Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

181–190 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#181
post #121

Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? I feel like, at least for the threat models that I consider likely, if someone manages to hack my laptop and get (for example) microphone access, the thing I am most worried about is that they will use acoustic analysis of keystrokes to recover my banking password, not that they will hear…

> far more sensitive content visible on the screen and filesystem of my computer than through its camera I mean, yeah, being hacked (and thereby compromising your screen/HDD's contents) is an issue in the first place and keyloggers are only a few lines of code, but I don't think there is anything wrong with controlling the parts that you can control. You can't make a physical "no keyloggers for this piece of text, pl…

There is a conscious and subconscious comfort in knowing that a surveillance camera and/or hot mic in your room is not on.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#182

Thanks to Purism laptops and phone for taking the lead on kill switches for sensors, https://puri.sm/learn/hardware-kill-switches/

Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card. This is from the same group that tries to explain how they don't use proprietary firmware blogs by using the Redpine chips just because the blog is already flashed on it rather…

It's about "who" you distrust. If you distrust the hardware vendor, hope is lost. If you distrust someone with physical access to the device it's about how hard it is, and firmware/hardware is harder to hack (generally) than software. The likelihood of finding a remote exploit into the firmware is a lot lower than finding a remote exploit into a software disable.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#183

Earlier quoted context omitted.

Max Headroom was an extremely subversive program and I continue to be amazed it was actually greenlit, produced and broadcast on mainstream television - in the United States for primetime broadcast, even!

There was a great article some time back about the hisstory behind it. A lot of the episodes satirized the show's own network and specific network executives - some of which flew under the radar and some of which probably hastened the show's demise, etc. Fake edit: I think this is it: https://www.theverge.com/2015/4/2/8285139/max-headroom-oral-...

Just read the whole thing, thanks for sharing.

Interesting story in many ways, particularly the wrestling for ownership of the show, and how they recreated it as a carbon copy for the American market. I remember hearing years ago that he wasn’t actually CG, which made a lot of sense — but as a kid I definitely thought he was.

The subversiveness of the show is great; but it’s particularly amazing how accurately they saterized the future.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#184
post #169
post #159

Earlier quoted context omitted.

The worry is more about stalkers and abusive partners. Abusive partner using it to further control you or hear that you plan to leave or hear that you talk with someone he disapprove (e.g. vuctim breaking out of isolation and distorted reality victim is in). Those situations are physically dangerous when they happen.

Sure but you're attacking the problem from the wrong vector: the partner has physical access to the device and control to install malware, and is abusive . Turning off the microphone or camera is going to trigger retaliation anyway - it doesn't help in this scenario because the problem is the abuser. Helping the victim out of that relationship is what needs to happen - no amount of technical cleverness is going to ma…

Ability to communicate privately is necessary for that "helping the victim out". The easier it is for abuser to control devices of abused, the harder it is to get out. And the harder it is to stay hidden after being out.

The default being "easy to spy and control someone else's devices" makes abuse easy and escape (both mental and physical) hard.

That helping and escaping and staying away is not something that happens without communication and privacy.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#185

Earlier quoted context omitted.

We just had a situation where they insisted on a design that they admitted was less safe in context but fit their standards better.

That's exactly what I would expect from a standards-based certification. But it's also why it's useful - "it is safer" is much easier to fudge (see also: Boeing) than "it is in compliance with this 40-item check list". Either way, it sets the baseline, so there's a net benefit so long as most products would be below that baseline without market pressure to certify.

Most standards have an escape hatch, like PCI's compensating controls. And we weren't blowing smoke, later one of our engineers broke his arm because of the changes on design they wanted.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#186

Also a physical switch to enable writing to the flash rom. That way, malware infections to standalone devices won't survive a reboot.

Most chromebooks have that actually. First stage bootloader is shipped read-only (and then there is a secure boot chain), but can be rewritten.

It's actually a screw, and it's not totally trivial to access though.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#187

Earlier quoted context omitted.

What you’re describing is possible and is done currently in corporate environments by forcing devices to accept a self signed cert that allows companies to spy on their employees traffic. Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.

Whenever the topic of MITM middleboxes comes up, there is usually a vehement opposition to them from much of the security community... while they bring up some valid points, I can't help but wonder if there is some deeper agenda behind that opposition, since these also seem to be the same people who are pushing the user-hostile walled gardens. (Personally have been using a MITM proxy on my network for over a decade.…

The solution to avoiding spying devices isn't MITM, it's making the devices run software that you can trust. If you buy an user-hostile walled garden then you frankly deserve it being hard to MITM.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#188
post #125
post #50

Earlier quoted context omitted.

a real life blank reg here. I live in an RV operate a MESHNET and do everthing i can to foster a common persons free decentralized infrastructure. As mentioned elsewhere ive been taping cameras and stabbing microphones for years now.

Tell me more about how I can get involved

ill put something up in show HN for now dont let any wifi stuff get trashed and wasted, even "broken things" have components vital to home brewing your own infrastructure.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#189
post #143

Earlier quoted context omitted.

Explore and evaluate meshnet projects, find one that you like, and educate others about them. Set up the hardware, link up with existing mesh if you're in a dense enough area. Push federated services like Matrix and ActivityPub based services like Mastadon, so when it's time to go mesh, people don't laugh when you say "It doesn't reach Facebook/Insta".

and check out the Project-Byzantium. https://github.com/Byzantium/Byzantium https://project-byzantium.org/ https://hackaday.com/2015/04/28/meshing-pis-with-project-byz...

Uses kernel 3.x and latest commit is dated 2014 though. I believe there are more actively maintained mesh networking options in OpenWrt.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#190

Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? I feel like, at least for the threat models that I consider likely, if someone manages to hack my laptop and get (for example) microphone access, the thing I am most worried about is that they will use acoustic analysis of keystrokes to recover my banking password, not that they will hear…

> Am I the only one who has far more sensitive content visible on the screen and filesystem of my computer than through its camera? Am I the only one who realizes that I may not be the one who may benefit the most from having a way to physically turn off the camera/mic device?

I.e.

All you people who insist on carrying eavesdropping devices near me are a threat to my privacy.

All of you people who persist in posting to FB and tagging pics I might be in are a threat to my privacy.

Yes. It is a problem.

Post reply on HN