Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old May 29th, 2012, 11:12 PM
redcell's Avatar
redcell redcell is offline
Regular Poster
 
Join Date: Sep 2010
Posts: 93
Big Grin Re: What is your privacy setup like?

Here's my security setup which focuses on anti-forensics.

Name:  u2012.JPG
Views: 560
Size:  19.0 KB

Last edited by redcell : May 29th, 2012 at 11:20 PM.
  #27  
Old May 29th, 2012, 11:51 PM
TigerRaptorFX TigerRaptorFX is offline
Regular Poster
 
Join Date: Sep 2011
Posts: 58
Default Re: What is your privacy setup like?

Firefox 13
No Script
Adblock Plus with Fanboy easylist
Bitdefender TrafficLight
Web Developer - Referrers disabled
Ghostery
BetterPrivacy set to 1 second delete
CS Lite aka Cookiesafe - All cookies are set to block by default. Registered sites are set to session.

Chrome 19 Only for multitasking.
ScriptNo
Adblock Plus with Fanboy easylist
TrafficLight
Ghostery
non add-ons
All cookies set to disable. Only registered sites are set to accept cookies.
Referrers disabled
Data sent to Google disabled.
BetterPrivacy works with Chrome when Firefox is active.
__________________
A little bird once told me. No amount of security software will protect you from yourself.
  #28  
Old May 30th, 2012, 09:44 AM
PaulyDefran PaulyDefran is offline
Frequent Poster
 
Join Date: Dec 2011
Posts: 737
Default Re: What is your privacy setup like?

Quote:
Originally Posted by redcell
Here's my security setup which focuses on anti-forensics.


I'd be interested in hearing about this setup. Have you recompiled TC with customizations?

PD
  #29  
Old May 30th, 2012, 10:26 PM
hashed hashed is offline
Regular Poster
 
Join Date: May 2012
Posts: 53
Default Re: What is your privacy setup like?

Quote:
Originally Posted by PaulyDefran
I'd be interested in hearing about this setup. Have you recompiled TC with customizations?

PD


Same here, especially with the "self-destruct" options

~h
  #30  
Old May 30th, 2012, 10:56 PM
redcell's Avatar
redcell redcell is offline
Regular Poster
 
Join Date: Sep 2010
Posts: 93
Lightbulb Re: What is your privacy setup like?

Quote:
Originally Posted by PaulyDefran
I'd be interested in hearing about this setup. Have you recompiled TC with customizations?

PD



I'm not using TC but I can only reveal it's one of the rarest commercial FDEs with preboot password destruction.

About the preboot password destruction:
If your attacker tries to bruteforce it with dictionary attack, it will kill off the hidden OS access.

About the startup hidden partition destroyer mechanism, this is easy on my setup (inside decoy OS):
Be sure to put tons of pictures of beautiful ladies/men to trick your attacker into thinking this is your dirty secret OS.
■ I've tweaked a whole range of registry settings; disabling, functions, taskbar, start button menus, task manager etc, desktop icons, drives, safe mode, etc.
■ Plant several zip bombs on startup, hide command popups.

Remember that the hidden OS is located inside decoy OS with "only few MBs of buffer".
When someone logs into Decoy OS, it is 100% chance the encrypted hidden OS will be overwritten at least partiallly rendering your secrets unrecoverable.

About the system crash mechanism hotkey, I use Bestcrypt Volume Encryption extra feature. You can assign your own hotkey to crash (blue screen of death) instantly.

The only weakness to current FDE is cold boot attack, which has maximum 5 minutes window after your computer shuts down.
In layman terms, your attacker needs to raid your place and spray (eg. liquid nitrogen) freeze your physical RAM within 5 minutes after your computer has been switched off. Make sure sure it's NOT attached to battery (if laptop) or UPS (if desktop).

Last edited by redcell : May 30th, 2012 at 11:07 PM.
  #31  
Old May 31st, 2012, 05:10 AM
Countermail's Avatar
Countermail Countermail is offline
Regular Poster
 
Join Date: Aug 2009
Location: Sweden
Posts: 114
Default Re: What is your privacy setup like?

Quote:
Originally Posted by redcell
The only weakness to current FDE is cold boot attack, which has maximum 5 minutes window after your computer shuts down.
In layman terms, your attacker needs to raid your place and spray (eg. liquid nitrogen) freeze your physical RAM within 5 minutes after your computer has been switched off. Make sure sure it's NOT attached to battery (if laptop) or UPS (if desktop).
Cold boot protection on my laptop
(Note: This removes all warranty)
Attached Images
 
__________________
http://www.countermail.com

Last edited by Countermail : May 31st, 2012 at 05:20 AM.
  #32  
Old May 31st, 2012, 10:52 AM
PaulyDefran PaulyDefran is offline
Frequent Poster
 
Join Date: Dec 2011
Posts: 737
Default Re: What is your privacy setup like?

