Live data from Hacker News

It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

theintercept.com

81–90 of 134 posts

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#81
post #67

Earlier quoted context omitted.

> What the author actually forgot to do was to add some honey into the honeypot. I.e. become an attractive target. Preicsely. All the author had to do was use his best broken English and pretend to be a member of The Shadow Brokers. The article would have been far more exciting had it involved speculating which three letter agency compromised the laptop the most, or the finer points of writing an article while being…

>The article would've been far more exciting had it involved speculating which three letter agency compromised his laptop the most, rather than simply mulling over a bunch of "what if" scenarios. If you would find this more exciting, there's no shortage of fiction already available on similar subjects. This article was about detailing the current risks, and the author's attempt to catch the attack in action. Not as e…

Thank you for that sombering reminder of why I rarely post here anymore.

>If you would find this more exciting, there's no shortage of fiction already available on similar subjects.

Any recommendations?

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#82
post #10

I run a dual-boot Debian + Windows 7 laptop, but my default position is to assume the Windows partition is exploitable, so for secure activities I boot Debian. That boots using an unencrypted /boot partition, but everything else running on luks (one big partition, LVM'd down). I have a VeraCrypt partition which is for files that I want to work on from both operating systems. Works really well, crypted disks doesn't m…

> but my default position is to assume the Windows partition is exploitable In reality, as the article explains, the windows partition is basically invulnerable to this class of attacks if you take the 5 minutes to enable bitlocker. OTOH Linux systems have no effective defense.

That may or may not be the case.

My primary concern - I should perhaps have spelled it out more clearly - is that the Windows partition is likely exploitable via Microsoft Windows.

Detecting data at-rest exploits such as described in TFA, and per my mitigation suggestions -- because they don't scale well -- implies that you're already of interest to your adversary.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#83

Earlier quoted context omitted.

He's a board member of the Freedom of the Press Foundation, a position also held by Edward Snowden and Daniel Ellsberg. Additionally, he has helped develop SecureDrop and various other tools to enable the anonymous spread of information. Finally, he works for The Intercept, an organization that has a history of receiving leaked information. Seems like a plausible target to me.

I didn't know that, thank you. Nevertheless, as his experiment have shown, that was not enough.

Or it shows that it was enough, and the tester was not able to detect it. It's also possible he was already compromised in a different manner, making the entire ordeal useless.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#84
I'm calling this a bad test in general.

Let's be honest here. None of the more cutting edge attacks are going to be risked by attacking. as hard a target as this guy. The level of sophistication of attack the author is starting to reach is going to be reserved for state-level persons-of-interest.

Espionage is a game of judging capabilities, and cracking some security researcher's laptop telegraphs to the rest of the world that you can. As a national actor you don't actually WANT to flex your spy muscles in obvious ways unless the payoff is JUST THAT CRITICAL. It removes the veil of the unknown, and gives potential adversaries/persons-of-interest that much better a chance of successfully applying tradecraft to hide what you actually want to monitor because they have more accurate knowledge of what your capabilities are. Contrary to popular belief, most organiztions capable of pulling an evil maid attack simply won't because of the revelation of capability already mentioned, and the PRISM problem. Too much information/access in general lends itself to becoming useless due to the difficulty of separating the tasty bits from the mundane.

Kudos to the guy for actually trying the experiment, but it doesn't really tell anyone anything we didn't already know 20 years ago.

Computers are inherently insecure. Every form of "security" is insecure at some point. Computers haven't changed anything except for making a person's computer a juicy target to get some juicy financial information/passwords for non-state actors, or making surveillance potentialities so much more horrifying on account of the ubiquity of networked cameras, sensors, and microphones on the ground waiting to be exploited.

Forget about laptop evil maid attacks. Start thinking about the ticking time bomb of 'poisoned' hardware rife with 'tailored access' whereby state actors can push a button and have every device with a camera/microphone within a certain set of GPS coordinates start silently acting as an input sensor. Combine that data stream with the right neural networks, and you'll see a world that no one in their right mind wants, but is well within our manufacturing capabilities to create.

