Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

31–40 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#31

This kind of thing would immediately stick out like a sore thumb to a lot of technical users. In the world of USB cables it’s HUGE, even though technically I know it’s very small for it’s purpose. Very cool nevertheless!

What if you just package it as usb hub & memory stick and hand it out for free?

I guess from this point on, given the extra space, it would be relatively trivial to also send the file structure.

Re: Inside a low-budget consumer hardware espionage implant

#32
post #10

I wonder what voltage is required to kill the Mediatek chip? Maybe a simple jig that put -24v through it could fry it? Of course, if you're expecting it, this device should be relatively simple to stop. I can imagine more stealthy variants however.

If you already know it's there, you probably don't need to go through the trouble of destroying it, unless you just want to fry random USB devices.

The idea is that you would apply a high voltage to just the cable, with nothing else attached. If it's just a cable, no harm no foul. On the other hand, if you start seeing smoke from the embedded electronics, you may want to use a different cable.

Re: Inside a low-budget consumer hardware espionage implant

#33

Earlier quoted context omitted.

If you already know it's there, you probably don't need to go through the trouble of destroying it, unless you just want to fry random USB devices.

The idea is that you would apply a high voltage to just the cable, with nothing else attached. If it's just a cable, no harm no foul. On the other hand, if you start seeing smoke from the embedded electronics, you may want to use a different cable.

You could also just use one of those cheap USB power/voltage monitors as the author does. Obviously a cable alone should not be drawing power.

Maybe an innovative company could add warnings for USB ports that draw power but have no recognized device. For the advanced ports with charging support and so on they should have power monitoring already.

Re: Inside a low-budget consumer hardware espionage implant

#35
post #10

I wonder what voltage is required to kill the Mediatek chip? Maybe a simple jig that put -24v through it could fry it? Of course, if you're expecting it, this device should be relatively simple to stop. I can imagine more stealthy variants however.

or you could unplug it, take it home and keep it as a pet

Or even better, take out the SIM and find to whom the number is registered to. In many countries numbers require registration, ie. you can't get one without showing personal papers. Of course intel agencies aren't required to do that, so that if you can't get a real name for that SIM then you're 100% sure you're being watched by people a bit more powerful and dangerous than your suspicious wife (unless your wife works for them :^). Using cellphones or anything related to them, especially if you don't plan to recover the device, is not good for spying because you're leaving behind tracks almost as important as DNA. Nice article though. If some of you want to experiment with these devices, you can get a SIM800 or A6 GSM modules then pair it with a small uC for a lot less than €10.

https://github.com/carrascoacd/ArduinoSIM800L

http://simcom.ee/documents/SIM800/SIM800_Hardware%20Design_V...

http://www.electrodragon.com/w/GSM_GPRS_A6_Module

https://www.makerfabs.com/desfile/files/A6_A7_A6C_datasheet-...

Re: Inside a low-budget consumer hardware espionage implant

#36

This kind of thing would immediately stick out like a sore thumb to a lot of technical users. In the world of USB cables it’s HUGE, even though technically I know it’s very small for it’s purpose. Very cool nevertheless!

How often do people look behind their desks at the usb cables plugged into their systems. Many do not.

As someone who was involved with redteaming: ~nobody does. It's very rare to get caught after bugging someone's equipment. Bugs like these blend in seamlessly with the massive amounts of cables behind most desks.

Re: Inside a low-budget consumer hardware espionage implant

#37
post #23
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

You can check the BIOS to see if there is an option to disable it.

The average user should not need to muck around with the BIOS.

Re: Inside a low-budget consumer hardware espionage implant

#38

Earlier quoted context omitted.

or you could unplug it, take it home and keep it as a pet

Or even better, take out the SIM and find to whom the number is registered to. In many countries numbers require registration, ie. you can't get one without showing personal papers. Of course intel agencies aren't required to do that, so that if you can't get a real name for that SIM then you're 100% sure you're being watched by people a bit more powerful and dangerous than your suspicious wife (unless your wife work…

Good luck with that, it not hard to convince random homeless guy to register sim card on his name, even for wife.
Post reply on HN