate what values are worth standing up for and what aren't.
I, like GP, fully intend to go after a thief. If he goes after my life, then I go after his. Either he gives up the laptop, or one of us gets killed.
It's as simple as that.
Nothing is ever as simple as that. Not only is it a foolish, immoral and illegal, you've also just communicated murderous intent. Have fun spending 20-to-life in a cell because you thought ultraviolence would be a good way to do your part towards society.
I've had more than my fair share of violent confrontations, and I assure you, no matter how well you think you are prepared, once the metallic taste of adrenaline hits you, all your plans and delusions of grandeur go out the window.
A bit of violence can be acceptable. Murder over property is not.
No I have not. It's your bias that colored it that way. Reread my comment. I never said I want kill a thief for stealing. I simply stated that I will take back what is mine. If, and only if, the thief tries to kill me will I respond in kind.
Again, it has nothing to do with grandeur and everything to d with doing what is right. I will take back what is mine, and threatening my life wont stop me.
It's always irrational to risk oneself for a principle, that might (or might not) be for the benefit of society.
If you aren't going to do it, fine. I'm not inclined either. But have the grace not to gratuitously criticize those who do. Try not to see them in the dichotomy of heroes or idiots, just as people who provide some leavening to society.
Obvious loss of life is extreme and trivial things is subjective, but I think the point stands. There is a practical consideration to be made about what the risk profile is and what the degree of crime is. Clearly charging a man holding a loaded gun because he swiped some gum would be silly. Charging a man with a loaded gun because he’s about to shoot a kid, different set of equations.
I do, thanks. I just think it's distasteful, dare I say boorish, to call other people's sacrifice "trivial" when it probably benefits me, even if slightly.
I don't think we live in a world where armed robbers are categorized as gum-stealers and child-shooters and never the twain shall meet. Some people are suspicious of even non-criminals having or using guns, believe it or not.
I'm not saying worship every vigilante as a hero, just accept that disproportionate reactions to antisocial behavior are never going to go away, are a fundamental part of human behavior, and can be stupid from an "economically rational person" perspective and beneficial to society, including you and me, some of the time.
If you call something another person is willing to risk their life for "trivial", you really don't care about their life. It's transparently an insincere reaction to feeling badly about being passive.
Meanwhile, in Texas you'd just shoot the laptop thief, either as soon as aware of the imminent theft or as the thief flees. It's fully supported by the law:
https://lawofselfdefense.com/statute/texas-sec-9-42-deadly-f...
Law enforcement in many communities would congratulate you for a job well done.
Debian was a particular problem until they switched to SystemD (which I think is possibly the only udevdaemon that gets it right) - even so some distros (Ubuntu I'm looking at you) screwed up starting the udevdaemon before they mounted root writable meaning that scripts run from it couldn't really do anything useful
Fortunately most distros are switching to SystemD so this will likely work in most places
(that way you can write code that works with all init systems, largely by avoiding them)
Source for startup: https://gitlab.com/chinstrap/startup
Example of the udev events in action: https://gitlab.com/chinstrap/pinebook-pro/blob/master/etc/st...
---1---
I have a OnePlus 6T with the stock ROM exclusively for my British phone number. On the 25th of December, someone from Canada logged into the GMail account used on that phone, from a OnePlus 3T.
The password was one randomly generated in KeePass (all of them are except for useless websites). They managed to change the password to the account, but seemingly nothing else, so that's just weird.
I received the notification on my other email, and recovered the account, reset the password, replaced with a new one.
---2---
Last week, I opened up a laptop I use for storage (3 drives fit inside, perfect for backups) and noticed a network drive with a Chinese name. It disappeared when I clicked on it. The laptop is always on connected to my router and to a VPN server.
Now I need to completely wipe the phone, root and use a custom ROM, as well as wipe the laptop (and two other computers?), upgrade OpenWRT on the router and change all of the passwords I guess. Yes, I still haven't done it heh.
---
----------->I am curious about your comments on this.<-----------
---
Never had anything really suspicious like this actually happen to me.
I don't even have anything good/useful on my devices, except a Keepass database with passwords to all bank accounts/emails/etc. If that's been opened, I'm a bit fucked, but I'd be receiving notifications on my phone and other emails.
Doesn't really matter though, it would've been mitigated by not keeping the KP database decrypted at rest or by using 2FA. Both of which are SOP for hardware token users.
For real, at this point if you don't have a yubi/nitrokey on your keychain, I assume you just don't care about actual account security.
The article's solution is amusing and "cool" but not really secure at all. If you're worried about physical security of devices, don't take them to coffee shops.
Yes, they could still be removed in some cases, but its often not for the feint of heart and not something many people would want to undertake.
Yet another major regression in the state of computing since the 90s.
echo o > /proc/sysrq-trigger
(read linux/Documentation/admin-guide/sysrq.rst before you try this)FWIW, this is just what I do with the keyboard (but more slowly) when something went wrong enough that I can't even switch to a text VT and recover. Sometimes even 'b' won't hard reset it-- which indicates everything was already hosed, or maybe just the keyboard. Presumably the umount didn't work either, but I gave it a chance.
("would've", not "would of")
That's when I gave up. There are a million other reasons to love my wife, and her proper use of 'would've' wasn't one of them to begin with :)
If I said "would ev" that would sound weird. It would sound very similar to "whatev":
But people are lazy. And words like caramel get blurred over. Or the one that bugs me the most of saying ‘ta’ instead of to.
My favorite is the Futurama universe where the word ask is official changed to ax instead.
There are USB devices that are so small, you can barely even see them in the port when plugged in.
Perhaps a hard-to-remove USB plug? (like child-proof plugs you might see in an electrical outlet)
You could also just use a thicker cord.
The project, no offense to the author, could be renamed: long USB cable with a magnetic usb attachment.
> As of yesterday, that’s [stolen laptop] a hard attack to defend against.
Which is just wrong; the author did not invent anything here - anyone I’ve known that’s ever been worried about this scenario has implemented it already with <yubikey/access card/arbitrary usb>.
* extra PSA: if you’re worried about this but somehow haven’t already required 2FA for all your accounts and admin access on your laptop, then you should re-evaluate your threat scenarios.
I’m aware - I’m pointing out that it’s extremely likely you already have a physical device you can attach to a cord/chain/braided-steel-cable and use for the “snatch and grab” scenario. And that a snatch and grab is just so unlikely compared to any other security threat imo.
Don't leave the house if you want to be safe.
For example, wipe the disk encryption key from RAM, but then pause all disk IO and present some kind of UI to re-enter the encryption key to continue using the system.
Encrypting all of system RAM can also quickly be done - perhaps a kernel module which in the case of a panic encrypts all of system ram with a key derived from your disk encryption key would be handy. Then when the key is available again, ram can be decrypted and processes resumed.
• whenever any USB drive is removed, trigger xscreensaver to lock the screen:
> ACTION=="remove", SUBSYSTEM=="usb", RUN+="DISPLAY=:0 xscreensaver-command -lock"
• whenever a specific USB drive is removed, shut down the computer:
> ACTION=="remove", SUBSYSTEM=="usb", ENV{ID_MODEL}=="Micromax_A74", RUN+="shutdown -h now"
So this is a "kill cord" in the meaning of a jetski, power boat, or treadmill where pulling out the kill cord triggers a fast but nondestructive stop.
It's clever, I'll admit, but the name leaves more to be desired with a name like 'buskill'
Not something most users likely need but I can imagine some TLAs being interested in something like this, as it looks pretty inexpensive to implement.
Today, most laptops have cameras which can offer the same level of proximity detection if you away from the laptop. That would make this type of solution doable via software that way, albeit a bit more of a software load overhead.
But for some killcord, I'd also have an alarm.
