Live data from Hacker News

Report: NSA intercepting laptops ordered online, installing spyware

forbes.com

31–40 of 57 posts

Re: Report: NSA intercepting laptops ordered online, installing spyware

#31
post #6

Maybe it would've been better for this news to have been broken a month or two ago, for maximum financial impact. In all seriousness, one has to wonder how shipments get diverted, and how easily this process can be taken advantage of. Surely the companies handling these "special" shipments are made aware of details on a need-to-know basis (eg: super-secret gov. employee is going to be taking the shipment for an hour,…

This capability already exists for counter drug and other interceptions. I'm sure it was FBI asking ups and fedex to hold a suspected drug shipment and let them look at it briefly; it is entirely possible no one at the shipper, and certainly not on the line, knew it was NSA. They might have said terrorism, too, but probably not. Maybe just "a law enforcement matter" with no questions asked.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#32

Earlier quoted context omitted.

This is probably one of the most important problems of our generation to solve (as hackers, not philanthropists) and it's sort of amazing that it's hardly known, let alone discussed. I've brought it up before and it seems like everyone's reaction is that it's not worth worrying about. But there are adversaries besides the NSA, such as malware. And since userspace programs can upgrade your BIOS, then therefore it's po…

Can the bios chips/eeproms be replaced on a running computer? Can you remove the bios chip, put it in a different (running) computer, use flashrom to read it, put it back, use flashrom to read it again, and compare the two? Either the virus doesn't hide itself (on calls to read from the bios nvram), and it will be visible on comparison with a pristine (if you have one) copy of the same bios, or it does hide itself an…

I'm so glad someone is thinking about the problem of "how do we know our hardware hasn't been subverted?" It's hard, and there are many facets.

As far as I can tell, what's needed is: (a) an open source BIOS, (b) coupled with some physical BIOS chip reader. And the chip reader needs to be cheap enough for us to assemble ourselves; we can't really trust some company to make it for us, because the company could be coerced into subverting it or it could be subverted in transit after we order it. So it seems like we need an open source blueprint of a BIOS chip reader that's cheap and easy enough for anyone to make themselves. (A tall order, to be sure.)

(a) is a requirement because if the BIOS is closed source, then there's no way to know whether it's backdoored. (b) is a requirement because if it's impossible for an external device to obtain a memory dump of the ROM, then we won't be able to verify that the open source BIOS hasn't been subverted. And it has to be a memory dump obtained by an external device; we certainly can't trust a BIOS to verify its own integrity. Hence a separate, physical device is going to be a necessary and standard security requirement for the first time in the history of the open source community's security practices.[1]

So when we build a new computer, the first step is to order the parts. (Note: the parts may be subverted by an adversary in transit.)

Then we'd either (1) order the parts for the open source BIOS verifier device, or (2) order the fully assembled BIOS verifier from some trusted company. As I said before, (2) is a dangerous idea because an adversary can simply intercept your packages in transit and subvert the verifier. So this whole process is unfortunately going to be so much of a pain in the ass that few people are going to want to do it. But a painful option is better than no option.

Now, the packages for your new computer arrive, along with the components for the BIOS verifier. You assemble the computer and the verifier. Then you boot from a bootdisc which is designed to replace your motherboard's BIOS with the open source one.

At this point -- and this is the part I'm unclear about -- the verifier somehow needs to be able to obtain a dump of the motherboard's ROM containing the BIOS. Then the verifier calculates the checksum of the dump, and you can finally verify that the checksum matches the expected one (the expected checksum would be published on the open source BIOS's website alongside each of its download links).

If all of these steps are followed, then we are safe. Otherwise no one can be sure they're safe, not even Colin. (I'm hoping if I mention often enough that Colin's security practices can be defeated by this, then people will realize the magnitude of the danger facing us.)

I'm sad because there's almost no way to turn this idea into a company. All companies (especially US companies) are constantly coerced or subverted by governments. So it's unlikely that the steps I've outlined will ever be widely adopted. But without these steps, there's no way to trust any of our security measures. This BIOS malware technique must have been one of the NSA's most lucrative and powerful, because nobody has yet even bothered to care about verifying BIOS integrity at the hardware level.

[1] - It's interesting to consider the question: Have even our most paranoid and trusted figureheads like Stallman ever verified the integrity of their computer's BIOS? Or did they simply trust that their Yeelong Lemote laptop BIOS wasn't subverted in transit after they ordered it? I'd bet the latter, because I've never heard of an external tool that can obtain a memory dump of a laptop motherboard's ROM, though I'd love to be wrong about that.

EDIT: And now this submission has been totally buried off the frontpage. So no one will even read this. Awesome. http://hnrankings.info/6983099/

Re: Report: NSA intercepting laptops ordered online, installing spyware

#34
post #22

This is starting to get really bad. Why aren't there demonstrations in the streets? I tried to sound out my relatives over the holidays to see what they think about Snowden/NSA and nobody seems to care.

