A stolen laptop is usually not considered "no big deal" basically everywhere I worked.
A stolen laptop is usually not considered "no big deal" basically everywhere I worked.
The videos I saw don't inspire much dread, there, but they may give the laptop to someone that can do digital forensics. Lots of LEOs in that lot. They would be smart enough to stay out of the building, but might have been waiting for someone to come out with something like that.
But, as someone pointed out, a lot of the folks wouldn't bother trying to read anything. They'd probably try to plant their own fantasies onto it, and send it to Rudy The Hair Dye Man.
https://www.independent.co.uk/news/world/americas/us-electio...
Most of the rioters seem like herpa-derpers, but some came there on a mission, like this guy: https://www.thesun.co.uk/news/13690389/us-capitol-rioters-zi...
(those are not regular zipties, but the "taking hostages" kind)
There were definitely some folks there with mayhem in mind.
For example, the lady who was shot trying to enter the VP bunker has a social media profile with extensive Qanon related postings.
Another was a Republican member of the House of Representatives. He was caught because he livestreamed himself breaking the law, as all genius criminals do.
The story about Antifa being in the riots was made up out of whole cloth by the Washington Times. The company they cited put out a press release saying that they had done no such thing and the whole story was a fabrication.
They have a photo of a guy on his hands and knees, cleaning the place. He's a congressman.[1]
[0] https://www.the-sun.com/news/2105149/trump-supporters-smeare...
[1] https://www.cnn.com/2021/01/08/us/congressman-capitol-trash-...
Leaving it on, the machine would detect loss of home network fairly quickly and lock itself.
The FDE key would depend on a key server on the home network, so it could not be rebooted and unlocked just with the physical on-board devices.
If some parts of the FDE were handled on the storage itself and required a periodic end-to-end refresh with the home network key server, then even freezing main RAM (literally) to extract keys later would not work.
More generally, the FDE key could be split over a number of components on the machine, all of them requiring end-to-end periodic refresh from the home network key server, making it extremely difficult to freeze all on-board devices effectively enough to extract the whole key and decrypt the storage contents. Add RAM encryption to complete the job.
Not to mention cold boot attacks if the laptop was still running.