Live data from Hacker News

It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

theintercept.com

41–50 of 134 posts

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#41
post #13

Computers that support “secure boot” or “verified boot,” such as Chromebooks and Windows laptops with BitLocker, aren’t vulnerable to this. The BIOS can detect if the unencrypted part of your disk has been tampered with, and if it has, it will refuse to boot. MacBooks and laptops that run Linux could potentially be attacked in this way. Really? (Search terms used: "secure boot linux" and "secure boot macbook") https:…

Mac secure boot is currently only supported on the iMac Pro, not any MacBook as far as I am aware.

Rather less likely to be lugging that through customs :)

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#42
post #8

Why not put a bounty of bitcoins on your laptop? If it's large enough it becomes worth taking even though that will alert you.

Because that only works for a small subset of attackers. If it's a state actor that's hacked your computer they're unlikely to be interested in any reasonable sum of money.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#43
post #40
post #6

Earlier quoted context omitted.

I think you have got a bit confused here. For example Fermat's Last Theorem is effectively "a negative": "no three positive integers a, b, and c satisfy the equation an + bn = cn for any integer value of n greater than 2"

That phrase applies basically everywhere else except math. It's only possible to prove a negative in mathematics because it's a fully logical system. On a side note Fermat's Last Theorem isn't a good counterexample because it hasn't been proven yet either.

It's proven:

https://www.theguardian.com/science/2016/mar/15/british-math...

https://en.wikipedia.org/wiki/Wiles%27s_proof_of_Fermat%27s_...

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#44

I thought it was impossible to prove a negative, generally?

This is true without perfect observation. In math you have perfect observation (sometimes), so you can do something like Fermat's Last Theorem. Once you enter the physical world, not so much.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#45
post #6

I thought it was impossible to prove a negative, generally?

I think you have got a bit confused here. For example Fermat's Last Theorem is effectively "a negative": "no three positive integers a, b, and c satisfy the equation an + bn = cn for any integer value of n greater than 2"

"You cannot prove a negative" basically means that you cannot prove that some claim or statement is, was, and always will be false (without perfect knowledge of the past, present, and future).

That parenthetical is an important and almost always unstated axiom.

The general inability to prove a false statement does not mean you cannot prove that the answer to some equation is a number below zero. I am not really aware of the phrase being used in the context of math, but rather more often with examinations or experiments that are susceptible to evidence.

To be sure, "you cannot prove a negative" is itself unproven. It more a rule of thumb to remind you not to assume that though some statement is false now that it always was false and always will be false.

It's not perfect, but it's also not a law of logic or anything. It's just a guideline.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#46
post #27

Earlier quoted context omitted.

Monitor, sure. But I don't believe that anyone has enough resources to backdoor everyone's machines.

That depends where in the design, manufacture, and provisioning stage this occurs, and by whom. It's quite possible Micah was looking at the wrong signifiers. (Difficult to prove, natch, but possible.)

Sure, it's possible.

We know that the NSA intercepts machines for modification. And it's possible that hardware is generally backdoored. Maybe even by Chinese manufacturers.

But what can one do, if everything is pwned? It's not practical to build machines from transistors etc. There are dreams of open-source hardware. But how could that even be done securely? The NSA can plant agents anywhere, in theory.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#47
post #15

Earlier quoted context omitted.

True. But after doing a standard LUKS install, you can move /boot to an SD card. You can also backup the LUKS header to the SD card, and wipe it from the system. Now the machine cannot be booted without the SD card. After restoring the LUKS header. And even if an adversary creates a new /boot on the machine, you can check for that, and nuke it before booting from the SD card. If you're detained, you can just chew up…

So put malware in the BIOS itself, or one of the other chips or ROMs available. I think I remember reading a story recently about Thunderbolt or maybe USB being connected to an Option ROM over PCIe (must have been Thunderbolt I guess) that allowed an attacker to simply plug in a USB stick and permanently and irrevocably pwn the system - right down to securing the flaw that allowed flashing of the ROM over the PCIe co…

So how come there's no key-authenticated USB? Something analogous to OpenSSH, maybe.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#49

If you're a target of a major intelligence agency, I think that you have to assume that all of your computers are irretrievably compromised. From Vault 7, we know that the CIA has long developed implants to infect both the EFI and hard drive firmware that load before any potential code that could detect them. These could be made arbitrarily hard to detect without physically opening the computer and dumping these flas…

Could all firmware be on WORM chips? Which can't be rewritten, no matter what an adversary does. Updates would require switching chips. But at least driveby implants would be impossible.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#50
post #13

Computers that support “secure boot” or “verified boot,” such as Chromebooks and Windows laptops with BitLocker, aren’t vulnerable to this. The BIOS can detect if the unencrypted part of your disk has been tampered with, and if it has, it will refuse to boot. MacBooks and laptops that run Linux could potentially be attacked in this way. Really? (Search terms used: "secure boot linux" and "secure boot macbook") https:…

Also curious about Linux vulnerabilities to this particular attack - any Linux wizards in thread?
Post reply on HN