Live data from Hacker News

Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

github.com

131–140 of 554 posts

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#131
post #110

Earlier quoted context omitted.

Soldering iron to the rescue. Locate the microphone and unsolder it. I haven't seen any microphone integrated in the processor. Yet

Going into full paranoid mode, I wonder if some other sensors / components can be used as a makeshift microphone. For instance, a sufficiently accurate accelerometer can pick up vibrations, right? Maybe even the laser in a CD drive? Anything else?

Camera + bag of chips: https://people.csail.mit.edu/mrub/VisualMic/

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#132
post #43

Earlier quoted context omitted.

macOS is a proprietary binary blob, remotely controlled by Apple. So, the light in the menu bar is not a reliable indicator of anything. There is no privacy on macOS, nor any other proprietary system. You can never be 100% sure what the system is doing right now, as can be anything it is capable of. Apple is putting a lot of money to "teach people" otherwise, but that is marketing, not truth.

> There is no privacy on macOS, nor any other proprietary system. Which is to say, every system in actual widespread use. All such CPUs, GPUs, storage devices, displays, etc. run closed microcode and firmware. It'd be funny if it wasn't so profoundly sad. And even if they didn't, the silicon design is again, closed. And even if it wasn't closed, it's some fab out somewhere that manufactures it into a product for you.…

Yes, ultimately, I want everything to be open. This is not a bag of rice. These are devices packed with sensors, in our homes. As for inspection, I do not have a problem trusting others. I just do not trust big corporations with remotely controlled binary blobs, no matter how much money they put into the safety and security ads. This is a personal opinion, of course.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#133
post #3

I thought the whole point of these camera LEDs was to have them wired to/through the power to the camera, so they are always on when the camera is getting power, no matter what. Having the LED control exposed through the firmware completely defeats this.

Since some sort of firmware is required, this seems like a "turing tarpit" security exploit from my laymans perspective.

There's no standard that I know, that, like "Secure EFI / Boot" (or whatever exact name it is), locks the API of periphery firmware and that would be able to statically verify that said API doesn't allow for unintended exploits.

That being said: imagination vs reality: the Turing tarpit has to be higher in the chain than the webcam firmware when flashing new firmware via internal USB was the exploit method.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#134
post #51
post #3

I thought the whole point of these camera LEDs was to have them wired to/through the power to the camera, so they are always on when the camera is getting power, no matter what. Having the LED control exposed through the firmware completely defeats this.

They are hardwired on Macbooks. From Daring Fireball, quoting an email from an Apple engineer. > All cameras after [2008] were different: The hardware team tied the LED to a hardware signal from the sensor: If the (I believe) vertical sync was active, the LED would light up. There is NO firmware control to disable/enable the LED. The actual firmware is indeed flashable, but the part is not a generic part and there ar…

Yeah, the camera needs a physical lid.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#135
post #85
post #9

Earlier quoted context omitted.

I'd like a law to this effect.

We have to be realistic though. We can't even get a law requiring right to replace a battery on our own iPhones...

We can’t? Then what is this? : https://environment.ec.europa.eu/news/new-law-more-sustainab... ?

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#136

I can see why some people might be concerned about the camera, but I'm far more concerned by the microphone. There's far more sensitive and actionable information that can be gathered from me that way! I'm glad that macOS started putting a light in the menubar when the microphone is in use, but I'd prefer to have unhackable hardware for that instead.

I believe it is possible to turn a speaker into a microphone. Found a paper which claims to do just that[0]. So, there is no safety anywhere? SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit It is possible to manipulate the headphones (or earphones) connected to a computer, silently turning them into a pair of eavesdropping microphones - with software alone. The same is also true for some types of loudspea…

[deleted]

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#137
post #29

Earlier quoted context omitted.

Hardware switch in line with the microphone. Can’t be turned on behind my back.

Wireless noise-cancelling headphones. Oh no, the microphone is back through bluetooth.

If you're half-serious about this sort of opsec, you already have bluetooth disabled. Ideally your hardware wouldn't have support for it at all. Same for wifi.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#138
post #57

I can see why some people might be concerned about the camera, but I'm far more concerned by the microphone. There's far more sensitive and actionable information that can be gathered from me that way! I'm glad that macOS started putting a light in the menubar when the microphone is in use, but I'd prefer to have unhackable hardware for that instead.

FWIW, modern Macbooks also hardware disable the mic when the lid is closed. https://support.apple.com/en-ca/guide/security/secbbd20b00b/...

How is that true? I use my macbook mic occasionally with the lid closed, and an external monitor.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#139

Earlier quoted context omitted.

I believe it is possible to turn a speaker into a microphone. Found a paper which claims to do just that[0]. So, there is no safety anywhere? SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit It is possible to manipulate the headphones (or earphones) connected to a computer, silently turning them into a pair of eavesdropping microphones - with software alone. The same is also true for some types of loudspea…

This only works on audio chipsets that allow pin retasking. Which is, coincidentally, all Realtek chipsets that are present in every PC... (you also need to plug the speaker directly, mostly limiting it to headphones and laptop speakers)

Even where it works, speakers are much worse microphones that dedicated microphones, and so the amount of data that can be gathered is low. Why bother when you probably have a microphone on the same PC that can capture far more sound?

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#140
post #50
post #43

Earlier quoted context omitted.

macOS is a proprietary binary blob, remotely controlled by Apple. So, the light in the menu bar is not a reliable indicator of anything. There is no privacy on macOS, nor any other proprietary system. You can never be 100% sure what the system is doing right now, as can be anything it is capable of. Apple is putting a lot of money to "teach people" otherwise, but that is marketing, not truth.

I get it, free software take, nothing new. But this is a pretty extremist take. Just because a company doesn't push source code and you can't deterministically have 100% certainty, doesn't mean you can't make any assertions about the software. To refuse to make any claims about software without source is as principled as it is lazy. Imagine an engineer brought to a worksite, and they don't have blueprints, can he do…

Yes, I think all devices packed with sensors that live in our homes should be transparent in what they do, that is their code should be available for everyone to see. And yes, it is extremist take, given where we ended up today.
Post reply on HN