Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

61–70 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#61

Thanks to Purism laptops and phone for taking the lead on kill switches for sensors, https://puri.sm/learn/hardware-kill-switches/

Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card. This is from the same group that tries to explain how they don't use proprietary firmware blogs by using the Redpine chips just because the blog is already flashed on it rather…

> Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card.

When using a physical kill switch you have to trust the hardware. You don't have to trust the firmware or operating system, as a physical kill switch usually disables the power lines to the device. That's something a remote attacker can't circumvent.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#62
“Must” according to who? Should, in many cases, sure.

I’d rather physically removable sensors rather than off switches, though.

Cameras on laptops are far from my greatest concern. Microphone on cellphone is a much bigger concern, as well as perpetual passive metadata plus sensitive data on third party servers required for normal functioning of most services.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#63
post #4

Note that a physical switch can be overridden just as easy as a soft switch, the vendor can just put a soft switch in parallel with it and you would never know it. The hard switch could turn off the display, speaker etc. while the processor and radio can stay on.

I thought lying about such functionality to consumers would be illegal. I feel that if you sell me a device with the explicit promise that “off means off”, then bypassing that would be.. false advertising? Is that true? Assuming they’d market it that way, originally?

Most people aren't capable of using a webcam correctly before the addition of a mechanical switch that adds a 50% chance they'll deactivate it and think it's broken. A physical hand-operated integrated cover that slides in front of the camera is a great option for software engineers and HN-level thinkers, but it will only cause grief for the majority of users. Having hidden redundancy would allow Apple's tech support to turn the camera back on when Grandma calls in unable to use FaceTime. How many failed attempts will a typical user make before permanently giving up on a feature, maybe 2?

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#64

Earlier quoted context omitted.

We may be back to building our own devices again.

We need a Bespoke Laptop Boutique Such that we have an open-ish platform built on a sound foundation of security.

Something that Neal Stephenson predicted in Snow Crash. Artisanal, single-origin laptops.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#65

Meh. Houses still have windows, and people still have binoculars, but we seem to get by fine with blinds. Tape over your webcam, unplug Alexa, or turn off your phone if you want more privacy. More importantly, there is a social norm that you don't look through people's windows with binoculars. Of course police, spies, or creeps might do it, but that's incredibly rare. Unfortunately, the social norm (and business mode…

> unplug Alexa, or turn off your phone if you want more privacy.

Fully turning off either means have to wait for the devices to boot up whenever you want to actually use them. That time adds up. A mic kill switch would allow the device to be immediately used at the flick of that switch.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#66

TVs and other gadgets that have no microphones or video cameras embedded in them should have a certification like "organic". "NoSpy Certified" or a similar trademark would be appropriate right next to the UL and CE marks.

Well, 'organic' as a certification doesn't really mean anything. And UL was kind of a joke from having dealt with them personally.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#67
post #4

Note that a physical switch can be overridden just as easy as a soft switch, the vendor can just put a soft switch in parallel with it and you would never know it. The hard switch could turn off the display, speaker etc. while the processor and radio can stay on.

Yes but you can't protect yourself against brands being hostile to consumer by asking them for features to protect you. The only protection against that is boycott.

No, the goal of the switches is to fend off 3rd party hackers.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#68
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Whenever the topic of MITM middleboxes comes up, there is usually a vehement opposition to them from much of the security community... while they bring up some valid points, I can't help but wonder if there is some deeper agenda behind that opposition, since these also seem to be the same people who are pushing the user-hostile walled gardens.

(Personally have been using a MITM proxy on my network for over a decade. Besides the filtering, it also has a useful side-effect of upgrading all connections to TLS 1.2, and when 1.3 becomes more common or mandated, I only need to upgrade the OpenSSL the proxy uses to start using it for all TLS coming from the network. Even older devices that don't support it will still use it when communicating outside the network.)

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#69
It's interesting that no laptop vendor seems to have made a physical webcam cover included by default- to me that seems like a no brainer that most customers would benefit from.

Edit: Thanks for all your comments. It seems that there a few vendors that do offer webcan covers by default now. Definitely will have to check those out.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#70

Earlier quoted context omitted.

I like the way the lens works on the new Lenovo Thinkpad camera. It slides sideways, thereby blocking the camera. That's how I like to see it done

That was my first thought when seeing Sanger's initial tweets about this. Someone else replied to the tweet pointing it out, and his response was along the lines of "that's not an off switch, it just blocks it". I'm not really sure why blocking the camera isn't strictly _better_ than a physical off switch, at the very least from a trust perspective

[deleted]
Post reply on HN