Earlier quoted context omitted.
> and no firmware is involved in enforcing the LED stay on for 3 seconds after a single frame is captured. I may be the oddball here, but that 3 second duration does not comfort me. The only time I would notice it is if I am sitting in front of the computer. While someone snapping a photo of me while working is disconcerting, it is not the end of the world. Someone snapping photos while I am away from the screen is m…
It's strange that none of these companies will include a closable cover for the camera. I got one aftermarket. It is very reassuring since no hacking or accidental misclicks on my part can move the cover.
Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
281–290 of 554 posts
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#282I'm surprised how much these X230s are still being used. People who love real keyboards love them. Personally I didn't think Lenovo's later keyboards were too bad. The one on my T490s was wonderful. However since my work moved to the T14s series, the keyboards have become terrible. The key movement range is too low now, and the feel is crap. It's too bad because Lenovo was the last holdout which still had decent keyb…
I swapped its keyboard with an x220 one, which is the thing to do if you are into the older thinkpad KB feel.
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#283Earlier quoted context omitted.
macOS is a proprietary binary blob, remotely controlled by Apple. So, the light in the menu bar is not a reliable indicator of anything. There is no privacy on macOS, nor any other proprietary system. You can never be 100% sure what the system is doing right now, as can be anything it is capable of. Apple is putting a lot of money to "teach people" otherwise, but that is marketing, not truth.
> There is no privacy on macOS, nor any other proprietary system. Nor is there on any free system for which you didn't make every hardware component yourself, as well as audit the executable of the compiler with which you compiled every executable. (You did self-compile everything, hopefully?)
If the components follow standards and have multiple independent implementations, you can be reasonable confident it's not backdoored in ways that would require cooperation across the stack. At least you raise the cost bar a lot. Whereas for a vertically integrated system, made by a company headquartered in a jurisdiction with a national security law that permits them to force companies to secretly compromise themselves, the cost of compromise is so low that it would be crazy to think it hasn't been done.
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#284Earlier quoted context omitted.
> and no firmware is involved in enforcing the LED stay on for 3 seconds after a single frame is captured. I may be the oddball here, but that 3 second duration does not comfort me. The only time I would notice it is if I am sitting in front of the computer. While someone snapping a photo of me while working is disconcerting, it is not the end of the world. Someone snapping photos while I am away from the screen is m…
It's strange that none of these companies will include a closable cover for the camera. I got one aftermarket. It is very reassuring since no hacking or accidental misclicks on my part can move the cover.
[1] https://www.businessinsider.com/lenovo-thinkshutter-laptops-...
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#285Earlier quoted context omitted.
I believe it is possible to turn a speaker into a microphone. Found a paper which claims to do just that[0]. So, there is no safety anywhere? SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit It is possible to manipulate the headphones (or earphones) connected to a computer, silently turning them into a pair of eavesdropping microphones - with software alone. The same is also true for some types of loudspea…
Despite this being a 2016 paper, it's worth noting that this is true in general and has been common(ish) knowledge among electrical engineers for decades. Highschoolers and undergrads in electrical engineering classes often discover this independently. What's notable about this paper is only that they demonstrate it as a practical attack, rather than just a neat fun fact of audio engineering. As a fun fact, an LED ca…
Not only is it common knowledge it's how drive-thru kiosks work!
Source: I used to test microphone/speakers for a kiosk OEM.
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#286Earlier quoted context omitted.
There seems to be widespread anxiety regarding cameras, but hardly anyone ever talks about microphones. Are conversations not much more privileged information than potentially seeing someone in their underwear?
"All Apple silicon-based Mac notebooks and Intel-based Mac notebooks with the Apple T2 Security Chip feature a hardware disconnect that disables the microphone whenever the lid is closed. On all 13-inch MacBook Pro and MacBook Air notebooks with the T2 chip, all MacBook notebooks with a T2 chip from 2019 or later, and Mac notebooks with Apple silicon, this disconnect is implemented in hardware alone." [1] [1] https:/…
We have no way of verifying that anything they said in that document is true.
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#287There's a reason that zuck has tape over his webcam and a 3.5mm dummy plugged into his combo headphone/mic jack
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#288Earlier quoted context omitted.
I believe that it’s not literally hardwired in the sense that powering up the camera also powers up the camera LED, and instead this relies on logic in the hopefully un-flashable camera+LED firmware. Someone correct me if I’m wrong. You need some logic to enforce things like a minimum LED duration that keeps the LED on for a couple seconds even if the camera is only used to capture one brief frame. I have a script th…
A capacitor can hold enough charge to power led for noticable amount of time even if powered for a brief moment, no logic needed
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#289Earlier quoted context omitted.
But still entirely impossible. So does it matter?
Network traffic monitoring is routinely done at enterprises. It's usually part-automated using the typical approaches (rules and AI), and part-manual (via a dedicated SOC team). There are actual compromises caught this way too, it's not (entirely) just for show. A high-profile example would be Kaspersky catching a sophisticated data exfiltration campaign at their own headquarters: https://www.youtube.com/watch?v=1f6Y…
If the attacker has little to lose (e.g. because they're anonymous, doing this massively against many unsuspecting users etc.), the chance of them eventually succeeding is almost certain.
Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
#290I thought the whole point of these camera LEDs was to have them wired to/through the power to the camera, so they are always on when the camera is getting power, no matter what. Having the LED control exposed through the firmware completely defeats this.
They are hardwired on Macbooks. From Daring Fireball, quoting an email from an Apple engineer. > All cameras after [2008] were different: The hardware team tied the LED to a hardware signal from the sensor: If the (I believe) vertical sync was active, the LED would light up. There is NO firmware control to disable/enable the LED. The actual firmware is indeed flashable, but the part is not a generic part and there ar…
I think it's simpler to assume that most devices can be hacked and the LED indicator isn't infailable than to always keep in mind which device lines are supposed to be safe and which ones aren't.