Most people who would want a kill cord probably have the camera blocked :P
First, it doesn’t solve for the scenario of person pointing a gun at you and telling you to access your top secret files for them. That will defeat most forms of security and so if physical access is a concern you probably shouldn’t be logging in at your local coffee shop.
Second, a thief who wants your computer for its monetary value isn’t interested in its contents. Your normal drive encryption and screen timeout restrictions have you covered there. They’re gonna wipe your computer, sell it, and move on.
Institutionally purchased hardware is often equipped with zero-touch provisioning (such as Apple Device Enrollment). These products can be bricked at the hardware level they moment they touch the Internet. They’ll need a new logic board, i.e. new soldered on storage, i.e. they’re not even necessarily worth stealing.
Third, the idea of a magnetic connector’s removal locking or bricking your computer seems awfully inconvenient. That’s gonna be constant false positives without a gain in security.
If you’ve got someone who is after you to obtain your secret company info and knows enough to cause mayhem, you’ve got much bigger problems than whether or not your screen is going to lock. They’re also probably going to use social engineering, targeted malware and spyware, not brute force physical access.
It's a solution to situations like https://en.wikipedia.org/wiki/Ross_Ulbricht#Silk_Road,_arres... , where the laptop is taken by people who (a) can legally seize it, (b) can legally search it, but (c) probably can't legally compel you to produce passwords.
(Not endorsing this usage!)
If there is no due process, all bets are off and your best defense is to be uninteresting to authorities.
And even if: A kill switch can simply hide / erase some things and present some weak evidence..
It's a very good solution for people who don't know you have something like this. Clearly if the FBI (or whatever) knew of the USB kill device, they'd take a slightly different snatch and grab approach. However if the adversary doesn't think or doesn't know you have something like this, then it can be used to great effect.
I've read that LEO in the USA specifically try to grab laptops / phones while they are unlocked.
This seems to be designed as a defense against that threat model.
Regardless, k_sze posted somewhere else in this discussion xkcd 538 (https://www.xkcd.com/538/) and I have to agree with him.
Your second point is moot, because the intent is not to protect the hardware, it is to revoke access to data. A self-destruct protocol is not about preservation of property.
Your third point is moot, because the intent is not to be convenient, the point is to create a dead man's switch.
You're thinking about this from a Consumer/Enterprise standpoint, but that's not what this is for. This would be great for political activists in oppressive countries, as an example.
Knowing your encrypted data is inaccessible to a thief is a huge relief, and may have saved this man's life:
A man working at Starbucks had his laptop stolen. He was killed when he chased down the thief. https://www.cnn.com/2020/01/01/us/oakland-laptop-thief-starb...
Not that a laptop or data is worth your life (usually).
They could blackmail you, sending you an email with a bitcoin address you should transfer money to or else the data will go public.
Its primary use is to thwart machine fuzzing and debugging using USB devices. The moment there's a change in USB state, down the machine goes.
Kudos for the imagination, but in real life for most developers not vendorizing and auditing their dependencies (+ downloading them all from production) is most likely to cause such havoc (regardless if dozen thousands or millions of damage)...
I imagine this might likely happen in places like security and programming language conferences, especially when you leave your belongings around unattended for a minute or two.
The ideal scenario IMHO would be to have to authorize/reject devices from connecting to your machine (and limiting the scope). I don't know much about USB-C and know it is hard, but I see Apple coming up with something like this in the future (maybe along with Apple Watch detection for quick logout - you can already use it for logging in).
If this is a situation you're actually concerned about, the approach in the article seems simpler and more foolproof.
Main difference is that you don't need to configure anything with mine :P
Does the dis connection of USB formats the laptop or just shuts it down?
This really just sounds like a way to inadvertently brick your computer 999 times out of 1000. Seems like something to secure it to your person would be mostly adequate.
"As of today, we have BusKill. The BusKill solution described in this article can trigger your laptop to self-destruct if it’s physically separated from you."