BusKill – A USB kill cord for laptops
buskill.in
buskill.in
User-Defined Phrase: "Please dont kill me", activates "duress" mode.
- A daemon listens in the background for a phrase of your choice. When detected, your laptop makes a sound effect that is not out of the ordinary for others to hear, but not something you would expect it to play when self destruct is activated. Git repos are committed/pushed with a duress demarcation code to an alternate branch. Your encrypted volumes are dismounted, buffers and caches cleared, camera and microphone start sending small chunks of audio/video to a destination of your choosing. Instructions for playback from your cloud of choice are emailed to emergency contacts. If you do not give the "all clear" in a user-configurable time period, the laptop does user-defined things like wiping encrypted volumes after giving an optional warning sound, optionally sending eeprom codes to brick the BIOS or replace the BIOS with a tracker and setting the screen to say "Stolen From User-Defined String, User-Defined Phone Number" after giving an optional warning sound. All of these actions could be optionally spaced apart based on risk, probably defined in a key-pair text file or json file.
User-Defined Phrase: "Computer, disable self destruct" disables "duress" mode.
- Giving the all clear code disables this behavior and your ship does not self destruct. The system plays a sound to acknowledge "all clear". Emergency contacts are emailed the all-clear, but audio/video continue to upload for user-defined time in the event your were forced to give the phrase.
Perhaps newer cars could also have this feature? Are there any existing open source projects that could be adapted/bent to accomplish these things?
If however the distress password gets entered, the script still runs, but the system unlocks into a virtual pc or another account which is not suspicious.
The paranoid dystopian counterpart is that you cannot prove you don't have a second partition either. Might get awkward if someone decided to compel the second password on less solid evidence. If you're not actually using the feature.
- email, including recently received and sent emails
- web browser history
- system logs
- software updates
In practice, I think it’s impossible to do that. If the police discovers, for example, that your system logs show your machine was off for a week, but they also just saw you reset it, what do you tell them?
That you're not a computer expert and have no idea why your computer wasn't keeping logs correctly?
Level of kink up to you.
You are probably thinking of the $5 wrench in https://xkcd.com/538/
It's based on the game theoretic idea that if your adversary has no way of knowing how many hidden partitions you have, then you have no way of proving to them that you've given them all your secrets.
As such, there is no benefit to you revealing any secrets under torture, because the torture would continue even after you've told them everything, therefore there is no point to them torturing you in the first place.
[0] https://en.wikipedia.org/wiki/Rubberhose_%28file_system%29
In reality they will torture you until you stop decrypting partitions, and then a bit more of special torture, just in case.
If you're in the business of protecting your secrets against torture then you need to also be protecting them against death because that is grimly inevitable.
If a torturer has good reason to believe you have valuable information regarding subject X, they'll simply torture you until they possess that information or you die. If you don't possess the information, you're screwed. If you do possess the information, it's likely that they'll stop after they get what they're after.
Hopefully civilization is not so far gone that police will imprison, torture or kill for failing to incriminate themselves. If it gets to the point cold-blooded torture is on the table, you'll probably get killed anyway.
I had an idea once, would it be possible to set up two sets of passwords? One to properly unlock your device, and one to trigger either encryption or scrambling of the data when entered?
Plausible deniability lets you pretend you do not have incriminating data, but it's tricky to use in the first place: https://gitlab.com/cryptsetup/cryptsetup/-/wikis/FrequentlyA...
Travelling with an empty disk seems like a more appropriate option. Dm-verity could probably be used to check that there has been no tampering.
I think you could get a pixel phone to do this in a useful way.
Darknet Diaries has a cool episode about the dark cellphone industry: https://darknetdiaries.com/episode/105/
* https://en.wikipedia.org/wiki/Duress_code
The feature is more relevant in (full disk) encryption software than OSes.
We do have a "LUKS Header Shredder" trigger (which we call self-destruct as it renders all the data on the FDE disk useless), but we (intentionally) don't include it by default and raise the barrier of entry because of the risk of data loss.
