Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

61–70 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#61
post #28

Earlier quoted context omitted.

That is a different issue. The article was about an external USB device. Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

Perhaps others are not so trusting and do not want to legitimize surveillance and would like to hold these companies to account. Privacy is not just some option, it is law. Surveillance and hidden surveillance of users is illegal in most countries and any technology with the capability to do so has to be disclosed with end user control.

Sure but most don't seem to value their privacy enough that they continue using Intel products. As such nothing will change.

Re: Inside a low-budget consumer hardware espionage implant

#63
post #28

Earlier quoted context omitted.

Good luck with that: http://www.zdnet.com/article/minix-intels-hidden-in-chip-ope...

That is a different issue. The article was about an external USB device. Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.

Say that we trust Intel completely. Does that somehow make AMT not a security concern? For the ME itself, especially if it's not connected to any networking hardware: Whatever. It seems more like a theoretical threat than a practical problem. AMT sounds like something that I don't want running on my machine, even if I trust Intel itself completely.

Re: Inside a low-budget consumer hardware espionage implant

#64

Earlier quoted context omitted.

If you already know it's there, you probably don't need to go through the trouble of destroying it, unless you just want to fry random USB devices.

The idea is that you would apply a high voltage to just the cable, with nothing else attached. If it's just a cable, no harm no foul. On the other hand, if you start seeing smoke from the embedded electronics, you may want to use a different cable.

Unfortunately, that approach will become less useful in the future, as all USB-C cables that support USB 3 and/or high power contain a chip to advertise that fact[1]. (And then there are Thunderbolt cables, which look the same but require even more sophisticated electronics.)

[1] https://e2e.ti.com/blogs_/b/analogwire/archive/2016/03/07/wh...

Re: Inside a low-budget consumer hardware espionage implant

#65
post #4
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

Bug or feature?

I’d call it a feature. I sometimes need to harvest energy from my computer’s power supply to charge my phone without the computer being on (waste of energy)

Re: Inside a low-budget consumer hardware espionage implant

#66

Earlier quoted context omitted.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

Nothing to hide, what’s the problem?

It's not nothing to hide, it's realistic threat model. But if these things become more popular and in more and more devices they'll just hoover up all the data they can get like already happens with web software. The average user probably should not have to learn what an extension is and figure out which adblocker to install, but this is the inelegant world we live in, and anyway I'm still on the fence for whether I really want to expect more from the average user or not.

Re: Inside a low-budget consumer hardware espionage implant

#67
post #18

Earlier quoted context omitted.

As others pointed out, this is unlikely to be used by "the deep state" - would you ever get a USB data cable from a public officer of any sort? This is for jealous spouses.

"would you ever get a USB data cable from a public officer of any sort?" Nope. But if somebody replaced the cable while you weren't looking ...

That sort of op has better tools already.

Re: Inside a low-budget consumer hardware espionage implant

#68
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

There are good reasons why USBs have been banned in the DOD for over a decade.

Re: Inside a low-budget consumer hardware espionage implant

#69

Earlier quoted context omitted.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

Nothing to hide, what’s the problem?

Facebook will mass deploy these to serve targeted advertising based on conversations it hears.

Re: Inside a low-budget consumer hardware espionage implant

#70

Earlier quoted context omitted.

The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?

Nothing to hide, what’s the problem?

This argument is similar to saying you don't care about someone else's freedom of speech because you have nothing to say.
Post reply on HN