Live data from Hacker News

Inside a low-budget consumer hardware espionage implant

ha.cking.ch

71–80 of 98 posts

Re: Inside a low-budget consumer hardware espionage implant

#71
post #45

Earlier quoted context omitted.

I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.

Okay lets say that the ethernet MAC has some gates that detect a particular 1024-bit random bit pattern in packets and that triggers a behavior change in certain sequence of instructions common in Windows security code to bypass it. How would you discover this?

https://isc.sans.edu/forums/diary/Intel+Network+Card+82574L+...

Re: Inside a low-budget consumer hardware espionage implant

#72
post #52

Off topic, but still: is that a price of almost 2 EUR per minute of call? (to that stranger's phone - 3333333) I thought calls inside EU are price-limited? Or is this some really old post?

I found that odd too. I live in Denmark and i pay a fixed amount and can call as much as i want.

How are remotely monitored sensors and devices, like weather stations and power meters, that need to send a small amount of data periodically, and that use the cellular network for that handled in Europe?

Those fixed price for unlimited calling plans that are great for human to human communication would suck for low data sensors and devices.

In the US these are handled by special plans that have zero or close to zero fixed monthly cost, but have a high per byte or per minute rate so that they are quite cheap for their intended use (e.g., power meter daily usage report) but are too expensive to use for high data applications.

If there are similar things in Europe, maybe that number was one of those?

Re: Inside a low-budget consumer hardware espionage implant

#73
post #51

I wonder why they even bothered with such a high end processor like the MT6261. Get a bare die micro like the MSP430, and a bare die GSM chipset, and you're set. You'd have to dissolve your SIM card in acid and wire bond it to the PCB, but wire bonding machinery is pretty cheap. Realistically, this is stupid easy for a state-level actor. A good hardware hacker worth their salt could probably set up a bug no bigger th…

> in a couple of months for a few hundred, less if they already have a wire bonding machine and microscope.

How do I get my hands on a wirebond machine for a few hundred? The bottom end of "old and crusty but not actually broken" seems to start at a couple thousand on eBay. If my budget were a few hundred I'd probably spend a month just machining and grinding replacement microscope parts.

I suppose you could be referring to the marginal cost of an hour on a wirebond machine at the nearest NNIN facility, but last time I priced out training options the overhead to get started would have been $500-$1k.

Re: Inside a low-budget consumer hardware espionage implant

#74
post #56
post #53

Earlier quoted context omitted.

> The weak part of all these systems is the constant GSM heartbeat, but even that is beatable. Curious: how do you beat that? Do you listen to other signals and try to transmit at the same time (if you must)?

You can broadcast on a timer, you can switch to a low frequency, low bandwidth transmitter, you can store locally and pick up the device later, etc. It all depends on the environment.

Or burst mode. That's been the speculated reasoning I've heard behind the USA's onerous POI restrictions on exported RTSAs.

Re: Inside a low-budget consumer hardware espionage implant

#75
post #56

Earlier quoted context omitted.

You can broadcast on a timer, you can switch to a low frequency, low bandwidth transmitter, you can store locally and pick up the device later, etc. It all depends on the environment.

Or burst mode. That's been the speculated reasoning I've heard behind the USA's onerous POI restrictions on exported RTSAs.

That's probably the better option.

I found an article about the export restrictions here.

https://signalhound.com/news/how-we-implemexport-controls/

seems like it has to do with the fact it's guaranteed to intercept a signal all the way down to 1.2 uS

Re: Inside a low-budget consumer hardware espionage implant

#76
post #59
post #55

Earlier quoted context omitted.

I feel part of the reason is that processors such as MT6261 are getting cheaper and cheaper. The marginal benefit of producing a simpler and smaller design is likely going to go away quickly. It is the end-game for hardware. Software has already been gobbled up by language designs which are less and less hardware-near for the very same reason.

I was thinking purely from a power consumption / die size / support stand point. Not sure what the MT6261 quiescent current is, but I'd expect it to be in the 100s of uA. An MSP430 can get down to 0.1uA, which is much more difficult to detect. If I had to guess, the MSP430 die is probably about 1/4 the size of the MT6261 die. Most importantly, I can't find a MT6261 datasheet anywhere except for taobao. This just make…

[deleted]

Re: Inside a low-budget consumer hardware espionage implant

#77
post #59
post #55

Earlier quoted context omitted.

I feel part of the reason is that processors such as MT6261 are getting cheaper and cheaper. The marginal benefit of producing a simpler and smaller design is likely going to go away quickly. It is the end-game for hardware. Software has already been gobbled up by language designs which are less and less hardware-near for the very same reason.

I was thinking purely from a power consumption / die size / support stand point. Not sure what the MT6261 quiescent current is, but I'd expect it to be in the 100s of uA. An MSP430 can get down to 0.1uA, which is much more difficult to detect. If I had to guess, the MSP430 die is probably about 1/4 the size of the MT6261 die. Most importantly, I can't find a MT6261 datasheet anywhere except for taobao. This just make…

Datasheet here: http://mediatek-club.ru/datasheet-mediatek-mt6261a

Re: Inside a low-budget consumer hardware espionage implant

#78
post #72

Earlier quoted context omitted.

I found that odd too. I live in Denmark and i pay a fixed amount and can call as much as i want.

How are remotely monitored sensors and devices, like weather stations and power meters, that need to send a small amount of data periodically, and that use the cellular network for that handled in Europe? Those fixed price for unlimited calling plans that are great for human to human communication would suck for low data sensors and devices. In the US these are handled by special plans that have zero or close to zero…

https://particle.io and https://hologram.io have almost worldwide availability for SIM's designed for this. There are probably older less-hip suppliers as well.

Re: Inside a low-budget consumer hardware espionage implant

#79

Earlier quoted context omitted.

The average user should not need to muck around with the BIOS.

I'm a Mac user and what is BIOS /s

We've asked you already to post substantively or not at all, and we ban accounts that won't. Would you please take a look at the guidelines and try to change this?

https://news.ycombinator.com/newsguidelines.html

Re: Inside a low-budget consumer hardware espionage implant

#80

Earlier quoted context omitted.

How often do people look behind their desks at the usb cables plugged into their systems. Many do not.

As someone who was involved with redteaming: ~nobody does. It's very rare to get caught after bugging someone's equipment. Bugs like these blend in seamlessly with the massive amounts of cables behind most desks.

It is scary as heck. I could be behind a desk and almost certainly would overlook this, or the mic I saw online embedded within an Ethernet cable the other day.
Post reply on HN