Live data from Hacker News

Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

github.com

331–340 of 554 posts

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#331
post #306

Earlier quoted context omitted.

I don't think it is backwards, personally. The threat of public humiliation, and the capability for someone to spy on what you do in your own home, is worse with the camera. > chats and email, browsing history, etc are all much more likely to result in harm if leaked than a recording of you innocently in your home. This is far less of an intrusion for most people than recording what they are actually doing in their o…

I think we may just be bumping into cultural differences here. I grew up in a household were being naked around family members was common. I spend time in clothing-optional spaces. I rarely draw the blinds on my windows, etc. I'm not concerned with what other people think in this way and such images could never be used to extort me. Consider the case of Germany - people there are extremely concerned about their priva…

I think, though am prepared to be wrong, that you'll probably find yourself in the minority there.

It's not just about nudity and extortion, but someone having access to watch you, whenever they feel like, in your safe space. That sense of violation that people also feel when (for instance) they have been the victim of burglary - the missing stuff is often secondary to the ruined sense of security. There's a vast difference between leaving your curtains open and having someone spying on you from inside your own home.

Is it rational to put this above other concerns? That's a whole different debate and not one I'm particularly interested in. But it explains why people are concerned about cameras over 'mere' data intrusion.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#332
post #264
post #163

Earlier quoted context omitted.

I happen to have some first-hand knowledge around the subject! In 2014 someone did a talk[0] on disabling the camera on some older Macbooks. It was fairly trivial, basically just reflashing the firmware that controlled the LED. I worked on the security team at Apple at the time and in response to this I attempted to do the same for more modern Macbooks. I won't go into the results but the decision was made to re-arch…

I assume you're not longer working on it, but why not just wire it so that: - The LED is in parallel, but with the sensor voltage supply, not the chip - Camera sensor idle voltage = low voltage for the LED (be it with stepping if needed) - Camera sensor active voltage = high voltage for the LED (again, stepping if needed) - little capacitor that holds enough charge to run the LED for ~3 seconds after camera goes back…

You can't drive an LED that way in production electronics: you need to use an LED driver circuit of some kind to ensure the LED has constant current, and also to protect against failure modes. Also, a capacitor large enough to power a daylight-visible LED for 3 seconds is not as "little" as you're thinking; there's likely not enough space in a laptop lid for one of those. A driver circuit would be smaller and thinner.

Agreed, however, that the LED should be controlled by the camera sensor idle vs. active voltage.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#333
post #61
post #43

Earlier quoted context omitted.

macOS is a proprietary binary blob, remotely controlled by Apple. So, the light in the menu bar is not a reliable indicator of anything. There is no privacy on macOS, nor any other proprietary system. You can never be 100% sure what the system is doing right now, as can be anything it is capable of. Apple is putting a lot of money to "teach people" otherwise, but that is marketing, not truth.

> There is no privacy on macOS, nor any other proprietary system. Nor is there on any free system for which you didn't make every hardware component yourself, as well as audit the executable of the compiler with which you compiled every executable. (You did self-compile everything, hopefully?)

> You did self-compile everything, hopefully?

Including the compiler, of course.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#334

Earlier quoted context omitted.

Yes, ultimately, I want everything to be open. This is not a bag of rice. These are devices packed with sensors, in our homes. As for inspection, I do not have a problem trusting others. I just do not trust big corporations with remotely controlled binary blobs, no matter how much money they put into the safety and security ads. This is a personal opinion, of course.

> As for inspection, I do not have a problem trusting others. I just do not trust big corporations with remotely controlled binary blobs I'll just highlight this excerpt of your own words for you, and usher you to evaluate whether your position is even internally consistent.

(not OP) Don't think that is inconsistent.

Trusting someone doing the right thing when you purchase is different from trusting them not tampering things remotely in the future. Companies can change management, human can change their mind. The time factor is important

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#335
post #305

Earlier quoted context omitted.

That's backwards. The LED should be connected to camera's power, or maybe camera's "enable" signal. It should not be operable via any firmware in any way. The led also has to be connected through a one-shot trigger (a transistor + a capacitor) so that it would light up, say, for at least 500 ms no matter how short the input pulse is. This would prevent making single shots hard to notice. Doing that, of course, would…

or, you can have a physical switch, like the Framework. that also hits your BOM but its not complex!

Would a bit of Post-It Note (for minimal adhesion) damage the screen coating if left on most of the time? Would even that much thickness stress the screen when opened and closed thousands of times? Is there a better (self-service) material?

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#336

Earlier quoted context omitted.

Yes, photos of naked people are used to extort them (usually into just paying the holder to delete them). https://news.ycombinator.com/item?id=42261730

This raises a different but related question. In what world should a victim of a crime be extorted for doing innocent things in their home. If a peeping tom took a photo though a window, could that be used to extort someone? When people are extorted for these kinds of things it's usually catfishing that leads to sexual acts being recorded. That's not related to cybersecurity.

Fear of harrasment. You don't want your coworkers see you naked, do you?

edit: s/baked/naked/ :D

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#337

Earlier quoted context omitted.

> There is no privacy on macOS, nor any other proprietary system. Which is to say, every system in actual widespread use. All such CPUs, GPUs, storage devices, displays, etc. run closed microcode and firmware. It'd be funny if it wasn't so profoundly sad. And even if they didn't, the silicon design is again, closed. And even if it wasn't closed, it's some fab out somewhere that manufactures it into a product for you.…

Yes, ultimately, I want everything to be open. This is not a bag of rice. These are devices packed with sensors, in our homes. As for inspection, I do not have a problem trusting others. I just do not trust big corporations with remotely controlled binary blobs, no matter how much money they put into the safety and security ads. This is a personal opinion, of course.

> I just do not trust big corporations with remotely controlled binary blobs

Only outstanding individuals such as Jia Tan.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#338
post #306

Earlier quoted context omitted.

I don't think it is backwards, personally. The threat of public humiliation, and the capability for someone to spy on what you do in your own home, is worse with the camera. > chats and email, browsing history, etc are all much more likely to result in harm if leaked than a recording of you innocently in your home. This is far less of an intrusion for most people than recording what they are actually doing in their o…

I think we may just be bumping into cultural differences here. I grew up in a household were being naked around family members was common. I spend time in clothing-optional spaces. I rarely draw the blinds on my windows, etc. I'm not concerned with what other people think in this way and such images could never be used to extort me. Consider the case of Germany - people there are extremely concerned about their priva…

Empirically, most low level extortion does seem to be about leaking video. I would see a threat model based on 'criminal wants to extort me for money'. As more reasonable than 'creep wants to look through my computer for creeping'. And it seems like extortion focusses on video, so that is the bigger threat. Even if it is less invasive.

I presume the reason behind this is that video is much more likely to be re-shared. Sending bob a zip of someone's inbox is unlikely to be opened, and even less likely to be shared with strangers. But send bob a video of Alice, and he might open it. Heck, he might not know what the video is until he opens it. So even if he is decent, he might still see it. And if he is less decent and shares it, strangers are much more likely to actually view it.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#339
post #193

Earlier quoted context omitted.

An indicator light hardwired is nice but I apparently can't trust hardware manufacturers to design it properly. My work laptop (HP Dragonfly) has a physical blocker that closes over the camera when I haven't explicitly pressed the button that enables the camera. The blocker is black and white stripes so it's very obvious when it's covering the sensor. This should absolutely be the security standard we all strive for…

The Dell Latitude business laptops now have a wired led and wired switch. Besides the white led, there’s no indication which is on or off, and I don’t trust any of the software or firmware chain to be reliable. (score one for macs being transparent and prescient)

Dell should go back to the basic design of the Latitude E6400, but with modern electronics and screen of course, and drop the optical drive. The keyboard on that laptop was fantastic, and the single captive screw on the back panel was great for serviceability.

Re: Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230

#340
post #305

Earlier quoted context omitted.

That's backwards. The LED should be connected to camera's power, or maybe camera's "enable" signal. It should not be operable via any firmware in any way. The led also has to be connected through a one-shot trigger (a transistor + a capacitor) so that it would light up, say, for at least 500 ms no matter how short the input pulse is. This would prevent making single shots hard to notice. Doing that, of course, would…

or, you can have a physical switch, like the Framework. that also hits your BOM but its not complex!

[deleted]
Post reply on HN