Live data from Hacker News

It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

theintercept.com

101–110 of 134 posts

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#101
post #10

I run a dual-boot Debian + Windows 7 laptop, but my default position is to assume the Windows partition is exploitable, so for secure activities I boot Debian. That boots using an unencrypted /boot partition, but everything else running on luks (one big partition, LVM'd down). I have a VeraCrypt partition which is for files that I want to work on from both operating systems. Works really well, crypted disks doesn't m…

> but my default position is to assume the Windows partition is exploitable In reality, as the article explains, the windows partition is basically invulnerable to this class of attacks if you take the 5 minutes to enable bitlocker. OTOH Linux systems have no effective defense.

BitLocker stores your encryption keys on a Microsoft server [1] and is a closed-source software, therefore by definition it cannot be trusted for encrypting anything important. (It is wrong even if your adversary is not a state, because that way you are getting used to a false sense of security that you don't actually have.)

[1] https://theintercept.com/2015/12/28/recently-bought-a-window...

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#102
post #101

Earlier quoted context omitted.

> but my default position is to assume the Windows partition is exploitable In reality, as the article explains, the windows partition is basically invulnerable to this class of attacks if you take the 5 minutes to enable bitlocker. OTOH Linux systems have no effective defense.

BitLocker stores your encryption keys on a Microsoft server [1] and is a closed-source software, therefore by definition it cannot be trusted for encrypting anything important. (It is wrong even if your adversary is not a state, because that way you are getting used to a false sense of security that you don't actually have.) [1] https://theintercept.com/2015/12/28/recently-bought-a-window...

"Stores keys on someone's server" cannot be trusted, no matter what the copyright status is of the code running on the server.

Code licensing or copyright status isn't a form of security.

The issue isn't just that the remote server's code is impervious to scrutiny. A locally installed program that you can reverse engineer isn't automatically trustworthy because it is open-source, or even copylefted. Someone actually has to reverse engineer the binary and prove that it matches the source code. Many users of free software trust upstream binaries. (Even if they compile their own programs, they trust compiler binaries at some point.)

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#103
post #80

Thesis: it is possible that someone may access your laptop without you knowing if you leave it unattended. Experiment: after having gone through a number of - some meaningless[1] - attempts to be able to proof that this happened, there was no evidence it happened. Doubt: did it happen nonetheless without leaving any trace ot it din't actually happened at all? Bonus: the experimenter learned that NVRAM exists in the s…

>Thesis: it is possible that someone may access your laptop without you knowing if you leave it unattended.

This is known to be true, this experiment was about seeing if anyone would access this laptop. Which also addresses what you view as meaningless, real world scenarios are trying to avoid their laptop being compromised while the author was hoping that it would.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#104
post #80

Thesis: it is possible that someone may access your laptop without you knowing if you leave it unattended. Experiment: after having gone through a number of - some meaningless[1] - attempts to be able to proof that this happened, there was no evidence it happened. Doubt: did it happen nonetheless without leaving any trace ot it din't actually happened at all? Bonus: the experimenter learned that NVRAM exists in the s…

>Thesis: it is possible that someone may access your laptop without you knowing if you leave it unattended. This is known to be true, this experiment was about seeing if anyone would access this laptop. Which also addresses what you view as meaningless, real world scenarios are trying to avoid their laptop being compromised while the author was hoping that it would.

I know that it is true, it is actually a truism.

The "experiment" has too few data points to be meaningful, and the proposed way to verify remains meaningless, two simple cases:

1) the evil maid simply makes a forensic image of the disk

2) a sector in the hard disk goes bad

Case 1: there was an intrusion, all the data was stolen, but the hashes do not show that (false negative)

Case 2: there was NOT any intrusion, but the hashes show that there was a change (false positive)

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#105
I believe it might be possible to replace the HD firmware that will effectively hide code, even in the HD firmware itself, that can only be accessed via a backdoor. For all we know, it comes that way from the factory. Just thinking, while we're being all paranoid here :)

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#106

I thought it was impossible to prove a negative, generally?

This is true without perfect observation. In math you have perfect observation (sometimes), so you can do something like Fermat's Last Theorem. Once you enter the physical world, not so much.

I don't see a hard line between math, then physics, then the 'real' world. They are levels of formalization.

Both in math and in the real world we don't have 'perfect observation'. There is plenty of conjectures in math and the real world that lack a proof of something being true or false.

I think "can't prove a negative" is one of the least informative ways of trying to say something, I assume he meant to say "absence of evidence is not evidence of absence" or perhaps "absence and evidence don't commute"

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#107

In other news : You can't prove a negative.

Here is a (wrong) statement:

* [the sum S of two even numbers A1 and A2] is an odd number

Here is its negation:

* [the sum S of two even numbers A1 and A2] is not an odd number

or alternatively:

* [the sum S of two even numbers A1 and A2] is an even number.

Let's "you can't prove the negative":

* A1 is even => there exists an integer a1 such that A1 = 2a1

A2 is even => there exists an integer a1 such that A2 = 2a2

by substitution the sum (A1+A2) = (2a1 + 2a2)

* by distributivity: (A1+A2)=2(a1+a2)

sum s of integers a1,a2 is an integer: a1 + a2 = s integer

* substitution (A1+A2)=2s with s integer

S=(A1+A2)=2s, hence S is even

an even number is not odd

* hence [the sum S of two even numbers A1 and A2] is not odd

We proved a theorem that was also a negation of a statement!!

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#108
post #53

If you care about this, then put the laptop in a tamper-evident bag. Those are necessarily imperfect too; but there's work making tamper-evident seals to resist up to state-level attacks, since that's relevant in stuff like enforcement of nuclear weapons treaties. That succeeds to the extent that you can find a physical effect that's easy to create and measure, but hard to recreate deterministically. (In concept, dum…

> If you care about this, then put the laptop in a tamper-evident bag. How does this procedure work for multiday evil maid situations? The first day while you're out the maid replaces your collection of plastic disposable tamper-evident bags with faulty ones that open with a particular chemical but otherwise look identical. The second day the maid tampers with your laptop and you don't notice. Do you just have to tak…

Professional poker players have been dealing with this type of risk for years. Major poker tournaments present a juicy target for organised hacking gangs. A high-stakes pro might have tens or hundreds of thousands of dollars deposited in their PokerStars account. Hundreds of professional players in a tournament cardroom means hundreds of very valuable laptops left in hotel rooms.

The most sensible precautions seem to be a) full-disk encryption with a strong passphrase, b) hardware 2fa using a token that is stored separately from the computer, c) physically securing the machine whenever possible and d) tamper-evident seals covering screwholes or seams.

If your adversary is capable of beating these precautions, you're probably screwed anyway.

https://www.f-secure.com/weblog/archives/00002647.html

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#109

Earlier quoted context omitted.

Pure handwave. Let's call an "exposure" a one-way trip plus half the hotel stay. So the author's laptop got (3+5) * 2 = 16 exposures. Air passengers make about 3B trips per year. A laptop lasts about three years. I said "tens of millions", so if I'm right then we have at least 16 * 20M exposures on existing laptops. That would mean at least one passenger in 28 travels with a laptop and is as careless as the author wa…

The kind journalists at The Intercept are likely to be targeted by state actors, who might even be prepared to risk some zero days too?

I don't think he thought he was targeted, if he thought the hacker stickers would make a difference. But if I had an exploit like that and was targeting a security-conscious journalist, then (a) I'd be mystified when he checked his laptop, and probably unprepared to take advantage, and (b) I doubt I'd risk my >$1M exploit--even if I could hide it perfectly in some firmware, it still has to communicate out to the world somehow, and that's where it's likely to get noticed.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#110
post #101

Earlier quoted context omitted.

> but my default position is to assume the Windows partition is exploitable In reality, as the article explains, the windows partition is basically invulnerable to this class of attacks if you take the 5 minutes to enable bitlocker. OTOH Linux systems have no effective defense.

BitLocker stores your encryption keys on a Microsoft server [1] and is a closed-source software, therefore by definition it cannot be trusted for encrypting anything important. (It is wrong even if your adversary is not a state, because that way you are getting used to a false sense of security that you don't actually have.) [1] https://theintercept.com/2015/12/28/recently-bought-a-window...

It's an option to store your keys on their server, but not a requirement. At least not the last time I set up BitLocker. In fact that computer didn't even have the on board Secure Storage thing that it prefers, so I had to make a note of the recovery key on paper.
Post reply on HN