Or stop worrying, go outside, and make a friend. It's way better for your mental health.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#85

If you care about this, then put the laptop in a tamper-evident bag. Those are necessarily imperfect too; but there's work making tamper-evident seals to resist up to state-level attacks, since that's relevant in stuff like enforcement of nuclear weapons treaties. That succeeds to the extent that you can find a physical effect that's easy to create and measure, but hard to recreate deterministically. (In concept, dum…

A border agent would just open that bag right in front of you, making it not a particularly useful measure of being tampered with.

I suppose a large amount of the problem could be solved just by taking checksums of all non-volatile memory on the device - however that doesn't check for, for example, hardware keyloggers which might be inserted without your consent, and then a thorough evaluation of the hardware would be necessary. However that still doesn't tell you if somebody has simply tried to copy data off of your device - so maybe in this case you need something which physically marks the device in the case that the hard drive is removed and presumably accessed outside your computer, like those dye traps they use in banks and when transporting money.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#86

Earlier quoted context omitted.

He's a board member of the Freedom of the Press Foundation, a position also held by Edward Snowden and Daniel Ellsberg. Additionally, he has helped develop SecureDrop and various other tools to enable the anonymous spread of information. Finally, he works for The Intercept, an organization that has a history of receiving leaked information. Seems like a plausible target to me.

But was there any specific thing during the course of his trial run that would have enticed an attacker? And given the fact that a supposed attacker would ostensibly be able to detect the existence of honey before the attack, would they not also be able to detect the absence of it? (And perhaps its simultaneous absence during the course of the trial) Seems like an experimental bias to me

This is a journalistic experiment not a scientific experiment. Experimental bias isn't a large concern, they're trying to record something happening not prove something.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#87

I thought it was impossible to prove a negative, generally?

If there are n possibilities and you can prove that y are always true, then the n-y remaining are never true.

Careful with that phrasing -- you need to prove that _only_ y are true.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#88
post #81

Earlier quoted context omitted.

>The article would've been far more exciting had it involved speculating which three letter agency compromised his laptop the most, rather than simply mulling over a bunch of "what if" scenarios. If you would find this more exciting, there's no shortage of fiction already available on similar subjects. This article was about detailing the current risks, and the author's attempt to catch the attack in action. Not as e…

Thank you for that sombering reminder of why I rarely post here anymore. > If you would find this more exciting, there's no shortage of fiction already available on similar subjects. Any recommendations?

I was trying not to be overly rude, but your post read like "this journalism would be better if it had more wild speculation rather than reporting proven facts."

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#89
post #64

I wonder if it’s practical to make a laptop suitcase where all external edges are touch sensitive? Have a serial number etched into each surface as well. Edit-the case could have additional logic and wireless charging for power.

Just get one of those fancy metal attaché cases, attach a capacitive sensor to it with some sort of ground plane inside the case, and wire it to some logging microcontroller. Add a gyro chip to boot. Honestly the embedded gyro should be enough, the MEMS chips in phones are CRAZY sensitive, and would easily detect being shifted by a cm.

Re: It’s Impossible to Prove Your Laptop Hasn’t Been Hacked

#90
post #36
post #30

Earlier quoted context omitted.

Good skills mate. So: Your user data is on the HDD and encrypted AND you use a removable disc to boot your machine AND you have a "something you know" (password) That looks quite secure to me, provided you look after your removable disc and password. I'm not familiar with IBM gear - is ExpressCard a removable disc? I tried to read the WP page on it but got confused. I have one of these for my laptop - Dell Inspiron 1…

ExpressCard is the succesor to PCMCIA. It's not limited to disks, you can also get cellular modems, gps cards, or whatever. The drives I use are these: http://www.wintecind.com/features/filemate/ssd/wf_expresscar... I agree my setup is probably pretty secure, but not any moreso than a single os install with FDE, especially since I often leave an OS ExpressCard in the machine and the other ones I leave scattered aroun…

The EOMA68 project is putting together an interesting variant on this approach. Instead of taking your hard drive with you, they are building computers with a mainboard on a PCMCIA card, so you can eject your entire system from its housing and take it with you. A small SSD is included, so you could literally bring your entire environment with you if you don't mind being limited to 8GB.

https://www.crowdsupply.com/eoma68/micro-desktop

Post reply on HN