Live data from Hacker News

Research shows how MacBook Webcams can spy on their users without warning

washingtonpost.com

1–10 of 241 posts

Re: Research shows how MacBook Webcams can spy on their users without warning

#2
Nice.

I own a Logitech C920 Pro and a software called webcam settings allows me to easily turn off the lights. If this software can do this, so can a malware.

Also, a malware can be designed to click quick snaps when there is no keyword or mouse activity for a specific period. This can help the malware go unnoticed without controlling the light. Want to take it to the next level? You can use the mic anytime to estimate the user's distance from the system and then enable webcam accordingly. I know this would not be very accurate, but possible.

Re: Research shows how MacBook Webcams can spy on their users without warning

#8
One of my friends always keeps her MacBook open, and had Skype set up to auto-answer video calls. (Until I fixed that for her.) She's a very educated professional woman who teaches at a university you've heard of.

In other words, HN readers might come up with defensive hacks, but 99% of the population is completely vulnerable to all kinds of spying, whether government or stalker, and the situation can only get worse as wireless electronics pervade every part of our lives. Books? Internet-enabled. Fridge? Internet-enabled. Car? Internet-enabled. Our own bodies? Carry wireless-connected smartphone 24x7.

Re: Research shows how MacBook Webcams can spy on their users without warning

#9
Honestly, I don’t understand why it’s so difficult to create a camera chip not susceptible to any software hack. The camera sensor needs electrical current to work. Simply place the LED inline or in parallel to the camera and you are done. Any time current is sent to the camera sensor, the LED cant help it but light up. My knowledge of electronics is limited, but I know for a fact that this can be achieved without the use of any reprogrammable microchips, with the use of a simple electrical circuit.

Re: Research shows how MacBook Webcams can spy on their users without warning

#10
So their proof of concept malware... actually changes the firmware in the camera micro-controller? Do I have that right?

Here's the research paper linked to in the story, if anyone wants to see what the researchers have to say. I haven't taken a look yet myself: https://jscholarship.library.jhu.edu/handle/1774.2/36569

Ah, there it is right in the abstract, yep:

> The same technique that allows us to disable the LED, namely reprogramming the firmware that runs on the iSight, enables a virtual machine escape whereby malware running inside a virtual machine reprograms the camera to act as a USB Human Interface Device (HID) keyboard which executes code in the host operating system.

Ooh, neat.

Post reply on HN