6 ms·
A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge
by devconsole 12y ago
A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 https://news.ycombinator.com/item?id=7609780
In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amount of open software running on your phone can stop. And as laptops become more and more mobile, it's going to seem strange that we've spent so long trying to tether our mobile phones to our laptops. Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee. Consumers would probably love it, because it's very enticing: you get internet access in most of the world without having to find a public hotspot or tether your phone. No more dealing with hotel wifi; no more dealing with logging in to someone else's.
The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. Desktop computers aren't ever going to go away, but hardware design seems to be trending towards having built-in theft prevention. One feature of theft prevention is having the ability to locate the computer, or send it remote kill signals. If trends like that do catch on with consumers, it's "gg no re," because once our hardware is compromised to the point of third parties being able to remotely access it on demand, we've all lost something precious, and there won't be any opportunity to fix it. The more I think about it, the more it seems like it's just a matter of time until this happens, precisely because once it's here, it's never going away.
More and more network adapters seem to have DMA access to your computer. It would be interesting if the protections afforded by open source software were defeated at the hardware level without most people noticing. There doesn't seem to be any way to defend against it, because open source hardware simply can't survive: no money is necessary to develop open source software, whereas large investment would be necessary for development of open source hardware down to the chip level.
- aliakbarkhan 12y ago> Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee. The future is now. http://www.dell.com/learn/us/en/19/campaigns/4g-3g-mobile-broadband-laptops http://www.dell.com/learn/us/en/19/campaigns/4g-3g-mobile-br... http://www.amazon.com/Samsung-XE303C12-H01US-Chromebook-3G-11-6-Inch/dp/B009M2YNWI http://www.amazon.com/Samsung-XE303C12-H01US-Chromebook-3G-1... http://www.bestbuy.com/site/mobile-phones/mobile-broadband-comparison-chart/pcmcat214500050010.c?id=pcmcat214500050010 http://www.bestbuy.com/site/mobile-phones/mobile-broadband-c...
- comex 12y ago> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. > More and more network adapters seem to have DMA access to your computer. With an IOMMU (VT-d or equivalent on other platforms), it should be possible to protect against malicious DMA from any source. Also, not all phones have basebands with DMA access to main memory. I think iPhones do not, though I am not sure, and some older iPhones have been attacked by turning on "auto answer", demonstrating direct access to the microphone.
- aliakbarkhan 12y ago> This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. Bingo. Even if you go all-out with security and only browse the web with a pure text web browser through Tor running on a VM that you purge after every use, use full-disk encryption with plausible deniability, fully shut down your computer and wait until the RAM is cool before leaving, inspect your computer for NSA/other implants every time before boot, tape your webcam and mic, never use your real name, and whatever else you can think of, you're just going to go nuts from all the paranoia, as well as from realizing all the myriad ways your security could still be broken (don't forget to check the keyboard for a built-in logger and look inside your case for PCI cards you don't recognize, and hope they don't have any implants that look convincingly like something you'd recognize as yours). Never mind that this isn't a very viable way to do most things most people actually use their computers for, like personal email, online banking, social networking, and so on.
- devconsole 12y agoUnfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if hardware becomes compromised, Tails will offer much less protection. Here's an interesting section of the article: The department must describe the computer it wants to target with as much detail as possible. For example, an investigator may be covertly communicating with a suspected child molester and know an IP address, and then obtain a warrant to use malware to find the actual location. In the case of botnets, malware might be used to try to free the compromised computers from a criminal’s control. Imagine if child molestors begin using Tails. The government response may be to try to set up some kind of "Tails dragnet" via compromised network interfaces. It should be possible for a network adapter to detect that Tails is running. At that point, since it has DMA access, and since few people use Tails at any given time, it should be possible to instuct a network adapter to search through a computer's memory for evidence of activities that the government doesn't like. Since Tails offers strong anonymity protection, there's no way to describe a computer "as specifically as possible" other than to say "it's running Tails while watching child porn." The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught. "If someone is using a strong anonymity tool and GPG to hide their conversation, we should probably configure their network card to monitor their activity." Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory.
- DanBC 12y ago> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. If your adversary is a well funded government you need to have: Secure software Secure firmware Secure hardware Secure staff who follow procedure Secure location Armed guards Etc Most people can not do all of this and this have been vulnerable to governments for a long time. Suggesting that your mobile communications data was ever secure when it was available to your telecoms provider seems odd to me.
- sliverstorm 12y agoThe takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. The government has always had access to everything if they a) really wanted to and b) had just cause. That's why search warrants, tailing suspects, court-approved phone taps, bank account freezes, etc etc etc exist. The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent.
- devconsole 12y agoThe notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent. I didn't intend to argue that. I'm saying that strong anonymity OS's like Tails will force governments to do dragnet surveillance using compromised hardware in order to track suspects down. There is no way to tailor surveillance to an individual using Tails, because it's set up to hide your IP address at the OS level (assuming Tails is implemented correctly). Assume child molestors begin using Tails or whatever environment that prevents FBI browser exploits from working. What then? There's one recourse: the government can set up your network card to monitor when you're using Tails for unlawful activity. And since it's very difficult to come up with a "footprint" of an individual Tails user, i.e. some way to monitor or attack one specific individual, this is likely to force the government into monitoring all activity. This can be done via compromised hardware, like a network card, which can be remotely configured to monitor memory for specific trigger conditions like "user is running Tails, and main memory contains specific terms for underage children." Sure, it sounds unlikely right now. But this is the general direction that technology has been headed in. How much ground should we concede in this debate? Is it ethical for a government to be able to subvert someone using strong anonymity tools if it forces them to broadly target everyone using such a tool? More broadly, what mechanism should we approve of the government using to inject your computer with code? If the government has DMA access to everyone's computer, then that hardware could be configured to monitor which operating system you're using, and only triggered into actively targetting you specifically when certain conditions arise, such as using a strong anonymity tool, or a certain specialized browser that child pornographers also happen to use. Should the government be allowed to be proactive in its hunt for offenders? Are we comfortable with a hardware device watching which OS we're running? There are a lot of issues that seem worth thinking carefully about.
- skrebbel 12y ago> Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee. We're getting bit off topic here, but my colleague has a 2-year old Sony Vaio laptop that has this. He also has a SIM card for it that came for free with his €50,- internet/tv subscription (incl more monthly GBs than he needs).
- zerohp 12y agoNo software running on your x86 chip can stop System Management Mode. http://en.wikipedia.org/wiki/System_Management_Mode http://en.wikipedia.org/wiki/System_Management_Mode
- somnabulis 12y agoI don't know what "gg no re" means.