We'll be publishing a more detailed write-up on the LUKS Header Shredder in 2 weeks. You can subscribe for updates on our website (buskill.in) or the campaign directly (crowdsupply.com)
As a side note, Emerson Knives makes a really nice highly durable set of pocket knives with a "wave" that forces the knife open when you extract it from your pocket. It's many times faster than a switch-blade but legal in most states and durable enough blade and handle to pry anything apart. Check with the laws in your state.
In any case, the primary idea here was not to prevent stealing the laptop, but to prevent walking away from the laptop without locking it.
Is it possible to register 2 keys, so that any of them is correctly recognised?
An additional refinement is to autolock the device if a certain personal key combo (ex. Shit - vol up - vol down) is not pressed every few minutes in response to an audible click. If not unlocked in a minute or so with a complex password, the device halts to a disk encrypted state and unpowered ram, minimizing the window attackers have to recover RAM state.
If you can be observed to use the combo (which you would have to be using regularly) somebody else could be pressing the combo or they could insert USB device that can generate the combo regularly.
I would also add that locking your laptop is not safe enough if you are serious about this. There are devices that can exfiltrate information from what I understand almost every operating system through USB.
If that is true, then it is a vulnerability. You should file bug reports.
For more safety: any plugged usb device should lock your screen so that a password is required before it can be used.
My point is that given how universal USB as long as a device can do both input and output it's going to be very hard to stop some exfiltration from being possible.
Do you really think a bug report should be filed on all OS's for allowing USB drives and keyboards to be plugged on a running system?
It is.
> Do you really think a bug report should be filed on all OS's for allowing USB drives and keyboards to be plugged on a running system?
Automatically trusting input devices is as bad as trusting user input. It's trivial to pass off a programmable USB keyboard as a mass storage device.
Convoluted way to put it I guess. For some reason was intuitive to me (proof of existence by example, more trivial example better).
Having access controls on USB-HID is just a local policy choice where most people would choose convenience over security.
But the comment I replied to seemed to suggest that the possibility of data exfiltration via USB is a bug in any OS.
Both the dongle and the computer have accelerometer-bump-tilt-oh-fuck-support.
A OTP has to be entered every 5 minutes, or a secure screen/dead sequence starts.
Sudden accelerated movements or a lack of presence-detection would also start the sequence.
I guess you could do the same, but shut down the computer instead.
A more sophisticated implementation could be done if you can write software on the device. A PineTime would be perfect for this.
I am not sure why mention iOS specifically, a phone is easily forgettable. Moreover, you don't really need to rely on any location API provided by the system, even if UWB or Bluetooth Location Services would do wonders for this, a simple RTT latency measurement or RSSI value should be enough.
I also got multiple LG watch R, I'm probably going to fiddle a bit with them when I have time, hopefully mainlining them and porting postmarketos over. I'm open to trying again with those. In the end, I don't really have sensitive documents on a laptop (besides work-related confidential stuff), so I'm not sure I'd crank paranoia to 11.
As for my phone, I often pull it out of my pocket and leave it on my desk, or abandon it somewhere, charging or powered off -- I should probably be more careful with that, but people know to expect some latency when contacting me.
I had a program like this back in PowerBook days. It automatically unlocked the computer if a specified Bluetooth signal reached a particular strength, and locked the computer again if the signal strength fell below another threshold.
It worked great, when it worked. It had maybe a 70% success rate, but that was good enough.
unless they hit you with the cryo, too.
Might as well go all in and epoxy the ram sticks/dimm slot assembly.
Putting epoxy around the top and bottom edges (where the retention clips are) and the right edge (where the contacts are) should make it extremely difficult to dislodge, but not impact the thermal performance of the chips (the black rectangles).
I've noticed many lower end have one soldered and one removable. Drives me crazy because then you end up with more RAM but less performance, so have to choose which hit is worse.
nah, that applies to many mid to high range laptops as well, eg. 14" thinkpads has had 1 soldered 1 removable dimm for years now.
For anything with more than one socket, you just plug in a second cable into a free socket, once the phases are synced up unplug the extension cord or cut the socket free.
For singular sockets straight into the wall, unscrew, clip on connectors with a V shaped knife and same as above.
Although when I was working we usually would take images onsite before even considering moving the devices.
It's definitely not bullet proof but I've set up my laptop to lock when Ethernet or the monitor is unplugged or any new USB device is plugged in. This stops most but not all live imaging.
