Slashdot Mirror


Location-Based Encryption

davidwr writes "Eweek reports Apple co-founder Steve Wozniak has a new way to prevent theft of company secrets on stolen laptops: 'Wozniak offered a peek into his vision for the company on Ziff Davis Media's Security Virtual Tradeshow, where he introduced "wOz Location-Based Encryption," an application that uses GPS tracking within a wireless hub to encrypt and decrypt sensitive data for large businesses.' Today's encryption is good enough but I do like the tracking capability. Imagine your laptop screaming 'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it."

239 comments

  1. Not totally secure? by nmg196 · · Score: 5, Insightful

    All GPS devices I've come across simply stream out NMEA data from a serial port (or over a bluetooth connection). What would stop someone that really desperate to get the data from hacking the GPS module or the dongle so they can stream in their own forged (or recorded) NMEA data which reports the laptops current position to be where they stole it from (after all, they should remember)? Usually anything these days that requires a GPS uses a standard GPS module, and at some stage, the position data from it ends up in an interceptable form on the edge interface of some module. Hardly bulletproof security?

    1. Re:Not totally secure? by jmcmunn · · Score: 4, Interesting


      Better yet, my portable GPS device allows me to "set my location" temporarily in case the signal is not strong enough. This allows the device to at least estimate where I am if it has a weak signal somehow. I don't really get all the details...but it works so I don't complain.

      So what's to stop someone from doing essentially the same thing with the laptop? Just tell it "you're still in the building" and you'd be all good. I think this is a pretty cheesy idea for security, you can always figure out a way to lie to a machine, regardless of what lie you're telling. This is less secure than a well-encrypted password if you ask me, or course I assume that the machine would still have the password as added security, so I guess that argument shouldn't carry any weight.

    2. Re:Not totally secure? by killua · · Score: 0

      Theres no such animal as bullet proof security, all we can do is make it more difficult to get around. 0.02$

    3. Re:Not totally secure? by PeteDotNu · · Score: 0

      It may not defend against the hackerly, but at least it will stop you average dumb criminal in his striped jersey.

      --
      My other processor is big-endian.
    4. Re:Not totally secure? by salvorHardin · · Score: 1

      That, or just jam the GPS device.
      Wouldn't help you open Rights Management stylee protected data, but it would stop your laptop from screaming "I'm being stolen!".

    5. Re:Not totally secure? by nmg196 · · Score: 5, Informative

      > This allows the device to at least estimate where I am if it
      > has a weak signal somehow. I don't really get all the details...
      > but it works so I don't complain.

      Well a GPS receiver has about 8-12 channels with which to look for the satellites. If it knows roughly where you are, then it can use that information, together with stored almanac data (info relating to the orbital positions of the satellites over time) in order to better guess *which* satellites it should try locking on to. It basically speeds up the process of getting the all important 'first fix'. If you didn't tell it where it was, it would simply take longer to get the fix - but it would still get there eventually.

      I must admit, I wasn't too impressed when I received my first GPS and the very first question it asked me when I turned it on is "Please select the location of this device using the map below". I was like, "huh, aren't you supposed to tell me that?!". :)

    6. Re:Not totally secure? by stupidfoo · · Score: 5, Funny

      When a laptop screams 'I'm being stolen! I'm being stolen!' and no one can here it, is it really making noise?

    7. Re:Not totally secure? by bsd4me · · Score: 1

      I think all consumer GPS devices do this, but there are lots of commercial/industiral GPS devices, too.

      I don't think it would be that hard to integrate one of the chipsets from Trimble into a WAP to provide the feature Woz is describing. Install the WAP in the ceiling, and run some RG-58 to the roof for the antenna, and I think that would make spoofing the GPS a lot harder.

      --

      (S(SKK)(SKK))(S(SKK)(SKK))

    8. Re:Not totally secure? by REBloomfield · · Score: 1

      Is this like what they did in Goldeneye?

    9. Re:Not totally secure? by recharged95 · · Score: 1

      If they can defeat lo-jack on cars, they can defeat this. (unless it's some SMT transmitter on the freakin chip, which is unlikely due to the power requirements at this point).

    10. Re:Not totally secure? by plover · · Score: 1
      Partly because these devices rely on security through obscurity, and sales through marketing-hype.

      If a security system is recognized and completely understood, it can be disabled or defeated. However, if the system is not recognized in time, it can use that time to phone home, re-encrypt the data, squirt stinky purple ink out the keyboard, whatever.

      So, if your concern is that James Bond and Bruce Schneier are going to conspire with the CIA to steal your laptop, well you're pretty much screwed even with this system. But if your bigger concern is that Tom in accounting is going to get pissed off at your new corporate dress code and steal the CEO's laptop in order to "get back at da man", well at least he isn't going to get a free copy of your customer database that he can sell to your competition.

      Remember, Woz isn't trying to sell to the CIA -- he's trying to sell to that CEO. Real world security isn't always about perfection -- it's frequently about tipping the odds in your favor as often as possible.

      --
      John
    11. Re:Not totally secure? by Anonymous Coward · · Score: 0, Flamebait

      I was like, "huh, aren't you supposed to tell me that?!".

      You were 'like'? Expand your vocabulary a bit. You will find it, like, totally cool when you do. You can like be like very clear in communitcating your thoughts. You will be like "wow".

    12. Re:Not totally secure? by Anonymous Coward · · Score: 0

      well yeah .. it's not bulletproof .. u can copy data off HDD et.. but it's a layer.

      Anyway .. since when do GPS signals work reliably inside a building anyway?

    13. Re:Not totally secure? by Psiolent · · Score: 2, Interesting

      I work for a company that makes it so you CAN hear it. It doesn't use GPS, but instead proprietary wireless receivers placed throughout a facility. If a marked asset (such as a laptop) leaves a predefined area, it initiates an alarm. Our software does, in fact, scream "I'm being stolen", or whatever you want, via text-to-speech over the facility's walkie-talkies.

      We don't do location based encryption, like Woz, but we will scream at you if your laptop is being stolen.

      See our asset theft detection here.

    14. Re:Not totally secure? by nmg196 · · Score: 2, Funny

      Sorry - I've just watched Finding Nemo and those turtles must have really got to me :)

    15. Re:Not totally secure? by stupidfoo · · Score: 1

      That text to speech is pretty good.

      Only a little glitch on "important assets" "announce alarms" and "dispatching".

    16. Re:Not totally secure? by Mr+Guy · · Score: 3, Funny

      Don't appologize. It's not your fault you were using slang that actually does mean what you were trying to convey. I'm assuming didn't actually speak to the device, correct?

      So in other words, you inclined to feel as though the machince should be telling you. Or perhaps your feelings could be described as resembling the emotions that sentence expressed. I think you'll find that's what the word like means, regardless of whether that's an encouraged sentence structure.

      If you feel I'm wrong, explain to me what's fundamentally different about the following sentences, besides using a sentence to describe the feeling instead of direct simile:

      I was like a cloud.
      It was like a state of total weightlessness.
      It made me feel like I buzzing around.
      I was like, "Wow, I'm a cloud".

    17. Re:Not totally secure? by inhalentbroom · · Score: 1

      Nothing is ever 100% secure. This will just add one more step to crack and possible decrease the chance that important data could be stolen. That is what every security principle has been about.

    18. Re:Not totally secure? by igny · · Score: 1

      On the other hand, if laptop screams "Wolf!" too often, won't people start ignoring the screams?

      --
      In theory there is no difference between theory and practice. In practice there is. - Yogi Berra
    19. Re:Not totally secure? by nmg196 · · Score: 0, Flamebait

      > Don't appologize.

      If you're going to be pedantic, it's spelt: apologise or apologize.

      > I'm assuming didn't actually speak to the device, correct?

      (I'm assuming *you*...)

      No I'm pretty sure I did actually say that out loud, but it was a rhetorical question.

    20. Re:Not totally secure? by Speare · · Score: 1
      When a laptop screams 'I'm being stolen! I'm being stolen!' and no one can here it, is it really making noise?

      Either you're coining a subtle and witty new verb related to finding something with a GPS transponder ("can you 'here' my stolen laptop, officer?"), or you are getting your homonyms mixed up. Given this site, I'll take the odds on a language blunder.

      --
      [ .sig file not found ]
    21. Re:Not totally secure? by Anonymous Coward · · Score: 0
      In 1988 we implemented a security system in our stores based on the Commodore Amiga 500. We placed one at each store's security desk, and wired it to our cash register system. Among many other really cool features, we had a way for the registers to send raw text messages to the text-to-speech device and 'speak' it to the guard at the desk.

      The normal messages were mundane generic alerts, such as "Assistance required on register 123." But one of the jokers of the day translated the messages with the "jive" filter (which was really popular back then.) So instead of saying "Attention. Alert on terminal 123. Cash drawer opened." the guard would hear, "Yo. Get yo' ass to terminal 123. Cash drawer bein' busted into!" Needless to say our security people thought it was the greatest change ever!

    22. Re:Not totally secure? by Mr+Guy · · Score: 1

      Don't worry, I didn't pick improper spelling in the pet peeve poll. The art of proper language usage and the fundamentals of spelling aren't as closely entertwined as some like to think.

    23. Re:Not totally secure? by Anonymous Coward · · Score: 0

      Even the most witty and intelligent comments lose a lot of their impact when the author ignores grammar and spelling.

      Or, in the local vernacular, "u r t3h $ux. j00 l0$3 @ 3ngl1$h, f00. pwnt."

    24. Re:Not totally secure? by virid · · Score: 1

      Curtail your sensitivity to your neighbor's vernacular. Priggish posturing does not a friend make.

      --
      "The world only exists in your eyes. You can make it as big or as small as you want." - F Scott Fitzgerald
    25. Re:Not totally secure? by Anonymous Coward · · Score: 0

      I'll whoopsie-doodle that, outglam. Snide my digs, so long? Or klondiff zoot-zoot-zootie, if that's nodule fancy.

    26. Re:Not totally secure? by Anonymous Coward · · Score: 0

      "Curtail your sensitivity to your neighbor's vernacular. Priggish posturing does not a friend make."

      What do dog's tails have to do with porches and pigs?

    27. Re:Not totally secure? by bodrell · · Score: 1
      When a laptop screams 'I'm being stolen! I'm being stolen!' and no one can here it, is it really making noise?

      Actually, what caught my attention was the part after that, "as the janitor walks out the door with it." Does the submitter have a problem with janitors? Or perhaps he had a bad experience in the past? In my office there have been thieves who stole people's lunches (among other things) and one of the thieves was a white-collar employee. I wouldn't automatically suspect the janitor if something were missing.

      --
      Si la vida me da palo, yo la voy a soportar Si la vida me da palo, yo la voy a espabilar
    28. Re:Not totally secure? by legirons · · Score: 1

      All GPS devices I've come across simply stream out NMEA data from a serial port, someone would just send their own NMEA stream

      The difference is, you're approaching this from the view of a technology expert. Try to think of it through the eyes of a marketer.

      "It's perfectly secure, the laptop can never be used outside of designated locations"

    29. Re:Not totally secure? by mr100percent · · Score: 1

      I believe you are thinking of Tomorrow Never Dies. However, they didn't jam or spoof the GPS signal, they used a US military encoder to re-program the satellites themselves. However, I always wondered how come the rest of the GPS-using world didn't notice that everything shifted a few hundred miles for a while...

  2. Or other more malign actions by _the_bascule · · Score: 5, Funny
    paging the boss, 'he's going home! he's going home!'

    --
    Our diversity is our strength
    1. Re:Or other more malign actions by Anonymous Coward · · Score: 0

      paging Microsoft that your PC has moved, and therefore now requires a new license fee.

    2. Re:Or other more malign actions by Anonymous Coward · · Score: 0

      "Malign" is a verb, mate. I guess you were thinking of "malignant", or perhaps the opposite: "benign". Hope this helps.

  3. Alarms by Anonymous Coward · · Score: 5, Funny

    What if they had that for cars? Imagine someone tries to steal one and an alarm goes off! Everyone will pay attention and call the police right away. Car theft will be a thing of the past for sure...

    1. Re:Alarms by lmfr · · Score: 1
      Car alarms require public interest and intervention.

      This, however, only requires interest and intervention from paid security officers working for the company.

    2. Re:Alarms by Anonymous Coward · · Score: 0

      Fer crissakes: these have been around forever:

    3. Re:Alarms by diqmay · · Score: 1

      Fer Crissakes: sarcasm has been around forever

    4. Re:Alarms by Oct · · Score: 0

      a friend of mine had his car stolen...and when they found it in a ditch like 5 miles away, the only things missing were the sterio and the alarm system :) heh

    5. Re:Alarms by ikegami · · Score: 1

      If a car alarm goes off in the parking lot, who cares. If someone was driving down the street with a car whose alarm is active, yeah, I'd call the cops. If someone was walking around with a laptop whose alarm is active, yeah, I'd call the cops. If it's a false alarm, the cops can sort that out.

    6. Re:Alarms by Anonymous Coward · · Score: 1, Interesting

      This system has been in use for years in Belgium which is notoriously known for its high "car-jacking" rate.

      When I've got the system installed on my car, the guy told me that they did not install a microphone in the trunk. I asked him why he would do that. He explained that car-jacker are now taking the owner with them and usually put them in the trunk and mine was too small. With the microphone, you can basically call the police and explain them not to shoot in the car.

      After having been car-jacked anyway, I moved to Switzerland!

    7. Re:Alarms by Anonymous Coward · · Score: 0

      They do. OnStar and Lojack have a record of catching theives and retreiving stolen vehicles, when privacy concerns don't get in the way (i.e., they're not always watching, you have to tell them it's been stolen).

      Just not everyone has them.

    8. Re:Alarms by retsaMedoC · · Score: 1

      They have something similar already. If you have LoJack installed and file a police report, the car will tell the police, "I'm stolen. Come get me." There's also an option where they will call your cell phone if the car moves without your keys so you can check on it. (Probably goes off when you are being towed.)
      http://www.lojack.com/

    9. Re:Alarms by Anonymous Coward · · Score: 0

      Um, why would the cops be shooting my car? "He stole a car! Shoot to kill!!" is a little overkill.

      Besides, what's to stop a carjacker from using the microphone to get the cops to back off?

    10. Re:Alarms by Anonymous Coward · · Score: 0

      I remember hearing about a car security system a couple years ago that, if you didn't disable it when you started the car, would let you drive to the first intersection and then shut off the engine for good.

  4. Does not work for cars too well by mi · · Score: 2, Interesting
    Automobiles had various "I'm being stolen" devices for years. From overt obnoxious sirens, that wake up the neighborhoods in the middle of the night to covert "Lo-Jack" and others. Does not help as much as was, I bet, expected.

    Or does it?

    --
    In Soviet Washington the swamp drains you.
    1. Re:Does not work for cars too well by Skater · · Score: 1

      LoJack does work, apparently:

      Google Answers that links to a Carnegie-Mellon study about it.

      --RJ

    2. Re:Does not work for cars too well by plover · · Score: 1
      My auto insurance company offers a blanket discount for "theft deterrent devices." I think we can safely assume that if an insurance company is willing to cut prices 10% because the ignition locks up if it's fiddled with, then there really is a measurable deterrent effect.

      It's quite obvious that the systems won't stop a dedicated thief, nor will they prevent many other sorts of insurable damage. But they obviously have some overall effect.

      --
      John
    3. Re:Does not work for cars too well by mikael · · Score: 1

      Unfortunately, these "I'm being stolen" devices also get set off whenever there is a major fireworks show like the Edinburgh Festival. Which of course is exactly at the same time as there are large numbers of visitors and their cars in the area.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    4. Re:Does not work for cars too well by Lonesome+Squash · · Score: 1
      Lojack works EXTREMELY well. And it's also socially beneficial. If I put an alarm on my car, thieves will go steal your car. If 5% of the people in an area have Lojack, becoming a professional car thief becomes significantly more difficult. By installing Lojack, you're benefiting all car owners in your area.

      These days, thieves will typically do things like park cars out on the street somewhere for a day or two to see if the police come and recover it before they bring it to their chop shop. This means there's a better chance of their getting caught even by normal means on cars that DON'T have Lojack.

      If I were a police officer, every once in a while I'd see if I could convince someone to leave their stolen and located car right where the thieves left it, so I could follow them when they pick it up.

      --
      Behold the riant ape! Beware, his crooked thumbs!
    5. Re:Does not work for cars too well by dr_dank · · Score: 1

      I remember one particularly obnoxious device that was sold in the Radio Shack catalog years ago. Instead of going off like a regular siren, this car alarm would actually be a woman's voice screaming "help me!" or "I was tampered with" if the alarm went off previously. That's just beyond the limits of good taste.

      --
      Where does the school board find them and why do they keep sending them to ME?
    6. Re:Does not work for cars too well by plover · · Score: 1

      My father in law's car (which did not have LoJack) was stolen a few years ago. But he lives in such a small town that it has only one real "flop-house", and that's where the sherrif found it parked later in the week.

      --
      John
    7. Re:Does not work for cars too well by pboulang · · Score: 1
      Lojack requires police involvement. Wouldn't you rather use a system that you can use to locate your car wherever it is on your computer? Or you want to track where your 16 year old son goes with your car. How about you get paged/called/whatever when the car leave some predetermined route or general area that you define?

      If I were a police officer, every once in a while I'd see if I could convince someone to leave their stolen and located car right where the thieves left it, so I could follow them when they pick it up.
      I imagine this would be fairly frequent... some people don't even want their cars back.. just need a policy in place to provide transportation while this is going on and I imagine even Insurance companies would get on board.
      --

      This comment is guaranteed*

      *not guaranteed

    8. Re:Does not work for cars too well by Anonymous Coward · · Score: 0
      Lojack works EXTREMELY well. And it's also socially beneficial. If I put an alarm on my car, thieves will go steal your car. If 5% of the people in an area have Lojack, becoming a professional car thief becomes significantly more difficult. By installing Lojack, you're benefiting all car owners in your area.


      This presumes that LoJack does not come with a sticker that you put in your car's window which states "This car protected by LoJack", in which case the social benefit is precisely the same as any other theft deterrent system. Does it?
  5. This could be applied to other things as well by uid100 · · Score: 3, Interesting

    Some though would have to be applied to this, but a GPS system in your car that alerts you if some operational parameters are crossed would be nice.

    "Hey, I'm being towed away from the parking garage, even though my keys are more than 100 yards from me"

    --
    ...yup...
  6. Zztxt Flrqtp fnz p47eltnzd. by mothz · · Score: 4, Funny

    Zztxt Flrqtp fnz p47eltnzd.

    Oh, I'm sorry, you need to move two steps to the left.

    1. Re:Zztxt Flrqtp fnz p47eltnzd. by ozbon · · Score: 0

      For once i really wish I had mod points - but it's Funny, not Interesting!

      --
      I say we take off and nuke it from orbit. It's the only way to be sure...
    2. Re:Zztxt Flrqtp fnz p47eltnzd. by Urban+Garlic · · Score: 1

      > Oh, I'm sorry, you need to move two steps to the left.

      Hmmm...

      Ccubu H'yeu]u h,c ]69t'u,cg

      Nope, still doesn't make any sense.

      --
      2*3*3*3*3*11*251
    3. Re:Zztxt Flrqtp fnz p47eltnzd. by DLWormwood · · Score: 1
      Ccubu H'yeu]u h,c ]69t'u,cg

      Let's try two steps forward...

      Qqbwb $9vzb/ 4yq /fjc9byq3

      Still no dice, even with a wraparound keyboard...

      --
      Those who complain about affect & effect on /. should be disemvoweled
    4. Re:Zztxt Flrqtp fnz p47eltnzd. by Anonymous Coward · · Score: 0

      this won't work too well. why? who gets GPS in their office? really. try it sometime. signal strength is crappy. not enough to lock onto location. so the laptop sees crappy signal strength. ok, the programmer can say, "when you have crappy signal strength, you're in an office and not being stolen". but then what's to prevent people who want to steal laptops from using those static proof bags that block RF and taking it to their car in that??? The GPS would still think it's in the office with no reception.

  7. Do you keep your laptop solely in the office? by mpathetiq · · Score: 5, Insightful

    It seems like the real risk would be when you are on-site, traveling, etc. As a consultant, my laptop never leaves my side. I'd hate to have to "check out" every time I left the building. Also, I don't think I would like my employer having the possibility of tracking my every movement. Sure, you could turn off the tracking, but then you've lost the security as well.

    1. Re:Do you keep your laptop solely in the office? by Nimey · · Score: 1
      I don't think I would like my employer having the possibility of tracking my every movement.
      Get your own laptop, then. Their property, they can do what they like with it.
      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
  8. In other news... by al_fruitbat · · Score: 2, Interesting

    ...thieves put stolen laptops in bags lined with aluminium foil. (can also be used for hats)

    1. Re:In other news... by Lonesome+Squash · · Score: 1

      You're missing the point. If the GPS doesn't report that the laptop is in an approved location, the thieves can't access the data. The data (actually, the secrecy of the data) might be orders of magnitude more valuable than the hardware.

      --
      Behold the riant ape! Beware, his crooked thumbs!
    2. Re:In other news... by al_fruitbat · · Score: 1

      Oh, sorry. He said 'janitor'. Anyone interested in industrial espionage is likely to be aware of encryption systems like this.

  9. Re:w0z is a nutjob at best... by chroot_james · · Score: 1

    I'd like to clarify a tad... GPS's aren't specific enough and can be inaccurate enough to make this not perfect security, like is always claimed with NEW AWESOME PRODUCTS! Traingulation may not be perfect either, but it might be a better lead to "only the boss gets internet in the boss's office" type things.

    --
    Reality is nothing but a collective hunch.
  10. Um.. by Daniel+Boisvert · · Score: 2

    Does anybody else see a problem with a laptop you can't use outside of the office?

    It's not like you'd buy a laptop so you could TAKE IT WITH YOU and work outside of the office, or anything..

    1. Re:Um.. by sarlen · · Score: 1

      Does anybody else see a problem with a laptop you can't use outside of the office? It's not like you'd buy a laptop so you could TAKE IT WITH YOU and work outside of the office, or anything..

      As with any optional security feature, I imagine it would only be implemented under the assumption it should NOT be used out of the confines of the office. Would that not be an effective deterent? Same principal as a car stereo that doesn't work once taken out of the car - sure you have it, but what was the point?

    2. Re:Um.. by Anonymous Coward · · Score: 0

      Then why not buy the cheaper, more powerful desktop?

    3. Re:Um.. by grommit · · Score: 1

      Who says that you can't take it out of the office? There merely needs to be a system set up where you can "check out" the laptop for business trips. After x number of days, if the laptop is not back at the home office, it gets disabled.

  11. Shut Down? by ZZeta · · Score: 5, Insightful

    Ok, may be I'm missing something, but wouldn't a simple shut down get rid of this 'feature'?

    And before you tell me how you can't shut it down without the apropriate password: Unplug / get rid of the battery. If you're stealing the notebook, why would you mind turning it off? After all, there'll be plenty of time back home to retrive the data.

    1. Re:Shut Down? by Have+Blue · · Score: 1

      Require a password on boot to unlock filesystem-level encryption.

    2. Re:Shut Down? by KiloByte · · Score: 2, Insightful

      Simple. Just have your server ping the laptop every second and launch an alarm if the connection goes down.

      Unless you knowingly turn the watchdog off, I can't see a way to work around this that doesn't involve meddling with the server or alarm -- if you use some secure ping like choosing a random number and running some private key cryptographic tool on both ends.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    3. Re:Shut Down? by Anonymous Coward · · Score: 0

      cuz after all, there's no reason for a network to ever be down unless something's being stolen. This wouldn't lead to too many false alarms, no more than 10^7 per day.

    4. Re:Shut Down? by KiloByte · · Score: 1

      If it's a planned outage, the watchdogs will be off. Such a setup isn't something that's likely to be something done for just a single machine -- you can't really forget about a system that watches all the laptops in your department.

      And for unplanned problems, well, the attention is needed anyway.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    5. Re:Shut Down? by bitslinger_42 · · Score: 1

      Better than a boot password (the data is still readable on the hard drive if someone pulls it out), I really like the looks of some new products that are coming out with whole-disk encryption implemented in hardware. They use a USB dongle to hold the private keys, so the attacker would have to steal both the laptop AND the key to have access to the data. I'd much rather see that implemented on all company laptops (even desktops) than watch these companies monkeying around with biometrics.

    6. Re:Shut Down? by kyrre · · Score: 1

      What is to keep me from replacing the laptop with another laptop that use the same ip-address? MAC filtering will not cut it because MAC can easily be spoofed.

    7. Re:Shut Down? by Anonymous Coward · · Score: 0

      Johnson, why are you still here, it's after midnight, go home!

      I can't, if I don't keep pressing a key every 10 minutes, my laptop goes to sleep and the alarms go off!

    8. Re:Shut Down? by Rich0 · · Score: 1

      As he indicated it wouldn't be a true ICMP ping, but an application that uses a challenge-response system of some sort. Send random bytes, laptop encrypts with private RSA key, sends back, security server decrypts with public RSA key - no way to impersonate the laptop without hacking into it, which means that you can't take it home to crack it.

  12. GPS? Inside a building? by Anonymous Coward · · Score: 0

    Hmm... doesn't sound too promising to me.

  13. I can see the error messages now... by Elphin · · Score: 3, Funny

    Error! Unable to open file!

    In order to open this file you must move 3 metres northwest of your present position

  14. British intelligence and self-destructo laptops by call+-151 · · Score: 5, Informative

    This has come up before- here is a link to a 2001 Wired article about the British intelligence services using laptops with ``a built-in electronic self-destruct mechanism that erases a laptop's hard drive if the case is opened by force'' when a code is forgotten, as well as ``a tracking feature that allows a computer gone astray to call home." This was after a spate of embarrassing episodes where laptops with lots of important info went missing. I don't know if it's been implemented but this does seem to have some interesting applications, potentially...

    --
    It's psychosomatic. You need a lobotomy. I'll get a saw.
    1. Re:British intelligence and self-destructo laptops by Slashamatic · · Score: 1
      I'm still trying to work out how a hard drive can be instantly trashed electronically. Even a single-pass low-level format can take a long time. My guess is an encrypted partition which relies on a key held in a PCMCIA dongle.

      The call-home program exists commercially and allows a machine to register its presence with a remote control.

    2. Re:British intelligence and self-destructo laptops by flosofl · · Score: 1

      Yeah, I was wondering the same thing. I work with some security modules that have tamper-resistant casing. If you try to force the locks or pry/cut the case, It zeros itself out. The difference here is that everything is solid state and stored in RAM and Flash memory. For the hard drive perhaps somekind of deadman switch on an electromagnet or something. But that would make for a damn big (and HEAVY) laptop (At least going by the size of our DeGaussers here at work).

      Anyone know what could be small and light (fit in a laptop case with all the other stuff) and still be able to wipe a drive isntantly (or near instantly)? Preferably without killing anyone (so no explosives or what-not!)

      --
      "This calls for a very special blend of psychology and extreme violence" - Vyvyan "The Young Ones"
    3. Re:British intelligence and self-destructo laptops by earthman · · Score: 1

      How about encrypting the whole hard drive, either by using an encrypted file system, or a HDD controller which encrypts all the data written to the disk on the fly. Store the encryption key in Flash or RAM or whatever. When any kind of unauthorized access is attempted, wipe the key, and nobody can access the disk anymore. This could be as simple as keeping the key in a bit of battery-powered RAM, and connecting this to a chassis intrusion switch, which will cut off power when the case is opened.

      Don't forget to keep a backup copy of the key somewhere in a location safe enough that when someone gains access to it, the backup keys are the least of your worries.

    4. Re:British intelligence and self-destructo laptops by Slashamatic · · Score: 1

      You also need to remember that a fancy disk drive would be very expensive. The Brits don't have that kind of money for specialised equipment. I have heard of devices that go into the PCMCIA slot that will hold a key in a tamper resistant module. If the driver exposes the standard Win Crypto API, then it would even be possible to integrate it easily.

  15. For a laptop? by 31415926535897 · · Score: 2, Insightful

    I was always under the impression that laptops were supposed to be mobile (but maybe that's just me)...

    It seems like this would be more useful for company systems that have highly proprietary, sensitive data on them that you wouldn't want moving around. I could see a very nice, dual G5 screaming "I'm being stolen" as the janitor carts it out with his supplies (though how it does that without a power source is beyond me, I guess you would need a secondary power source just for this system).

    Also, and I'm really not trying to start a flame war here, but first, what's wrong with a janitor having a laptop, and why assume that it's a janitor stealing the laptop? I would guess that it's a disgruntled employee or just-fired employee (that's not properly escorted out) that would pull a stunt like that. And I would think that laptops are stolen from public places like libraries and parks rather and work places where I think a system like this might not be as useful.

    1. Re:For a laptop? by Tenebrious1 · · Score: 1

      Also, and I'm really not trying to start a flame war here, but first, what's wrong with a janitor having a laptop, and why assume that it's a janitor stealing the laptop? I would guess that it's a disgruntled employee or just-fired employee (that's not properly escorted out) that would pull a stunt like that. And I would think that laptops are stolen from public places like libraries and parks rather and work places where I think a system like this might not be as useful.

      I don't have any numbers, but most of the laptops that I've heard of being stolen were stolen by complete strangers who managed to sneak into secured areas. Usually dressed in suits, they just wander around purposefully until they see an unwatched laptop grab it and quickly walk out. That's why it's important not to let strangers in behind you.

      --
      -- If god wanted me to have a sig, he'd have given me a sense of humor.
    2. Re:For a laptop? by Sai+Babu · · Score: 1

      Why of course it's the janitor! How the hell do you think he accrues the scratch for those Hummer payments?

      I'm trying to imagine what can be stolen by carting off the laptop that can not be stolen by copying from the laptop to a smaller (than the laptop) storage device. In other words, it's not going to do a thing to prevent employee theft of data.

      The best way to limit theft of the actual hardware is a firmware exec that 'phones home' with location from built in GPS or handshake with cellular phone system. The cell phone system registers phones that are turned on. This registration is returned to the cell phone company, regardless of the system the phone registers with. There is also a repetitive handshake. This system is already in use for tracking trucks and containers. It's cheap and easy to add to laptops as a prodction (model specific) option. There are enough bytes free in the handshake packets to encode GPS data for precise location without the need to initiate a call. I'm really surprised this hasn't found it's way into laptops yet. For additional data (keys, keystroke logging, etc), the phone could actually be subscribed with periodic calls to update data. It's a hell of a lot cheaper way to go because the hardare, infrastructure, and tracking system already exists.

    3. Re:For a laptop? by No+Such+Agency · · Score: 1

      Also, and I'm really not trying to start a flame war here, but first, what's wrong with a janitor having a laptop, and why assume that it's a janitor stealing the laptop? I would guess that it's a disgruntled employee or just-fired employee (that's not properly escorted out) that would pull a stunt like that. And I would think that laptops are stolen from public places like libraries and parks rather and work places where I think a system like this might not be as useful.

      Thank you for mentioning this. My first thought upon reading that was "What a classist thing to say". I too suspect that laptop theft by janitors is in the distinct minority. I can much more easily imagine office employees stealing "their" own laptops. They can walk around with them without getting funny looks for one thing.

      --
      Freedom: "I won't!"
  16. I'm being stolen! by six11 · · Score: 1

    Laptop: "I'm being stolen! Security guys, help!"
    [Security guy shows up, gun drawn]
    Security guy: "You there! Hands up"
    Innocent guy: "But, I'm just bringing Bob's laptop over to him in building 4!"

    I do like the idea, however, even though it may have issues. You could also use a wireless signal that pervades your company that is used as a key to decrypt.

    1. Re:I'm being stolen! by KiloByte · · Score: 1

      Yeah, and if the guard believes the guy, that's the biggest (and most common) issue.

      For the wireless signal: just have a centralized server decrypt everything, to keep the secret keys locked up nice and tight.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
  17. Quote from article by ender1598 · · Score: 2, Insightful

    "Throughout the entire process, Wozniak said the encryption key is controlled in a central location through a secure transmission. Because the wOz Platform and the wOzNet network are proprietary, he said it is not open to Wi-Fi spoofing or password sniffing."

    proprietary != secure from sniffing

    I wonder if it's based on the current wireless encryption or if it's something completely new.

    --
    There are 10 kinds of people in the world; those that understand binary and those that do not.
    1. Re:Quote from article by bhima · · Score: 1

      I think his point was wOz != WEP

      --
      Nothing in the world is more dangerous than sincere ignorance and conscientious stupidity.
  18. Thinkpads and RFID by terrencefw · · Score: 4, Informative

    IBM Thinkpads have had RFID in them for a while now, to prevent them being taken out of specific areas.

    --
    Like tinyurl, but one letter less! http://qurl.co.uk/
  19. tracking device by hostylocal · · Score: 1

    i like the idea of this. just so i can find stuff after i put it down somewhere...

  20. Not a lo-jack by zarthrag · · Score: 1

    This is hardly feasable. However, it *is* possible to construct your TxRx that can lock your equipment to the area. But if you're that serious about locking something down, why not just use a mainframe and some dumb terminals?

    This could only possibly work with other layers of security - GPS data isn't what I'd choose unless you can afford to launch some slightly more "useful" satellites of your own. Those sattelites would have to encode a sort of "encrypted timestamp" into the their data, so that that you can be *sure* your position is accurate, and not injected into the system.

    Of course, this is also fakable, but at much more expense and pain. I'm sure even more elaboration could possibly yield something. Maybe adding a tuner that looks for TV/radio local station carriers, blah-blah-blah

    --
    Why can't all fpga/microcontroller manufacturers just release free optimizing compilers???
  21. Why must it always be "the janitor"?? by gambit3 · · Score: 3, Insightful


    A few years ago, a securtity head-honcho at my company gave a presentation about keeping confidential documents off our desks, because "you never know when the janitors can come in and just swipe it out with them. I know they don't speak Englis, but it doesn't take a lot to swipe stuff off a desk..."

    I've had my fair share of stuff stolen, and it's never been a janitor.

    1. Re:Why must it always be "the janitor"?? by gambit3 · · Score: 0

      oh, and forgive the missing "h" at the end of "English."

      I've been having trouble with the "h" key in my keyboard.

      Must be those damn janitors that stole it!

    2. Re:Why must it always be "the janitor"?? by Anonymous Coward · · Score: 0

      I know they don't speak Englis

      Looks like you don't either :p

    3. Re:Why must it always be "the janitor"?? by wootest · · Score: 1

      I've had my fair share of stuff stolen, and it's never been a janitor. You're right. The butler did it.

    4. Re:Why must it always be "the janitor"?? by PoopJuggler · · Score: 1

      At a company I used to work for, there were several instances of stuff being stolen, and in all cases it was the janitorial staff. I think the stereotype is justified.

    5. Re:Why must it always be "the janitor"?? by Jucius+Maximus · · Score: 2
      "A few years ago, a securtity head-honcho at my company gave a presentation about keeping confidential documents off our desks, because "you never know when the janitors can come in and just swipe it out with them. I know they don't speak English, but it doesn't take a lot to swipe stuff off a desk...""

      It's easy to blame the person who's not in the room. Why do you think they blame the project's current problems on the person who jumped ship and left the company?

      And FWIW, there were only two occasions I know of where things were stolen from an office where I worked or visited. One of them (involving the theft of the database peoples' candy/cookie stock) was never solved as far as I know. The other one (involving the theft of computer equipment) was conclusively traced to a person on the custodial staff. This person was hired on Tuesday, a thief on the Wednesday, and fired on the Thursday.

    6. Re:Why must it always be "the janitor"?? by xxavierg · · Score: 1

      well, i am glad your anecdotal evidence, from your personal experience in one company is enough to justify an entire stereotype.

    7. Re:Why must it always be "the janitor"?? by Jucius+Maximus · · Score: 1

      Erm, correction: There was a third theft that I forgot about. It turned out that some guy was walking into the building from the street, following people through the security doors after they used their cards, and trying to steal computers. I'm know at one point some employees spotted him and stopped him, but this was after he had gotten some loot already. His description went out in the company e-mail and I don't think we heard from him again.

    8. Re:Why must it always be "the janitor"?? by sanctimonius+hypocrt · · Score: 1

      it's never been a janitor.

      In my experience, it's more likely to be the VP of Marketing.

    9. Re:Why must it always be "the janitor"?? by nels_tomlinson · · Score: 2, Insightful
      I've had my fair share of stuff stolen, and it's never been a janitor.

      I don't think I've ever had anything stolen at the office. I've been a janitor, too.

      If the janitors think they have a soft job with high pay, they aren't going to jeapordize it by stealing a laptop or a paper off your desk.

      If they figure that they wouldn't get screwed any worse elsewhere, I guess the situation would be different.

      The point here is that the janitors are just like you: if they're feeling screwed, they are a lot more likely to compromise their personal standards when tempted. Bear in mind that your excellent employer may contract janitorial services from a contractor who screws his employees.

    10. Re:Why must it always be "the janitor"?? by deletedaccount · · Score: 2, Funny

      Why must it always be "the janitor"?? It's not always the janitor, sometimes it's the butler instead.

    11. Re:Why must it always be "the janitor"?? by Anonymous Coward · · Score: 0

      And its pretty neat that he works at a company with the distinct ability to identify all perpetrators of each and every theft occurence.

      He must work for a detective agency.

    12. Re:Why must it always be "the janitor"?? by Inda · · Score: 3, Interesting

      In my place the high paid engineers do all the stealing of laptops. The rest of us don't have access to them...

      They take them home to do work in the evenings. They dial into the network for free internet. Their kids download Britney. Their begged CD burner is constantly burning audio CDs - they have to beg because there is no real reason for laptops having burners...

      ...they find out that they are unable to install latest_spyware_infested_program. They wipe the hard drive, install their own software (disabling dial-in in the process) and the laptop never sees the office again. They know they'll have a lot of explaining to do if the laptop ever needs rebuilding.

      They see it as one of the perks of the job.

      --
      This post contains benzene, nitrosamines, formaldehyde and hydrogen cyanide.
    13. Re:Why must it always be "the janitor"?? by rowland · · Score: 1

      Speaking as a programmer, the janitors I have been acquainted with have had, on average, higher integrity and a better work ethic than than the average programmer. Also, in my experience, programmers have typically been given greater access to company assets and exhibit a greater sense of entitlement.

      (If you are a programmer and currently work with me, I'm not talking about you--I'm talking about the "dearly departed.")

      To address the point of the article, I think location-based encryption is a clever idea, but it may need to work at the level of the hard drive. I have had the experience of walking into a server room to find a server torn apart and the hard drives missing. I haven't disassembled my laptop, but doubt it would be any harder to remove its hard drive.

      --
      100,000 lemmings can't all be wrong.
    14. Re:Why must it always be "the janitor"?? by voss · · Score: 1

      If the Janitor is a long term employee with benefits , they are probably the most trustworthy employees in the company.

      The custodians who steal tend to be temps/contractors.

    15. Re:Why must it always be "the janitor"?? by Spoing · · Score: 1
      In my experience, janitors and other after hours staff do steal equipment about 1/2 the time.

      The funniest one was right after stealing some equioment, the guilty janitor (who also had keys to the server room) went to 'pop the tape' and found it was entirely hard drive based. The guy still kept the computers and had his house raided to return the stolen equipment.

