Live data from Hacker News

Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

tech.firstlook.media

61–70 of 80 posts

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#61
post #7
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

Interesting....source?

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#62
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

You could put the whole thing in a faraday cage and look at the emissions with a spectrum analyzer. There's probably a bunch of wide spectrum noise though, thanks to all those squarewaves running at various frequencies. If you were smart, you might try modulating one of those signals(sort of like the 'spread-spectrum' feature of many BIOSes, but with information doing the modulation and not just noise). You might be…

Transmitting radio waves with a spread-spectrum CPU clock, you say?

Here's a project to turn the Raspberry Pi into an FM radio transmitter using this exact trick:

http://www.icrobotics.co.uk/wiki/index.php/Turning_the_Raspb...

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#63
post #15

Earlier quoted context omitted.

The NSA can see through tin now. You must upgrade to superconducting hats.

Shhhh. Don't tell them. http://web.archive.org/web/20100708230258/http://people.csai...

> certain frequencies are in fact greatly amplified [by the helmets]

Oh, interesting!

> These amplified frequencies coincide with radio bands reserved for government use

I mean, if you take all of the common RF spectrum and look at what is reserved for civilian use, the vast majority is not freely usable. I'm not surprised it's within licensed spectrum.

> the use of helmets may in fact enhance the government's invasive abilities

Right.

> We speculate that the government may in fact have started the helmet craze for this reason.

Riiiiight.

This went from fun project to three levels of conspiracy theory real fast.

And looking at the contents (instead of the summary/abstract) more critically, they investigated >=10kHz waves. The brain waves that I know of are in the range of 1-150Hz: https://en.wikipedia.org/wiki/Neural_oscillation

... actually, this page is a joke, right? The more I read on the page, no way that this is serious.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#64

We’re not sure exactly what the technicians did to remove the chip – heat gun, maybe? – but it came off cleanly and you wouldn’t notice it was missing unless you were specifically looking for it on the board. Almost certainly, or more precisely, a "hot air rework station". For someone with experience, it only takes a few minutes to remove and replace BGAs with one.

And on top of that, it’s just about the only way it can be done non-destructively.

Another (and for large-ish BGAs actually better) way is IR rework station.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#65
post #63

Earlier quoted context omitted.

Shhhh. Don't tell them. http://web.archive.org/web/20100708230258/http://people.csai...

> certain frequencies are in fact greatly amplified [by the helmets] Oh, interesting! > These amplified frequencies coincide with radio bands reserved for government use I mean, if you take all of the common RF spectrum and look at what is reserved for civilian use, the vast majority is not freely usable. I'm not surprised it's within licensed spectrum. > the use of helmets may in fact enhance the government's invasi…

>... actually, this page is a joke, right? The more I read on the page, no way that this is serious.

Yes, I think it's very much a joke.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#66
post #11
post #7

Earlier quoted context omitted.

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

Why wouldn't an organization fake their job postings to lead people astray? Like if the FSB started hiring string theorists or telekinesthetics positions to waste the NSA's time figuring out why they're doing that.

> Like if the FSB started hiring string theorists or telekinesthetics positions to waste the NSA's time figuring out why they're doing that.

They already did that: https://www.atlasobscura.com/articles/nikolai-khokhlov-kgb-p...

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#67
post #7
post #3

I'm imagining a "stealth" wifi controller on one of the custom chips, hung onto a pin connected to an internal antenna realized on an internal copper layer of the motherboard. If you used a non-standard frequency and protocol, who would know? You could probably get an okay transmit-only signal with fairly unremarkable on-chip hardware (say, a simple PCM) and something that didn't look too much like an antenna even if…

The NSA developed their own networking protocol, separate from TCP or UDP, which operates just above the physical layer. The idea is that you rewrite the network card firmware so that there’s an NSA MITM running on it. The host computer never knows, because as far as the computer is concerned the network card is sending exactly the data you would expect. And even if you hook up network monitoring tools externally, yo…

" They can fake everything else, but not those."

