9 ms·
Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-d
by devconsole 12y ago
Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted.
This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.
Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if hardware becomes compromised, Tails will offer much less protection.
Here's an interesting section of the article:
The department must describe the computer it wants to target with as much detail as possible. For example, an investigator may be covertly communicating with a suspected child molester and know an IP address, and then obtain a warrant to use malware to find the actual location. In the case of botnets, malware might be used to try to free the compromised computers from a criminal’s control.
Imagine if child molestors begin using Tails. The government response may be to try to set up some kind of "Tails dragnet" via compromised network interfaces. It should be possible for a network adapter to detect that Tails is running. At that point, since it has DMA access, and since few people use Tails at any given time, it should be possible to instuct a network adapter to search through a computer's memory for evidence of activities that the government doesn't like. Since Tails offers strong anonymity protection, there's no way to describe a computer "as specifically as possible" other than to say "it's running Tails while watching child porn."
The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught. "If someone is using a strong anonymity tool and GPG to hide their conversation, we should probably configure their network card to monitor their activity."
Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory.
- cinquemb 12y ago>The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught. I think that is too naive. Snowden types don't assume they won't be caught, they probably assume that it is only a matter of time until they are caught, and play the cards they have in such a way that you make it really hard to send your garden variety cia/dia/spec ops/defense contractors out on a pick up operation not only only from a feasibility standpoint, but from a geopolitical stand point (e.g. What will Beijing's/Moscow's/D.C.'s response be if we run such an operation in their front yard? What precedents might we be setting?). Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems which might very well be other nation states (or appearing to originate from such).
- devconsole 12y agoAlso to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems. If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance. For example, I think Tails is going to force governemnts into monitoring at least which operating system you're using. There's no way to target a specific Tails user, so the only recourse is for the government to do dragnet surveillance of everyone using Tails, or ignore the activities of those using Tails. Since the latter seems politically untenable, the former is becoming more likely with time. When the government can passively check whether your activity is fitting the pattern of some kind of criminal activity, the situation is about as asymmetric as I can imagine. Is there really any technical knowledge that could protect you?
- cinquemb 12y ago>If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance. Whats DMA access? Direct Memory Access access? That aside, I'm not willing to concede that across every computer than has been/can be built and be exploited by a government out of the box remotely [because dragnet] (most of them, I will concede probably can though, and conversely anyone technical enough can probably exploit many systems in the same way for their own means[don't trust your spouse/freinds/employees?, bug them with remote backups of data to analyze in real-time, hell, companies do such things now as-a-Service]). But continuing on with your conclusion of a dragnet (which is more or less present today), access isn't really the problem, but you have a signal and a noise problem, wherein you will have false positives and false negatives. Text book example of the mal-possibilities is the NSA providing data which led to the targeting phones in the ME, which drone strikes we're initiated and hit innocent civilians[0]. Just wait when we're at the point when this is happening within a countries national borders by domestic agencies, one day, someone is going to be taken out that wasn't meant to be taken out. Can't ignore the false neg/positives forever, though governments seem to try very hard to do so. I think corporations are more forthright about the extent the data they collect is able to be used because if you knowingly contract/ utilize bogus data for certain applications, someone else will eat your lunch eventually. >activity is fitting the pattern of some kind of criminal activity From a predatory-prey/evolutionary standpoint, criminal activity is always evolving (typically every living being and the systems they rely on are). Not to mention the time sensitive nature of these systems that do the analysis so if $criminal_activity is always changing and over a defined period of time, you risk that you will get no signal for those who conduct such $criminal_activity in less than the defined period of time or that by the time the analysis has been done, or any signals collected from such device will be moot (i.e. computer was destroyed, thrown away or even worse: passed along to/associated to someone else which also means any point there after associated with such systems is akin to going after a ghost within the machine). >Is