Live data from Hacker News

FBI director: Cover up your webcam

thehill.com

271–280 of 307 posts

Re: FBI director: Cover up your webcam

#271

Isn't this really just a sign of flawed hardware design? In my opinion hardware should be designed so that the camera LED lamp should always be lit if the camera is used. If there is a malfunction with the LED, then the camera should also not work. Also there should be a hardware LED for when the microphone is being used which should work in the same fashion for laptops with built-in microphones. In the webcam driver…

Here's the problem with this solution - it assumes that everyone equates the LED being on all day long every day with "oh shit, I'm hacked". No, the average person is going to just say "Oh great, another thing's broken on my computer."

Your average computer has a lot of LEDs active anytime it's plugged into the wall (let alone running) - what protection will yet another LED offer to your average consumer?

Re: FBI director: Cover up your webcam

#272

Isn't this really just a sign of flawed hardware design? In my opinion hardware should be designed so that the camera LED lamp should always be lit if the camera is used. If there is a malfunction with the LED, then the camera should also not work. Also there should be a hardware LED for when the microphone is being used which should work in the same fashion for laptops with built-in microphones. In the webcam driver…

>If there is a malfunction with the LED, then the camera should also not work. Many would argue that this is the more flawed design.

It seems like a "fail safe" to me. The current design is a bit closer to a "fail deadly" in that it creates a mode that's the worst-case from the user's perspective: the camera works but the indicator doesn't.

It is probably worse to have an unreliable indicator light than it is to not have any indicator light at all.

Re: FBI director: Cover up your webcam

#273

Earlier quoted context omitted.

Of interesting note: ThinkPads have (had?) independent mute, volume and microphone buttons with LEDs to indicate volume or microphone muting. It's clearly at least partially software or driver driven, because with Windows 10 microphone muting is no longer functional. The warm and fuzzy feeling that discovery gave me is why my daily driver is still on Win7 since I almost always have both audio directions muted.

Surely that leaves open the possibility Windows7 was always in control and if hacked, could lie to you? The fact that Windows10 breaks it surely suggests it's a software feature?

Yes, but....

There's a difference between "I can turn this off as long as the driver is properly installed and has not been hacked" and "I can't turn this off." While the second statement is abstractly true for both, the bar for some software silently and invisibly turning on the microphone is quite a bit higher if it also requires replacing or hacking the audio hardware drivers.

Re: FBI director: Cover up your webcam

#274

Earlier quoted context omitted.

Recording conversations has nothing to do with the camera. You might be thinking of the microphone. Should we put a little LED on that too?

Yes of course. It should be connected to both. You can't put a piece of tape over a microphone.

But the microphone is always on if you enable voice activation, e.g., "Okay Google", "Hey Siri", "Hey Cortana". That recognition is handled in software, so no "hacker proof" hardware indicator can distinguish between the use cases.

"Hey Siri" works on desktop devices: https://9to5mac.com/2016/07/15/how-to-enable-hands-free-hey-...

"Okay Google" was removed from desktop: http://www.theverge.com/2015/10/16/9553051/ok-google-removed...

Re: FBI director: Cover up your webcam

#275
post #267

Earlier quoted context omitted.

It's not only pics of people staring into a screen. There was a case about 5-6 years ago when a guy recorded and streamed his secretly gay roomate having sex in the dorm. The gay roomate committed suicide later. Work computers can be taken home or to business trips where things can happen in the hotel after the deal is struck.

>where things can happen in the hotel after the deal is struck. Serious question: what happens when a deal is struck? They go out to drink? They go back to their hotels? They have sex with their coworkers?

Serious answer: whatever happens is none of your or FBI's business ;)

Re: FBI director: Cover up your webcam

#276

"The head of the FBI on Wednesday defended putting a piece of tape over his personal laptop's webcam, claiming the security step was a common sense one that most should take." One needs to ask why is the head of the FBI telling you this? Cui bono? This is a red herring. The FBI has no interest in filming you through your webcam. They want to listen to your microphone, watch your screen, get the keys you've typed, see…

Taking screenshots at exactly the same time when the observant is typing something into the very same laptop makes for undeniable evidence to the judge.

Re: FBI director: Cover up your webcam

#277

At some of my house parties I require guests to check their phone at the door. Price of admission. (I keep a landline and am ok with giving that number out as an emergency contact number). Boy does this get the conversation started. I can tape my phn camera, but what about the other 20 phns in the room? I have no control over them to keep them from posting photos of me drinking or whatnot during a party, photos I do…

It'd be amusing to have a little Faraday cage by the door for them to deposit into. :)

Re: FBI director: Cover up your webcam

#278

What about the part where we stop buying products with integrated cameras? What about the part where we stop buying devices that we have seeemingly no hope of control over? What about that? Is boycott a word too strong? Gee, you're right. We should all just give up, and accept that what we're sold, is that which we must buy.

I think you're being a bit quick to judge people here… Having an integrated camera is obviously a lot easier to deal with, logistically, than lugging along an external USB camera. I think a lot of the people here would love to have hardware-level kill switches for their video camera. And mic. And WiFi. (I would; I used to own a Thinkpad with a hardware kill switch for WiFi. It was useful, even aside from the privacy…

I would trust a physical sliding camera cover a lot more than some internal "trust us, the hardware kill switch works" kind of production.

Although, I suppose if they were lying about such a thing it would become obvious quite quickly when someone takes it apart, and the PR shitstorm would be popcorn-tastic.

Re: FBI director: Cover up your webcam

#279
post #71
post #19

Earlier quoted context omitted.

Similarly Hilary advocates for banning encryption yet makes her staffers using Signal application to encrypt their correspondence. Our government is full of hypocrites.

>Similarly Hilary advocates for banning encryption Does she? Her tech platform seemed pretty supportive of Apple's stance on encryption: http://appleinsider.com/articles/16/06/29/hillary-clintons-t...

It's really hard to say what she supports. She changes her opinion so often trying to appease everyone, but is clear that she wants government to be able to decrypt communication: https://www.techdirt.com/articles/20151220/08101633141/hilla...

Re: FBI director: Cover up your webcam

#280

Earlier quoted context omitted.

It's not just blackmail that I worry about. A hypothetical, ruthless hacker manages to install malware on a person's computer. Hell they could target certain zip codes. All the information is on the Internet. Hell, they could get a picture of your home. (By the way, Google will blure out you home, if you ask. It tends to reappear, although they claim its permanent. If your house has been sold recently, a thief/crimin…

This is all true, but wouldn't somebody who has the technical skills to pull this all of, be able to pull in a legal income far in excess of what burglary is likely to yield?

A lot of trojans are like off-the-shelf kits that anyone can grab. The technical skills amount to convincing someone to run an executable (email, malicious USB keys, poorly managed advertising networks, etc) and then clicking a few buttons in a GUI to connect to them and do what you will.

For the slightly more technical, you've got frameworks like metasploit which can perform network attacks, but even that is getting much more like a kit these days. Port scan for services, fingerprint them, check database for known vulnerabilities, automatically attempt to exploit known vulnerabilities, deploy payload (the trojan).

Post reply on HN