Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security Data Storage Encryption

USBKill Transforms a Thumb Drive Into an "Anti-Forensic" Device 288

Orome1 writes with a snippet from a report at net-security.org; a hacker going by Hephaestos has shared with the world a Python script that, when put on an USB thumb drive, turns the device in an effective kill switch for the computer to which it's plugged in. USBkill, as the programmer dubbed it, "waits for a change on your USB ports, then immediately kills your computer." The device would be useful "in case the police comes busting in, or steals your laptop from you when you are at a public library," Hephaestos explained.
This discussion has been archived. No new comments can be posted.

USBKill Transforms a Thumb Drive Into an "Anti-Forensic" Device

Comments Filter:
  • we coulda had in school
  • Doesn't TrueCrypt support full drive encryption and USB-based hardware keys for decryption? That sounds like all this "invention" does. It doesn't actually kill your computer.
    • by Orestesx ( 629343 ) on Tuesday May 05, 2015 @11:05AM (#49621631)
      This is to be used in conjunction with TrueCrypt. The summary is alluding to the arrest of the alleged founder of Silk Road at a public library. He was using a computer with full disk encryption, but they physically separated him from the laptop before he could power it off. Attach this to your wrist, and the machine will be powered off when the USB drive is removed from its port.
      • Ohhh so the drive isn't a decryption key, it's just a monitored device and the script basically runs
        shutdown /s /t 1
        a second after it noticed the USB device has been removed. Clever :D
      • Re: (Score:3, Interesting)

        Which opens you up to all kinds of high circumstantial evidence prosecution. Evidence that you may have been involved in a crime coupled with a psychotic behavior in which you put your computer data at severe risk to handle an unexpected seizure? If they have weak evidence showing your involvement in a crime, the corroborating behavior provides circumstantial evidence supporting their weak evidence; either by itself may be inadmissible.
        • by Dunbal ( 464142 ) * on Tuesday May 05, 2015 @12:03PM (#49622267)
          If they have a tactical team breaking into your house you are pretty much fucked on circumstantial evidence anyway... It might mean the difference between 5 years in prison and life in prison though. "We're sure he had 'x' on his hard drive" is a lot weaker than "we found 'x' on his hard drive"...
        • The question isn't "is this suspicious behavior," since it clearly is. The real question is, "is this suspicious behavior worse than the gigabytes of evidence that is easily collected without it?" If yes, don't bother; if no, use it.
          • Thing is, someone wiping their drive isn't evidence of a crime. At the same time, various evidence of a crime--Internet connections, behaviors, associates--isn't going to get you a conviction, at all. When you put these together, you get a different picture: we have a highly-circumstantial pattern of behavior that may or may not prove the suspect was a criminal, and the subject panicked and destroyed the thing that may have but was not certain to contain hard evidence proving that this behavior pattern

            • This doesn't prevent suspicion and it doesn't prevent your from being arrested. The police arrest you and seize your property because they think you've committed a crime - at that point, there's no convincing them that you didn't. This is about avoiding conviction or keeping highly sensitive information secret. Of course, if the information on your computer isn't highly sensitive and you aren't doing anything illegal, and you are not super paranoid about your privacy, then you probably shouldn't be using t
              • Arrest is largely a non-issue; it's conviction I'm talking about. Raising suspicion by these activities can get you a conviction.
                • by Orestesx ( 629343 ) on Tuesday May 05, 2015 @01:27PM (#49623171)
                  Maybe. But getting caught with incriminating data is almost certain to get you convicted. Think about it this way. You're a defense lawyer. Would you rather explain your defendant's suspicious behavior, or an excel spreadsheet showing how much coke he's sold this month?
          • by TheCarp ( 96830 )

            Actually there is no downside AT ALL to using it.

            In the end, the drive still exists, you still have the data. If there is nothing there to find, you can always find a way to cooperate and use the data on the drive. However, this tool lets you do that at your option rather than at theirs.

        • by mysidia ( 191772 )

          with a psychotic behavior in which you put your computer data at severe risk to handle an unexpected seizure

          Auto locking your computer is not putting your data at risk.

          There is a very legitimate concern that you might forget to lock it, and you might become the victim of identity theft if some robber pilfers your computer, when you stepped away for a bit and forgot to lock the screen.

