I know that some attributes in AD are classified as personal information and some are classified as public information (see the "property set" column here - http://www.kouti.com/tables/userattributes.htm).
My question is, how do I use that information to hide those attributes when users are logged in from a particular computer. I'm thinking this would be a great extra layer of protection against data leakage if you were planning to put a computer in a public area. If the machine got compromised this should limit the amount of data that can dumped from AD.
I don't want to restrict access to these attributes based on the user account, I only want to restrict access to attributes classified as "personal information" from a particular computer.