A dead man's switch for your computer?
blog.viktorpetersson.com
blog.viktorpetersson.com
It's unwise to use your phone for this purpose, because a phone and laptop might both be swiped if you're not holding on to both. This has happened to folks at cafes or on mass transit in the Bay Area.
Would make for a pretty good DMS; being deceiving with a battery attached and the OS reporting a full charge.
I wonder if there's a way to modify the mainboard (knife a lead or something) to be incapable of using the battery while still charging and the OS still being able to get reporting data.
Why go the hardware route? The AC adapter state is reported to the operating system; for instance, KDE on my laptop plays a sound when a blackout cuts the power to the AC adapter. It should be simple to have something else monitor the power state and tell logind to lock all screens on AC power loss, or even force a shutdown if you're paranoid.
Not that it would help much; there are devices which can keep the AC power on while a computer is unplugged and transported, even for desktops (which have no internal battery). Nothing prevents these devices from also being used on laptops.
Still capable of being worked around, but looking into that may help identify how to best implement a dead man's switch.
A 'vigilance control' device would work as intended in these cases - a message is issued to the user (possibly via covert means), and failure to respond locks the device:
http://en.wikipedia.org/wiki/Dead_man%27s_switch#Vigilance_c...
Sure over time their methods will evolve but ask Ross if he'd rather have had a DMS or not. It'd be unequivocally yes.
If your point is 'if you're a big enough target, you're pretty much fucked whatever you do given enough time' then yes that's probably true, too.
Let's assume that /dev/sdb1 is the LUKS volume. First backup the LUKS header: "cryptsetup -v luksHeaderBackup --header-backup-file=/tmp/LUKS-header /dev/sdb1". Then encrypt (gpg -c) the LUKS-header, and anonymously stash a few copies online. This is the weak point. You must remember where at least one of them is, and also remember the passphrase.
When sensors fail, swatd runs "head -c 1052672 /dev/urandom > /dev/sdb1; sync; shutdown -P now".
To recover, you would just boot into initramfs, restore the LUKS header, and reboot.
head -c 1052672 /dev/urandom > /dev/sdb1; xinput --disable 9; xinput --disable 10; xset dpms force off; sync; echo o > /proc/sysrq-trigger
Of course, I have no use for such a thing, so I would never waste my time implementing it...
Another thought, what about a little coin-sized watch battery device that does bluetooth low-energy. Press a button it locks your computer (or triple click wipes something, etc).
I think a system would need to highly tend towards false positives, giving you a short ~5 second grace period to perform some positive challenge that things are OK.
And if this means that every day you end up accidentally having to reboot and start up Tor, well small price for physical security. But really, you should be far more focused on getting your online opsec right so you don't have to worry about thugs. If they're physically grabbing you it's very likely game over.
One countermeasure would be to find people and pay them anonymously to look like you. That is, proxy through their laptop, maybe even have them do some lightweight writing or chatting. Use their life details to leak things, like about weather or other local goings on. Essentially using them as a canary. If they get tackled, you know it's time to burn everything and hide.
(i.e. you have a lanyard with a magsafe-like connector with two pins. There's a resistance wire that runs inside the lanyard from the connector, up through the loop, and back to the connector. The computer checks that the resistance remains the same.)
If you want to get fancy, you can embed a RC network in the lanyard and have the computer sweep frequencies measuring reactance.
Add in the always-on voice recognition that some Android phones have, and have the key wipe itself as soon as it hears "Freeze... FBI".
A few years ago there were companies that did this for most operating systems, and fairly inexpensively too, but I'm having trouble finding them now.
[1] http://en.wikipedia.org/wiki/Contactless_smart_card#Security
If you're up against an enemy capable of realizing ahead of time that you've RFID-protected your device, and capable of cloning your RFID tag without your knowledge, then you're probably screwed no matter what you do.
https://github.com/kristoffer-marshall/XScreensaver-RFID-Unl...
Anyone who may be logged on to multiple TTYs should prefer `vlock -an` over `xscreensaver-command --lock`.
Less conspicuous, and no strings to cut.
I.e. instead of comp -> wireless -> device, you go comp -> extender <comp> -> extender <device> -> device -> extender <device> -> extender <comp> -> comp.
However, that would only be effective against a petty thief and not against a forensic team. In that case you'd probable want to additionally flush the filesystems (if you care about data integrity in case of a false positive), overwrite the encryption keys in memory (maybe on disk as well, but then there's no coming back without a backup) and shut down. I wonder if the init scripts prompting for the password, cryptsetup and the LUKS subsystem have been designed to always overwrite copies of the entered password and decrypted keys ASAP.
Based on the testimony everything was encoded from the same one time pad so to speak. That kinda' misses the point of one time pads.
Anyway enough thinking like a criminal or a spy for one day.
If there are any Apple product developers listening, I'll definitely buy the next iPhone if part of its feature set is that as long as the phone is on and in my pocket, I never have to type in a password to unlock my computer(s). It would be even better if that feature was extended to developers so any developer could use the fact that my phone is in close proximity to my computer as grounds for successful authentication.
But I have no idea how practical is this.
Looking at conventional hard drives we see pretty strong magnets a few CM away from the platters so you'd need something freaking huge to wipe the drives passing theough a doorway.
As to practically It seems quite unfeasible. First of all since magnetic forces fall off according to the inverse square law, you're going to need a seriously large magnet to for it work at say 1 meters distance or so. You're basically going to have seriously retrofit your entire house, and it's going to be very hard to hide. Secondly and more importantly even the most powerful commercial hard drive degaussers require that the drive be in contact with the magnet for up to 10 seconds to guarantee that all the data is erased, so someone just walking through a door isn't going to be in the field for anywhere near enough time.
Anyway, the time issue remains.
...but that basic idea did give me another one: electromagnets on a separate circuit inside the drive enclosure or laptop body.
Fail to pass a security check on schedule and the circuit is engaged, destroying the HDD.
I'm no hardware wizz although I did make a motor out of a nail and copper wire once.
The problem then is false positives. Only 1 mistake and kablooie.
And right next to the magnetic coil, behind a small blast shield, was an old PC... an early 90s beige box looking like a 486 or early pentium, controlling some measurement equipment.
We asked how that worked, and whether there are any problems with "EMP" with the hardware or the hard disk. The answer was, no, the PC works fine. But you have to be extremely careful not to leave any screws or screwdrivers around, because "above xxx T/m field gradient, iron starts to fly", as evidenced by lots of scratches on the concrete.
edit: i found it:
http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/
First security in layers is the best option.
1. USB HID watcher that shuts down system when plugged in. If we use a mouse, we can exclude that. But any other HID, shutdown -r now.
2. Fingerprint scanner. It's not foolproof, but does make duplicating fingerprints a pain if you dont cooperate. And jailcells usually have concrete. No more fingerprints :)
3. Most laptops have webcams built in. I'm looking in OpenCV FaceRecognizer class to see how it works, and if it's viable for fingerprinting a user. We could also do other checks, like 3d facial recognition over multiple video frames.
4. We could also potentially use the accelerometer built in laptops. When others have made a sshd knock script, we could provide a knock script to the physical device.
5. Lock on ac power removal. Simple and effective, unless the enemy has AC separation tools.
There's a few ideas. And of course, mix in live filesystems in ram, or virtualbox funniness, and you're in business.