Live data from Hacker News

The Google plasma globe affair of 2012

lcamtuf.coredump.cx

31–40 of 103 posts

Re: The Google plasma globe affair of 2012

#31
post #20
post #7

Earlier quoted context omitted.

A power user wouldn't (shouldn't) expect a device merely using USB for power to pop up anything on the PC it's plugged into. That would be a dead giveaway that it's doing something it shouldn't be doing.

I’m pretty desensitized to window’s CMD prompts popping up when I install a program or plug in a device. My Razer keyboard even installs borderline malware when you plug it in. However, if this happened on my Mac I would immediately be skeptical.

They make me pretty nervous on windows too… but it's windows so I don't know enough to presume for sure I'm infected or it's just windows.

Re: The Google plasma globe affair of 2012

#32
Bit of a weird opening with the car crash stuff considering that driving is one of the most dangerous actives people do every day, and lots of people still die or are hurt by/from vehicles every day.

https://www.cdc.gov/vitalsigns/motor-vehicle-safety/index.ht...

Re: The Google plasma globe affair of 2012

#33
post #20
post #7

Earlier quoted context omitted.

A power user wouldn't (shouldn't) expect a device merely using USB for power to pop up anything on the PC it's plugged into. That would be a dead giveaway that it's doing something it shouldn't be doing.

I’m pretty desensitized to window’s CMD prompts popping up when I install a program or plug in a device. My Razer keyboard even installs borderline malware when you plug it in. However, if this happened on my Mac I would immediately be skeptical.

[deleted]

Re: The Google plasma globe affair of 2012

#35
post #28
post #20

Earlier quoted context omitted.

I’m pretty desensitized to window’s CMD prompts popping up when I install a program or plug in a device. My Razer keyboard even installs borderline malware when you plug it in. However, if this happened on my Mac I would immediately be skeptical.

> My Razer keyboard even installs borderline malware What does the software do? I assume it asks for permission and you decline? In a couple of decades of buying USB keyboards I have never let one install software and I have never noticed any problems.

Razer Keyboards and Devices auto-install weird proprietary "drivers" (borderline adware), and the software they auto-install also used to give anyone root/admin privileges (borderline malware) - https://www.engadget.com/razer-mouse-windows-10-security-vul... as an example

Re: The Google plasma globe affair of 2012

#36
post #30

This could be improved by adding a microphone to help determine a good time to execute.

Rather than a microphone, measure the plasma globe current consumption. They use more power when they are being played with. At that point the user is probably logged in and distracted.

Ohh that's good!

Re: The Google plasma globe affair of 2012

#37
The author links to UKIP[0], a Linux daemon that they built to try to protect against these kinds of attacks. Did a quick "apt search" on my Debian machine, but nothing came up. Do any major distros package this, and do any install and enable it by default?

I guess it uses heuristics to determine if a device is evil, and that could cause a lot of false positives (which would create spurious bug reports and support cases for distro maintainers), so maybe having something like that installed and running by default isn't a great idea.

[0] https://github.com/google/ukip

Re: The Google plasma globe affair of 2012

#38

I wonder if it flopped for anyone because they had a different keyboard layout (like Dvorak) set.

It's a really interesting point. I've had to go through quite a bit of trouble to get non-keyboard HID devices (like Yubikeys) "un-Dvoraked" so that they work as expected.

Re: The Google plasma globe affair of 2012

#39
Watching the video, they mention that in order for the red team to reach their goal (downloading Google Glass schematics), they had to pivot from the users they compromised with the plasma globe (who were not working on the Glass project) to users on the Glass team. They seemingly did that using an image attached to an email that executed its payload when the email was opened. They didn't elaborate what the payload did, but mentioned that it "captured the user's fingerprint" and enabled them to use that to access the Glass schematics.

Although it sounds much less exciting, this sounds like a much more serious exploit than a compromised USB plasma globe - embedded in an image and requiring minimal user interaction to execute. I wonder whether they identified a novel 0day in a common image parser or something.

Re: The Google plasma globe affair of 2012

#40
post #21
post #19

Earlier quoted context omitted.

That was not a side project from my limited understanding ;) I believe the M$/Alphabet/Meta security teams are probably more advanced or on par with the best state sponsored teams. I could be wrong, plus the state sponsored teams might have infiltrated the FAANG security teams ;) However, I think the FAANG companies act somewhat more restricted. Three letter agencies don't have qualms about things like "chloroforming…

NSA’s TAO surely has many orders of magnitude more budget than Google’s red team?

I don't think the NSA pays as well though. You also have large restrictions. Not just stuff like never having smoked weed in your life (we are talking about CS people...) but that once you even have a security clearance (a pain to get in the first place) you have a lot of daily life headaches. You have to carefully watch what you say. International travel has to be reported (and can even be a big hassle). Etc. I'm not sure if the same is true for Google's Red/Blue teams, but I feel pretty confident in saying that they probably get paid more.
Post reply on HN