It's not as though you tampered with the device after the confiscation. Intent is also hard to prove on such a thing. I didn't want my dimms to fall out at any time if the machine was dropped is pretty good plausible deniability.
Basically the internal battery is used as a buffer for power peaks. So the laptop can use more than the adaptor can provide for a short time. If it didn't throttle it would become unstable.
Also, if you are being targeted this hard you need to have something for when you are left in front of your laptop and a gun is put to your head. Or the attackers threaten the welfare of your family.
Yeah, this wouldn't have saved the admin of Alphabay, a now defunct darknet market. The FBI staged a car crash outside his house so when he'd come out to see what was going on they could arrest him and likely get to his laptop while it was unlocked. Then again, he really shouldn't have left his computer unlocked.
Related video is all I could find about this: https://www.youtube.com/watch?v=HXrXD1M6kXk
Surely there were a bunch of other options to consider before "let's stage a car crash"?
This article on Vice[0] seems to confirm it:
> Phirippidis told the audience that the bureau managed to corner Cazes and arrest him while he was still logged in as the admin of AlphaBay by ramming a car through the front gate of his home in Thailand.
[0] https://www.vice.com/en/article/59wwxx/fbi-airs-alexandre-ca...
The part abour crashing it through his front gate makes it more likely he'll respond which makes more sense.
Eight years of false imprisonment sounds like lawsuit city, to me.
...and expose the contents of the screen to any camera with a good zoom? And the passwords you type? Not good.
It's just an very overpriced thing that can protect you from a thief and not the FBI.
I understand the first part of my idea is dead in the water, we hardly get additional ports, let alone a slot hardly anyone will use. But I would like to see a way to retrofit a KSS on a laptop.
This device would had made a difference in the initial library-swipe confrontation, but would had definitely not kept Ross out of jail by any means (even that day)
He would had always of went to prison, even if they didn't get his HDD unencrypted. He used his personal email to promote his Mycology website, had the Obama administration to contend with, and was the first to sail westward.
Free Ross (The Department of Parks and Recreation)
They could still yank you. It would pretty hard for you to execute the self destruct sequence after the undercover fbi agent knocked you over from your chair.
1. https://www.usenix.org/system/files/1401_08-12_mickens.pdf
Sure it is not _super_ secure but being able to leave my laptop for 1 minute in a public place is nice. Instead I have to put the macbook in my backpack and take it with me.
BusKill can trigger your laptop to lock, shutdown, or self-destruct if it's physically separated from you.
I understand lock and shutdown but self-destruct? Really? Your laptop/data is one bump away from destroying itself?Do they allow truly offline backup and restore?
I switched away to an Android, so this isn't something I'm taking advantage of personally.
iCloud Backups are not "unencrypted backups"
https://support.apple.com/en-us/HT202303
I do wish they would bump the backups to "end-to-end encryption" category though, at least as an option.
Also, it would make sense to include a simple proof-of-intentionality system, like the old Nokia keypad unlock feature to prevent pocket dials. The phone could prompt you to type a displayed 4 digit code before typing your actual PIN attempt, for example.
One thing of note here, don't put LUKS header on any kind of flash (like SSD) or SMR HDD.
Why not?
If the system is interrupted after data is deleted there is a good chance you can still get it back.
On a normal HDD you still have to wipe the data (ie. physically overwrite it half a dozen times). But this is not possible to execute reliably on SSD or drive-managed SMR HDD.
[0]: https://wiki.archlinux.org/title/Securely_wipe_disk#Flash_me...
Reversibility is not a feature of destruction, lexically-speaking. A better description might be "locked".
More importantly in this case: if you are able to reverse it, you can be compelled to reverse it. This is no different than having a secret passphrase.
An interesting way of strengthening such a system is to split the recovery code between multiple people in multiple jurisdictions. Convincing them to hand over their piece of the key could require various levels of proof-of-free-will, ranging from "Hey, I need those numbers on that piece of paper I gave you" (asked on a video call, in a public park) to "I've booked a flight and I'll meet you at the agreed place next Monday at the standard time".
These approaches can be combined with a protocol of "If I use the duress phrase, then give me a fake key and then send a message to the other members of the group / the public / the media that I've been compromised". Of course this sort of system assumes you are part of a wider organisation or at least have friends you can trust to implement all this opsec securely, without adding to your risk profile, but for some people this will be viable.
This script itself was actually an easter-egg in the explainer video at 50 seconds :P
* https://youtu.be/S3LtLyuaBvI?t=46
We're just finishing a very detailed write-up on the "LUKS Header Shredder," and we'll be publishing it in ~2 weeks. You can subscribe to our newsletter on our website (buskill.in) or crowdsupply.com for updates :)
If you've already planned for the possibility of self-destruct, a laptop can be a very transient device. Maybe the only important thing on the laptop is your bitcoin wallet key, but you also have a physical copy stashed in a lockbox somewhere. Maybe you're only using the laptop for its browser, and you've memorized all the passwords you need to enter.
Someone snatching the laptop might be doing so to grab the one keyphrase that you logged in with. The actual device is unimportant to you, then.
As described on the crowdsupply page, the cross-platform GUI app (as opposed to the udev rule for which BusKill was originally designed) currently only has the "lock screen" trigger. In the future, we'll add a "shutdown" trigger.
While we have developed a "LUKS Header Shredder" trigger (what we call "self-destruct" trigger -- as it renders your FDE disk's data permanently inaccessible), we will never ship that directly with the app by default.
There's definitely a use-case for it, but most people probably don't want it. For those that do, we're publishing a guide on how to use the "LUKS Header Shredder" script (tested on Ubuntu and QubesOS) in 2 weeks. For updates, you can subscribe to the website's RSS feed, our website's newsletter (buskill.in), or the crowdsupply.com newsletter.
It wouldn't surprise me if Apple imports more emergency wipe features into macOS from iOS.
So the premise is that if using kill-switches becomes common among criminals, we can expect suspects in computer crime cases to be apprehended in ways such as unexpectedly being hit in the head with blunt force trauma, gassed with anesthesics or similar violence. Seems like it would challenge some pretty central democratic principles!
No knock raids, which are inherently violent, to "preserve evidence" and reduce the risk to LEO happen about 20000 times a year in the US.
> reduce the risk to LEO
I remember reading news about an american who killed an officer who entered without knocking. He was not convicted, it was ruled self-defense.
Besides the USA is not Al Qaida, there is a chance they would respect the Geneva convention: https://ccrjustice.org/home/get-involved/tools-resources/fac...
I just don't think it's going to prevent a Silk Road incident and could make it worse for the suspect.
The idea that you could completely immobilize someone at a public library so rapidly and without their awareness that they could not even move their arm 20 cm or so during a struggle seems ludicrous to me. Particularly as the kind of person who would buy this device would be setting themselves up with their back to the wall to prevent captures from behind.
I am fairly strong and have wrestled and grappled for over a decade, and I would not put my faith in an operation that required me (even with another agent) to completely immobilize even a weak person enough that I could guarantee they could not trigger this.
This takes a flick of a finger to trigger, or moving your arm a small distance away from the laptop.
Well, they did — and without even touching him.
[0] https://www.businessinsider.com/ross-ulbricht-will-be-senten...
This device is indeed clearly designed for a no-knock raid situation, or other surprise grab.
I'm simply saying that, if you're attached to your laptop by a 50cm cable, which of you separate your arm further than that from will lock your computer, it will be very difficult for the agents to guarantee you won't be able to lock your computer.
First, intentionally hiding or destroying evidence of a crime is itself a crime (self-incrimination is restricted only to verbal statements) of which you can be convicted even if you're not guilty of the original accusation;
Second, destroying evidence in this manner enables the legal concept of 'adverse inference' where essentially the judge can require the jury to assume that the destroyed evidence did contain whatever prosecution wanted to find there, and convict you based on that.
This is getting into the security question of what your threat model is. If you're seriously expecting a nation-state intelligence agency to be after your laptop, I'd really, really recommend not having anything on your laptop because unless you've got your own security team they're going to find some way to get it and will observe you to see if you're using something like a killswitch first.
[1] List of canaries: https://www.buskill.in/tag/canary/ [2] https://www.buskill.in/canary-002/
The canary-002 says:
Status: All good
Release: 2021-06-13
Period: 2021-06-01 to 2021-12-31
Expiry: 2022-01-31
EDIT: Oh, the issue is just that they failed to update the wording of: "We plan to publish the next of these canary statements in the month of June 2021." Looks like a copy from canary-001.I'll try to remember to update the verbiage of that lower line to reference the top line to prevent this from happening again in the future.
Thanks for pointing it out!
No, you should not be concerned. The latest canary #002 literally says:
Period: 2021-06-01 to 2021-12-31
Expiry: 2022-01-31
Source: https://www.buskill.in/canary-002/What matters is what's cryptographically signed. Did I make a mistake somewhere else?
The next canary will be posted before 2022-01-31.
They will bridge the outlet, and take the outlet, AC adapter, and everything connected, without the AC adapter even reading a voltage drop.
Probably wouldn't work the same in Euro countries which have other plug types.
The agents arresting him did in such a way that they prevented him from touching his laptop (by creating a diversion), because they were feared that such a protection might exist.
The man was running a multi-million dollar drug marketplace in a public library.
A public library is even worse for that purpose, because of security cameras and witnesses.
But that's literally the scenario this physical-separation killswitch was designed for.
He wouldn't have had to touch his laptop to trigger this. Quite the opposite.
It has no remote part, it doesn't matter how far the user is.
If you're thinking about attaching the trigger to your hand with a lanyard, the agents could easily hold your hand in place, cut the lanyard, ...
I don't understand why people always assume the FBI is brain-dead and could not use countermeasures against devices such as this if they become wide spread.
If the user is attached to the switch and moves more than 50 cm or so from their laptop, the switch is triggered.
EWX_FORCEIFHUNG 0x00000010
Forces processes to terminate if they do not respond to the WM_QUERYENDSESSION or WM_ENDSESSION message within the timeout interval. For more information, see the Remarks.
If the EWX_FORCEIFHUNG value is specified, the system forces hung applications to close and does not display the dialog box.
You'd have to watch out that you don't let the system store a memory dump, of course, that'd be the exact opposite of what you want.
The way we implemented the self-destruct (currently only available in Linux), it locks the screen before attempting to wipe the LUKS Header. I imagine we'll do something similar in Windows, so the worst-case would be the soft shutdown hangs but at-least the screen is locked immediately.
Hopefully we can force an immediate, uninterruptible, hard-shutdown in Windows, too.
DPR is Dread Pirate Roberts from Silk Road.
“What unfolded next was a piece of improvisational theater. At 3:14 pm, DPR was typing away, writing to Cirrus. Just then, a middle-aged woman and man came toward Ross, ambling along in the kind of semihomeless shuffle you might often see in a San Francisco library. “Fuck you!” the woman yelled when they were directly behind Ross’ chair. As if they were a deranged couple about to fight, the man grabbed the woman by the collar and raised his fist.
Ross turned around for just a second, during which a hand reached across the table and grasped Ross’ Samsung. The petite, unassuming young Asian woman sitting across from Ross this whole time was, to everyone’s surprise, also an FBI agent. Ross lunged for his machine, a hair too late, as she turned like a quarterback for a quick handoff to Kiernan, who appeared out of nowhere—as instructed—to get the laptop. It took less than 10 seconds. From afar, Tarbell was astonished by the elegant choreography of the whole thing. It looked like the police procedural version of a tight jazz quartet.”
It's just as impractical as money belts, key chain alarms, Tiles(tm)
I mean, too impractical for me, but there is definitely a market for it.
while { if(!monitored_device.plugged) { setComputerOnFire() } }
It must exist somewhere. And for the magnetic gimmick, any magnetic usb (which, btw, are actually pretty useful) cable from amazon would do the trick.
The problem is that there are no USB-A magnetic breakaways available on Amazon. If there were, then I wouldn't have launched this campaign!
Actually, Amazon did have USB-A magnetic breakaway components before, but they went EOL and sold-out when I first published my DIY article on how to build-your-own-BusKill-cable last year.
* https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-k...
The reason I started making my own was a response to all the folks that asked me how they could get a USB-A BusKill cable since they sold-out (and they also were never available in Europe -- now they are!).
You could make one for yourself cheaper, though, if you have the know-how.
Though a basic face detection-based screen lock could be quite more useful and cheaper, at the cost of increased battery consumption.
It's the same USB magnetic cable that you can buy in many shops for $2.
> but what is comically impractical about this?
That you have to carry such contraption around and find a place to tie it to.
If you have to spend more than $30 for a custom device you can detect if a laptop is being moved away from a table in many better ways.
> That you have to carry such contraption around and find a place to tie it to.
If you're the type of person who uses a laptop lock, I could see something like this being a welcome enhancement. But in that case it would be most practical if it were built into the lock itself.
The $59 price still includes worldwide shipping.
> That you have to carry such contraption around and find a place to tie it to.
I mean you are already carrying a laptop, and probably a charger with cables, so carrying a magnetic cable doesn't seem a big stretch. You would put it to the same bag with your other laptop-related accesories.
It is also quite popular to wear pants with belt loops, which would seem suitable for tying this one. Granted dresses and skirts have these less commonly; even then perhaps one could use a belt. For sportswear I don't have a good suggestion.
I notice you refer to these "better ways" yet you don't enumerate any. At least I wouldn't consider accelerometer and radio-based solutions proper alternatives to this (unless using proper latency-based distance measurement, I wonder if this truly can be implemented for less than $30). The camera solution I proposed might be realistic one, but it eats battery.
In all seriousness though, I can see how this product could be useful to someone in very specific circumstances and is also an interesting idea.
The current app is limited to locking your screen. Future releases will include soft/hard shutdown. So, by default, your clumsiness would just mean you have to type your password to unlock your screen. Not a big compromise :)
We do have a "LUKS Header Shredder" trigger (which we call self-destruct as it renders all the data on the FDE disk useless), but we (intentionally) don't include it by default and raise the barrier of entry because of the risk of data loss.
We'll be publishing a more detailed write-up on the LUKS Header Shredder in 2 weeks. You can subscribe for updates on our website (buskill.in) or the campaign directly (crowdsupply.com)
This does the same thing, but you can use any USB hardware as the entry/remove trigger. And you can script it to whatever you want.
But... that doesn't sell unneeded hardware.
usbkill triggers when a device is inserted. BusKill triggers when a device is removed. It's an important difference.
I actually didn't start BusKill to sell devices. It was originally a DIY project. The problem is that after I published the article describing how to make it, the one manufacturer of USB-A magnetic breakaways EOL'd their product and it sold-out (my & Hacker New's fault). It also wasn't for sale outside the US.
This campaign is a response to people who asked me how they could build their own USB-A cable with a magnetic breakaway. Before they couldn't. Now they can.
Of course, you can still build your own. We encourage it. All our designs are open-source.
* https://docs.buskill.in/buskill-app/en/stable/hardware_dev/i...
It would be nice to have a BT dongle that could react to the distance to the owner and to being unplugged.
> But bluetooth...
> Using a radio-based Dead Man Switch introduces complexity, delays, and an increased vector of attack. BusKill is a simple hardware kill cord and is therefore more secure than any wireless solution.
* https://www.crowdsupply.com/alt-shift/buskill
When I designed BusKill, I intentionally avoided wireless solutions.
BusKill is designed for situations where the risk is extremely high, and you'll find that the radio-based solutions aren't very secure. They're faulty and have huge surface areas of attack.
Or you could always just carry an enormously strong electromagnet on you :-)
Very keen on picking one of these up purely for the novelty, price isn't too bad. Although I think the demographic who would and could actually benefit from a failsafe for having their laptop physically yanked away from them is quite small.
Keep an eye on the number of journalists who are murdered in oppressive regimes. It's very sad :'(
No contact information (as in "who runs this?") is provided on the site. Privacy policy is not GDPR compliant (no contact information provided), no names, nothing.
This might be fine for a personal blog, but for doing business this is (at least for me) a no-go.
Though a couple of relevant regulations state this should not be done, and no site is going to send away a potential customer by saying “we don't want to follow your laws/regulations so can't do business with you” when they can instead just get away with just ignoring, or in the case of sites run from elsewhere in the world claim to have no no knowledge of, those regulations.
