Live data from Hacker News

Hard, Not Soft, Kill Switches

puri.sm

21–30 of 82 posts

Re: Hard, Not Soft, Kill Switches

#21
post #7
post #3

Earlier quoted context omitted.

> i would be in favour of a separate Bluetooth and Wifi kill switch. that's what I thought as well. About the microcode, this won't be fixed. But see the weekly updates on their blog[1] that states progress they make with the coreboot developers. Hopefully they can free the number one problem with intel chips[2] which is the Management Engine firmware. [1] https://puri.sm/posts/weekly-update-on-librem-production-201.…

Assuming they're running Intel Wireless chips (which is very likely), this is impossible because they are run on the same antennas by the same chip. You can disable this in software by passing "bt_coex_active=N" to the iwlwifi kernel module, but of course, who knows if that's actually sufficient. I'm pretty sure the situation with other vendors is similar or worse. Big vendors like Broadcom have terrible open source…

I think he means two switches, one for camera and microphone and one for blutooth and wifi; not a separate wifi switch and a bluetooth switch. Of course, a little DIP panel with a toggle for each device would be nice, too!

Re: Hard, Not Soft, Kill Switches

#22
This company states that privacy is very important to them. It's also to me.

But now I'm wondering, what's the purpose of the killswitch besides having no wifi-connection for a certain period of time?

I mean, when you switch back to enable wifi again, everything you did on your computer during 'airgap-time' is still there, waiting to be compromised by corps/govs? Isn't it?

Please correct me if I'm wrong. I'm really curious to this concept.

P.S. I really dig the design of their laptops.

edit: Changed markup and added P.S.

Re: Hard, Not Soft, Kill Switches

#23

I wonder if there would be any way to use some other component in a laptop as a microphone. Similar to the Funtenna stuff demoed by Ang Cui in several of his talks. https://www.blackhat.com/us-15/briefings.html#emanate-like-a... I'm unsure on how that would perform practically with audible soundwaves or if any other research has been done in that area. It would however be hard to mitigate, if possible at all.

Modern laptops (and sometimes even HDDs) have accelerometers used to detect freefall and park HDD's heads before impact. Maybe those could be abused to function as a makeshift mic?

Re: Hard, Not Soft, Kill Switches

#24

This company states that privacy is very important to them. It's also to me. But now I'm wondering, what's the purpose of the killswitch besides having no wifi-connection for a certain period of time? I mean, when you switch back to enable wifi again, everything you did on your computer during 'airgap-time' is still there, waiting to be compromised by corps/govs? Isn't it? Please correct me if I'm wrong. I'm really c…

You could be booting off a USB running something like Privatix during the time you have wifi killed - so that system would be air gapped whenever it is running. But if you trust Privatix you don't really need a HW switch.

Re: Hard, Not Soft, Kill Switches

#26
> There is other NO laptop on the market today that has a physical means to turn off a machine’s built in Webcam and Microphone.

That was shocking to read, actually. I assumed that Purism wasn't the only company doing this.

Re: Hard, Not Soft, Kill Switches

#27

This company states that privacy is very important to them. It's also to me. But now I'm wondering, what's the purpose of the killswitch besides having no wifi-connection for a certain period of time? I mean, when you switch back to enable wifi again, everything you did on your computer during 'airgap-time' is still there, waiting to be compromised by corps/govs? Isn't it? Please correct me if I'm wrong. I'm really c…

A couple of possible ideas:

* Heightened risk of compromise in particular physical locations?

* Use in conjunction with something like TAILS so it's harder for someone who breaks into your computer to achieve persistence?

* Decreased risk of compromises that involve multiple machines attacking each other?

* Attackers may be wary of storing huge amounts of data persistently because the associated changes in storage media could be detected by forensic spot-checks?

(The third one probably requires that the forensic examination can get access to everywhere that the data could be stashed ... like nonvolatile memory inside onboard devices, not just the hard drive and main RAM contents.)

Re: Hard, Not Soft, Kill Switches

#28

This company states that privacy is very important to them. It's also to me. But now I'm wondering, what's the purpose of the killswitch besides having no wifi-connection for a certain period of time? I mean, when you switch back to enable wifi again, everything you did on your computer during 'airgap-time' is still there, waiting to be compromised by corps/govs? Isn't it? Please correct me if I'm wrong. I'm really c…

Wi-Fi can, and will, send data behind your back even if you're not connected to any network. Some of it is a part of normal protocol operation (and can be used to track you). Malware on your system could initiate connection without you knowing. And then a malicious actor targeting you personally may spoof a network you often connect to (e.g. local coffee shop) and exploit the default autoconnect to known networks behaviour. Hardware switches protect you from all the above.

Re: Hard, Not Soft, Kill Switches

#29

It would be cool if there was a fail safe switch that nuked the hard drive with microwaves or something crazy like that when it was pressed. That would be one laptop I'd buy.

If you're going to go that route, you want an encrypted hard drive whose keys can be destroyed at a moment's notice. I believe that's off-the-shelf tech now, but I'm not sure where to point you at it.

Re: Hard, Not Soft, Kill Switches

#30
post #12

This is the first I've heard of Puri.sm. It seems like a very ambitious company. I'm not sure features like this are important enough to me to persuade my buying decision. However I love the idea of having another choice besides apple when it comes to hardware. I've just been really unhappy with everything else. I'm excited for another choice when looking for a high-end laptop!

I, too, welcome the existence of a company trying to compete based on preserving privacy and users' freedoms rather than invading it and spying on everything.

Personally, I would consider having hardware switches to disable external sensors and wireless communications channels in a laptop to be a significant factor in a purchasing decision. Other things being equal, I would opt for such features, and I would be willing to pay a bit extra to have them.

Unfortunately, it appears that other things are not equal. Unless I'm missing something, these systems seem to be relatively expensive for the rest of their spec.

More significantly, there is only so much you can do with hardware alone. For now, we also have the usual problem with installing an entirely free/open source software base, which is that much of the software that is useful for getting real work done is not from the FOSS world and the closest FOSS equivalents are not competitive if they exist at all. Being on-line is essential for a lot of activities, but as soon as you're on-line there is still a problem if you don't trust at least the OS and networking software as well as the hardware, and in a Windows 10 world that surely won't be true for many who would be interested in this kind of hardware in the first place.

Still, this seems like a step in a healthy direction, and for that alone I wish them success.

Post reply on HN