Live data from Hacker News

Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

tech.firstlook.media

51–60 of 80 posts

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#51
post #34

> This sounded reasonable, so I ventured to the streets of New York City to seek the help of some professionals! If the author of the article is here - I'd suggest turning to Louis Rossmann of YouTube fame: https://www.rossmanngroup.com/ https://www.youtube.com/user/rossmanngroup He has the equipment and skill to repair a logic board, and may have some valuable insights about failure modes of common chips on MacBooks…

Man, oh man can he ever be cynical though. At some point,l I have to believe it’s because he’s playing for the camera. Or, at least, I hope so. I’ve seen him get extremely stressed out over the silliest things.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#52

We’re not sure exactly what the technicians did to remove the chip – heat gun, maybe? – but it came off cleanly and you wouldn’t notice it was missing unless you were specifically looking for it on the board. Almost certainly, or more precisely, a "hot air rework station". For someone with experience, it only takes a few minutes to remove and replace BGAs with one.

As far as hardware hacking goes, this is tremendously unimpressive work. They didn't even check for PCB antennas, which would have been trivial.

It would probably take six months, minimum, of real work to actually airgap a Macbook (with any level of confidence in its security).

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#53
post #25
post #24

Earlier quoted context omitted.

> which operates just above the physical layer. So at the link layer? If so, what you described does not sound like an effective technique to exfiltrate data over the internet, unless the NSA also controls the LAN/internal network the target device is on. Why? Because any non-standard protocol data will be thrown out by the first switch or router on the path out of the target LAN. In other words, the exfiltrated data…

One thing the NSA is very good at is getting access to virtually every type of networking card. If they achieve access to a target, it's likely they control a path to it. If the target is a wifi device, the custom protocol becomes doubly effective: Exfiltration is a matter of having a receiver anywhere in the vicinity. And that receiver can amplify the signal to blast it a few miles. There are tools to sweep the EM s…

> If they achieve access to a target, it's likely they control a path to it.

Without specific, documented cases this is speculation of course. But I don't see why they'd use a link level protocol. 1. It requires patching multiple networking devices in the path, which is not very quiet. 2. It sticks out in any monitoring (via mirror ports) more than a UDP packet to a random host. DNS or ntp as a transport would be much simpler to hide.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#55
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

You could use an already existing wire as an antenna. For instance, many cell phones use the headphone wire as the antenna to receive digital TV.

On a laptop, there are several wires long enough to be used as an antenna. For an obvious example relevant to this article, the wires for the camera.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#56
post #32

Earlier quoted context omitted.

Of course, there is the GA evolved antenna. https://en.wikipedia.org/wiki/Evolved_antenna

Slightly related, an FPGA circuit designed by a genetic algorithm which ended working due to analogue effects and hardware-specific magnetic flux interference. https://www.damninteresting.com/on-the-origin-of-circuits/

It makes you wonder if it would be useful to create a programmable circuit where such analogue effects are the intended working principle.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#57
post #24
post #7

Earlier quoted context omitted.

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

> which operates just above the physical layer. So at the link layer? If so, what you described does not sound like an effective technique to exfiltrate data over the internet, unless the NSA also controls the LAN/internal network the target device is on. Why? Because any non-standard protocol data will be thrown out by the first switch or router on the path out of the target LAN. In other words, the exfiltrated data…

Could packet delays perhaps survive over the network?

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#59
post #34

> This sounded reasonable, so I ventured to the streets of New York City to seek the help of some professionals! If the author of the article is here - I'd suggest turning to Louis Rossmann of YouTube fame: https://www.rossmanngroup.com/ https://www.youtube.com/user/rossmanngroup He has the equipment and skill to repair a logic board, and may have some valuable insights about failure modes of common chips on MacBooks…

https://www.youtube.com/watch?v=tw3-j_RaX74

This guy doesn't seem very bright, but perhaps that was the joke?

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#60
post #49
post #7

Earlier quoted context omitted.

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

Do you have a source for this claim?

Exactly my question!
Post reply on HN