Live data from Hacker News

Did this Tor developer become a victim of NSA's laptop interception program?

privacysos.org

81–90 of 169 posts

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#81

Earlier quoted context omitted.

As per my other post, the keyboard is most likely a PS2 keyboard interface (physical or emulated) connected to a simple PS2/LPC(ISA) bus interface inside the EC. It will literally deliver an IRQ to that bus (IRQ 1) at which point the EC has to suck down a character from the keyboard buffer and do something with it. It's not clever, can't use DMA and generally is the dumbest thing in the entire machine. If they someho…

Thanks for the clarification! But one question remains: how does the EC control stuff like the bluetooth radio and webcams? They're USB devices to the OS, so in theory there should be a USB hub inside the EC?

Not necessarily. It may only have power control function. If you pull a USB device out it's the same as turning it off in theory and vice versa. It's probably just turning the device off or setting it into standby mode.

edit to add: some Intel south bridges have integrated EC which makes things a little uncertain.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#82
post #31

Earlier quoted context omitted.

I don't understand. Richard's point doesn't depend on an Amazon bug that transposes tracking codes. But your point does depend on the NSA redirecting packages to Alexandria in such a way that anyone who checked their order status would notice.

Why do you think NSA cares much about hiding their activities from you? I can tell you a story. Some years ago, back in Russia, as a [naive] kid, I've developed a surveillance system for Telrad telecom exchange [ultimately for FSB]. Do you think anyone cared to do that project in secrecy? I can give you the answer. Nope. As far as I understand NSA can legally intercept packages and can legally install undetectable su…

During the cold war (and shortly after), this type of activity would be exactly what red-blooded Americans would say differentiated us from Russia (not hiding it, but doing it at all). Americans have constitutional protection against unreasonable search and seizure by the government.

These days you could probably drop the country and year and have trouble differentiating tactics used by the US and Russia.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#83
post #67

Earlier quoted context omitted.

Worse: laptop keyboards are usually connected to a special embedded firmware (IIRC on my Clevo laptop it's called EC, short for embedded controller), which handles the FN+x key combos like LCD brightness, volume control, keyboard backlight (Lenovo!), WiFi/BT/cellphone-data connectivity, webcam enabling (!) and other detailed functions. Now, if this EC chip is vulnerable, a malicious keyboard can have direct DMA acces…

Laptop keyboards are directly connected to embedded controller primarily because they are completely passive switch matrices (and EC includes - often directly in hardware - logic for scanning keyboard matrix), so there is nothing meaningful to exploit on the EC side. Also connecting EC directly to some PCI bus does not make much sense from both system design and cost perspectives. Usual place to connect EC to is LPC,…

Hold a second, BIOS flash? /me smells #badBIOS

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#84
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

You are asking which is more likely. I.e. is the probability of compromise higher than 50% ? I'd say the the probability is less than that. But I think even risks with lower than half probability are worth worrying about.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#85
post #11

The obvious explanation here is that the USPS fucked up. As the tweet says, you'd think the NSA program would be more subtle. Further, there isn't much in the way of intelligence presence in Alexandria. So what's more likely: that the NSA does this program in a secret location that's still right next to all the non-secret stuff, and they can't cover up the tracking data, or that the USPS accidentally sent a package t…

At this point aren't we all just guessing? Reading this thread I'm surprised how strongly many folks I respect (like you - viva FQ&A!) are insisting this could not be an NSA screw up. The truth is we don't know, so why rush to conclusions (even benign conclusions) instead of waiting to learn more?

And imagine if you were Andrea and you develop software that dissidents around the world depend on with their life, while also knowing the NSA has simultaneously tried to weaken it. If the laptop does get rerouted to her with an apology from USPS and you were her, are you saying you wouldn't hesitate even a little before accepting it and transferring your data onto it?

Ultimately, I think that's the real story here. The biggest problem with having a government that watches its citizens isn't the watching per se, it's the loss of trust.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#86
post #31

Earlier quoted context omitted.

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

I don't understand. Richard's point doesn't depend on an Amazon bug that transposes tracking codes. But your point does depend on the NSA redirecting packages to Alexandria in such a way that anyone who checked their order status would notice.

No one thinks redirection would be visible to 'anyone'. The theory is thhis could be a one-time screw-up, like a redaction failure, revealing a waypoint that was supposed to be secret. (Maybe a label that was supposed to go on the outer box went on the inner box instead?)

I'd agree an innocent screw-up is far more likely, here and in any particular case where something weird happens. Weird stuff happens with shipping all the time.

But since we know shipment interception is part of the NSA toolkit, and the NSA cares about Tor, people aren't crazy to be curious and even paranoid around remote possibilities. And if I were a Tor developer, I might buy all my hardware from store shelves with cash.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#87
post #43

Earlier quoted context omitted.

The NSA does rely heavily on outside contractors though. Maybe this page is of interest? https://www.ida.org/aboutus/organization/hpcc.php http://en.wikipedia.org/wiki/Institute_for_Defense_Analyses Spy the address down at the bottom. And if you wanna get really crazy or are just interested: http://en.wikipedia.org/wiki/Columbia_University_protests_of...

I don't get it. Why is an administrative non-profit at all interesting here?

You're using public sources of information to refute theories of where a highly-secret and officially-denied program might operate. That makes no sense.

Whatever office, department, or contractor does the NSA's package intercepts, all public sources will describe it as something innocent and unrelated.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#88
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

>HEY, KIDS! Do YOU know what time it is?!

It's science time. Ideas are tested by experiment.

Have other NSA-intercepted laptops displayed this sort of diversion in USPS tracking? Is this the only case of its kind?

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#89
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target.

A few comments:

• This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't authorized. He wasn't the janitor or some clueless field agent.

• Did Snowden expose operational shortcomings? Absolutely. A lot of the programs that have been publicly revealed through his leaks have been running for over a decade without ever seeing the light of day, though. That tells me these "pervasive operational shortcomings" aren't very pervasive. (If they were, the NSA would be absolute shit at their mission.)

• I don't think Andrea is a "high value target," or at least high value enough to risk compromising whatever method they might use to bug her keyboard. I don't say this to belittle her or her work in any way — she seems to be a skilled programmer/hacker/infosec person. And that's exactly why this whole "the NSA is bugging her keyboard" theory doesn't make any sense.

Let's assume for the sake of argument that the NSA had planned to bug her keyboard, and that keyboard is now sitting in an NSA (or contractor) facility in/near Alexandria, Virginia, waiting for some modification to be made before shipping it back out. But, oops, they screwed up and forgot to fake the USPS tracking information. They know she knows because she tweeted about it. She's also tweeted that she can never trust the keyboard if/when it shows up. Why would they ship her a bugged keyboard at this point? If/when the keyboard shows up, she's probably going to take it apart and share anything interesting she finds with the world. There will be hard evidence.

Even if they hadn't bungled the tracking information in our hypothetical argument, they're risking exposure of the exact methods they use to bug a machine for not much potential gain. (Remember, Andrea's a skilled hacker/programmer. There's a very good chance she'll figure out what's going on and tell the world if she has any inkling that her laptop's been tampered with.)

• The keyboard she ordered fits a ThinkPad T60/T61/T400/T500 (and the equivalent "R" models, plus a few others). Internally, the keyboard and TrackPoint speak PS/2. While they could log keystrokes to an on-board chip and transmit keystrokes via radio, there aren't any especially interesting things the NSA can do to her laptop via a modified keyboard. They certainly won't be rooting it that way.

• I said that I don't think Andrea is a "high value target," despite her work on Tor, because everything about Tor is open. Anyone can download the code and see exactly how it works. The protocol is well-known. There's no curtain to peek behind and gain strategic information about Tor's workings.

So while I don't reject the argument that the NSA is trying to bug her laptop as impossible, I think it's exceedingly improbable. My money's still on "seller screwed up the tracking number."

I also like the part where the NSA is guarded by the Catch-22 "it wasn't them, because if it was, you'd never know", such that that there's no scenario in which you could be convinced that the NSA did anything.

The flip side of this argument, which everyone here seems to be clutching onto and running with, is that if the NSA is capable of it, they're doing it at every available opportunity, even when it doesn't make any sense to.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#90
post #11

The obvious explanation here is that the USPS fucked up. As the tweet says, you'd think the NSA program would be more subtle. Further, there isn't much in the way of intelligence presence in Alexandria. So what's more likely: that the NSA does this program in a secret location that's still right next to all the non-secret stuff, and they can't cover up the tracking data, or that the USPS accidentally sent a package t…

> Further, there isn't much in the way of intelligence presence in Alexandria.

ARE YOU SERIOUS?

Come.

On.

Post reply on HN