Live data from Hacker News

Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

tech.firstlook.media

11–20 of 80 posts

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#11
post #7
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

Why wouldn't an organization fake their job postings to lead people astray? Like if the FSB started hiring string theorists or telekinesthetics positions to waste the NSA's time figuring out why they're doing that.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#12
This story made me realize: I haven't seen the phrase "tin-foil hat" used much in the past couple of years. Huh.

Which reminded me of a quote:

"For a while you wondered whether the fools were pretending to be fools as some kind of deception, or whether there was a real efficient service somewhere else. Later in my fiction, I invented one. But alas the reality was the mediocrity." — Le Carre

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#13

In Apple's computers the web cam light cannot be disabled, because the web cam is controlled by a co-processor as demoed here. In the newer Pros with Touchbar Apple uses their own chip for this same function. On a lot of PC webcams, you can run the camera without the light or visa versa[0]. [0] https://blog.erratasec.com/2013/12/how-to-disable-webcam-lig...

Previous hacks of the iSight cam involved rewriting the firmware of that separate microcontroller. IIRC there was also a delay at one point, so that it was possible to take a picture really fast before the LED turned on.

Of course, the T-series processors were not a thing back then…

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#14

uhhh...how does this prove that the chip doesn't have radio functionality? they didn't figure out any information about the chip's actual functionality beyond its PCI device name, which would ostensibly not be "SUPER SECRET DATA EXFILTRATION RADIO FOR NSA". they just took it off, unplugged the wifi card, and then said "well, it doesn't connect to wifi networks now. must be fine".

As far as I can tell, the only reason they thought it was a wifi chip is that iFixit labeled it as such and it's made by Broadcom. It could conceivably have a secret wifi chip hidden inside it, but so could any other component from the battery to the USB port; there's no reason to think that they do.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#15

This story made me realize: I haven't seen the phrase "tin-foil hat" used much in the past couple of years. Huh. Which reminded me of a quote: "For a while you wondered whether the fools were pretending to be fools as some kind of deception, or whether there was a real efficient service somewhere else. Later in my fiction, I invented one. But alas the reality was the mediocrity." — Le Carre

The NSA can see through tin now. You must upgrade to superconducting hats.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#16

uhhh...how does this prove that the chip doesn't have radio functionality? they didn't figure out any information about the chip's actual functionality beyond its PCI device name, which would ostensibly not be "SUPER SECRET DATA EXFILTRATION RADIO FOR NSA". they just took it off, unplugged the wifi card, and then said "well, it doesn't connect to wifi networks now. must be fine".

there’s no way to conclusively prove what you suggest. This article isn’t about proving that though, it’s about “hey I wonder what this chip is for.”

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#17

We’re not sure exactly what the technicians did to remove the chip – heat gun, maybe? – but it came off cleanly and you wouldn’t notice it was missing unless you were specifically looking for it on the board. Almost certainly, or more precisely, a "hot air rework station". For someone with experience, it only takes a few minutes to remove and replace BGAs with one.

And on top of that, it’s just about the only way it can be done non-destructively.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#18
post #5
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

…something that didn't look too much like an antenna… The Raspberry Pi Zero W has a perfectly serviceable antenna which is simply a cavity formed between layers of copper and two tiny capacitors which look about like grains of salt. You can read more at https://www.raspberrypi.org/magpi/pi-zero-w-wireless-antenna... They are designed by some very clever Swedes. http://www.proant.se/en/news.htm That second page shows…

Antenna design is total black magic. Intuition is useless here.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#19
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

You could put the whole thing in a faraday cage and look at the emissions with a spectrum analyzer. There's probably a bunch of wide spectrum noise though, thanks to all those squarewaves running at various frequencies. If you were smart, you might try modulating one of those signals(sort of like the 'spread-spectrum' feature of many BIOSes, but with information doing the modulation and not just noise). You might be able to sneak other signals in amongst all the noise. Hell, spread spectrum signals can sit below the noise floor... I don't really think there's a way you could be 100% certain that the laptop wasn't exfiltrating data.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#20

uhhh...how does this prove that the chip doesn't have radio functionality? they didn't figure out any information about the chip's actual functionality beyond its PCI device name, which would ostensibly not be "SUPER SECRET DATA EXFILTRATION RADIO FOR NSA". they just took it off, unplugged the wifi card, and then said "well, it doesn't connect to wifi networks now. must be fine".

Not sure why you were down voted. The test only showed removing the chip disabled the camera. The chip BCM15700A2 is a WLAN/Bluetooth chip used on Intel 8260 cards and lots of Dell laptops. There is a Linux kernel driver written for this chip used for 802.11a wireless.

Got a source for that? I can't find any references to the 15700A2 being on intel 8260 cards.
Post reply on HN