there really any technical knowledge that could protect you? Well since the focus is on tails [but mostly on the dragnet], one can clone the sc[1] and go through it for what could possibly define one as a Tails user, replace that with something else, build their own image and voila, you just avoided being in the dragnet. The thing about dragnets is that they can only really capture the lowest common denominator, deviate only slightly from that, and the adversary will have to expand resources going for an targeted operation (any adversary, not just nation states is technically possible of doing these things and by definition not a dragnet). This is what happens today. Not in some far off distant dystopian future meant (intended or not) to invoke fear in the ignorant/lazy. Yes if one wants to avoid being in a dragnet with some of the tools they use, then one will take the steps necessary to keep such information obfuscated/opaque from the dragnet. [0]: http://www.policymic.com/articles/16949/predator-drone-strikes-50-civilians-are-killed-for-every-1-terrorist-and-the-cia-only-wants-to-up-drone-warfare http://www.policymic.com/articles/16949/predator-drone-strik... [1]: https://tails.boum.org/contribute/build/ https://tails.boum.org/contribute/build/
- comex 12y ago> Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory. In the future (or today, depending on your setup), IOMMU. In the present, there is no evidence that baseband backdoors of this type actually exist (as opposed to hacks). When the adversary adds backdoors deeper in the hardware? ...well, we'll see if that is discovered someday. To editorialize a bit, I guess it can't hurt to worry about and try to head off anticipated future threats - it's not like anticipating different threats is mutually exclusive - but still, I somehow can't shake the feeling that people's emphasis on secret backdoors unduly weights threats that are easier to romanticize over more pragmatic but more dangerous ones.
- devconsole 12y agoThe reason it's good to proactively think of future threats is because so many past concerns have proven to be true. Several months ago, no one on Hacker News really believed that BIOS backdoors were much of a threat. But today it's a well-established fact, for example. The tools of law enforcement probably aren't going to be revealed, and they're hard to discover. Nobody knew about the zero-day exploit employed against Tor browser, for example, and there are almost certainly many more tricks like that up their sleeve. They already take steps to conceal them; parallel construction is an unfortunate reality. And since there's not much justification for a whistleblower to reveal the techniques, it's unlikely someone will come out and talk about them. We'll probably need to think along the lines of "What's technologically possible, and how is it useful to law enforcement?" It's not a good idea to wait until a weapon is used before thinking about how to react to it. The history of communications technology and how governments have reacted to the technology is actually quite fascinating. Wiretaps used to be extremely commonplace, and since there's not too much legal protection from the government rifling through your digital life at will (at least compared to getting permission for wiretapping your phone), it seems like it's better to err on the side of caution. It's also important to realize that even though some governments follow due process, several powerful ones don't. Also, there are other global other considerations. The US has made it pretty clear that their legal restrictions are designed to apply to US citizens, not any foreign person. You may be forced into a situation of choosing which governments you'll trust, especially when cross-nation collaboration becomes even more pervasive. Assuming that other countries adopt a similar attitude of "Our citizens are protected; other citizens are examined," then the US may simply outsource their databases of information to be examined by some other government, like any other member of the Five Eyes. I understand your concern and skepticism though. It was a question I've often wrestled with myself.
- andreyf 12y ago> projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted That iPhones used to completely trust physically connected devices without any verification was obvious to anyone paying attention even before it was verified at Black Hat USA 2013 [1]. This was fixed in iOS 7. The evidence we have of DROPOUTJEEP says it is installed via "close access methods" [2]. I wouldn't be surprised if remote vulnerabilities exist that could be used to install it remotely, but I am aware of no public evidence that they are being exploited now. 1. http://www.zdnet.com/researchers-reveal-how-to-hack-an-iphone-in-60-seconds-7000018822/ http://www.zdnet.com/researchers-reveal-how-to-hack-an-iphon... 2. http://www.zerohedge.com/news/2013-12-30/how-nsa-hacks-your-iphone-presenting-dropout-jeep http://www.zerohedge.com/news/2013-12-30/how-nsa-hacks-your-...
- cam_l 12y ago"strong anonymity tool and GPG" just thinking, the problem, it seems, is that end-to-end encryption is not really end-to-end. the user is the endpoint, not the computer. from a ux point of view, a dongle between screen / keyboard and computer for an encryption overlay could be a way to unambiguously protect information - so information never exists decrypted in a machine.. just the screen. user input-output accessories are much more technologically static than software / hardware, so an open-source hardware solution may be possible?