Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

81–90 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#81

Earlier quoted context omitted.

The average user should not need to muck around with the BIOS.

The average user wants their phone to keep charging, even if they turn their computer off. The non-average user should have no problem mucking around in BIOS settings.

The simple solution to this is using a physical switch instead of hiding that functionality in a BIOS setting. A clever designer could even design it into/near the port itself so each port can be switched independently.

Re: Inside a low-budget consumer hardware espionage implant

#82
post #61

Earlier quoted context omitted.

Perhaps others are not so trusting and do not want to legitimize surveillance and would like to hold these companies to account. Privacy is not just some option, it is law. Surveillance and hidden surveillance of users is illegal in most countries and any technology with the capability to do so has to be disclosed with end user control.

Sure but most don't seem to value their privacy enough that they continue using Intel products. As such nothing will change.

Please stop blaming the victim for being ignorant and/or falling prey to marketing.

> most don't seem to value their privacy

Most people do value their privacy, but are either ignorant of how strongly technology can damage their privacy[1] or fee there isn't any other option or alternative.

> nothing will change

It will change when the people that do understand technology work to preserve privacy over profit and convenience, educate the general public about privacy issues, and inform them of privacy respecting alternatives.

[1] Businesses tend to encourage ignorant and/or misleading beliefs when they promise impressive features backed u[p with useless promises to "take security seriously".

Re: Inside a low-budget consumer hardware espionage implant

#83
post #64

Earlier quoted context omitted.

The idea is that you would apply a high voltage to just the cable, with nothing else attached. If it's just a cable, no harm no foul. On the other hand, if you start seeing smoke from the embedded electronics, you may want to use a different cable.

Unfortunately, that approach will become less useful in the future, as all USB-C cables that support USB 3 and/or high power contain a chip to advertise that fact[1]. (And then there are Thunderbolt cables, which look the same but require even more sophisticated electronics.) [1] https://e2e.ti.com/blogs_/b/analogwire/archive/2016/03/07/wh...

If anything this is just more reason to avoid USB-C.

Re: Inside a low-budget consumer hardware espionage implant

#84
post #52

Off topic, but still: is that a price of almost 2 EUR per minute of call? (to that stranger's phone - 3333333) I thought calls inside EU are price-limited? Or is this some really old post?

You can usually trade off monthly fees and per-unit costs for SIM cards. You can get one for $50/month that includes unlimited calling or one for $3/month that has high per-minute costs.

Re: Inside a low-budget consumer hardware espionage implant

#85
post #81

Earlier quoted context omitted.

The average user wants their phone to keep charging, even if they turn their computer off. The non-average user should have no problem mucking around in BIOS settings.

The simple solution to this is using a physical switch instead of hiding that functionality in a BIOS setting. A clever designer could even design it into/near the port itself so each port can be switched independently.

And those switches can go next to the ones for power to the camera, microphone, wifi, bluetooth, speakers, and anything else that I might want to be electrically disable-able, right?

Physical switches for the USB ports sound like they'd be as confusing for most people as the physical wifi switch was, when that was common. I think that means that if some manufacturer decides to introduce them, they won't be around long.

Re: Inside a low-budget consumer hardware espionage implant

#86
post #51

I wonder why they even bothered with such a high end processor like the MT6261. Get a bare die micro like the MSP430, and a bare die GSM chipset, and you're set. You'd have to dissolve your SIM card in acid and wire bond it to the PCB, but wire bonding machinery is pretty cheap. Realistically, this is stupid easy for a state-level actor. A good hardware hacker worth their salt could probably set up a bug no bigger th…

> in a couple of months for a few hundred, less if they already have a wire bonding machine and microscope. How do I get my hands on a wirebond machine for a few hundred? The bottom end of "old and crusty but not actually broken" seems to start at a couple thousand on eBay. If my budget were a few hundred I'd probably spend a month just machining and grinding replacement microscope parts. I suppose you could be refer…

Yeah, it's kinda tricky -- costs could be much higher. Wire bonders aren't exactly hot ticket items; very few people are using manual machines. A cheap Chinese made one from Taobao/Alibaba costs around $250, but add in shipping, and you're close to $500 already. Something made in the USA from eBay will be of similar price, just two decades older.

If you're lucky enough to already be in China, I can't imagine it would be to difficult to get a small run made for a much lower cost, although I've never done so. Lots of factories making high volume, low end products use wire bonders to attach bare die to a PCB -- think calculators, gift cards, etc.

The simple fact is there's no comparable level of electronics manufacturing in the US, making it hard to get the parts and machinery necessary.

Re: Inside a low-budget consumer hardware espionage implant

#87
post #68
post #3

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off . So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.

There are good reasons why USBs have been banned in the DOD for over a decade.

What they still use PS/2?

Re: Inside a low-budget consumer hardware espionage implant

#88
post #81

Earlier quoted context omitted.

The simple solution to this is using a physical switch instead of hiding that functionality in a BIOS setting. A clever designer could even design it into/near the port itself so each port can be switched independently.

And those switches can go next to the ones for power to the camera, microphone, wifi, bluetooth, speakers, and anything else that I might want to be electrically disable-able, right? Physical switches for the USB ports sound like they'd be as confusing for most people as the physical wifi switch was, when that was common. I think that means that if some manufacturer decides to introduce them, they won't be around lon…

I can just imagine the call to technical support for a laptop like that. "Have you tried turning it off and on again?" times a dozen switches

Re: Inside a low-budget consumer hardware espionage implant

#90
post #68

Earlier quoted context omitted.

There are good reasons why USBs have been banned in the DOD for over a decade.

What they still use PS/2?

The other poster meant USB sticks. Manning’s leaks were the reason they changed the rules.

I believe you have to use CDs instead for a lot of cases.

Post reply on HN