Live data from Hacker News

Report: NSA intercepting laptops ordered online, installing spyware

forbes.com

1–10 of 57 posts

Re: Report: NSA intercepting laptops ordered online, installing spyware

#3
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

Well, with current practice you don't even get OS recovery CDs anymore. You probably get a "Recovery Partition" with preconfigured OS image. And OEM windows license might not allow you to install from elsewhere and re-use your license.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#4
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

The linked article on Der Spiegel has a section on what they call "persistence:"

The specialists at ANT, which presumably stands for Advanced or Access Network Technology, could be described as master carpenters for the NSA's department for Tailored Access Operations (TAO)... The ANT developers have a clear preference for planting their malicious code in so-called BIOS, software located on a computer's motherboard that is the first thing to load when a computer is turned on... This has a number of valuable advantages: an infected PC or server appears to be functioning normally, so the infection remains invisible to virus protection and other security programs. And even if the hard drive of an infected computer has been completely erased and a new operating system is installed, the ANT malware can continue to function and ensures that new spyware can once again be loaded onto what is presumed to be a clean computer. The ANT developers call this "Persistence" and believe this approach has provided them with the possibility of permanent access.

http://www.spiegel.de/international/world/catalog-reveals-ns...

Re: Report: NSA intercepting laptops ordered online, installing spyware

#5
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

From the article:

>The latest report, this time via Der Spiegel and based on internal NSA documents, reveals that the NSA, in conjunction with the CIA and FBI, has begun intercepting laptops purchased online in order to install (quite literal) spyware and even hardware ... Agents divert shipments to secret warehouses ... install the software and/or hardware ...

So if they're installing hardware/firmware that is something a clean reinstallation won't fix. Probably should have titled the submission software/hardware.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#6
Maybe it would've been better for this news to have been broken a month or two ago, for maximum financial impact.

In all seriousness, one has to wonder how shipments get diverted, and how easily this process can be taken advantage of. Surely the companies handling these "special" shipments are made aware of details on a need-to-know basis (eg: super-secret gov. employee is going to be taking the shipment for an hour, don't ask why and don't tell anyone), but are they able to verify that their handlers are who they say they are?

Would you trust a shipping company based in China? Why would you trust an American one any more than a Chinese one?

Re: Report: NSA intercepting laptops ordered online, installing spyware

#7
post #4
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

The linked article on Der Spiegel has a section on what they call "persistence:" The specialists at ANT, which presumably stands for Advanced or Access Network Technology, could be described as master carpenters for the NSA's department for Tailored Access Operations (TAO)... The ANT developers have a clear preference for planting their malicious code in so-called BIOS, software located on a computer's motherboard th…

My bad - I didn't read Der Spiegel article.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#8
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

Seriously? Why on earth should Joe Average be made to clean reinstall OS after buying a new hardware?

Re: Report: NSA intercepting laptops ordered online, installing spyware

#9
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

Seriously? Why on earth should Joe Average be made to clean reinstall OS after buying a new hardware?

no one said 'be made'. He said the average joe should acknowledge that it is a good idea. Previously I have suggested other people reinstall to get rid of bloatware installed by the vendor.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#10
post #4
post #2

Even Joe Average should be acknowledged that clean reinstallation after getting new hardware is a good practice. Ed: BTW, does somebody know how to audit your laptop in its current state?

The linked article on Der Spiegel has a section on what they call "persistence:" The specialists at ANT, which presumably stands for Advanced or Access Network Technology, could be described as master carpenters for the NSA's department for Tailored Access Operations (TAO)... The ANT developers have a clear preference for planting their malicious code in so-called BIOS, software located on a computer's motherboard th…

This is probably one of the most important problems of our generation to solve (as hackers, not philanthropists) and it's sort of amazing that it's hardly known, let alone discussed. I've brought it up before and it seems like everyone's reaction is that it's not worth worrying about. But there are adversaries besides the NSA, such as malware. And since userspace programs can upgrade your BIOS, then therefore it's possible to write a viruses to infect your BIOS exactly as described here. If the BIOS security model is even slightly broken, then malware will find a way into it, and security is hard to do perfectly. Why are we trusting proprietary motherboard manufacturers not to have backdoors in their closed-source systems? The answer is probably because we have little choice in the matter. Thus we're giving up a basic right: for us to have faith in our security practices. If, say, Colin Percival's careful security habits can simply be circumvented by his motherboard, then none of us are safe.

We need an open source motherboard for people who care about protecting themselves from this kind of thing. Or at least an open source BIOS. But it's an insidious problem, because once a BIOS is infected, it controls everything that may ever replace the BIOS. Therefore it's almost impossible to detect if your BIOS has been "man in the middle'd," and hence even an open source BIOS may not be enough.

I don't have a good solution, but this is a terribly important problem to solve.

Post reply on HN