LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 11-07-2016, 07:03 AM   #1
validator456
Member
 
Registered: Apr 2013
Location: Rotterdam, The Netherlands
Distribution: Crunchbang Linux
Posts: 234

Rep: Reputation: Disabled
How to protect one's laptop?


How do you protect your laptop against usb-sticks that can inject malware or usb-sticks filled with software that can extract information from your laptop?
 
Old 11-07-2016, 07:16 AM   #2
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,882
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
I think the most important step is to not run anything on the stick or attempt to open any files unless you know what the files are. Things like pictures and documents are known file extensions, so opening them should be with the standard, known means to view or edit those types of files.
 
Old 11-07-2016, 08:12 AM   #3
validator456
Member
 
Registered: Apr 2013
Location: Rotterdam, The Netherlands
Distribution: Crunchbang Linux
Posts: 234

Original Poster
Rep: Reputation: Disabled
That is not what I mean. Seen this on television: burglars get into the house and attach USB-stick to computer and with a script on this USB they were able to download valuable information to it.

This was not a movie. This was a documentary on how to break into somebody's house.
 
Old 11-07-2016, 08:21 AM   #4
snowday
Senior Member
 
Registered: Feb 2009
Posts: 4,667

Rep: Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411Reputation: 1411
If the burglar is in your house with physical access to your computer, then they have easy access to all unencrypted data on your computer. For example: Boot computer with Live USB of any Linux distro, mount your hard drive, copy your data.

Strong encryption is probably the best solution for your particular scenario.
 
Old 11-07-2016, 08:30 AM   #5
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939
But you can also set up your laptop with the equivalent of a "BIOS password" and to set it up so that it will not boot up from another device without entering such a password.

Also: "ummm, the much-maligned UEFI," which has been bantered-around in these parts as "Microsoft trying to take over the world?" Yes, this is exactly the sort of vulnerability (among others) that this layer of software was designed to prevent. It enables the firmware (once called the "BIOS") of your computer to recognize which operating-systems it should and should not boot from.

Also remember that "scenarios that you see on a television program" may or may not be realistic scenarios. When deciding what to "defend against," you should be pragmatic and a bit skeptical. Quite frankly, I'd expect a thief to steal your computer (and any other potentially-"fence-able" valuable-looking thing in the room), rather than plant malware on it.

Last edited by sundialsvcs; 11-07-2016 at 08:31 AM.
 
Old 11-07-2016, 08:46 AM   #6
rokytnji
LQ Veteran
 
Registered: Mar 2008
Location: Waaaaay out West Texas
Distribution: antiX 23, MX 23
Posts: 7,111
Blog Entries: 21

Rep: Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474
Having numerous computers. Numerous motorcycles, Numerous Bicycles. Numerous period. Plus living on the Mexican Border.

I find visiting the local dog pound and rescuing a dog off of death row. Has been the best type of security for

Quote:
That is not what I mean. Seen this on television: burglars get into the house and attach USB-stick to computer and with a script on this USB they were able to download valuable information to it.

This was not a movie. This was a documentary on how to break into somebody's house.
Though once on a hot day. I slipped up once.

http://www.linuxquestions.org/questi...abrones-36501/
 
Old 11-07-2016, 12:02 PM   #7
DavidMcCann
LQ Veteran
 
Registered: Jul 2006
Location: London
Distribution: PCLinuxOS, Debian
Posts: 6,140

Rep: Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314
The sensible thing to do with a laptop is to encrypt /home. Burglars are more likely to be interested in stealing you laptop for resale, but financial information would be a bonus.
 
Old 11-07-2016, 03:51 PM   #8
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,978

Rep: Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624Reputation: 3624
Physical access is generally the most difficult to defend against. I think I've seen some of the newer systems have ways to disable usb in password protected bios.

Kind of one of the promises of uefi that devices would have greater control in bios or devices would only be available to the OS by settings. Not sure how well all those promises do.

Guess you could put some epoxy in the ports.
 
Old 11-07-2016, 05:54 PM   #9
suicidaleggroll
LQ Guru
 
Registered: Nov 2010
Location: Colorado
Distribution: OpenSUSE, CentOS
Posts: 5,573

Rep: Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142
Easy solution - encrypt your drive and leave the machine shut down when you're not there. Nothing else will keep an intruder with physical access to your computer from getting your files. Not UEFI, not disabling USB, not a super-glued USB port. All those will do is slow them down a few minutes at best.
 
Old 11-07-2016, 09:44 PM   #10
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939Reputation: 3939
"Better yet, put your (thank you... pound rescued ...) dog in the foyer of your house, so that s/he might simply eat the would-be intruder . . ."
 
Old 11-08-2016, 07:20 AM   #11
fatmac
LQ Guru
 
Registered: Sep 2011
Location: Upper Hale, Surrey/Hants Border, UK
Distribution: Mainly Devuan, antiX, & Void, with Tiny Core, Fatdog, & BSD thrown in.
Posts: 5,487

Rep: Reputation: Disabled
Keep all your personal info on an external disk & lock it away when you leave your laptop.
 
Old 11-08-2016, 08:19 AM   #12
Timothy Miller
Moderator
 
Registered: Feb 2003
Location: Arizona, USA
Distribution: Debian, EndeavourOS, OpenSUSE, KDE Neon
Posts: 4,005
Blog Entries: 26

Rep: Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521Reputation: 1521
Quote:
Originally Posted by sundialsvcs View Post
"Better yet, put your (thank you... pound rescued ...) dog in the foyer of your house, so that s/he might simply eat the would-be intruder . . ."
Can't argue with that plan. Not only does it keep your laptop safe, but it also helps to keep others that the intruder would have preyed upon safe. And cuts down on your dog food bill.
 
Old 11-10-2016, 03:41 PM   #13
replica9000
Senior Member
 
Registered: Jul 2006
Distribution: Debian Unstable
Posts: 1,125
Blog Entries: 2

Rep: Reputation: 260Reputation: 260Reputation: 260
All of my machines' storage is encrypted. Non of them auto mount USB either. I'm also in the habit of locking the screen when I leave the room for a while.
 
  


Reply

Tags
security recommendations



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How to Protect Yourself Against Laptop Theft LXer Syndicated Linux News 1 11-26-2012 12:26 PM
Protect from other sudoers? ktek Linux - General 12 11-27-2008 09:52 PM
Protect directory Blisk Linux - Security 2 12-03-2007 03:22 PM
How Do You Protect Yourself? nuka_t Linux - Security 5 08-18-2004 11:35 PM
How do you protect your eyes? koyi General 33 08-13-2003 09:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration