Technology Review - Published By MIT
Advertisement

Solving Laptop Larceny

Continued from page 1

By Lamont Wood

Monday, June 19, 2006

smaller text tool iconmedium text tool iconlarger text tool icon

The tracking system also helps keep students honest. "Before, we had a huge rate of people dropping out of the program and not bringing their laptops back," Gomes recalled. "Now I let them know that I can track them. Their eyes kind of open, and they bring it back right away."

The Computrace service costs about $50 per year* per machine. At that price, Gomes figures the service will pay for itself if it prevents ten $2,000 machines from disappearing. A boxed consumer version of Computrace, called "Lojack for Laptops" (after the car-tracking device), costs $49.99 per year.

Some 80 percent of stolen or wayward laptops protected by Computrace are recovered, according to Jickling. A thief would be safe if he kept the stolen laptop off line -- but that rarely happens, especially now that Wi-Fi networks have sprouted in every apartment building and corner café. Absolute Software has placed the instructions for contacting Computrace into the basic input-output system (BIOS) of recent Hewlett-Packard, Gateway, Lenovo, Dell, and Fujitsu laptops, so that even reinstalling the operating system will not stop the machines from reporting in, Jickling says.

Nevertheless, since tracked machines remain in the hands of thieves until they're recovered, another security measure may also be useful: encryption. One firm licensing Absolute's software, CyberAngel Security Solutions in Nashville, TN, combines tracking with an encryption scheme. Their software creates an encrypted partition on the hard drive, says spokesperson Bradley Lide. If someone boots the system without inputting the right password, they will be able to use the machine -- but it will hide the encrypted partition from the user while sending alerts to the tracking service.

"If you steal it, boot it, and connect it, and violate authentication, the computer operates like a honey pot, as we draw in the thief while protecting the confidential information on it," says Lide. The service starts at about $60 per machine per year.

But "kill" switches are the most dramatic -- and drastic -- way to foil thieves. As with Computrace, laptops equipped with kill switches report to a central server at intervals. But no tracking is attempted; instead, the purpose is to check whether a machine should start destroying its data files.

When a stolen machine reports in, it can be instructed to overwrite selected files, explains Jeff Rubin, a representative of Santa Clara, CA-based Beachhead Solutions, which offers a kill service called Lost Data Destruction. Deleting a file -- simply putting it into a trash can or recycle bin, is not sufficient, since the data is still on the disk. The Pentagon, for instance, requires three over-writes to expunge sensitive data. Beachhead's system, which starts at $129 per year, can be set to overwrite as many as eight times.

"If the VA [Veteran Affairs] had had this, there would have been no problem," says Rubin.

*Correction: In the original version, we wrote that this service costs $50 per month.

Comments

  • home-built alternative
    this is an excellent idea. and it's something that someone could build themselves relatively easy, provided they have their own server and domain name or static IP address.
    Rate this comment: 12345
    Guest (brunascle)
    06/19/2006
    Posts:1
  • BIOS-enabled
    The point of it being BIOS-enabled is that many theives re-format the harddrive post theft. Absolute's software survives a reformat.
    Rate this comment: 12345
    Guest (Scott)
    06/19/2006
    Posts:1
    • BIOS-enabled
      Ok. So now Computrace has published the fact that programmed instructions in the bios will serve as the tracer. The thief that is aware of this simply has to only upgrade the bios or simply overwrite it with the oem version. Not too difficult to do.
      Rate this comment: 12345
      Guest (John)
      06/19/2006
      Posts:1
      • BIOS-enabled
        The program is part of the unwritable portion of the BIOS, so a BIOS upgrade will have no impact.
        Rate this comment: 12345
        Guest (Scott)
        06/20/2006
        Posts:1
        • Re: BIOS-enabled
          If it's part of the unwritable portion of the BIOS, how does it get on there in the first place? Or is it just retrieving the (unwritable) serial number from the BIOS? (i'm a coder, but i dont know much about hardware-related stuff)
          Rate this comment: 12345
          Guest (bruanscle)
          06/20/2006
          Posts:1
          • BIOS-enabled
            It is put on during the manufacturing process.
            Rate this comment: 12345
            Guest (Scott)
            06/20/2006
            Posts:1
            • Re: BIOS-enabled
              That's right. There are two ways to achieve this, either through mask ROMs where the program is built into the silicon without burning as you would know it or through write protect fuses. Fuses are quite common as the program can adapt over time (masking a new ROM is very expensive) just program the BIOS as you normally would then blow it's fuse and the data becomes permanent. The nicest thing is that you don't need to put the fused or maked ROM into the BIOS chip, you could build it into the northbridge or some other unreplacable chip.
              Rate this comment: 12345
              Guest (Andrew)
              06/29/2006
              Posts:1
              • BIOS-enabled
                Question?  Is that why the consumer can purchase the software/service after they purchase the computer...the BIOS can be altered at any time?
                Rate this comment: 12345
                Guest (techinfo)
                07/16/2006
                Posts:1
                • BIOS-enabled
                  Yes, the BIOS can be altered at any time. It's called flashing the BIOS. However, its far from simple, and unless you know what you are doing it is down right risky. Absolute offers two products: software based and BIOS-based. I would recommend installing the software based one until you purchase a new computer, then have it manufactured with the BIOS-based already installed.
                  Rate this comment: 12345
                  Guest (Scott)
                  07/20/2006
                  Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

The Marcellus Shale Gas Rush
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.