Many local US-based TV news/newspaper sites do this albeit with a slightly more opaque message. And customer still mostly fits because these sites are ad-supported (usually with a mix of local/non-local ads.
Just a website with no contact information, no names, adresses, business registration, whatever?
As far as I can see, this could very likely be a scam of some sort, because anybody who's into doing "real", honest, business would be fine with giving his name and address.
I’d feel fine deciding if I feel fine.
That’s also why I have a credit card. I can get scammed and not be out $100.
I'm not sure it's even possible to have a valid contract with an unknown party...
The provided information on this website is not enough to do legally binding business (at least in some parts of Europe, it's not only Germany).
As far as I understand German law is very flexible about what constitutes a valid legally binding contract.
§312f for example defines that customers must receive "a copy of a contractual document signed by the contracting parties in such a way that their identity is identifiable" (translated via DeepL).
A simple mail address is not an identity in German law, especially not when doing business with B2C as you always have a 14 day period to cancel your order (except for downloads and various, special products).
edit: If you want to cancel, you must be able to do so via (offline) mail, too.
* https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-k...
The above article front-paged on Hacker News, and I got a lot of people asking me how they could buy one and use it in on Windows and MacOS. Over the past year, many people have contributed in porting it to those platforms (I originally just designed it for myself, and I use Linux).
The BusKill project is not owned by me. All our work is open-source, and it's owned by the community. As such, I don't put just my name on it because it's not just my work. But if you dig around, you do see my name pop-up in a few places.
The list of contributors can be found on our documentation's "Attribution" section.
* https://docs.buskill.in/buskill-app/en/stable/attribution.ht...
The main website is mostly just a landing page, blog, and a store so people can buy with cryptocurrencies and Tor since CrowdSupply doesn't run an Onion Service and doesn't accept crypto payments.
Not everyone who has contributed to the BusKill project is still active, but some of us are. You can find our names & photos at the bottom of the Crowd Supply campaign page:
* https://www.crowdsupply.com/alt-shift/buskill
Contact information is provided on the website. There's a link to it in the Footer* and on the GitHub page. Not sure how I can make that more clear:
> Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:
> (a) the identity and the contact details of the controller and, where applicable, of the controller’s representative;
Usually, these contact details are in the privacy policy.
It's certainly unusual for a website to omit this, and in most cases I wouldn't buy from a site where it's missing. In this particular case, maybe it's less strange.
However, I still wouldn't order without knowing from where the package will be sent. Something from Estonia arrives here without any import taxes, something from outside the EU can do (the CrowdSupply site says they handle VAT), but can also attract high processing fees.
https://gdpr-info.eu/art-13-gdpr/
(Note I'm not interested in buying a BusKill; I'm just procrastinating.)
It certainly added cost to the final product, but I figured it was more fair & transparent to everyone to set shipping to $0 internationally (I hate it when you finally make it to payment and only then learn shipping is $20 :/).
With the T2, this still exists, but you need to wait more seconds and use a 2step combination. This is a pain because you can no longer use it to do an emergency shutdown.
I vaguely remember there being special hard drives with an "acid release" tab for rapid physical destruction. The military being a prime consumer. For laptops, I'm thinking a Thermite kill switch would be effective.
Total ripoff.
* https://www.crowdsupply.com/alt-shift/buskill
When I designed BusKill, I intentionally avoided wireless solutions.
BusKill is designed for situations where the risk is extremely high, and you'll find that the radio-based solutions aren't very secure. They're faulty and have huge surface areas of attack.
Another idea is to use voice recognition.
I'm careful. I'm using a laptop that has this kill switch. I only keep my work on this laptop, it's so sensitive.
The bad guy gets a whiff I'm digging around him. He sends armed thugs to my lair. They enter, so I pop the kill switch. "Where is the data?!", they ask me. "I don't know what you're talking about!" They beat me down, then one thug says to the other: "Hey comrade, look, maybe it's all on this laptop?" — "Let's see". The laptop doesn't boot. They turn to me: "Funny how this laptop of yours doesn't even boot, why would you have a non-working toy?" I play dumb, they train their guns on my head. "Okay, okay," I say, "the data on this laptop has self-destructed, you're not getting it, no one is getting it!" — "Really?" — "Really!" — "It's good, motherfucker," says the thug and double-taps me in the head.
