Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

21–30 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#21

This kind of thing would immediately stick out like a sore thumb to a lot of technical users. In the world of USB cables it’s HUGE, even though technically I know it’s very small for it’s purpose. Very cool nevertheless!

How often do people look behind their desks at the usb cables plugged into their systems. Many do not.

Re: Inside a low-budget consumer hardware espionage implant

#23
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

You can check the BIOS to see if there is an option to disable it.

Re: Inside a low-budget consumer hardware espionage implant

#24

Earlier quoted context omitted.

+1 for the thought -100 for the thought... But at the end of the day, we dont want to encourage the deep surveillance state... but we techie always look at this sort of thing and then say "hmmm... wouldnt it be interesting if..."

I don't think products like this encourage the "deep surveillance state" - if anything, they weaken it by loosening their monopoly on high-tech covert surveillance. These things can be used for good as well as evil - you could spy on a corrupt official or catch someone cheating just as easily as anything else.

Agreed. Anything that renders the previously invisible (state surveillance techniques) visible via consumer availability is anathema to state surveillance.

The majority of these techniques are allowed in the US because Congress doesn't know / care.

The more popular exploits of insecure technologies we get, the more security becomes an economically beneficial differentiator. And the more concerned calls your local Congressperson receives.

Re: Inside a low-budget consumer hardware espionage implant

#25
post #18

Earlier quoted context omitted.

+1 for the thought -100 for the thought... But at the end of the day, we dont want to encourage the deep surveillance state... but we techie always look at this sort of thing and then say "hmmm... wouldnt it be interesting if..."

As others pointed out, this is unlikely to be used by "the deep state" - would you ever get a USB data cable from a public officer of any sort? This is for jealous spouses.

"would you ever get a USB data cable from a public officer of any sort?"

Nope. But if somebody replaced the cable while you weren't looking ...

Re: Inside a low-budget consumer hardware espionage implant

#26
post #23
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

You can check the BIOS to see if there is an option to disable it.

Good luck with that: http://www.zdnet.com/article/minix-intels-hidden-in-chip-ope...

Re: Inside a low-budget consumer hardware espionage implant

#28
post #23

Earlier quoted context omitted.

You can check the BIOS to see if there is an option to disable it.

Good luck with that: http://www.zdnet.com/article/minix-intels-hidden-in-chip-ope...

That is a different issue. The article was about an external USB device.

Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

Re: Inside a low-budget consumer hardware espionage implant

#29
post #10

I wonder what voltage is required to kill the Mediatek chip? Maybe a simple jig that put -24v through it could fry it? Of course, if you're expecting it, this device should be relatively simple to stop. I can imagine more stealthy variants however.

Simply removing the SIM would sort you out to stop it doing much, it seems.

Re: Inside a low-budget consumer hardware espionage implant

#30
post #28

Earlier quoted context omitted.

Good luck with that: http://www.zdnet.com/article/minix-intels-hidden-in-chip-ope...

That is a different issue. The article was about an external USB device. Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.
Post reply on HN