Quote:
Originally Posted by redcell

I'm not using TC...

So I'll assume it's DCPP and you also run BCVE for the 'Crash' Command? Does that 'Crash' option also wipe DCPP's keys? I assume you don't encrypt anything with BCVE since DCPP is doing it all?

PD
  #33  
Old May 31st, 2012, 10:54 AM
PaulyDefran PaulyDefran is offline
Frequent Poster
 
Join Date: Dec 2011
Posts: 737
Default Re: What is your privacy setup like?

Quote:
Originally Posted by Countermail
Cold boot protection on my laptop
(Note: This removes all warranty)

JBWeld is a wonderful product

PD
  #34  
Old May 31st, 2012, 01:37 PM
Chiron Chiron is offline
Regular Poster
 
Join Date: Jun 2010
Posts: 173
Default Re: What is your privacy setup like?

How to Protect Your Online Privacy
__________________
How to Stay Safe While Online
  #35  
Old May 31st, 2012, 01:59 PM
happyyarou666's Avatar
happyyarou666 happyyarou666 is offline
Frequent Poster
 
Join Date: Jan 2012
Posts: 677
Default Re: What is your privacy setup like?

Quote:
Originally Posted by Countermail
Cold boot protection on my laptop
(Note: This removes all warranty)


can already imagine the pain in the ~ Snipped as per TOS ~ replacing ram will be with this , nice idea thou , something to consider

Last edited by JRViejo : May 31st, 2012 at 02:04 PM. Reason: Possibly Offensive Word Removed - JRViejo
  #36  
Old May 31st, 2012, 08:16 PM
hashed hashed is offline
Regular Poster
 
Join Date: May 2012
Posts: 53
Default Re: What is your privacy setup like?

Quote:
Originally Posted by happyyarou666
can already imagine the pain in the ~ Snipped as per TOS ~ replacing ram will be with this , nice idea thou , something to consider

I've found a group of people as paranoid as I seem to be

~h
  #37  
Old June 1st, 2012, 03:14 AM
happyyarou666's Avatar
happyyarou666 happyyarou666 is offline
Frequent Poster
 
Join Date: Jan 2012
Posts: 677
Default Re: What is your privacy setup like?

i almost forgot one thing theres something in dev once this gets integrated with TC coldboot attacks will be a thing of the past and no jb weld required

that would be TRESOR
  #38  
Old June 1st, 2012, 04:30 AM
LockBox LockBox is offline
Very Frequent Poster
 
Join Date: Nov 2004
Posts: 2,137
Default Re: What is your privacy setup like?

Quote:
Originally Posted by redcell
I'm not using TC but I can only reveal it's one of the rarest commercial FDEs with preboot password destruction.

About the preboot password destruction:
If your attacker tries to bruteforce it with dictionary attack, it will kill off the hidden OS access.

Before your attacker does anything, they're going to clone the drive. How do you feel software FDE with any kind of "self-destruct after X number of attempts" will protect you at all?

Am I missing something?

-
  #39  
Old June 1st, 2012, 07:52 AM
PaulyDefran PaulyDefran is offline
Frequent Poster
 
Join Date: Dec 2011
Posts: 737
Default Re: What is your privacy setup like?

Actually, I can see this as a useful tool (I know it's a hot button topic in the FDE community). There is one real world incident where, if the detainee really had some data he wanted destroyed, it could have helped him. The individual was Kevin Mitnick:

http://news.cnet.com/8301-1009_3-10054569-83.html

He goes into a lot more detail on TWiT a few weeks later. IIRC there were some times where they asked for his password, or had him log into other devices. A destruction password would have worked wonderfully. Our potential adversaries aren't all MENSA candidates, and all scenarios aren't 'no knock' raids where you never get to touch your gear again.

PD
  #40  
Old June 1st, 2012, 11:38 AM
happyyarou666's Avatar
happyyarou666 happyyarou666 is offline
Frequent Poster
 
Join Date: Jan 2012
Posts: 677
Default Re: What is your privacy setup like?

Quote:
Originally Posted by LockBox
Before your attacker does anything, they're going to clone the drive. How do you feel software FDE with any kind of "self-destruct after X number of attempts" will protect you at all?

Am I missing something?



-


hence the reason why it hasnt been included in the first place from the TC devs, it is indeed kind of useless against no knock raids , a strong passphrase with fde and thats all you need , then comes jbweld or TRESOR once its ready, and make sure you have a motion detector activated for when your not at home that cuts off your electricity from your pc and hdds
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:20 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums