Prey on MAC OS X Lion: Some questions!

520 views
Skip to first unread message

Mac_Prey_11

unread,
Aug 10, 2011, 11:27:33 AM8/10/11
to Prey
First, thanks to the developers for the great software, and all the
work done so far on it.

I installed, ran and tested Prey on my Macbook Air with Lion,
everything works wonderfully fine: reports, cronjob still running
after reboot, alert message, etc etc

Now, here is my worries/problems:

1) Lets assume a real life scenario. A thief steals the laptop, goes
home: either he starts using the macbook, or if he his smart just
formats it and reinstall the OS, in which case Prey wont help anyhow.
Now, lets say I was using the admin account with a password for the
screensaver and login. When the thief opens up the laptop, he wont be
able to login.. which means also, he wont be able to connect to a
Wifi. Most of the Wifi spots in 2011, at least around me, are password
protected. Actually on average, 95% of them are pwd protected. So in
this case, the thief cannot login and cannot connect to the internet.
There is no point to hook up his ethernet cable if he cannot login in
the first place! We are stuck here. I know Prey runs as root through a
cronjob, so at login screen its still executing the script, but if we
cannot get the report, we are out of luck.

Any solutions to this? Well, I only can think of 2 things:
A) create a guest account and have it password-less so he can try that
and login, allowing only for example a browser and Airport to run, and
maybe network setup.. then we can hope he connects online. I have not
tested this scenario yet, technically the script should still be
executed. I might give it a try.
B) leave the login/screensaver without a password, but at the same
time encrypt the important files/apps/data in a folder under Lion. The
rest is not really THAT important, as long as the browser does not
have any important tabs open with email account, etc etc. Still, its
risky, but at least we give also the thief more chances of getting
online, which is our goal.

2) If we password protect the BIOS, and without an admin pwd, the
thief may have only a couple of possibilities:
A) swap the HDD.
B) Use the guest account and keep the laptop (good for us).
C) Give it to some tech savvy guy and try to bypass the BIOS pwd, and
the login pwd. More work here, but duable.
D) Physically destroy the laptop.

I believe if there is no Guest account enabled, we are making it much
harder for him to connect online, and we are forcing him to swap HDD
or to bypass the pwds (BIOS/admin), which is bad for us, the owners.

I just wanted some feedback/ideas on the above if possible. Thanks.

Drew Reece

unread,
Aug 10, 2011, 2:11:39 PM8/10/11
to prey-s...@googlegroups.com
1.
Yep Prey has flaws. It will look for an open wifi network even without an active user session, not really much else can be done unless Apple start fitting cellular connections &/or GPS devices.

1A.
A standard OS X user account without a password may be suffice to get the user online. You could also include a password hint to help users who fail 3 times in a row. A savvy Mac OS X user will know that a guest account deletes your work on logout so it may discourage them from using it, hence my suggestion for a standard account. There may be info info in the Prey FAQ about 'honeypot accounts' I just can't see it, there is Firmware password info in there.

1B.
It's best if your account locks down when it goes out of your sight, your keychain uses the same password as the account (by default). This potentially unlocks the passwords you have saved. Consider the 'lock keychain' options to lock it on sleep/ x minutes etc. It is in the Keychain Access Preferences.
Also look at the security options in System Prefs - I'd consider secure RAM & the file vault option. You can also store important files inside encrypted disk images & don't store the password in the keychain. 

Exposing you own account is a bad idea, you will inevitably forget something & the thieves may be able to exploit that data eg your holiday schedule & address details or some browser cookies… You also could have important data stolen in a few seconds by someone who only has access to the machine & you may not realise. Admin accounts can also edit other accounts if the user is smart, so you are potentially opening up any other accounts too.

2.
A Firmware password is a good idea on a laptop, the tool is in the Apps/Utilities folder in Lion IIRC.
Sadly they can also be defeated with some simple tricks (I'm not tellin' :^) ) but they add another layer to the security of your data.

You are correct, a single secure account may make it less likely to get reports, I suppose you could set the honeypot account to auto login if you could face the hassle of logging out of it after every reboot. There is also the possibility of making your own account not appear on the login window, but this involves setting the UID to below 500 & can break file ownership.

Just evaluate how important the data is to you (in terms of cost to replace & your privacy) & how much inconvenience you are wiling to put up with to protect it.

Drew 
--
------------
Want to help translating Prey to your language?
Write us: transl...@preyproject.com
------------
You received this message because you are subscribed to the Google
Groups "Prey" group.
To post to this group, send email to prey-s...@googlegroups.com
To unsubscribe from this group, send email to
prey-securit...@googlegroups.com
For more options, visit this group at
http://groups.google.com/group/prey-security?hl=en_US?hl=en

Mac_Prey_11

unread,
Aug 11, 2011, 11:59:17 AM8/11/11
to Prey
Hi Drew.

Thanks for your feedback and comments.

1.
I agree.

1A.
Interesting. I agree the standard OS X user account could be a good
idea, but I also think that the password would have to be left blank.
I am not sure that the thief would be willing to guess or spend time
guessing the password! But lets keep in mind that we are not
encouraging the thief to use our guest/standard account daily or in a
regular basis, most of the time we just need this ONE report sent and
that should be enough for us. Unless the thief is accessing the web
from a public place, in this case more reports would always be better.
Again, in this case I don't see much difference between guest and
standard account. A password-less standard account would look more
suspicious to the guy than a guest account without any pwd, IMO. I
created a standard account with no password, that way they will
believe a password was forgotten to be entered.

I tried with the guest account, Prey still works without any issues
and reports were sent. btw, I searched and I have not found anything
related to the honeypot accounts, any idea where it is?

1B. I think I do agree. In the worst case, we should not leave the
admin account without a password. I think standard/guess account works
best with limited roles/privileges.


2. Well when I enabled firmware password on Lion, I could not go into
Single user mode anymore. Since its a Macbook Air, would not the only
way to go around that is hardware-based? If you can direct me to the
right place to read, I would appreciate it.


I believe the best approach is to: put all important data in an
encrypted container (I have trucrypt for that). That password is
different than any other pwds in the system. Then password protect the
admin account, and leave a guest or standard account open without any
passwords while restricting the apps/functions that can be used.

Now the thief does have one advantage, and that physical access. If he
is savvy enough, he would know exactly what to do with the machine
when stolen: hide camera/disconnect the bluetooth/Wifi card before
starting the system, and then proceed to try and circumvent the admin
password or firmware password. In this case, I believe protecting the
firmware password is crucial. If that breaks, everything else will, so
I would be very interested in the methods used to bypass the firmware
pwd and from there I could maybe protect against them.

I still believe the absolute best option would still be GPS tracking,
but thats gonna be even more tricky with the size of the macbook Air,
and the extreme lack of room!

Drew Reece

unread,
Aug 11, 2011, 12:30:00 PM8/11/11
to prey-s...@googlegroups.com
Honeypot info may only be on this list, sorry I cant recollect where it was. I suspect it was some discussions on best usage.
Your testing with password-less accounts is basically the 'honeypot' idea. You can name the account something to make it look desirable to login for a thief.

I thought the Apple support listed the efi/firmware password reset instructions but I only found this after a quick search. http://support.apple.com/kb/TS2391& http://support.apple.com/kb/HT1352 it is hardware tweaks that can override the password, so the Air may be less vulnerable (first link suggests apple tech needs to do it). Is the case entirely enclosed or is the RAM removable?

GPS would be nice, maybe you could glue an iPhone onto the back of the screen :)

Physical access is incredibly difficult to beat. Removing the HD defeats most security systems. Only strong encryption with good passwords will slow attacks down. Take a look at the Lions full disk encryption if you really want, I suspect the honeypot account will add a vulnerability to the system, so encrypted an home folder may be better for your account.

Drew

Mac_Prey_11

unread,
Aug 11, 2011, 4:09:17 PM8/11/11
to Prey
Well Apple basically tells you to bring it to the store, which am not
sure what they do afterwards with it, do they reset the pwd through
some mean I am not aware of, replace the logic board, do they replace
the MBA, etc. Maybe for fun when I have more free time I will pretend
I forgot it and go there and see what they will do :P

The RAM is NOT removable on the MBA.. It would require unsoldering/
resoldering RAM, which is a PITA. The SDD is removable though, so they
can swap the SSD to another one, BUT that would technically NOT solve
the firmware password issue, which I believe is independent of the
SSD. Now, if they can swap the SSD to another "stolen" MBA which does
not have the firmware password set, will it boot fine? Maybe. Actually
it should unless FileVolt is used.

Under Lion, I could not really find the lock Keychain after XX minutes
option. Maybe they removed it?? The ones I found were:

- Synchrnoise login keychain password with with account (Check/
uncheck) --> I believe uncheck is what we want.
- Set login chain as default --> Same as above?

Also, no where I could find the encryption of RAM under system prefs.
Did they also remove that?!

Drew Reece

unread,
Aug 11, 2011, 4:41:07 PM8/11/11
to prey-s...@googlegroups.com
I don't have Lion yet, I'm slow to upgrade.

The RAM may be described as 'Use Secure Virtual Memory' in the security section of the system prefs (also try the search in the toolbar).
On 10.6 each keychain has a popup menu on right click, change the settings for it if they are still there.

I'd rather not describe how to defeat the firmware password on a public forum, it is available on the internet.

Drew

Mac_Prey_11

unread,
Aug 11, 2011, 4:51:44 PM8/11/11
to Prey
Found the answer: for the virtual memory, its automatically and always
enabled in Lion: https://discussions.apple.com/thread/3192016?start=0&tstart=0

They also did changes to the keychains and all, so I gotta do some
researching and reading on that front.
> > Write us: translati...@preyproject.com
Reply all
Reply to author
Forward
0 new messages