Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

21–30 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#21

I have a friend that works for a chip company and he said he couldn’t get into details but the amount of back doors in communication companies and in chips would scare the shit out of me.

I question this. Actually I'm going to assert this is only true if your friend is referring to hidden back doors that he believes exist. I don't believe any employee of a chip company is aware of a back door knowingly added to their own product (with one exception see below).

I say this because NSA seems more clever than that, and because any scheme to explicitly add back doors is bound to be eventually exposed.

Instead they do things like have their former employees and contractors hired into tech companies, and those folks add innocuous bugs that can plausibly be denied as back doors. Also I bet they look for bugs that can be used as back doors, given access to source code and chip design data, then fail to fix them.

Re: Spy agency ducks questions about 'back doors' in tech products

#22
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

a little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network

Exactly what have they got, if you never connect it to a network afterward, either? A key-log that never makes it back to them?

(I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function — but without big antennas, how’s it going to report?)

Re: Spy agency ducks questions about 'back doors' in tech products

#23

The director of the NSA lied while under oath to congress, and nothing happened. As far as I'm concerned, what 3 letter agencies say publically is irrelevant.

To be fair, Clapper did come back for a follow up, and basically said, "oops, looks like I was wrong." That's it. Congress didn't push back, and thanked him for his service. So looks like Congress is complicit as well.

Re: Spy agency ducks questions about 'back doors' in tech products

#24
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

a little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network

And it can add a slight flicker that can be used as a signal and detected from outside.

Re: Spy agency ducks questions about 'back doors' in tech products

#25
post #22

Earlier quoted context omitted.

a little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network

Exactly what have they got, if you never connect it to a network afterward, either? A key-log that never makes it back to them? (I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function…

Researchers have been able to make integrated circuits emit radio waves.

Re: Spy agency ducks questions about 'back doors' in tech products

#26
post #15
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

Hope you have your bluetooth also turned off

Re: Spy agency ducks questions about 'back doors' in tech products

#27
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

or rather they're not getting in _or_ out. they might already be in. as long as both in _and_ out are disconnected, you're set.

A 2g or 3g module is If the NSA has enough of an interest to be intercepting your packages, they're not going to shy away at adding in a transmitter or two of their own preference.

Re: Spy agency ducks questions about 'back doors' in tech products

#28
post #15
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA.

Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right.

With closed firmware and wireless capabilities, you can never know what they're doing at a given time.

Stuxnet reached systems which were seriously air gapped. Consider a what a laptop with a witty wireless card firmware can do.

I'm not getting into TEMPEST attacks and their newer versions, passive surveillance, etc.

I've listened tales about Cisco devices which were configured to isolate and prevent internet traffic but, they mistakenly forgot to drop some magic packets. Uh.

---

Random facts about this stuff:

- Your Intel system runs a special version of Minix on its Management Engine. A version of Minix customized for Intel by its original developer.

- There are photos of Cisco devices which were delightfully enchanced by NSA before shipping to its customer via special firmware and/or hardware. NSA still retains this capability.

Re: Spy agency ducks questions about 'back doors' in tech products

#29

>Three former senior intelligence agency figures told Reuters that the NSA now requires that before a back door is sought, the agency must weigh the potential fallout and arrange for some kind of warning if the back door gets discovered and manipulated by adversaries. Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences. And even now, they just need…

"Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences."

Kinda. There apparently is some approval process and such but I'm not sure everyone at he agency was able to make such requests in the first place...

I'm with your gist, I'm just not sure we know how widespread it really was. I'm not inclined to agree that it must have been ultra widespread.

Re: Spy agency ducks questions about 'back doors' in tech products

#30
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

They totally still call you paranoid. Snowden unfortunately meant nothing to the general technology consumer mass. They're more than happy to defend tooth and nail their jails. See Discord or Zoom as prime current examples.

It is ridiculous that he had to go through this just for people to shake their shoulders and keep on, except for the few that already were inclined to care.

Post reply on HN