In case of a corrupt government, if they wanted to lock you up, they wouldn't strictly need any evidence at all. Having a gizmo that can potentially destroy evidence is a bonus. Otherwise, they will throw you behind the bars for 18 years for jaywalking. If you had a controversial businessman and his thugs after you, destroying the evidence only means they wouldn't have to destroy it themselves after having killed you.
In any case, if you're working on sensitive stuff and you want to pretend you're writing some innocent poetry, I don't think any kind of jamesbondian device would help you look inconspicuous.
For plausible deniability, you need a second account on the machine that has all your poetry in. Then, when the thugs (or border guards) tell you to log into your laptop, you use the other username and password and say "Feel free to read all this poetry. I'm particularly proud of the one called 'My government isn't corrupt at all'."
Also, in this scenario, you should probably store your raw information (with the names of innocents redacted) in a public cloud somewhere outside your jurisdiction, encrypted, and have a time-based dead man's switch (hosted somewhere else) which sends an email to your colleagues containing the URL and decryption key.
But what about your sources? In this situation (if you actually can't remember the anonymous email address of your source), it's not your life that's being saved -- it's the identity and the life of the whistleblower.
You can add any number of security layers, but you should always presume someone might get their hands onto whatever you’re working on at the moment in cleartext and you want any damage to be minimal.
However, if you are under physical threat then this is still useful because 1) you can protect witnesses and others and 2) you can make forwarding this information to remote sources part of the self-destruct.
That is, "Sorry, I no longer have the data - the laptop self-destructed. The data and my name and location have been posted to reddit publicly or sent to a list of contacts in six countries"
The point is, they want 1) you to stop and 2) to recover the data. You can bargain for your life by setting up the actions taken should this be activated.
Would love to see a write-up with more info on how to do this :)
DIY is great. The problem is that after I published that article, everyone on Hacker News went and bought-out all the USB-A magnetic breakways on Amazon. And they literally never re-stocked (I found out later it was EOL from the manufacture).
The reason I launched this crowdfunding campaign was to put these USB-A magnetic breakaway cables back on the market so people could build their own again (and to sell the whole kit, to lower the barrier of entry to non-techie journalists).
* https://docs.buskill.in/buskill-app/en/stable/hardware_dev/i...
The website also runs fine over Tor with javascript disabled. And I spent a lot of time modifying the theme to remove as much third party content (eg google fonts) as I could.
We don't expect blind trust, but we do try to be totally transparent to earn it.
* https://docs.buskill.in/buskill-app/en/stable/hardware_dev/i...
The reason this campaign is limited to USB-A is because there's no USB-A magnetic breakaway cables on the market.
Please support the campaign to make it available to folks who need USB-A BusKill cables.
–Shutdown has been stop, would you like to keep those Chrome Tabs?
And to think now, the same people are pushing the narrative how PGP is bad.
BusKill does not ship with destructive triggers. The current app is limited to locking your screen. Future releases will include soft/hard shutdown.
We do have a "LUKS Header Shredder" trigger (which we call self-destruct as it renders all the data on the FDE disk useless), but we (intentionally) don't include it by default and raise the barrier of entry because of the risk of data loss.
We'll be publishing a more detailed write-up on the LUKS Header Shredder in 2 weeks. You can subscribe for updates on our website (buskill.in) or the campaign directly (crowdsupply.com)
Also, while I recognize there are limits in PGP, I encourage it and actively train journalists and activists on how to use it (though I do prefer messaging solutions that make e2ee required and use PFS like Signal, Threema, Wire, etc).
* https://youtu.be/S3LtLyuaBvI?t=26
I didn't know snowmobiles had this too! I guess it's my bias since it never snows where I'm from :D
I bet they'd go crazy if someone accused them of this being designed for illegal activities
I mean it may, hypothetically, be used to hide illegal activities, but if you go that way you go down the slippery slope and will be advocating for weakening or backdooring encryption just in case it's used for illegal activites.
It might also be useful for whistleblowers, although I doubt that there is any advantages over strong file and disk encryption.