Live data from Hacker News

It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

theintercept.com

51–60 of 134 posts

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#51
post #26

Earlier quoted context omitted.

So put malware in the BIOS itself, or one of the other chips or ROMs available. I think I remember reading a story recently about Thunderbolt or maybe USB being connected to an Option ROM over PCIe (must have been Thunderbolt I guess) that allowed an attacker to simply plug in a USB stick and permanently and irrevocably pwn the system - right down to securing the flaw that allowed flashing of the ROM over the PCIe co…

Yes, it was Thunderbolt.[0] Firewire had the same issue. As does PCIe. But maybe USB 2.0 can be secured. If so, just fill other ports with epoxy. And use metal-flake nail polish to tamper protect seams. If USB isn't securable, give up, I guess. 0) https://news.ycombinator.com/item?id=12383130

That’s the great thing about USB-C - If you epoxy the ports, you now can’t charge.. sigh

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#52
post #12

The best defense is being someone too uninteresting to bother. Once you're interesting so some resourceful adversary, it's very hard to avoid devices being hacked, and virtually impossible to determine if they've been hacked.

Or not be a coward and be interesting, speak up, and not back down. If more of us do that than not then they will at least have a very difficult time in tracking us all.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#53

If you care about this, then put the laptop in a tamper-evident bag. Those are necessarily imperfect too; but there's work making tamper-evident seals to resist up to state-level attacks, since that's relevant in stuff like enforcement of nuclear weapons treaties. That succeeds to the extent that you can find a physical effect that's easy to create and measure, but hard to recreate deterministically. (In concept, dum…

> If you care about this, then put the laptop in a tamper-evident bag.

How does this procedure work for multiday evil maid situations? The first day while you're out the maid replaces your collection of plastic disposable tamper-evident bags with faulty ones that open with a particular chemical but otherwise look identical. The second day the maid tampers with your laptop and you don't notice. Do you just have to take the whole box of additional bags with you everyday? That seems prohibitively inconvenient.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#54
post #53

If you care about this, then put the laptop in a tamper-evident bag. Those are necessarily imperfect too; but there's work making tamper-evident seals to resist up to state-level attacks, since that's relevant in stuff like enforcement of nuclear weapons treaties. That succeeds to the extent that you can find a physical effect that's easy to create and measure, but hard to recreate deterministically. (In concept, dum…

> If you care about this, then put the laptop in a tamper-evident bag. How does this procedure work for multiday evil maid situations? The first day while you're out the maid replaces your collection of plastic disposable tamper-evident bags with faulty ones that open with a particular chemical but otherwise look identical. The second day the maid tampers with your laptop and you don't notice. Do you just have to tak…

If this were a job interview, then I'd say "put the spare bags in with the laptop"...

Or the "bag" can be the laptop's existing case. You can put seals (stickers, or the sparkly nail polish trick mentioned below) over all the fasteners and seams of the laptop, fill all the non-power ports with epoxy, etc. None of these make tampering impossible, but they can make it uneconomic.

I don't think anyone at serious risk of these kinds of attacks lets computers out of their physical control. I've seen agencies that do the seals/epoxy even for computers inside their secure facilities, presumably to give their guards more time to catch an inside tamperer.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#55
post #10

I run a dual-boot Debian + Windows 7 laptop, but my default position is to assume the Windows partition is exploitable, so for secure activities I boot Debian. That boots using an unencrypted /boot partition, but everything else running on luks (one big partition, LVM'd down). I have a VeraCrypt partition which is for files that I want to work on from both operating systems. Works really well, crypted disks doesn't m…

> but my default position is to assume the Windows partition is exploitable

In reality, as the article explains, the windows partition is basically invulnerable to this class of attacks if you take the 5 minutes to enable bitlocker. OTOH Linux systems have no effective defense.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#56

I would think a fully encrypted OS partition would be harder to sneak a backdoor into? Now infecting everything before the OS boots is outside my scope of knowledge, but if you have your partition unencrypted it's definitely much much easier to hijack your OS with physical access.

Large part of the article explains why full disk encryption is not a sufficient protection against an attacker with physical access.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#58
post #49

If you're a target of a major intelligence agency, I think that you have to assume that all of your computers are irretrievably compromised. From Vault 7, we know that the CIA has long developed implants to infect both the EFI and hard drive firmware that load before any potential code that could detect them. These could be made arbitrarily hard to detect without physically opening the computer and dumping these flas…

Could all firmware be on WORM chips? Which can't be rewritten, no matter what an adversary does. Updates would require switching chips. But at least driveby implants would be impossible.

For the average person (i.e. threat model is criminals not states) I think this would be less secure due to the difficulty of patching

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#59
post #13

Computers that support “secure boot” or “verified boot,” such as Chromebooks and Windows laptops with BitLocker, aren’t vulnerable to this. The BIOS can detect if the unencrypted part of your disk has been tampered with, and if it has, it will refuse to boot. MacBooks and laptops that run Linux could potentially be attacked in this way. Really? (Search terms used: "secure boot linux" and "secure boot macbook") https:…

Also curious about Linux vulnerabilities to this particular attack - any Linux wizards in thread?

Not a Linux wizard but as a long time user, I remembered this 2012 news from Canonical: http://blog.canonical.com/2012/06/22/an-update-on-ubuntu-and...

Perhaps the author meant there was no 'universal' Linux implementation, however it's been available for a while in certain distros.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#60
My Linux laptop is fully encrypted and I’ve signed and enrolled my own secure boot keys. Just following best practices and now wondering where this leaves me vulnerable. I think it should prevent tampering with the bootloader but not sure about hdd/net Firmware etc.
Post reply on HN