          The concern about data theft is also a reason to use full drive encryption, Or even back the system up to an encrypted

        • It doesn't put your data at risk. It doesn't wipe the drive, it just powers off the machine.
      • by mcrbids ( 148650 )

        So then the police just cut your hand off. One more reason why biometrics isn't such a great idea.

        • by Zmobie ( 2478450 )

          Peter Gibbons once put it best: "This isn't Riyadh. You know they're not gonna saw your hands off here, alright? "

      • Attach this to your wrist, and the machine will be powered off when the USB drive is removed from its port.

        You mean attach a cord to the USB thumb drive, tie the other end to your wrist, and insert the thumb drive into your computer before using it?

        Seems like a hassle. The cord would have to be pretty short for this to work. It might be ok for temporary sessions on a laptop at the public library, but not for daily use with your home desktop (which is likely not on your desk but on the floor).

        Someone should make a wireless version. Using a USB wireless mouse with those little snub receivers you plug into the USB

        • so at home you tie it to the leg of your desk and if the door opens step on the string pulling the usb
  • by OzPeter ( 195038 ) on Tuesday May 05, 2015 @10:59AM (#49621561)

    I mean my USB hub never drops my mouse connection or anything like that. So there is no chance of a false positive.

    • by SecurityGuy ( 217807 ) on Tuesday May 05, 2015 @11:08AM (#49621673)

      No real risk, beyond that of inconvenience. All it does is shut your computer down. It's not wiping anything or physically damaging the hardware, it's just turning it off and relying on you using full disk encryption to actually protect your data.

      • Actually, if you shutdown at an important time, that could very much be a problem.

        I would personally use a better setup with a lower-level protocol. For example, you could use two GPIO pins connected together. If they disconnect for more than x milliseconds, it fails. (A direct physical connection, no protocols, no hubs.) You could use an audio cable with a dedicated sound port (pci/usb soundcards are dirt cheap) and ensure the signal doesn't terminate. You could use a serial port and send a constant stre
        • by gatkinso ( 15975 )

          It is invoking the poweroff command (shutdown on Apple), not yanking the power. Read the code.

        • Shutting down the computer even in the middle of writing is the least of your concerns when you are trying to hide information from the authorities or someone else. What you want is to avoid the system being left in a logged in state.

          Last I checked you can also reconfigured what your power button does. You can have it so it shutdowns. In some BIOS you can set it so it turns off "AT PSU" style which is an instant power off.

    • by gatkinso ( 15975 )

      I would imagine that the consequences of the information on the computer being compromised outweighs the inconvenience of an accidental shutdown.

    • by mysidia ( 191772 )
      A slight variant, would be on USB device drop/change.... immediately lock screen Beep, and system will hard power off if not unlocked within 15 seconds. Other mitigating measures might also be taken such as purging any sensitive creds from RAM; temporarily shutting off all network interfaces and unloading unnecessary drivers such as Wireless NIC, Firewire, that might present attack surface.
    • by Moof123 ( 1292134 ) on Tuesday May 05, 2015 @12:43PM (#49622711)

      That is probably a tactic to be used by the authorities. If they get a hold of the laptop and sneak in some piece of hardware to make the USB drop every now and then, the suspect will pretty soon disable it.

      Way back when I worked for a 3 letter acronym this was a pretty low tech solution often employed to circumvent alarms of all sorts. Just randomly trigger the alarm a every few hours at night and within a few days it will be turned off out of disgust or at the orders of any cops that have been dispatched the last half dozen times. Now you can waltz in and do your dirty work.

  • Too bad that's not installed by default on the two most used desktop operating systems.

    • If you don't have access to Python, I feel bad for you, I really do.

      That being said, to be more serious, it's not like you can't port the concept to any language, and any port/protocol. You could have it connected to a bluetooth watch/key/anything and if you walk too far from your computer it automatically shuts down.
    • by stooo ( 2202012 )

      Python is cross platform, you can use it on any OS.

  • by xxxJonBoyxxx ( 565205 ) on Tuesday May 05, 2015 @11:03AM (#49621605)

    Here's the source:
    https://github.com/hephaest0s/... [github.com]

    What's next - a tutorial on how to press the power button?

    • It even syncs the disks before shutting down! v_v

      Such a non-news story... omg, this this is "interesting" in so far as an odd tool that has little possible use(?)

    • Are you sure that is the final source?
      Is it possible that this is the code for validating the USB interaction and he didn't want to actually brick his computer with every test?
    • That reboots the machine! use -h at least. geez
    • She thinks she turns off her computer by pressing the power button on her monitor. she also calls the internet...AOL.

  • Deadmans Switch (Score:5, Insightful)

    by Liquidretro ( 1590189 ) on Tuesday May 05, 2015 @11:05AM (#49621625)
    So it's a deadman's switch basically.
    • Re: (Score:3, Informative)

      Comment removed based on user account deletion
      • Re:Deadmans Switch (Score:5, Informative)

        by smallfries ( 601545 ) on Tuesday May 05, 2015 @11:42AM (#49622031) Homepage

        No. A deadman' switch is an idea that has been around in analogue fail-safe systems for a long time. It is typically a device that you have to hold onto in order to keep the machine running. What you describe is one software implementation of that idea, but the GP is correct that this is another.

        • Comment removed based on user account deletion
  • Comment removed (Score:5, Interesting)

    by account_deleted ( 4530225 ) on Tuesday May 05, 2015 @11:09AM (#49621675)
    Comment removed based on user account deletion
    • by infolation ( 840436 ) on Tuesday May 05, 2015 @11:21AM (#49621787)

      Wiping the contents of your laptop, or refusing to give a password in the US, is generally met with unfavourable consequences

      Better than in the UK, where it's a criminal offence punishable by two years imprisonment. (Regulation of Investigatory Powers Act 2000, Part III)

      And people are really locked up for that [pcpro.co.uk] here.

      • by Dunbal ( 464142 ) *
        But two years might be better than the alternative.
    • by ScentCone ( 795499 ) on Tuesday May 05, 2015 @11:28AM (#49621867)

      "In case the police come busting in" is a condition typically followed by a hailstorm of bullets here in the United States

      I see. You live inside a bad television episode? How many hacker apartment door breakdowns followed by "hailstorms of bullets" can you cite from this month, here in this country of over 300,000,000 people? Please be specific.

      • He overstated it a little bit: if you're dealing drugs in 'cyberspace,' they'll just arrest you. It's only 'meatspace' drug dealers that get shot.

      • That's right. It never happens. The police always knock three times and leave quietly if nobody answers. You know what's sad about the summary there is that we have to fear the cops as much as any other common thief.

    • The abuses you describe have all happened in one form or another, though they're fortunately not the universal experience here.

      met with unfavourable consequences

      Clearly you favour spellings that add a bit of colour to the Queen's English, eh? OK, just kidding, but it is fun to speculate that you might be from Canada or the UK.

  • If you're that worried just work on a remote machine in a secure location via an encrypted remote desktop session. Nothing in local ram or disk. Anyway, since when does "kill" equal "shutdown nicely"? *sigh*
  • by mveloso ( 325617 ) on Tuesday May 05, 2015 @11:10AM (#49621687)

    How do you pee if this is attached to you? Do you keep a bunch of one-gallon jugs next to your desk?

    • Clever users will detach it, I assume.
      • But then they'll just forensic your laptop while your gone,

        only solution is to bring it with you

    • If you're going for a pee break, leaving your laptop alone, powered, is a ridiculously stupid thing if you're security conscious.

      You power it off, you take it with you.

    • It's not a kill switch that destroys your computer. It's a kill switch that shuts it down after flushing the disk cache (under the assumption that, as a career criminal with a vested interest in keeping your evidence locked down, you have an encrypted file system). So if you go use the bathroom, your PC turns off. If you have a SSD it will take you literally several seconds to boot again and remount your encrypted file system. Slightly inconvenient, but much better than if the police are able to rip you
    • by suutar ( 1860506 )

      shut down, go to bathroom, come back. If you're using this, you have decided that unattended uptime is not acceptable.

    • >> Do you keep a bunch of one-gallon jugs next to your desk?

      At the homeless-packed library near my office you'd fit right in.

    • by dissy ( 172727 )

      How do you pee if this is attached to you? Do you keep a bunch of one-gallon jugs next to your desk?

      Step 1 - You get up and go pee.
      Step 2 - You come back to the computer and press the power button.
      Step 3 - You continue with whatever it was you were doing before nature called.

      Not all that difficult for a select tiny few, though I can see how most people would be confused and bewildered at the requirements.

  • .... qualify as deliberate tampering with evidence?

    Even if you aren't guilty of whatever they were believing that the evidence on the computer would incriminate you for, that's still a crime, and not a very lightly taken one.

    • by DarkOx ( 621550 )

      Its kind of grey area. Full disk encryption could itself be though of in those terms. I mean why are ciphering literally every block of information your store? Certainly it must be because you have something to hide right.

      If you immediate start destroying the equipment when the cops show up that is a problems but in the case we have a device that has a normal operating behavior of putting itself into a secured state (by shutting down) whenever your wrist leave its proximity. Its not illegal (yet) to use

    • by burni2 ( 1643061 )

      It's all about the question that the definition "seized" and "going to be seized". are clearly laid out.

      If the tool is installed to automatically prevent access to the data on that pc - you are not tampering with evidence.

      The computer does it on it's own. Also when police comes to you, and you see them your pc is not yet seized, so all actions up until the moment when they take something away are ok.

      You should not have a remote connection to the pc (via umts modem, infrared or else) that you use to access t

  • I read the introduction, and was expecting a Mission: Impossible-style "This computer will self-destruct in 5 seconds" with smoke and everything...

  • by eastjesus ( 3182503 ) on Tuesday May 05, 2015 @11:51AM (#49622129)
    Reminds me of something I wrote back around 1981. Working with the early IBM PC at the machine code level several flaws surfaced and for fun I packaged them all together in the boot sector of a 5 1/4" floppy which we put in a "break glass" box and put on the wall (There were no hard drives yet, the XT wasn't out yet). If you placed the floppy in the boot drive it would destroy the hardware in a few seconds. First, there was a bit on the original IBM display adapter (mono text only) which would lock the horizontal sweep on the standard IBM monitor forcing the horizontal output power transistor to overheat and burn out. You would see the display image collapse while the monitor would squeal while smoke (literally!) would come out the sides and back, and die with a $200 repair to fix it. Second, there were no stops on the head movement on those original floppy drives - with the right loop they would step out until the heads fell off inside the case with a pair of clunks if you had a 2 drive system. (Not a difficult repair, but you had to know what your were doing and get into the floppy drives themselves to fix it.) Finally, the speaker ran off of a shift register which could be loaded with a really nasty PWM sound and set to free run. With interrupts disabled and the CPU halted, the machine sat there smoking with a very loud nerve-rattling siren, completely dead and unable to boot. It would require major physical repairs to get it working again. The monitor would stink for weeks afterwards.
    • by PRMan ( 959735 )
      I used to work at a place that got a virus similar to your code. A user got it from a bad floppy and the EGA monitors kept blowing up (the user's and 2 more I hooked it up to). I finally hooked it to a Hercules monochrome monitor and the screen came up. I looked up the virus on a virus vendor's BBS system and printed removal instructions and removed it.
  • by Lumpy ( 12016 ) on Tuesday May 05, 2015 @12:14PM (#49622381) Homepage

    Just set up a script on the machine looking for a specific USB device, start shutdown if the device is not present. This is pretty common stuff, hell my old Lenovo laptop has a smartcard slot in it that would do the same thing if the card was removed.

    In fact if you look you can find the same thing all over the place for the last decade on many hacking sites, even back in the late 90's this kind of stuff was on the "scene" I had back to back modems in telcom rooms inside boxes that if the box was opened it dumped 110V into the modem logic boards so that when discovered they would self destruct.

    Most "hackers" today probably dont even own a buttset.

    • by gatkinso ( 15975 )

      Why a specific USB device? This can be used for any device. Also, you can white list devices. Read the code, or is that not old school enough for you?

      • by Lumpy ( 12016 )

        Because making it look for ANY device means I can insert another USB device and then disconnect yours.

Trap full -- please empty.

Working...