Because the average person is short sited. They don't do anything (or don't realize how terrible it is) until it directly affects them.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#35
post #29
post #14

My suspension of disbelief is getting really close to breaking. Don't get me wrong, I'm fully against the entire NSA spying deal. But these "reports" just keep getting more and more outrageous. The problem is not that I don't think these things have been happening, but rather that the continuous slow leaking by news media is causing the next big reveal to be just more background noise. We need a big, sudden, destruct…

I don't think this operation is very unreasonable if highly targeted. If they did this to computers bought by Iran's nuclear program, or known watched mid level jihadis , the only problem I'd have would be I don't have enough money to buy an open bar for everyone involved. No one is arguing this was pervasive. The dangerous area IMO would be domestic law enforcement or political use (well , not so gray), and attackin…

The problem is the NSA has shown itself to be indiscriminate in its targeting for other methods of info gathering. So trusting them to 'use responsibly' is a bit like trusting a bunch of teenagers to 'use responsibly' with a case of beer and the parents away.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#36

Interesting my Lenovo order just delayed by over 30 days. Not that I won't wipe it and put Linux on it anyway, but if the hardware or BIOS was tempered with I'd be none the wiser. (Not that I'd be worth effort, but anyway)

same with my order (finally being delivered tomorrow), though i'm highly doubtful that they do this for all computers. prolly only ones for already-monitored targets. doing it for everyone is highly impractical and expensive.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#37
post #29

Earlier quoted context omitted.

I don't think this operation is very unreasonable if highly targeted. If they did this to computers bought by Iran's nuclear program, or known watched mid level jihadis , the only problem I'd have would be I don't have enough money to buy an open bar for everyone involved. No one is arguing this was pervasive. The dangerous area IMO would be domestic law enforcement or political use (well , not so gray), and attackin…

The problem is the NSA has shown itself to be indiscriminate in its targeting for other methods of info gathering. So trusting them to 'use responsibly' is a bit like trusting a bunch of teenagers to 'use responsibly' with a case of beer and the parents away.

This operation as described leaves enough of a physical record that it couldn't be used universally.

I'm much more concerned about "NSA backdoor firmware", and vastly more concerned about China doing the same. It's a lot easier to do this at design/manufacture than en-route.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#38
post #37

Earlier quoted context omitted.

The problem is the NSA has shown itself to be indiscriminate in its targeting for other methods of info gathering. So trusting them to 'use responsibly' is a bit like trusting a bunch of teenagers to 'use responsibly' with a case of beer and the parents away.

This operation as described leaves enough of a physical record that it couldn't be used universally. I'm much more concerned about "NSA backdoor firmware", and vastly more concerned about China doing the same. It's a lot easier to do this at design/manufacture than en-route.

>I'm much more concerned about "NSA backdoor firmware", and vastly more concerned about China doing the same.

No reason the 'upgrades' couldn't be firm/hardware. Just upthread a bunch of people complain about "customs" delays when ordering computers, one person for > 30 days. That is way, way more than enough time. Yes, easier at manufacture. No, not necessary at manufacture. Yes, possible en-route.

Also why would you be more concerned about China doing the same?

edit: and also the problem wouldn't be using the technique 'universally', as in doing it to every machine. The problem would be giving an org like the NSA full control over deciding who to target, incl. US citizens. That is, being indiscriminate in terms of completely disregarding domestic laws, protections, etc., rather than being indiscriminate in terms of spamming loaded chips in every box.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#39
post #17

And suddenly, people like Richman Stallman seem much less crazy when they ask for free (as in libre ) hardware, free BIOS, free everything.

Is 'free as in libre' hardware really any protection if the NSA intercepted your device at the border and planted undetectable MITM malware/hardware? Are you really gonna take the whole thing apart and check every chip for modifications?

No. And Stallman (unfortunately) doesn't seem to focus too much on the security aspect of it. His focus is mostly on the freedom, as in ability to copy/modify/do-as-you-please aspect of it.

Re: Report: NSA intercepting laptops ordered online, installing spyware

#40
post #37

Earlier quoted context omitted.

The problem is the NSA has shown itself to be indiscriminate in its targeting for other methods of info gathering. So trusting them to 'use responsibly' is a bit like trusting a bunch of teenagers to 'use responsibly' with a case of beer and the parents away.

This operation as described leaves enough of a physical record that it couldn't be used universally. I'm much more concerned about "NSA backdoor firmware", and vastly more concerned about China doing the same. It's a lot easier to do this at design/manufacture than en-route.

The article doesn't specify if the backdoors installed en route are hardware or firmware/software.
Post reply on HN