since there has been some talk about pirates getting jail time for
warez and moviez in the news lately. I thought I would post a
countermeasure.
I have built a freebsd file server with windows file sharing, GBDE whole disk
encryption and a hacked serial port program to monitor physical security that will
lock, destroy, or nuke your data when physical security is breached, great for
unexpected raids by the authorities. No evidence no jail time.
there is absolutely no way I am walking you through the steps to install and configure
freebsd or install the ports you will need (like samba), use man pages and google for that.
once you have a server configured and visible on your windows network, download
the file below and and start reading the included PDF's, build the serial port hardware
and modify the tripwire.c source code for your server configuration. compile the
source and install.
you should use a separate disk for your encrypted data, and make sure it is not
mounted at boot time. or you will have to input the password for the disk during
the boot process which really sucks if you have a headless server hidden in a
closet.
http://www.mediafire.com/file/bdyfno2hdxz/Gbde.zip
links:
http://linuxfocus.org/English/January2001/article186.shtml
http://www.openaddict.com/installing_freebsd_6_2.html
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/disks-encrypting.html
http://www.bsdforums.org/forums/showthread.php?t=43796
take that MPAA/RIAA
Thats some pretty usefull info right there. Hey, how about this... dont do warez! Hey look, no need to encrypt anything! HUZZAH!
Believe it or not, some of the laws here in the USA concider encryption "witholding evidence". If the authorities have a warrent to sieze your shit and you dont give them passwords and how-to instructions, that could be more jail time for you. Last i remember the 5th ammendment states "The accuesed may not be forced to testify in their own behalf" which pretty much means if you are accused of a crime, you dont have to get on the stand and be questioned. Also, by not testifying that does NOT prove guilt. Forcing someone to reveal evidence against them sounds like a violation of the 5th if you ask me... Im no law expert *shrugs*
Encrypting the file system, wont that slow down HDD performance? And if you are running SMB Shares, all someone has to do is log into the share and d/l the content, so encrypting the HDD is kinda' pointless. If they have physical access to the machine, the first thing they do is pull the power cord out, so the failsafe serial tripwire is pointless. The first thing they do once they have your machine is clone the HDD. They literally do that RIGHT THERE on the spot. They pull your power cable out, open the machine, pull the HDDs and clone them.
Even if they dont clone the HDD, if the OS isnt encrypted they can pull the SMB passwords out of the config file, slap an XP box to LAN and just d/l the contents of all the shares.
This seems like a great idea for the insanely paranoid, but I dont think its going to be effective with how they sieze and clone shit right away. Even if you erase everything, they try to recover anything viable to hold against you. Good idea, but a better idea would be not to do massive amounts or piracy and warez.
The links I posted address most of your points,
there is a performance penalty but mostly on the cpu side.
pulling the power wont work, the contents of the drive are encrypted
on the fly, the encryption keys are held in ram, pulling the power
will lock the drive. the lock file and the password are nessary to
mount the drive store the lock file on a thumb drive and keep the
password in your head only.
this encryption scheme was devloped with human rights and war crime
investigators in mind, so it is assumed that an attacker has physical
access to the drive and has government level resorces to attack the
encrypted disk.
the encryption method has provisions to destroy the lock sectors on
the disk making it impossible to retrive the data even if you gave
them the usb thumb drive and the password. editing the C code so it
would destroy the lock sectors instead of lock the drive is easy, adding
another line to kill the samba process is easy, turning off the computer
would be another line of code all VERY easy to do here is some code
Sounds great, but... just... dont... do... warez
If you arent seeding thousands of TB from your home connection, or kiddie porn, whats to really worry about?
Regular porn on the other hand, is highly encouraged.
Oh my god, its Dortz!! Where the hell have you been man! get back on IRC, or ELSE!
Nice idea. But my dedi server has somthing like that but it frys the harddrive ![]()
~Needlz
Thermite. When you absolutely, positively have to kill every motherfucking platter in the machine accept no substitutes.
Who needs encryption when your hard drive is turned into a melted pile of metallic goo?
Powered by Invision Power Board
© Invision Power Services