      Lesson? Don't let anyone have keys to the !@#$!@#$! server room! Extrapolate other lessons from there....

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    16. Re:Why must it always be "the janitor"?? by Spoing · · Score: 1
      1. They take them home to do work in the evenings. They dial into the network for free internet. Their kids download Britney. Their begged CD burner is constantly burning audio CDs - they have to beg because there is no real reason for laptops having burners...

      Not where you work. I burn work-related disks frequently. It's expected now, though I attempt to get people to use the network instead.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    17. Re:Why must it always be "the janitor"?? by Spoing · · Score: 1
      1. And its pretty neat that he works at a company with the distinct ability to identify all perpetrators of each and every theft occurence.

        He must work for a detective agency.

      They are called SECURITY CAMERAS. Most small to moderate facilities have them.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    18. Re:Why must it always be "the janitor"?? by Anonymous Coward · · Score: 0

      Right... and people only steal things in plain view of the completely hidden cameras that are in every office.

    19. Re:Why must it always be "the janitor"?? by MoneyT · · Score: 1

      You would be suprised. When I worked at G.E. we had some laptops stolen. Not only did the employee steal them on camera, but he used his own ID badge to get into the building and through the doors.

      People are stupid.

      --
      T Money
      World Domination with a plastic spoon since 1984
    20. Re:Why must it always be "the janitor"?? by celerityfm · · Score: 1

      The guy looks like he has an honest face atleast :)

      --
      ...unfortunately no one can be told what The Mat^H^H^HGoatse is...they must experience it for themselves...
    21. Re:Why must it always be "the janitor"?? by Minwee · · Score: 1

      As opposed to someone more qualified for his job, like the janitor.

    22. Re:Why must it always be "the janitor"?? by Spoing · · Score: 1
      1. You would be suprised. When I worked at G.E. we had some laptops stolen. Not only did the employee steal them on camera, but he used his own ID badge to get into the building and through the doors.

      Me, nope, I wouldn't be surprised. Stupidity on both ends of the theft -- the thief and the guardians -- seems to be the norm.

      1. People are stupid.

      Yep.

      --
      A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
    23. Re:Why must it always be "the janitor"?? by Anonymous Coward · · Score: 0

      Is this the purported janitor?

    24. Re:Why must it always be "the janitor"?? by Anonymous Coward · · Score: 0

      'cause he's the clever one on Dilbert.

  22. GPS spoofing by Mordac+the+Preventer · · Score: 2

    So... how easy is it to spoof a GPS signal?

    --
    SteveB.
    1. Re:GPS spoofing by Mordac+the+Preventer · · Score: 1

      Replying to my own post is a bit off, but an even better thought... Say that BigCorp uses this idea to protect all of its really valuable data. You get a GPS transmitter that's transmitting a spoofed postion a few miles away, and all of BigCorp's laptops go "OMG, I've been stolen: 'rm -rf /data'".

      --
      SteveB.
    2. Re:GPS spoofing by kk49 · · Score: 1

      Easy but expensive.
      You buy a GPS Constellation Simulator
      Example: http://www.iechome.com/pages/products/simulator.ht ml

      --
      You can have your god back when you are old enough to handle the responsibility.
    3. Re:GPS spoofing by nessdog · · Score: 1

      Nar dont use that, use a proper simulator.... http://www.positioningtechnology.co.uk/ Now thats what I call a simulator!

    4. Re:GPS spoofing by legirons · · Score: 1

      "So... how easy is it to spoof a GPS signal?"

      Depends what system you want to fool.

      If you want a GPS receiver to believe it's in a certain position, you need something like this, which is in the 'telephone our salesman to negotiate' price range (or it might be 'US government only', I can't quite tell..)

      If you want a computer to believe its attached GPS receiver is in a different location, you simply send formatted text from a serial port.

  23. Janitor walks out with it? by Anonymous Coward · · Score: 0

    This isn't the first time s/d has made the janitor an evil person you insensitive clods.

  24. article probably wrong by brlewis · · Score: 1

    I seriously doubt they would use only GPS data as an encryption key. Likely the dongle is doing challenge-response interactions with the wireless hub, and certain actions get triggered when the hub is no longer in wireless range.

    1. Re:article probably wrong by nmg196 · · Score: 1

      No, but at some stage, the device relies on a raw GPS signal. All I was wondering is, what would happen if you spoofed that signal somehow... Maybe the rest of the encryption process won't notice and it will be happy to show you the data.

      As we've seen many times before on Slashdot, lots of new encryption techniques turn out to be gimmicks or marketing ploys designed to sell one specific product. How often do these weird encryption mechanisms actually become mainstream? Not very often.

      Not having a device to examine, none of us can really say yet, but if the GPS part of this system has been done to woo naieve company directors into buying their products who are excited by the buzzwords and technology, then maybe that'll be enough for this company to sell a few products and then disappear off the face of the earth before the first workaround or crack for it appears on BitTorrent and eMule :)

    2. Re:article probably wrong by GotNookie2000 · · Score: 0

      While it may not be impossible to "Spoof" a GPS signal. It's certainly able to be jammed like any other radio signal. I think that location based encyption is a very cool idea, but I can see that they will need to work out issues like this to make it truely secure.

  25. Oh Come ON! by Claire-plus-plus · · Score: 1

    I don't see how this system will stop theft of data. If you want to steal the data just copy the data and leave the machine there.

    I can see the security department scratching their heads while saying "who would have thought of putting all that data on a floppy disk"!

    --
    99 bottles of beer in 175 characte
  26. CUSTODIAN!!! by oiarbovnb · · Score: 0, Offtopic

    what do you got against us anyways?

  27. DVD Regional restrictions redux? by 0x00000dcc · · Score: 1

    I am somewhat ignorant Woz's plan, but does this not remind anyone of DVDs not being able to be played outside of specified regions? How do we know the same thing won't happen?

    --

    -- (Score:i, Imaginary)

  28. Spoof by Renraku · · Score: 1

    It's not a big deal to spoof. All you'd have to do is build a couple small GPS-emulator transmitters and aim them at the device, and have them tell the device that its sitting its comfortable office environment 5,000 miles away.

    --
    Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
  29. "Unplug / get rid of the battery" by da5idnetlimit.com · · Score: 3, Informative

    True, very true...

    Also one should note that in most cases, when someones steals a laptop, it is for the laptop itself, and they couldn't care less for the data on it...as long as they can download the corresponding drivers later on...

    One the laptop get sold, it'll suffer a quick reinstall. and the security dongle will become a nice high tech keychain 8)

    + This system assumes I have a physical access to the machine...

    If I have physical access to the machine (usually you find them plugged into the network, and no screensaver password...) all I have to do is either install a quick soft from the net or from the cd/usb key I have with me...

    Keylogger/bot/zombie/spyware/remote desktop... I can do whatever I want...and your security is breached...

    --
    It takes 40+ muscles to frown, but only four to extend your arm and bitchslap the motherfucker
  30. Reliable GPS *INDOORS*??? by rwyoder · · Score: 2, Insightful

    I've been playing with a high-end GPS device recently, and the first thing I learned was that you can forget about getting a reading indoors. So how will this device work when there is no GPS reading in the office???

    1. Re:Reliable GPS *INDOORS*??? by iggymanz · · Score: 1

      when it starts getting a gps reading, it knows it left the building. Anyway, in most buildings gps will work in some places and not in others - alot of risk for the thief. I suppose one could place a lo-jack type laptop in a faraday cage, but again risky when it comes type to either strip or access it.

    2. Re:Reliable GPS *INDOORS*??? by silentmusic · · Score: 1

      Search for "Indoor GPS" on google

      Global Locate, SiRF, Qualcomm (snaptrak),...

      --

      Things are not as they appear, nor are they otherwise.

  31. Re:w0z is a nutjob at best... by erikharrison · · Score: 4, Interesting

    Wozniac is a nutjob no doubt about it. He'd still be a legend, though, even if it weren't for Apple. He was an early phreaker, and a good friend of John Draper - Cap'n Crunch for gods sake! He was an important figure in the Silicon Valley hobbyist community, and even if he hadn't done either Apple or phreaking he'd still be a footnote in the big book of commodity PCs because of that. Certainly more than you or I can claim.

    He and Jobs didn't start their relationship selling computers together - they originally sold blue boxes. Woz still works for Apple, mostly as a consultant, and he and Jobs still collaborate (though Woz has claimed that on many occasions Jobs credits him with ideas that he had minimal participation in).

    Since leaving Apple he's been as much a humanitarian with his skills and money as Bill Gates (though in smaller absolute amounts). He personally provides free tech support for the local school system, and (at least when System 8 was still cutting edge) held computer classes for preschool and elementary school kids. He's sponsered charity concerts, and more.

    Problem with Wozniak is he has a great technical mind, a wonderful sense of playfulness, and even a good sense of what users want in products, but his business sense is poor. That's why there hasn't been as much output from Woz since leaving Apple - their hasn't been a Steve Jobs. Wozniak was the Paul Allen to Job's Bill Gates, and much like Allen, Wozniak has dabbled here and their, with no truly successful financial venture yet. That doesn't mean he's worthless

  32. GPS and Signal. by jellomizer · · Score: 2, Insightful

    With my experience with GPS. They tend not to get a signal unless you are outside and have a clear view of the sky. When Driving in tunnals, or a road with a thick covarage of trees I tend to loose signal. And I have never got it to work while I was inside my apartment. Most people tend to use Laptops inside buildings and a lot of them are not nessarly near windows or have the window shades open (the heat of an afternoon sun in summer is pritty bad). So for most cases this will not work because they cannot get a GPS signal.

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    1. Re:GPS and Signal. by Ulath · · Score: 1

      To get the laptop out of the building, you'd have to leave the building, probably into a carpark, which usually have large clear views of the sky, and I guess as soon you did the system would be alerted...

    2. Re:GPS and Signal. by jellomizer · · Score: 1

      But a lesser chance of having network access in the carpark. And all the criminals out there who steel all this equipment will stand out in the open air. This is slim.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
  33. Woz? by Claire-plus-plus · · Score: 1

    Will Bill Gates soon be inventing a product with the Acronym "B.I.L.L" for the product name?

    --
    99 bottles of beer in 175 characte
  34. New Game? by rihock · · Score: 1

    Why do I see this as new GPS game-- find the hidden PC and try to find the hotspot to de-encrypt the secret message??? Coming to reality TV near you (sort of near, or as close as GPS can)

    --
    # nohup ./start_sig
  35. floppy? by Anonymous Coward · · Score: 0

    512MB USB keychain flash, actually.

    1. Re:floppy? by Claire-plus-plus · · Score: 1

      some companies have these blocked on their pcs. Nobody blocks floppies though.

      --
      99 bottles of beer in 175 characte
  36. good against wardriving by spectrokid · · Score: 2, Interesting

    Imagine that your WEP gets encrypted with a key dependent on your location. A large company could enable campus-wide WIFI, but you would only be able to get on the network if you are inside one of the buildings. Not the ultimate protection, but one extra barrier.

    --

    10 ?"Hello World" life was simple then

    1. Re:good against wardriving by matts-reign · · Score: 1

      But what about those of us who like to go outside with our laptops .... wait ... this is /. ... we don't go "outside"

      --
      Waffles rock.
  37. Probably is more than plugging a GPS in. by hey! · · Score: 1

    Yes, but he's not talking about putting a GPS on the serial port.

    What he's talking about is something closer an iButton dongle that would only work at a particular position. This will communicate with a wireless infrastructure that will provide the key to unlock data.

    How GPS figures in is not entirely clear from the article, but it appears to be a kind of two factor security: you can get to your data if (a) you are in the presence of an authorization agent and (b) you are in the right geographic place. In effect you will be able to say that a particular memo is only readable on campus. You can't take it home with you, for example.

    My guess is that the GPS is attached to the authorization agent, not the laptop. For one thing, it's rare to get any kind of GPS coverage inside buildings. The reason for this is that it would prevent you from stealing the authorization agent as well as the data on the laptop. Again I'm guessing, but you'd run a coax cable to an outside antenna. As you point out the NMEAstring is childishly simple to fake, but the actual radio signal would require building special hardware and software to fake.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
    1. Re:Probably is more than plugging a GPS in. by Ced_Ex · · Score: 1

      Sure, the page may not load should you be outside of the set geographic range, but what's really stopping anyone from getting in range, take a screen capture and take off?

      Perhaps if you can only get the laptop to turn on in pre-determined geographic locations it would be more benefitial, but then again, that would defeat the purpose of having a laptop to begin with.

      --
      Live forever, or die trying.
  38. Indiana Jones by MetalliQaZ · · Score: 1

    ...So THATs how the temple knew that they were stealing the holy grail! Always wondered how they did that.

    -d

    --
    "Here Lies Philip J. Fry, named for his uncle, to carry on his spirit"
    1. Re:Indiana Jones by iggymanz · · Score: 1

      yes, but for civilian religious booby-trap use the ancient gps signals were intentionally randomly time shifted so accuracy was only to the nearest 3 cubits.

  39. Oh please by Anonymous Coward · · Score: 0

    Woz has had a SUCCESSION of crappy ideas, turned into crappy products.

    While some of us are busting our butts trying to do hard work, why does he get an automatic free pass into Slashdot (and elsewhere) every time he has another hallucination and dips into his pocket to have a few things built?

    The guy built a really cool floppy disk drive once. Why again does this equate to a free PR pass to report his every burp?

    And yes i did R the F A

  40. Mobile PC. by leuk_he · · Score: 1

    Isn't the point of a laptop that are designed to be mobile? And if you want to restrict the mobility wouldn't it be easier to attach a network cable & lock to it instead of this fancy encryption?

    Or if it is to be used in 2 places use 2 desktops? what am i missing?

    Ok, this is no solution for the boss who must have the most fancy laptop there is to see the best screensaver. (dilbert)

    1. Re:Mobile PC. by farnz · · Score: 1
      Simple scenario:

      You have a large campus, and certain employees are expected to move around campus, setting up their laptop to work wherever they happen to be. This may be in the factory, with Accounts, next to an engineer, anywhere on campus. How do you ensure that they can't leave the campus with their laptop?

      A lock to the desk doesn't work; it stops them going around campus. If you're looking at this sort of solution, you don't want to rely on trust, either.

    2. Re:Mobile PC. by leuk_he · · Score: 1

      f you're looking at this sort of solution, you don't want to rely on trust, either.

      You don't trust your engineer with his laptop, but you do trust him to tinker with your machines? And you do trust some hardware lock. Check yourself.

    3. Re:Mobile PC. by farnz · · Score: 1
      No, you do trust your employee, but you're too paranoid to depend on that trust when you can add a technical solution to check up on him.

      Should he start trying to take the laptop off-site without permission, you may decide not to trust him in future, in which case his job is at risk.

  41. Re:You make me sick by julesh · · Score: 0

    I think the theory is more along the lines of, if you want to steel a laptop from X company to get data from its hard disk, the easiest way of doing this is probably to get a job there as a janitor and swipe one while you're doing your rounds.

    Janitors get access to all areas of an office, even ones that are usually kept secure. There are few qualifications required for the job, beyond having good references (which can be faked if you have the infrastructure for it). It's simply the easiest way in. And even if you can't, it's a low paying job which means that those doing it are more likely to be bribable than, say, the IT staff.

  42. Easy to overcome... by Maljin+Jolt · · Score: 1

    Cut and break 'top to pieces. Pick the hard drive from the rubble.

    --
    There you are, staring at me again.
    1. Re:Easy to overcome... by Lonesome+Squash · · Score: 0, Redundant
      3. Try every possible cryptographic key to read the contents of the drive.

      4. ?

      5. Profit!

      --
      Behold the riant ape! Beware, his crooked thumbs!
    2. Re:Easy to overcome... by Maljin+Jolt · · Score: 1

      Why did you try so called "every possible" crypto key? If you are not a complete moron, you should already know the correct coordinates. And everything other (keys, software) must be on the disk already.

      --
      There you are, staring at me again.
    3. Re:Easy to overcome... by Lonesome+Squash · · Score: 1
      Why did you try so called "every possible" crypto key? If you are not a complete moron, you should already know the correct coordinates. And everything other (keys, software) must be on the disk already

      Because not being a complete moron, the designer of the device would not take the plaintext coordinates and use that as the cryptographic key. The designer would create a hardware black box that has an integrated GPS. The device spits out a key. If you're in the right location, it's a valid key. If you're not, it's an invalid key. Standard crypto software then uses that key to decrypt the contents of the drive

      However, you're correct that it's unlikely that you'd need to try every single possible key. On average you'd only have to try about half of them, leaving you plenty of time to use the data before the heat death of the universe. :-)

      --
      Behold the riant ape! Beware, his crooked thumbs!
  43. dongle reader and emulator by Anonymous Coward · · Score: 0

    Easily fits between laptop and Dongle!

    Emulates either laptop or dongle via selectable switch.

    Coming soon to a store near you....

  44. Keeping your data safe from thieves by Mwongozi · · Score: 1
  45. Probably nothing... by computational+super · · Score: 1
    Imagine your laptop screaming 'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it.

    I would imagine this would get the same immediate response from law enforcement and concerned citizens that a blaring car alarm gets right now.

    --
    Proud neuron in the Slashdot hivemind since 2002.
  46. Getting stupid... by evilviper · · Score: 1

    Countermeasures to laptop theft are really getting stupid at this point.

    Put 2.5" HDDs in a bit of a caddy to protect it, then you just pull it out and put it in your pocket. Notebooks could be made so that they pop the HDD out when the lid is closed, it is shut-down, or put into standby, and beep after a few seconds if the HDD hasn't been removed.

    This won't help immensely if you leave your laptop running, with an open lid, unattended, in a public place, but you probably don't care about security if you do that.

    For high security (eg. MI5), it could be attached by a chain or cable to the individual.

    The hard drive isn't much bigger or heavier than the smartcards being used to encrypt some notebook's hard drives. Plus, it's a MUCH BETTER solution.

    --
    Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
  47. Airplane by Anonymous Coward · · Score: 0

    So wait .. the whole point of a laptop is portability. Why not have critical data on a server or desktop instead of on a laptop?

    I suppose if the device allowed usage of the laptop outside the building but disallowed access to certain files deemed critical .. that would be nice.

  48. In Soviet Russia by myukew · · Score: 0

    In Soviet Russia people encrypt the satellite's data not the other way round

  49. GPS inside? by nessdog · · Score: 1

    Has anyone given a thought to the fact that the GPS signal is weak and wont penetrate a building. They would have to install somesort of repeater system or psudolites.

    1. Re:GPS inside? by silentmusic · · Score: 1

      Actually I think that the first people do to something about it are all rich now. Look at what qualcomm paid for snaptrak.

      Just search for "indoor gps" on google. This is a hot area right now.

      --

      Things are not as they appear, nor are they otherwise.

  50. Dongle hell by famouswhendead · · Score: 0

    I absolutely hate dongles... Lose it and it becomes a really tedious operation to get a dongle back from the manufacturer. (YES sir we do believe who you are but we will need verification, please send your first born and a pint of your blood please)

  51. Not another dongle! by Anonymous Coward · · Score: 0

    Hell, dongles were used for copy protection long ago, and people despised them. Now someone's trying to introduce them again? We already know they're a pain in the ass.

  52. GPS is extravagant for most applications. by thegnu · · Score: 0

    You could just embed transmitters in the walls. That would do the job for businesses trying to keep their hardware on grounds. Although I guess all you'd have to do is steal or reverse-engineer a transmitter before you stole the hardware.

    The best solution would be a combination of both, I suppose, a GPS integrated into the system and a wireless boot key. You could even do away with the physical external dongle if you wanted.

    The other issue is I would hate the idea of working for a corporation that assumed I was a criminal from the get-go. But I guess most corporations are that way.

    --
    Please stop stalking me, bro.
  53. RTFA mods :) by Anonymous Coward · · Score: 0

    "The dongle can be programmed to delete data or shut down sections of the device. Once the computer is removed from the physical zone, the keys are lost or unavailable, and the hard disk is gibberish," Wozniak added.

  54. GPS does not work indoors by Anonymous Coward · · Score: 1, Insightful

    Unless you have a veiw of the sky.

  55. Better idea - wireless hardware key-pair by Se7enLC · · Score: 2, Interesting

    I have a better idea - you build a pair of hardware keys that operate like rfid ID tags, sort of (except that the key would be battery powered and generate different keys based on what it was given for a timestamp - like a secureID card for a vpn).

    You'd hang one of these little devices off your belt or on your keys or something. When the laptop is within a few feet of you, you can access the encrypted data. When it's not, you can't. Seems simple enough....now we just have to make sure that nobody gets smart and tapes the device to the laptop (or packs it in their laptop bag).

  56. Should be presence not location by Anonymous Coward · · Score: 0

    Location based encryption seems like the wrong solution since it removes the one big advantage a laptop has over a desktop, mobility. If you don't want people to carry certain files out of the office on their laptops, make sure those files can't be put on the laptops in the first place.

    However, presence based encryption could be interesting. And there are many ways to detect presence most of which are probably more reliable and even work indoors, unlike GPS. Those darned RFID tags in your clothes (finally a use for them), the bluetooth signal from your wireless phone, a removable USB device, a password that has to be re-entered every so often.

  57. Same as... by Sax+Maniac · · Score: 1
    Imagine your laptop screaming 'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it."

    Yawn. It would probably get the same reaction as car alarms do these days: great, some idiot accidentally set off their car alarm again. Where's the coffee?

    --
    I can explanate how to administrate your network. You must configurate and segmentate it, so it can computate.
  58. Do you fly? by Slashamatic · · Score: 1

    Then your laptop goes through security. You may get held up by the search and your latop sits there waiting to be taken. This has happened a few times at airports even though you would think the security area was crawling with personnel and videoed.

    1. Re:Do you fly? by mpathetiq · · Score: 1

      I guess I was not 100% accurate. It rarely leaves my side. Luckily, I have not yet run into an instance where my laptop was left in an unsafe environment for longer than about 5 minutes or so.

      My Lappy 486 is treated better than my cat.

    2. Re:Do you fly? by Slashamatic · · Score: 1

      It really is the five minutes that makes all the difference. Actually modern laptops are smaller/lighter but even briefcases get stolen. Unfortunately it seems that the best line of defense is to have a bag that doesn't look like it holds a laptop.

  59. Yawn... by Fahrenheit+450 · · Score: 1

    So someone's finally doing something with Dorothy Denning's Geo-Encryption and location based authentication ideas from a couple of years ago.

    Wake me when Woz has an original, interesting idea...

    --
    -30-
    1. Re:Yawn... by TheLink · · Score: 1

      Yeah and Caveman Ogg came up with this idea tens of thousands of years ago. Unfortunately for various reasons it wasn't implemented.

      Douglas Engelbart and his team's systems/technologies were way way before their time. Hardly anybody else "got it", or even if they did, they couldn't really make full use of it.

      Decades later, people came up with the same ideas but this time the market was ready for their adoption.

      Original and interesting ideas are nice, but it can feel like a curse if you have them way too early or lack the resources to implement them.

      --
  60. Stop! by buss_error · · Score: 3, Interesting
    'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it."

    I've been in offices for many many years. There has been only one time the Janitor Did It, and it was a case of they put it somewhere we wern't expecting.

    Can we stop with the steriotype? All of the janitors I have known have been honest, hardworking people that are just trying to make a living. While I a sure there are dishonest janitors around, I sure that like anywhere else the vast majority are not crooks.

    --
    Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves.
    1. Re:Stop! by Anonymous Coward · · Score: 0

      Can we stop with the steriotype? All of the janitors I have known have been honest, hardworking people that are just trying to make a living.

      I don't think it's a stereotype. When people talk about office security, there are inevitably people who look around and go "oh, non of my co-workers are thieves, and nobody else comes into the office, so I don't need to worry about security, the locks on the doors are enough". The janitor example is merely a reminder that they haven't thought it through properly.

    2. Re:Stop! by rthille · · Score: 2, Interesting

      I don't know that the use of the janitor is meant as an inditement of janitors and their honesty, but rather of society. The reason that janitors are used is because they have opportunity (because they have to to clean) and and due to the inequity in society they can be said to have motive. After all, when you're working around equipment that costs as much as you make in a year, there's more temptation to steal it than if you work around stuff that costs what you make in a day. It's the same reason why people who drive expensive cars don't feel comfortable parking their car in a poor neighborhood.
      But you're right, statistically, it's the employee making $80k who thinks he should be making $120k, rather than the janitor making $10k

      --
      Awesome furniture, accessories and cabinetry in Santa Rosa, CA: http://humanity-home.com/
    3. Re:Stop! by TomorrowPlusX · · Score: 3, Informative

      Not to mention that janitors -- being blue collar and generally lower on the social totem pole -- *know* they're the first to be suspected/fired when something goes missing.

      Generally speaking the theives are coworkers, with sticky fingers. But usually it's people -- dressed nicely -- who just walk in off the street, looking like they belong, and picking something up and quietly taking off.

      We've had a fair bit of the latter where I work.

      --

      lorem ipsum, dolor sit amet
    4. Re:Stop! by Erwos · · Score: 1

      "Can we stop with the steriotype? All of the CEOs I have known have been honest, hardworking people that are just trying to make a living. While I am sure there are dishonest CEOs around, I sure that like anywhere else the vast majority are not crooks."

      -Erwos

      --
      Plausible conjecture should not be misrepresented as proof positive.
    5. Re:Stop! by Anonymous Coward · · Score: 0

      It's not that the janitors steal things because they are dishonest. It's that thievs can become janitors to gain access to your secrets.

    6. Re:Stop! by Eraser_ · · Score: 1

      I think janitors are some of the smartest people around. Who else could trivially pilfer anything in the building and get away with it all these years? Careful planning and manipulation have created a society completely dependent on someone else doing the dirty work. The same thing with this whole computer fad. Systems administrators have total control over your dataflow, much like the janitor controls the paperflow. Janitors have been training people like them, long hours which start early and end late in the night, and who are badgered by everyone to do even the most minor of tasks.

      Carefully, sysadmins and janitors will join forces to rule the world.

      Is your tinfoil hat OSI network model compliant? Seven layers of tin foil or they might hi-jack your datalink.

  61. Janitor detection algorithm by titten · · Score: 1

    Yeah, yeah... Anyone can use a GPS for what they want.
    What impresses me, is how this will detect that the janitor took your laptop.

  62. Wish we had more details by Andy+Dodd · · Score: 1

    The article makes it sound like the system relies partially on security-through-obscurity (the w0zNet thing), but that doesn't sound like something Wozniak would ever think of trying to rely on... He's just too brilliant for that.

    I wouldn't be surprised if in addition to a decent amount of obscurity, the system also has plenty of true security, i.e. it would be secure even if every detail of how the system works was known.

    Also, the whole GPS thing doesn't make much sense to me. Too easy to spoof an incorrect GPS location at the access point, and most of the time, the dongle itself wouldn't be receiving GPS signals (most office buildings are constructed mainly from metal, the end result is most RF signals don't penetrate the walls. Cell phones barely worked in most areas of the last place I worked, no way GPS receivers would have.)

    --
    retrorocket.o not found, launch anyway?
  63. They're small fry next to the white middle class by Zhe+Mappel · · Score: 1
    Evil, laptop-stealing janitors? The ones who used to eat steak with welfare coupons, and now surf for Russian porn on our Powerbooks and T1 lines?

    Well, how else are they supposed to get in on the $300 billion annual orgy of white collar crime? Or use this honcho's services?

  64. GPS indoors? by uqbar · · Score: 2, Informative

    I have a 1st generation GPS device so maybe my info is out of date, but it has a hard time getting a location in heavy forest, never mind in a massive concrete and steel building. All this seems like it would rule out most real world applications, so I think something is missing in this story - Woz aint no dummy. Any conjectures?

  65. Secure? I don't think so... by Anonymous Coward · · Score: 0
    Ok, lets think about it a minute. A "GPS position" can not be used as a "key" directly. The data jumps around, bits changing, constantly. Taking the "position" and finding the delta from the center part of a "zone" will also be jumping/drifting so the bits are not stable enough to use as a key either. That leaves using something like:

    if ( fabs(position - zone) < X.max_distance)
    load_the_key_for_zone_(X.the_key)

    Which just implies that the key exists on the laptop drive, or the dongle, for each zone defined. So, yank the drive, plug it in to another machine, find the key and decrypt the data!

    Ok, yea, the key itself might be encrypted but then what do they use to encrypt that? Passwords? We all know how to handle that problem too...

  66. casual classism by Anonymous Coward · · Score: 0

    Yes, only janitors steal. Esp. if they're black or brown. Notice how you'll never find a Jewish janitor? Otherwise they'd steal, too, believe you me.

  67. I am not Woz by museumpeace · · Score: 1
    but I had an idea like this. When USC and the movie industry started a reasearch consortium two years ago to figure out how to digitally distribute movies to theaters securely, I offered them this suggestion:
    1. embed GPS location data in the encryption key
    2. build [like tighlty integrated and potted] a GPS reciever into the digital theater playback equipment.
    3. scramble the GPS output in some way that is also accounted for in the encryption of the digital movie stream and is unique to the serial number of the playback equipment
    4. if the digital copy of the movie is not being decrypted on a playback unit that is in the right place, all you get is a call from the FBI.
    I am leaving out a few details here of course ;)
    But I never heard back from them...like I said: I am not Woz. This application of location-based encryption does not have the numerous problems many posters have raised concerning location based enabling of functions in a laptop [or any other equipment desinged NOT to have a set location...duh!]. Also, these ideas add cost to anything you apply them to: laptops are commodity items and very cost sensitive but a movie theatre spends gazillions on its [FIXED LOCATION] equipment anyway.

    Slashdotters: I can't think of a better bunch of people to share wortless ideas with!
    --
    SLASHDOT: news for people who can't concentrate on work or have no life at all and got tired of yelling back at the TV.
    1. Re:I am not Woz by museumpeace · · Score: 1

      Doris Dennings work cited by other poster might have been seen as prior art...it was 6 years ahead of me. the USC facility I mentioned is on line at http://www.etcenter.org/DCL.asp

      --
      SLASHDOT: news for people who can't concentrate on work or have no life at all and got tired of yelling back at the TV.
  68. burning mod points in defense of the janitors by Anonymous Coward · · Score: 0
    Poor janitor...

    He's been accepted into the US to do a job nobody else wants do do...

    He's been instructed to take trash out of the cubicules, an ingrateful task he's been faithfully carrying day in, day out...

    Back in his country, he graduated in Computer Sciences, but the civil unstability and the widespread violence and police corruption made him choose the US, hoping to give his kids and family better oportunities and living standards...

    One day, after everyone has left the office, he sees a stray laptop running XP. It was loaded with viruses and had no firewall, a fact he deduced by the large number of windows popping up spontaneously, pushing penis enlagement pills. "Poor guy", the janitor concludes, "He just can't get any work done". Eager to impress, taking a proactive action, using his knowledge of CS and IT, he takes that laptop into the trash bin, since no one should be forced to use that s****...

    "I've done something good today" he tells his wife, ater his shift is over, when he's back home. He enjoys a nice dinner and sees his kids play and goes asleep. He's happy and all the hard time he's endured back in his 3-rd world country is just a faint impression left in the back of his mind.

    Next morning the local police pays him a visit. They did not lock him up, though, but he's promptly fired from the company he used to work for and now faces a legal suit by the previous owner of that laptop.

    He finds out that he cannot get a job elsewhere, given the increased xenophoby after 9-11. Yeah. The janitor learned, in the harsh way, how people is ingrateful. Poor janitor. It's always the janitor.

  69. Why so complicated just to make it 'not work' by Anonymous Coward · · Score: 0

    Why not just use WiFi to distribute keys to authenticated users near by? If you move to another WiFi location the key is different, or just absent. Just leave the WiFi non-"dongle" locked in your file safe so the key is not available when your laptop is not at work, or in your pocket/keychain so the laptop only works when you are physically near by.

  70. Can you image by Anonymous Coward · · Score: 0

    a beowulf cluster of stolen laptops!

  71. Similar to an idea I recently had by K-Man · · Score: 1

    I was thinking it would be nice if my iBook could auto-recognize my home hub and auto-login there. Outside the "zone", it could default back to login-on-wake. Coupled with the various options for encrypting my home directory, etc., this could be similar to what Woz is proposing.

    Of course, I haven't sat down to figure out the cryptological protocol needed. For the average thief, a simple insecure method would probably work.

    --
    ---- "If we have to go on with these damned quantum jumps, then I'm sorry that I ever got involved" - Erwin Schrodinger
  72. How long till this is applied to people? by multiOSfreak · · Score: 1

    Every time I hear about this kind of cool tech, my mind immediately kicks into conspiracy gear. You know the US government is going to be interested in this type of tracking, probably for people. Especially, you know, "enemy combatants" within US borders.

    Commence with the tin-foil hat jokes.

  73. i think there on the right track... by Legato895 · · Score: 1

    i think location based encryption IS the way to go becaue its essentially getting to the very root of the problem, that is, access of encrypted information outside of the company. while something such as gps is maybe not as hack proof as it could be, why not just bombard the structure with signal that the pc could read and realize its in the building. copper mesh coat the walls and there you have it. the signal could be anythign from radio to wifi, mix it up, have it synced with the laptop and alway changing.

  74. Okay by pjt33 · · Score: 1
    > nw


    It is dark. You might be eaten by a grue.

  75. Lots of peoples missing point by foniksonik · · Score: 1

    If this is about encryption it has nothing to do with the laptop being stolen and everything to do with the data being stolen.

    Forget about how easy it is to unplug/shutdown said laptop and leave.. obviously it's quite easy.

    What this would do is to only allow decryption of the data stored on that laptop while within the vicinity of the approved location.

    Anywhere else and the data is encrypted. sure you can wipe the drive, but that is what they want you to do anyways...

    And yes people do store sensitive data on their laptops.. plenty of business men have very sensitive financial information stored on their laptop and typically they do encrypt it but this system would make that encryption just a little more secure by salting the method with the GPS data.

    --
    A fool throws a stone into a well and a thousand sages can not remove it.
  76. Sci-fi comes true again by zoeblade · · Score: 1

    This sounds a lot like Akili Kuwale's encryption method in Greg Egan's novel Permutation City. It's always good to see sci-fi coming true :)

  77. bigotry against janitors by Anonymous Coward · · Score: 0

    sorry, folks, you are bigoted against janitors. you need to realize that theft of office material is more likely from rich people who know they can just blame it on the janitor, and use the inherent classism and bureaucratic infighting of the workplace to get away with it.

    no janitor i have ever met would steal a laptop. maybe a little cash, maybe a coca cola. but a laptop? they know all sorts of hell would break loose and that they would be the primary suspects. furthermore, it would be wrong.

    get off your high horse. how many of you stole thousands of dollars of software or movies in the name of 'education'?

  78. Janitor? by ZappaSoft · · Score: 1

    Why you all over Janitor's video controller?

  79. umm imagine this by Anonymous Coward · · Score: 0

    "Imagine your laptop screaming 'I'm being stolen! I'm being stolen!'"

    Imagine me ripping out the battery first then formating my new laptop

  80. "PAUL ALLEN WAS HERE!" by Saeed+al-Sahaf · · Score: 1
    Wozniak was the Paul Allen to Job's Bill Gates, and much like Allen, Wozniak has dabbled here and their, with no truly successful financial venture yet. That doesn't mean he's worthless

    Wow. You don't live in Seattle, obviously. Otherwise you would have more knowledge about some of the very big things that Paul Allen has his fingers in (and I don't mean EMP). Thing about Allen is that he doesn't seek out the spotlight, so his many ventures don't have "PAUL ALLEN WAS HERE!" plastered all over them.

    --
    "Who are in control, they are not in control of anything - they don't even control themselves!" - Glen Beck
    1. Re:"PAUL ALLEN WAS HERE!" by Anonymous Coward · · Score: 0

      I lived in Seattle for a few months, during which time EMP opened. I recall that someone paid for the municipal busses to have painted on the side, /en espanol/ for some reason, "Thank you, Paul Allen, for EMP!"

      Gods, that was nauseating, even though I even admit that I rather liked EMP itself...

  81. blech... by Morphine007 · · Score: 1

    Imagine your laptop screaming 'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it."

    myes.... and imagine the look on the face of your boss when he realizes that by "working from home", you really meant working from the strip club ;-)

    1. Re:blech... by taradfong · · Score: 1

      I dunno, I'd admire the dedication that he brought his laptop *everywhere*.

      --
      Does it hurt to hear them lying? Was this the only world you had?
  82. hidden RFID providing secret by a1bert · · Score: 1

    i do not care HW but I care my data, what about asking hidden rfid (it's small, it can be hidden well) for secret key ......

  83. Encryption can only go so far... by Anonymous Coward · · Score: 0

    Encryption systems can only do so much to protect data. The problem is that there is always, always the human factor. People in general are not always aware of what they are doing, especially with computers.

    People will forget to activate encryption protocols, or even unknowingly deactive them. Even without that, a wise enough information theif will know ways to make a target actually give him information.

    I'm not saying that encryption is unnecessary, it has a purpose. But it's kind of like the old saying: "Locks will only keep out the honest criminals."

  84. My defense against my laptop being stolen... by allanc · · Score: 1

    It's a piece of crap.

    Seriously, the PS/2 controller chip burned out, so it no longer has a working trackpad, and the cover over the RAM got lost. I suppose someone could steal one of my exposed SO-DIMMs, but one of those doesn't work (I've been too lazy to try to figure out which), so it's 50/50 that I'd be fine anyway.

    All this and it's only a 400MHz PII, too.

    --AC

  85. "Save me, Jimmy!" by jaywood · · Score: 1

    Imagine your laptop screaming 'I'm being stolen! I'm being stolen!' and paging security as the janitor walks out the door with it."

    Good, because that worked so well for the flute in H.R. Puffenstuf

  86. A better solution for location awareness... by kazzaerexys · · Score: 1

    There is a company called DAT that is developing a technology that does (1) non-GPS based location awareness and (2) strong non-algorithmic random numbers. There technology is accopanied by a security framework that allows for all sorts of configurations, particurly dynamic access level based on verifiable location.

    Anyone who is interested in this thread should go check out their site. Very interesting stuff!

    K.

  87. MOD PARENT UP by taradfong · · Score: 1

    Thank you. It took 15 posts before someone actually got it.

    --
    Does it hurt to hear them lying? Was this the only world you had?
  88. This isn't new by codewritinfool · · Score: 1

    Dorothy Denning proposed it back in 1996, I think.

  89. Re:w0z is a nutjob at best... by Keith+Handy · · Score: 1

    Never underestimate how knowledgeable you can become by watching a movie. ;)

    --
    -- -Keith
  90. Now available with contrast by Anonymous Coward · · Score: 0
  91. Does in work? by Anonymous Coward · · Score: 0

    Doesn't think GPS work indoor...

  92. Re:Does in work? by shadowsurfr1 · · Score: 1

    As long as there's a signal to a bunch of satellites in space or event units in the building acting as satellites, it should be fine with the right hardware and software.

  93. Re:You make me sick by otterpop378 · · Score: 1

    I don't know though... Every janitor that i've ever known has been married / had a significant other. Can't say the same for IT staff... and who says the bad guys would bribe with money anyway?

    A case of jolt cola, a couple of pr0n dvds... the whole data center can be yours.