Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Assuming this physical access claim is truthful (and i have doubts), I would feel at this point its budget letting him down. If your threat model includes "targeted attacks from people with physical access", it's time to run a vm on aws or azure and use the tooling they make available to secure it further. If you want tonnes of resourcing at a quite low budget, there's only a certain amount of "calling out" the group that supplied it that's reasonable.


I believe most of these "physical attacks" are datacenter support teams being socially engineered and not state-level actors. They hook up a USB rescue drive to "help" you back into your server, using full disk encryption or locking down the BIOS can thwart such attacks.


You know as much as I'm generally unhappy with what MS is doing with forcing TPMs on Windows 11, I have to say Bitlocker on Windows is basically single click and a perfect solution, and I'm a bit disappointed in the scale of every comparable Linux guide I just Googled up. I can see why the average company doesn't have it deployed.


LUKS isn't rocket science, you're looking at the wrong guides. using the TPM to encrypt a partition is a few commands on the shell.


Sure, perhaps, but parent’s point still stands that AWS techs are not plugging USB drives into servers, because their threat-model already includes state-sponsored attacks.


Not necessarily SE, there's been tons of 0days exploited against stuff like WHMCS, Hostbill, Kayako and many other systems used by hosting companies to manage this kind of thing.

Colocation and epoxy in any relevant ports is the obvious way to avoid this.


If he has enough Bitcoins for it to be possible for ‘many of them’ to be stolen, he doesn’t have a small budget.


Just makes this thread stranger. I know if I had over $3m in btc and was working professionally with them I wouldn't state my top budget was $55.

Edit: his tweets specifically talk about not using "cloud nonsense " and states getting your own key to a rack is too expensive for him.


My goodness. Really? He refers to "cloud nonsense", then uses a "dedicated server"? That's a new kind of special.


From his tweets: he was renting a physical server for $55/m. So, a total joke.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: