HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
Did this Tor developer become a victim of NSA's laptop interception program?
151–160 of 169 posts
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#152Earlier quoted context omitted.
My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…
Devil's advocate: you don't necessarily need all the data - the keystrokes are plenty valuable information on their own. Alternatively, such a keyboard could try to do something clever when a shell is focused, although it's risky.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#153By posting before getting the package, the NSA could see the Twitter post and give a non-modified one instead.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#154Earlier quoted context omitted.
My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…
What would you need DMA for? Here's a fun thought exercise for you, since my first reply didn't spark one. Imagine you're an evil keyboard. What evil could you accomplish? Hint: you don't even need your own radio, the computer's already got one.
"we describe how to tamper with a firmware upgrade to the Apple Aluminum Keyboard. We describe how an attacker can subvert an off-the-shelf keyboard by embedding into the firmware malicious code which allows a rootkit to survive a clean re-installation of the host operating system."
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#155...
Also the large segment around them that still feel dismissive about their now confirmed fears.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#156Earlier quoted context omitted.
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#157Earlier quoted context omitted.
My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…
Devil's advocate: you don't necessarily need all the data - the keystrokes are plenty valuable information on their own. Alternatively, such a keyboard could try to do something clever when a shell is focused, although it's risky.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#158Earlier quoted context omitted.
I would speculate that they might be interested in submitting a patch that compromises the Tor network in some subtle way that only they can exploit, and doing it in her name. Maybe added on to some other big change she submitted, in the hope that nobody will notice it. Seems the Tor project is using Git for all of their projects, so doing something like that would probably require pwning whatever system she's creati…
The Tor project was started by the US Navy, and receives 80% of its funding from the US Government. This is how you think they get them?
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#159Earlier quoted context omitted.
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…
So with less snark: I don't think it's exceedingly improbable at all, and whether ultimately it turns out to be the case or not, smugly guffawing the idea that the NSA may have used a trick like that isn't warranted. They really do intercept people's laptop shipments [1] to plant malware in them. They really do sneak tiny radio transmitters into end-user hardware. They really are trying to get backdoors into communication tools. I'll put it this way: if I worked on the kind of software Andrea works on, I would be seriously alarmed. Would you keep the keyboard?
On some specific points you made:
* That Snowden had access to other people's credentials seems like a serious operational shortcoming to me. The "low-level" part wasn't an attack on Snowden; the point is that a lot of people have that level of access. In general, the US intelligence apparatus makes a lot of well-publicized mistakes; I'm sure they make a great number of more subtle ones.
* On the NSA's shortcomings generally, I think this is actually nicely illustrative. Because a lot of the stuff Snowden revealed were things a lot of credible people already believed, based on things like weird locked server closets in telecom buildings and PRNGs that seemed fishy and pointless and heresay reports of requests for backdoor access to communication tools and so on. There was just little hard evidence before Snowden. And there won't be here either. So this is entirely consistent with the what the NSA was like in those decades where their programs "never saw the light of day".
* I think being a core Tor developer makes her high value target. It's hard to imagine the NSA wanting to subvert all the things it's subverted and not wanting to backdoor Tor. Keylogging her keyboard is a great way to do that, either by compromising her somehow, or by just stealing her credentials. So I don't follow the "it doesn't make any sense" line of thinking.
* That she's now tweeted about certainly makes it unlikely that, if the NSA has it, they'll go through with sending it bugged. But so?
Where I come out on this is that yes, it's probably nothing, but it should be treated with suspicion and carefulness, not laughed off because haha, what, do you think you're in a spy movie or something? Because, basically, we are.
[1] Yes, I know this is just the keyboard. I don't think that's a relevant difference.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#160When I read the headline, and the comments here before reading the article, I was expecting to see tracking data that went from the seller to the buyer with a mysterious stop near the NSA. Then I read the article. The tacking data shows a delivery to a destination near the NSA. Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destina…