Protecting a Laptop from Simple and Sophisticated Attacks
grepular.com
grepular.com
pmset -a destroyfvkeyonstandby 1
I use pmset -a destroyfvkeyonstandby 1 hibernatemode 25
to always hibernate the laptop instead of suspending. The FileVault key is erased and the memory is dumped to disk encrypted.http://support.apple.com/kb/HT1352
edit: added Apple link.
If its good enough for the NSA it's almost good enough for everyone else /tinfoilhatting
Much of the security-related technologies, especially FileVault, have been either seen significant changes or been replaced. As far as I can tell, it was last updated during the 10.4 days.
Aside from the general secure computing tips, it's a historical document.
As Timo Juhani Lindfors points out in the comments,
> The "xhost +local:mike.firefox" will let your mike.firefox user inject keystrokes to your X. This allows it to trivially escape the jail. I have personally been investigating solutions to this problem. The ones that I have found are: [qubes and xpra/vnc].
Finally, giving Firefox the ability to read audio is not ideal - it's probably enough to get a fairly decent keylogger going, for instance. (Persons and keyboards have characteristic sounds for keys/phrases.)
Running it under a different user id means that if it is compromised, there is an extra step required before it can access files. A step which could lead to the compromise being noticed.
This is one of the reasons why its ok to be scared of "crypto stuff"... leave it to pros like him that hand you a readily configured system like this, which sounds, after all is said and done, pretty userfriendly for the amount of security it provides.
About 11 months ago, my MacBook Pro was stolen from my house. I didn't keep a password on it as any of my secure files were encrypted, so the theif did use it for a bit. I had installed Prey, similar to this author, and a keylogger on the computer, so I was able to collect copius amounts of information about the theif (name, address, picture, phone number, email, usernames, passwords, etc.). I had more than enough info to catch the theif including the address of where the computer was being kept. I relayed everything I had to the police officer in charge of my case. Basically, it was an open/shut case, he just need to go and get it. To make a long story short, he did nothing. He never pursued the case at all and I never got my computer back.
After a few months of inaction by the police, I did the best thing I could and ssh'd into the computer and rm -rf'd it so the theif would have to reinstall the OS and I wouldn't have watch someone else use my computer. I would have retrieved the computer myself, but I was very aware of the theif's criminal record which mostly included assault, unlawful possesion of a firearm, attempted murder, etc.
tl;dr - If your computer is stolen there is little to no hope for retrieval, so do everything possible to prevent its theft.
The most common attack vectors are not super spies silently breaking into your home or office and attacking your boot loader. Far, far more frequently, the culprit is operating system and non-OS application vulnerabilities. Remote root exploits are obviously the most severe, but even information leaks, access gained without privilege escalation, insufficient transport layer security and others can relatively easily compromise the data that is being so thoroughly protected by complex security measures. The important thing to understand is that these attacks run while the computer is running, not against a cold hard disk. Military grade encryption would not protect against these threats.
Again, I would always say that the more security you can throw on a system without negatively impacting user experience, the better; that said, make sure to install malicious host detection software, use an IDS, employ access control lists, and more than anything, make sure you're checking security advisories and keeping your patch levels up to date. In my professional experience, the biggest security problems are caused by people using "very stable" software who don't want or see the need to update.
Anyway, I'm not trying to bash the article at all--I thought it was a great read--but while we're on the subject of security, it's better to protect against common threats than against a state-sponsored intelligence agency trying to steal your text files.
A couple years ago some Cisco researchers infiltrated a botnet and got to interview the operator. They asked him what vulnerabilities he uses to grow his network, and he said none:
http://www.cisco.com/web/about/security/intelligence/bots.ht...
Instead he spams instant messaging networks with "check out this cool software: [link]", and he could count on 1% doing it.
This is the sort of thing my parents and grandparents fall for. Combine it with social networks and the message appears to come from a trusted person.
For this reason I'm glad to see the arrival of curated app stores, despite their many drawbacks. For regular users I think it will make it harder to be tricked into voluntarily installing malware. But I don't know how significant this problem is compared to not staying patched.
That's about it. I like telling the people I know who work in security and watching them get a mix of pity and shame in their eyes.
You can nest the volumes. So give attacker A-->B-->C instead of A-->D-->E Also, there is no way of proving the existence of a hidden volume. It basically makes the Rubberhose attack unreliable as an attack vector. That doesn't mean some poor soul won't be beaten again, it just means that the folks doing the beating aren't so sure this $5 wrench is a decent attack vector.
Doing this would protect against the scenario where he happens to leave a root terminal open and the maid copies his /etc/shadow to a usb drive and gives it to some government agent to crack... well good luck to them.
I've just recently been able to stop having any plaintext credentials on my drive, though it takes a bit of work in some security-naive programs like s3cmd: https://github.com/technomancy/dotfiles/commit/da64e1c390421...
PS - We are hiring! Especially looking for experienced Linux kernel developers.
Does anyone know of a simple step-by-step guide for doing this? I tried once in the past but got stuck (I forget where) and gave up instead used a third party service like StrongVPN which i'm not too happy with.
I would think it's a common enough use-case that maybe there's a repo I could clone or something to make it super-simple.
http://web.mit.edu/press/2012/thwarting-eavesdropping-data.h...
Edit: added link
Also, does anyone know what he does that the security of his laptop merits this level of care?
For most people, just having an encrypted drive is enough, since their data probably isn't valuable enough for people to go out of their way to steal it. You are mostly trying to protect your data from ordinary thieves.
1. Why not find some permanently-read-only media for the boot drive and then not have to be so paranoid about its physical integrity?
2. Why not leverage the PGP smart card for more things like signin via PAM, etc?
3. Will Wayland help keep processes isolated from an eavesdropping perspective? My understanding is that, worse than firefox having access to your user files, that any X window can read/write from other X windows?
As for the PGP smartcard, I've posted a comment on the blog that it could hold the private key used for decrypting the keyfile for the Full-Disk Encryption.
tboot is a version of grub modified to perform a TPM-measured launch of the OS. It's not sufficient by itself to do what you want, but you could build on that by, say, sealing a volume encryption key under that measurement, such that if the boot loader is modified, virtualized, etc., it won't be able to decrypt the volume. (Or less aggressively, sealing a user-secret that is displayed at the grub-menu, allowing you to verify the above, but not completely hosing you if the measurement changes unexpectedly due to a software upgrade etc.)
tboot as described above requires your system (CPU & chipset dependencies above and beyond the TPM) to support Intel's "Trusted Execution Technology". See, e.g., http://ark.intel.com/search/advanced/?s=t&TXT=true
In either case, you end up with a record (cryptographic hash chain) of what kernel + initrd + config options in some of the TPM's PCRs (Platform Configuration Registers).
I'm not aware of any existing software to protect your FDE (full disk encryption) key by "sealing" (a TPM operation) under those PCRs (i.e., decryption impossible unless they match) and unsealing at boot time, but many of the tricky components already exist as open-source projects. See also: http://trustedjava.sourceforge.net/