Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's especially creepy is that many devices (e.g. laptops) with USB ports continue sending power to those ports even when the device is off.

So someone bugged with something like this implant could fully power off their laptop when discussing sensitive information, and if they left a bugged USB drive plugged in, they could still be compromised.



You can check the BIOS to see if there is an option to disable it.


The average user should not need to muck around with the BIOS.


The average user wants their phone to keep charging, even if they turn their computer off.

The non-average user should have no problem mucking around in BIOS settings.


The simple solution to this is using a physical switch instead of hiding that functionality in a BIOS setting. A clever designer could even design it into/near the port itself so each port can be switched independently.


And those switches can go next to the ones for power to the camera, microphone, wifi, bluetooth, speakers, and anything else that I might want to be electrically disable-able, right?

Physical switches for the USB ports sound like they'd be as confusing for most people as the physical wifi switch was, when that was common. I think that means that if some manufacturer decides to introduce them, they won't be around long.


I can just imagine the call to technical support for a laptop like that. "Have you tried turning it off and on again?" times a dozen switches


The average user has an almost zero risk of having to worry about being bugged via their USB. Is your Aunt Irma a target for espionage?


I guess the answer to that question depends on if you or someone else that irma is associated with is the target of espionage


Nothing to hide, what’s the problem?


It's not nothing to hide, it's realistic threat model. But if these things become more popular and in more and more devices they'll just hoover up all the data they can get like already happens with web software. The average user probably should not have to learn what an extension is and figure out which adblocker to install, but this is the inelegant world we live in, and anyway I'm still on the fence for whether I really want to expect more from the average user or not.


This argument is similar to saying you don't care about someone else's freedom of speech because you have nothing to say.


Facebook will mass deploy these to serve targeted advertising based on conversations it hears.


This is sarcasm, right? (dozen apps already listening the mic in our pockets).


[flagged]


We've asked you already to post substantively or not at all, and we ban accounts that won't. Would you please take a look at the guidelines and try to change this?

https://news.ycombinator.com/newsguidelines.html



That is a different issue. The article was about an external USB device.

Also I don't understand the concern with people not trusting Intel. By using their hardware in any form you are inherently trusting them. Unless you are able to check their design and fabrication process, they could easily hide something in there to disable protections in Windows or Linux based on certain patterns of network traffic.


Say that we trust Intel completely. Does that somehow make AMT not a security concern? For the ME itself, especially if it's not connected to any networking hardware: Whatever. It seems more like a theoretical threat than a practical problem. AMT sounds like something that I don't want running on my machine, even if I trust Intel itself completely.


Perhaps others are not so trusting and do not want to legitimize surveillance and would like to hold these companies to account.

Privacy is not just some option, it is law. Surveillance and hidden surveillance of users is illegal in most countries and any technology with the capability to do so has to be disclosed with end user control.


Sure but most don't seem to value their privacy enough that they continue using Intel products. As such nothing will change.


Please stop blaming the victim for being ignorant and/or falling prey to marketing.

> most don't seem to value their privacy

Most people do value their privacy, but are either ignorant of how strongly technology can damage their privacy[1] or fee there isn't any other option or alternative.

> nothing will change

It will change when the people that do understand technology work to preserve privacy over profit and convenience, educate the general public about privacy issues, and inform them of privacy respecting alternatives.

[1] Businesses tend to encourage ignorant and/or misleading beliefs when they promise impressive features backed u[p with useless promises to "take security seriously".


I don’t think “don’t blame the victim” applies to voluntary transactions. Consumers have shown we will not sacrifice much for privacy or security. That’s a trade-off made in the market by millions of people, independently, every day.


I think a CPU that has no mini PC inside it is much easy to verify, you can try a lot of inputs and see if the output gets weird, I think this technique was used to discover some hidden switches in Intel that the government uses to work around the ME on their own systems.


Okay lets say that the ethernet MAC has some gates that detect a particular 1024-bit random bit pattern in packets and that triggers a behavior change in certain sequence of instructions common in Windows security code to bypass it. How would you discover this?



What do you mean the ethernet card triggers changes in Windows instructions? Do you mean it can scan the RAM and do some changes? I am not familiar with how recent hardware works but I would be worried if hardware could scan RAM and edit executable code bypassing the kernel and drivers, so more reasons to get open hardware and drivers.


There are good reasons why USBs have been banned in the DOD for over a decade.


What they still use PS/2?


The other poster meant USB sticks. Manning’s leaks were the reason they changed the rules.

I believe you have to use CDs instead for a lot of cases.


Bug or feature?


Feature. It allows, among other things, for a computer to be woken up via the (USB-connected) keyboard.


Also a branding/design feature.

I've encountered extended color coding on multiple gaming oriented motherboards: Black for USB 2, Blue for USB 3.1 (so far so standard), Red for persistently powered.

That way you can have your phone connected to that port and have it charge overnight, etc.


Or USB connected IR/RF remote (think media center PC's)


I’d call it a feature. I sometimes need to harvest energy from my computer’s power supply to charge my phone without the computer being on (waste of energy)


Configurable option. Charge my iPhone, don’t power a bug.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: