Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

41–50 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#41
post #19

Earlier quoted context omitted.

Or hook it up to a Twilio and receive text notifications when a new recording is available. Optionally auto-transcribe and do topic modeling to extract only discussions of interest.

But the low quality audience for this device is likely incapable of doing such a thing. Now, a company with questionable ethics could facilitate this for clients...

> Now, a company with questionable ethics could facilitate this for clients...

OK, I will bite. I would not call any company doing what is already possible more convenient for users a company with questionable ethics. That, to me, is perfectly OK.

In my book what is questionable (despicable, actually) is making a product that, as a byproduct, generates side-effects undesired by users (such as easy tracking) and does not try to allow the user who cares to turn such features off.

Re: Inside a low-budget consumer hardware espionage implant

#42
Wow: " This is probably not an elaborate scheme to harvest phone numbers and send them to China, but rather the way the default manufactured SIM code was implemented and it was never trimmed down to the needs of this device. Nevertheless, I found it interesting seeing how the device is accessing virtually everything on the SIM. " I agree, but it's rare to see someone not go fake ballistic claiming phone book capture for page views...

Re: Inside a low-budget consumer hardware espionage implant

#43
post #7

This is obviously not good, but I'm not sure it is particularly useful for something "important". Any target of high value will be pursued and observed by trained humans with advanced tools. The amount of data collected, I suspect, would be less but more accurate. A device like this just lowers the bar (really low) on tracking. However, it increases the noise/inaccuracy. If combined with some key logger and other dev…

It's probably great for abusive spouses who track their partner.

Re: Inside a low-budget consumer hardware espionage implant

#44
post #23

Earlier quoted context omitted.

You can check the BIOS to see if there is an option to disable it.

The average user should not need to muck around with the BIOS.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

Re: Inside a low-budget consumer hardware espionage implant

#45
post #28

Earlier quoted context omitted.

That is a different issue. The article was about an external USB device. Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.

Okay lets say that the ethernet MAC has some gates that detect a particular 1024-bit random bit pattern in packets and that triggers a behavior change in certain sequence of instructions common in Windows security code to bypass it. How would you discover this?

Re: Inside a low-budget consumer hardware espionage implant

#46
post #28

Earlier quoted context omitted.

Good luck with that: http://www.zdnet.com/article/minix-intels-hidden-in-chip-ope...

That is a different issue. The article was about an external USB device. Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

Perhaps others are not so trusting and do not want to legitimize surveillance and would like to hold these companies to account.

Privacy is not just some option, it is law. Surveillance and hidden surveillance of users is illegal in most countries and any technology with the capability to do so has to be disclosed with end user control.

Re: Inside a low-budget consumer hardware espionage implant

#47
post #15
post #4

Earlier quoted context omitted.

Bug or feature?

Feature. It allows, among other things, for a computer to be woken up via the (USB-connected) keyboard.

Also a branding/design feature.

I've encountered extended color coding on multiple gaming oriented motherboards: Black for USB 2, Blue for USB 3.1 (so far so standard), Red for persistently powered.

That way you can have your phone connected to that port and have it charge overnight, etc.

Re: Inside a low-budget consumer hardware espionage implant

#49

Earlier quoted context omitted.

The average user should not need to muck around with the BIOS.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

I guess the answer to that question depends on if you or someone else that irma is associated with is the target of espionage

Re: Inside a low-budget consumer hardware espionage implant

#50

Earlier quoted context omitted.

The average user should not need to muck around with the BIOS.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

Nothing to hide, what’s the problem?
Post reply on HN