Earlier quoted context omitted.
I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.
Okay lets say that the ethernet MAC has some gates that detect a particular 1024-bit random bit pattern in packets and that triggers a behavior change in certain sequence of instructions common in Windows security code to bypass it. How would you discover this?
Inside a low-budget consumer hardware espionage implant
71–80 of 98 posts
Re: Inside a low-budget consumer hardware espionage implant
#72Off topic, but still: is that a price of almost 2 EUR per minute of call? (to that stranger's phone - 3333333) I thought calls inside EU are price-limited? Or is this some really old post?
I found that odd too. I live in Denmark and i pay a fixed amount and can call as much as i want.
Those fixed price for unlimited calling plans that are great for human to human communication would suck for low data sensors and devices.
In the US these are handled by special plans that have zero or close to zero fixed monthly cost, but have a high per byte or per minute rate so that they are quite cheap for their intended use (e.g., power meter daily usage report) but are too expensive to use for high data applications.
If there are similar things in Europe, maybe that number was one of those?
Re: Inside a low-budget consumer hardware espionage implant
#73I wonder why they even bothered with such a high end processor like the MT6261. Get a bare die micro like the MSP430, and a bare die GSM chipset, and you're set. You'd have to dissolve your SIM card in acid and wire bond it to the PCB, but wire bonding machinery is pretty cheap. Realistically, this is stupid easy for a state-level actor. A good hardware hacker worth their salt could probably set up a bug no bigger th…
How do I get my hands on a wirebond machine for a few hundred? The bottom end of "old and crusty but not actually broken" seems to start at a couple thousand on eBay. If my budget were a few hundred I'd probably spend a month just machining and grinding replacement microscope parts.
I suppose you could be referring to the marginal cost of an hour on a wirebond machine at the nearest NNIN facility, but last time I priced out training options the overhead to get started would have been $500-$1k.
Re: Inside a low-budget consumer hardware espionage implant
#74Earlier quoted context omitted.
> The weak part of all these systems is the constant GSM heartbeat, but even that is beatable. Curious: how do you beat that? Do you listen to other signals and try to transmit at the same time (if you must)?
You can broadcast on a timer, you can switch to a low frequency, low bandwidth transmitter, you can store locally and pick up the device later, etc. It all depends on the environment.
Re: Inside a low-budget consumer hardware espionage implant
#75Earlier quoted context omitted.
You can broadcast on a timer, you can switch to a low frequency, low bandwidth transmitter, you can store locally and pick up the device later, etc. It all depends on the environment.
Or burst mode. That's been the speculated reasoning I've heard behind the USA's onerous POI restrictions on exported RTSAs.
I found an article about the export restrictions here.
https://signalhound.com/news/how-we-implemexport-controls/
seems like it has to do with the fact it's guaranteed to intercept a signal all the way down to 1.2 uS
Re: Inside a low-budget consumer hardware espionage implant
#76Earlier quoted context omitted.
I feel part of the reason is that processors such as MT6261 are getting cheaper and cheaper. The marginal benefit of producing a simpler and smaller design is likely going to go away quickly. It is the end-game for hardware. Software has already been gobbled up by language designs which are less and less hardware-near for the very same reason.
I was thinking purely from a power consumption / die size / support stand point. Not sure what the MT6261 quiescent current is, but I'd expect it to be in the 100s of uA. An MSP430 can get down to 0.1uA, which is much more difficult to detect. If I had to guess, the MSP430 die is probably about 1/4 the size of the MT6261 die. Most importantly, I can't find a MT6261 datasheet anywhere except for taobao. This just make…
Re: Inside a low-budget consumer hardware espionage implant
#77Earlier quoted context omitted.
I feel part of the reason is that processors such as MT6261 are getting cheaper and cheaper. The marginal benefit of producing a simpler and smaller design is likely going to go away quickly. It is the end-game for hardware. Software has already been gobbled up by language designs which are less and less hardware-near for the very same reason.
I was thinking purely from a power consumption / die size / support stand point. Not sure what the MT6261 quiescent current is, but I'd expect it to be in the 100s of uA. An MSP430 can get down to 0.1uA, which is much more difficult to detect. If I had to guess, the MSP430 die is probably about 1/4 the size of the MT6261 die. Most importantly, I can't find a MT6261 datasheet anywhere except for taobao. This just make…
Re: Inside a low-budget consumer hardware espionage implant
#78Earlier quoted context omitted.
I found that odd too. I live in Denmark and i pay a fixed amount and can call as much as i want.
How are remotely monitored sensors and devices, like weather stations and power meters, that need to send a small amount of data periodically, and that use the cellular network for that handled in Europe? Those fixed price for unlimited calling plans that are great for human to human communication would suck for low data sensors and devices. In the US these are handled by special plans that have zero or close to zero…
Re: Inside a low-budget consumer hardware espionage implant
#79Earlier quoted context omitted.
The average user should not need to muck around with the BIOS.
I'm a Mac user and what is BIOS /s
Re: Inside a low-budget consumer hardware espionage implant
#80Earlier quoted context omitted.
How often do people look behind their desks at the usb cables plugged into their systems. Many do not.
As someone who was involved with redteaming: ~nobody does. It's very rare to get caught after bugging someone's equipment. Bugs like these blend in seamlessly with the massive amounts of cables behind most desks.