Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

91–98 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#91
post #42

Wow: " This is probably not an elaborate scheme to harvest phone numbers and send them to China, but rather the way the default manufactured SIM code was implemented and it was never trimmed down to the needs of this device. Nevertheless, I found it interesting seeing how the device is accessing virtually everything on the SIM. " I agree, but it's rare to see someone not go fake ballistic claiming phone book capture…

Ah, come on. It's not like consumers are going to insert their sims into this device anyway.

Re: Inside a low-budget consumer hardware espionage implant

#92
post #42

Wow: " This is probably not an elaborate scheme to harvest phone numbers and send them to China, but rather the way the default manufactured SIM code was implemented and it was never trimmed down to the needs of this device. Nevertheless, I found it interesting seeing how the device is accessing virtually everything on the SIM. " I agree, but it's rare to see someone not go fake ballistic claiming phone book capture…

Ah, come on. It's not like consumers are going to insert their sims into this device anyway.

And it's not like in 2017 anybody stores their contacts in their SIM

Re: Inside a low-budget consumer hardware espionage implant

#93

Earlier quoted context omitted.

or you could unplug it, take it home and keep it as a pet

Or even better, take out the SIM and find to whom the number is registered to. In many countries numbers require registration, ie. you can't get one without showing personal papers. Of course intel agencies aren't required to do that, so that if you can't get a real name for that SIM then you're 100% sure you're being watched by people a bit more powerful and dangerous than your suspicious wife (unless your wife work…

>If you can't get a real name for that SIM then you're 100% sure you're being watched by people a bit more powerful and dangerous than your suspicious wife

If you conveniently "forget" or show heavy reluctance to give your info and papers when buying a new phone, you can get an unregistered SIM. Just promise them you'll give the info "later". The salespeople don't like the hassle and just want to secure the sale.

You can also easily give fake info and "forget" your ID card, since it's not verified, but that's dangerous if you get caught.

Simple social engineering.

Re: Inside a low-budget consumer hardware espionage implant

#94
post #82
post #61

Earlier quoted context omitted.

Sure but most don't seem to value their privacy enough that they continue using Intel products. As such nothing will change.

Please stop blaming the victim for being ignorant and/or falling prey to marketing. > most don't seem to value their privacy Most people do value their privacy, but are either ignorant of how strongly technology can damage their privacy[1] or fee there isn't any other option or alternative. > nothing will change It will change when the people that do understand technology work to preserve privacy over profit and conv…

I don’t think “don’t blame the victim” applies to voluntary transactions. Consumers have shown we will not sacrifice much for privacy or security. That’s a trade-off made in the market by millions of people, independently, every day.

Re: Inside a low-budget consumer hardware espionage implant

#95

Earlier quoted context omitted.

How often do people look behind their desks at the usb cables plugged into their systems. Many do not.

As someone who was involved with redteaming: ~nobody does. It's very rare to get caught after bugging someone's equipment. Bugs like these blend in seamlessly with the massive amounts of cables behind most desks.

Found the picture of the ethernet bug. https://twitter.com/nblr/status/928526534226391040

That I would never notice behind a desk

Also, in the usb cable with cell https://twitter.com/nblr/status/929132160602296320

Re: Inside a low-budget consumer hardware espionage implant

#96

Earlier quoted context omitted.

Nothing to hide, what’s the problem?

Facebook will mass deploy these to serve targeted advertising based on conversations it hears.

This is sarcasm, right? (dozen apps already listening the mic in our pockets).

Re: Inside a low-budget consumer hardware espionage implant

#97
post #78
post #72

Earlier quoted context omitted.

How are remotely monitored sensors and devices, like weather stations and power meters, that need to send a small amount of data periodically, and that use the cellular network for that handled in Europe? Those fixed price for unlimited calling plans that are great for human to human communication would suck for low data sensors and devices. In the US these are handled by special plans that have zero or close to zero…

https://particle.io and https://hologram.io have almost worldwide availability for SIM's designed for this. There are probably older less-hip suppliers as well.

> have almost worldwide availability for SIM's designed for this.

They are great if you have sensors travelling to different countries or your volume isn't large enough to negotiate with a local telco.

If you are deploying many devices in one country it will be far cheaper to talk to a local telco about getting a custoomized data package for your SIM cards.

https://eseye.com is another company supplying these roaming SIM cards.

Re: Inside a low-budget consumer hardware espionage implant

#98
post #45

Earlier quoted context omitted.

I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.

Okay lets say that the ethernet MAC has some gates that detect a particular 1024-bit random bit pattern in packets and that triggers a behavior change in certain sequence of instructions common in Windows security code to bypass it. How would you discover this?

What do you mean the ethernet card triggers changes in Windows instructions? Do you mean it can scan the RAM and do some changes? I am not familiar with how recent hardware works but I would be worried if hardware could scan RAM and edit executable code bypassing the kernel and drivers, so more reasons to get open hardware and drivers.
Post reply on HN