Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

111–120 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#111

Earlier quoted context omitted.

This is absolutely untrue. "Organic" is a regulated term by the USDA, requiring verification from an accredited certifying agency.

USDA organic allows non organic pesticides and herbicides. It's a joke of a standard.

[deleted]

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#113
post #14

Earlier quoted context omitted.

I’d imagine a vendor bothering to put an off switch will know that a simple teardown will show if it actually disconnects the device or just signals software to do it. The effort and expense would be for nothing. Most users would never bother to care about the off switch anyway, and the ones that do will know the truth.

Eh, as someone else mentioned the soft switch, you could very easily make this teardown resistant by putting the covert power rail on an inner layer of the pcb with the switching transistor out of the way connected to vias. It’s not teardown-proof, but wouldn’t be obvious with a trivial inspection.

Perhaps but this would also remove any pretense of deniability from the manufacturer. If discovered it would just show that they went to great lengths (extra engineering effort to implement and hide) which could only be explained by the conscious decision to make it a back door and bypass it later in software.

So the issue would no longer be one of ignorance (no button) but of premeditation (button with hidden bypass).

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#114

Thanks to Purism laptops and phone for taking the lead on kill switches for sensors, https://puri.sm/learn/hardware-kill-switches/

Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card. This is from the same group that tries to explain how they don't use proprietary firmware blogs by using the Redpine chips just because the blog is already flashed on it rather…

In Android, you actually can't trust when the OS says the WiFi is "off."

Yes, the network is not connected, but google is still tracking SSIDs.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#115
post #16

Earlier quoted context omitted.

Hopefully this would easily be detected, and the brand damage from the resultant public shaming should be enough of a deterrent. But maybe it's really well hidden and eludes detection, or people just don't care and there is no brand damage, or maybe even there's no "real" brand to damage (OEM crapware).

What's the brand damage from the resultant public shaming of e.g. Google Nest Guard' 'hidden' microphone?

I don't think we know yet.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#116
post #104

Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? I feel like, at least for the threat models that I consider likely, if someone manages to hack my laptop and get (for example) microphone access, the thing I am most worried about is that they will use acoustic analysis of keystrokes to recover my banking password, not that they will hear…

In any security conversation, the vector one should care about is the path of least resistance.

If the keystroke analyzer was an automated script, being used by some script kiddie who found it on the internet in the near future, the path of least resistance ends up with a really really large number of lanes.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#117

Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? I feel like, at least for the threat models that I consider likely, if someone manages to hack my laptop and get (for example) microphone access, the thing I am most worried about is that they will use acoustic analysis of keystrokes to recover my banking password, not that they will hear…

Use a password manager!

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#118
I wonder if/when the vendors of those home assistants will be required by law to activate on a list of confidencial sounds like screams, gunshots etc.

Maybe not in one year, but in five.. ten?

If they get proper penetration it would be a tempting target for various governments for differing reasons.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#119

Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? I feel like, at least for the threat models that I consider likely, if someone manages to hack my laptop and get (for example) microphone access, the thing I am most worried about is that they will use acoustic analysis of keystrokes to recover my banking password, not that they will hear…

Settup 2FA, e.g. TOTP — then even directly observing you typing in both the password and the token won't do much.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#120
post #118

I wonder if/when the vendors of those home assistants will be required by law to activate on a list of confidencial sounds like screams, gunshots etc. Maybe not in one year, but in five.. ten? If they get proper penetration it would be a tempting target for various governments for differing reasons.

And regulation will require that you have one in your home, just like a fire alarm.

The future is bleak.

Post reply on HN