They could hire through front companies, obfuscating the connection to the NSA.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#68

This story made me realize: I haven't seen the phrase "tin-foil hat" used much in the past couple of years. Huh. Which reminded me of a quote: "For a while you wondered whether the fools were pretending to be fools as some kind of deception, or whether there was a real efficient service somewhere else. Later in my fiction, I invented one. But alas the reality was the mediocrity." — Le Carre

It comes up plenty, but more in reference to people who believe in chemtrails and pizzagate.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#69
post #51
post #34

> This sounded reasonable, so I ventured to the streets of New York City to seek the help of some professionals! If the author of the article is here - I'd suggest turning to Louis Rossmann of YouTube fame: https://www.rossmanngroup.com/ https://www.youtube.com/user/rossmanngroup He has the equipment and skill to repair a logic board, and may have some valuable insights about failure modes of common chips on MacBooks…

Man, oh man can he ever be cynical though. At some point,l I have to believe it’s because he’s playing for the camera. Or, at least, I hope so. I’ve seen him get extremely stressed out over the silliest things.

I've never had a negative interaction with Louis personally, nor has anyone I've known. A friend birthed a repair store from his videos, and Louis' personality is very bright. His comments on the style of videos that Linus Tech Tips puts out compared to his own were hilarious.

I really enjoy Louis' videos. His decision of swapping from edited video to raw streams mostly as well is quite nice. Seeing his channel grow, and every trait that he has grow with that has been an interesting process. Maybe this is because I am quite cynical as well, but I have no idea. In 2 years he has grown from 40k subs to 442k, so he's doing something right.

I think everyone can get stressed over silly things.

Re: Air Gapping a MacBook Air: The Great BCM15700A2 Mystery

#70
post #24

Earlier quoted context omitted.

> which operates just above the physical layer. So at the link layer? If so, what you described does not sound like an effective technique to exfiltrate data over the internet, unless the NSA also controls the LAN/internal network the target device is on. Why? Because any non-standard protocol data will be thrown out by the first switch or router on the path out of the target LAN. In other words, the exfiltrated data…

Could packet delays perhaps survive over the network?

Yes. I used both header fields and delays as covert channels in the past since I know security professionals never looked for them. I derived them by just applying a standard, covert-channel analysis on the protocol. Others have described some methods publicly:

https://defcon.org/images/defcon-10/dc-10-presentations/dc10...

https://engineering.purdue.edu/dcsl/publications/papers/2009...

The oldest methods of finding stuff like this are Kemmerer's Shared Resource Matrix (1983) for storage channels and Wray's updated characterization (1991) that were used in DOD's security certification (TCSEC). They work for hardware, too, since it's how they found cache-based, timing channels in hardware hosting the VAX Security Kernel in 1992.

http://www.cs.ucsb.edu/~sherwood/cs290/papers/covert-kemmere...

http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.534....

For transport, military-grade security often mandated fixed-size, fixed-rate transmission with error handling itself not able to leak stuff. Tricky on error part, inefficient other part. A primitive software defense is to clear the storage channels while throttling and randomizing the timing of delivery. Works best on non-real-time or already-slow configurations. Idea fit for store-and-forward messaging, which was preferred for high-assurance security. Another option from 1990's high security was to have a PCI card or something running a security kernel do the actual transfer from a labeled source. As in, the source can be as malicious as it wants with it unlikely to effect secure kernel. The kernel might prevent it, detect it, shut it down, or preserve logs for traceability. There was also the "force everything over link/network encryptor" concept to attempt to cheat. Leaves some metadata which can be mitigated or obfuscated by other means including prior transmission method.

Hope that helps. Current work uses models or languages to track shared resources for automatically detecting storage or timing channels among other things. I'll dig some out of my collection if anyone wants them.

Post reply on HN