Live data from Hacker News

Headphones can be hijacked to surreptitiously record audio

wired.com

141–150 of 158 posts

Re: Headphones can be hijacked to surreptitiously record audio

#141
The article as a whole is quite sensationalist.

Once people have access to your underlying device - what exactly do you think is going to happen?

"Oh but if you disconnected your microphone then think again". How many bloody people do that? A few dozen in the world?

What a piece of shit.

Now the technical underpinning that jacks can be reassigned isn't new for Realtek, lots of PC motherboards have given the option for years and years.

This is all not really news.

Re: Headphones can be hijacked to surreptitiously record audio

#142
post #50
post #46

Earlier quoted context omitted.

> Headphones also make a really crappy mic -- try it out by plugging them into a microphone jack (essentially what this malware emulates) and recording yourself: you'll need to hold them inches from your mouth to be intelligible. The article itself claims two orders of magnitude better reach: > In their tests, the researchers tried the audio hack with a pair of Sennheiser headphones. They found that they could record…

> with a pair of Sennheiser headphones. And that's where this falls apart. While some people buy quality headphones, many will be using cheap, or rebranded low-quality headphones, like beats, or even no-name headphones.

I have a pair of shitty Sennheizer headphones. Apparently they dilluted their brand a lot.

Re: Headphones can be hijacked to surreptitiously record audio

#143
post #142
post #50

Earlier quoted context omitted.

> with a pair of Sennheiser headphones. And that's where this falls apart. While some people buy quality headphones, many will be using cheap, or rebranded low-quality headphones, like beats, or even no-name headphones.

I have a pair of shitty Sennheizer headphones. Apparently they dilluted their brand a lot.

Which model, and could you be specific about what is so crappy about them?

Re: Headphones can be hijacked to surreptitiously record audio

#144

Earlier quoted context omitted.

You don't even need to disconnect the ear bud, just tap it. The voltage pulse from an audio signal is sufficient. Back in the days of rotary phones I used to show off how to dial numbers by simply tapping the receiver on the table.

That doesn't seem to work - I have a POTS line here, and no amount of tapping or striking the phone receiver on a surface is the equivalent of dialing (I tried the phone itself and my headset microphone). Perhaps a local VoIP ATA works that way, but my Telco does not. And I'm not surprised, there's a big difference between detecting an audio signal and detecting a local loop interruption through 18,000 feet of copper…

I'm under impression that pulse dialing had been phased out in many countries, with tone dialing being the replacement.

Re: Headphones can be hijacked to surreptitiously record audio

#145

Earlier quoted context omitted.

In the US, ex post facto laws cannot be made.

That's nice. But if you decide to run for high office 30 years from now it will become known that drew pony porn in college and never really stopped. That's the meaning of kompromat .

Not if your record is better than their's.

Re: Headphones can be hijacked to surreptitiously record audio

#146

Earlier quoted context omitted.

In the US, ex post facto laws cannot be made.

> In the US, ex post facto laws cannot be made. That fact has been so inconvenient for the government that the entire system has been redesigned to thwart it. Can't prove Al Capone is a mobster? Prosecute for tax evasion. Keep passing broad overlapping laws and they can charge anyone with something. Then they don't have to change the law, only who they decide to prosecute.

Are you saying Capone didn't evade taxes?

Re: Headphones can be hijacked to surreptitiously record audio

#147

Earlier quoted context omitted.

Do you get a corresponding "Is that a speaker you just plugged in?" popup if you plug a speaker into the microphone port? How does the computer know whether you've plugged a speaker or a mic into the port?

Microphones have a higher impedance than speakers. A moderately clever circuit can differentiate the two.

Mics have lower impedance than active speakers, which is the kind you plug into those jacks.

Re: Headphones can be hijacked to surreptitiously record audio

#148
post #144

Earlier quoted context omitted.

That doesn't seem to work - I have a POTS line here, and no amount of tapping or striking the phone receiver on a surface is the equivalent of dialing (I tried the phone itself and my headset microphone). Perhaps a local VoIP ATA works that way, but my Telco does not. And I'm not surprised, there's a big difference between detecting an audio signal and detecting a local loop interruption through 18,000 feet of copper…

I'm under impression that pulse dialing had been phased out in many countries, with tone dialing being the replacement.

Perhaps so in some countries, but in the USA, pulse dialing still works (even VoIP ATA's here support it). There's lots of older automated equipment out there that depends on it (elevator call boxes, alarm systems, building front door call boxes, etc.)

My "in case of power failure" phone is an old red Bell System desk phone with rotary dial. Still works great.

Re: Headphones can be hijacked to surreptitiously record audio

#149
post #144

Earlier quoted context omitted.

That doesn't seem to work - I have a POTS line here, and no amount of tapping or striking the phone receiver on a surface is the equivalent of dialing (I tried the phone itself and my headset microphone). Perhaps a local VoIP ATA works that way, but my Telco does not. And I'm not surprised, there's a big difference between detecting an audio signal and detecting a local loop interruption through 18,000 feet of copper…

I'm under impression that pulse dialing had been phased out in many countries, with tone dialing being the replacement.

[deleted]

Re: Headphones can be hijacked to surreptitiously record audio

#150

Earlier quoted context omitted.

And New Zealand, where it was like Sweden, but backwards. 0 made 10 pulses, 1 made 9 pulses, and dialing 9 would make 1 pulse. This is why the emergency number in NZ is 111, we had equipment from the UK, where the number was 999. As to why it was backwards, I have no idea.

112 still works as an emergency number in the U.K. to this day.

That's more like "ever since digital mobile phones came around". The number 112 is in GSM standard.

Technically, the network gives it a priority, and you can make a 112 call even without a SIM card, or even if your operator does not have coverage. The call goes through any operator that has coverage. (You can actually see this in the phone display when making a 112 call; it handles it quite differently. I have done it a few times; unfortunately, most of those times, someone has died...)

If the network is so busy that all traffic channels in GSM are occupied, and you make a 112 call, one of the existing calls is dropped and you get the emergency call.

This had some interesting side effects in China. There, prior to introduction of GSM, the number 112 was allocated to phone company technical complaints. Police was 110 and fire alarm was 119 and so on.

So, if you were making a GSM phone call to a friend, and the network was full - not that infrequent in China - you wouldn't get through. But you could call the technical complaint line at 112, and this was a priority service which dropped one of the existing calls. Once the technical complaint service was ringing, you could drop that call (to the network, an emergency call) and you'd have one free GSM time slot in your cell. And you could call your friend.

Until the next guy did the same, and your ongoing call would get mysteriously dropped.

Post reply on HN