Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FDE only works if the machine is powered off. If a machine is stolen while it is still running there's a risk the user account could be compromised. Depending how sophisticated your adversary is they could potentially completely compromise the machine and extract all of the data. When you have physical access and no time pressure the options are vast.


FDE could be made to protect the data when the machine is out of range of its secure home network too.

Leaving it on, the machine would detect loss of home network fairly quickly and lock itself.

The FDE key would depend on a key server on the home network, so it could not be rebooted and unlocked just with the physical on-board devices.

If some parts of the FDE were handled on the storage itself and required a periodic end-to-end refresh with the home network key server, then even freezing main RAM (literally) to extract keys later would not work.

More generally, the FDE key could be split over a number of components on the machine, all of them requiring end-to-end periodic refresh from the home network key server, making it extremely difficult to freeze all on-board devices effectively enough to extract the whole key and decrypt the storage contents. Add RAM encryption to complete the job.


> Depending how sophisticated your adversary is

The videos I saw don't inspire much dread, there, but they may give the laptop to someone that can do digital forensics. Lots of LEOs in that lot. They would be smart enough to stay out of the building, but might have been waiting for someone to come out with something like that.

But, as someone pointed out, a lot of the folks wouldn't bother trying to read anything. They'd probably try to plant their own fantasies onto it, and send it to Rudy The Hair Dye Man.


Are you sure?

Most of the rioters seem like herpa-derpers, but some came there on a mission, like this guy: https://www.thesun.co.uk/news/13690389/us-capitol-rioters-zi...

(those are not regular zipties, but the "taking hostages" kind)


On another note, the same publication (a redtop, so the language is rather "pithy") has this story[0], in which the "Fine People on All Sides" smeared feces around the place.

They have a photo of a guy on his hands and knees, cleaning the place. He's a congressman.[1]

[0] https://www.the-sun.com/news/2105149/trump-supporters-smeare...

[1] https://www.cnn.com/2021/01/08/us/congressman-capitol-trash-...


I also notice he’s masked. That was unusual for that lot.

There were definitely some folks there with mayhem in mind.


Yes it would be really interesting to find out who those guys were, were they Proud Boys, Antifa, foreign agents, undercover domestic agents, etc?


There have been several arrests already. Thus far it seems to be right wing extremists.

For example, the lady who was shot trying to enter the VP bunker has a social media profile with extensive Qanon related postings.

Another was a Republican member of the House of Representatives. He was caught because he livestreamed himself breaking the law, as all genius criminals do.

The story about Antifa being in the riots was made up out of whole cloth by the Washington Times. The company they cited put out a press release saying that they had done no such thing and the whole story was a fabrication.


They'll probably give it to that computer repair guy in Deleware so he can pull off all of the emails from March of 2021 and somehow lose them in the mail when he tries to send them to Fox News.


Time to update your internet boogeymen memes. Fox News and Trump are enemies. He's into Newsmax now.


I was making an allusion to the actual Hunter Biden laptop story.

https://www.independent.co.uk/news/world/americas/us-electio...


Who is to say that a few opportunistic spies weren't in that push looking for anything of interest? Historically, this has been the case during these sorts of events. When the Stasi HQ was overwhelmed by protestors, Western intelligence agents were the first in the building securing lots of information.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: