Your USB cable, the spy: the NSA’s catalog of surveillance magic (2013)
arstechnica.com
arstechnica.com
I call BS on this one, everybody knows radar cant go through cars/walls. It would be a too big of an equipment to be of any practical use.
They have EM bugs placed close to target sites. But these bugs have to be powered/recharged, so the NSA use focused radar to power the bug itself. Information is then sent back down the radar signal by modulating it.
EM spying is very real[0] and documented. "The Thing"[1] from 1945 actually uses some of the principles they're discussing here, they're just combining it with Tempest. Nothing they're describing is science fiction, it is very possible.
[0] https://en.wikipedia.org/wiki/Tempest_(codename) [1] https://en.wikipedia.org/wiki/The_Thing_(listening_device)
Who says you need to go through them? People leave doors open a lot and most rooms have some kind of duct or opening at thresholds.
Neal Stephenson's Cryptonomicon had a whole section on it that was fantastic.
The article is referring to a USB cable that has been modified to phone home using either RF or some other covert channel. I'd think that USB Kill would be completely unaware of any such compromise given that it's only looking for a disrupted connection.
(Unfortunately, AFAIK, most USB hubs don't report power draw for devices that are "just" drawing power and don't use the data pins, so you don't get that.)
It is likely that you could be. But as with all criminal proceedings they'd need to prove it beyond a reasonable doubt. If the KillUSB software itself was unrecoverable it might prove difficult.
It would be incredibly interesting to learn what Gemalto and CISCO have meanwhile managed to come up with in order to tighten their supply chain and ensure their clients they don't receive compromised equipment.
To me, if I want full "evidence custody chain" style logs of device location, for physical equipment, that would be the way to go. Now, the real question is, how much would you really trust the government mail program vs a NSL or interdiction for implant vs a private company vs a NSL or interdiction for implant. I think there is room for discussion there, but I would tend to side with the government one, because the company will have very little recourse, but the gov entity is likely to be staffed by bone-headed gov employees, who are surprisingly good at bad policy pushback when compared to their private counterparts. Perhaps I'm wrong on that though. Sometimes I find interesting insights into IT by listening to lawyers...
Definitely, although an important question is whether they want to solve the problem and are able to solve the problem. (We still don't know how these package interdictions are done -- what induces the packages to be turned over to governments for tampering.)
http://csrc.nist.gov/publications/secpubs/rainbow/tg008.txt
Note: Yet another for everyone to remember when you hear someone say the old security certifications were just red tape. Stopping interdiction is just red tape. Haha.
Here's a basic set of recommendations for supply chain security that provides at least a start on various aspects:
http://www.albint.com/en-us/company/Suppliers%20Documents/Su...
U.S. government is freaking about about what they, err the Chinese, can do. They're implementing their own research with stuff like this:
http://www.technology.org/2015/07/09/sandia-tamper-detecting...
http://www.darpa.mil/program/supply-chain-hardware-integrity...
Personally, I think being able to print or wire-wrap the electronics yourself can be helpful given they might be able to attack inside the PCB. It's a speculative attack I came up with many, many years ago that I can't remember if anyone has implemented. It would be difficult to detect with some of these internet-of-things style chips implemented w/ minimal packaging.
There's a lot to this subfield of IT. Verification of incoming components & manufacturing process with trusted couriers is the baseline, though.
Anyway, this is the sort of thing I'd expect the NSA to be doing against specific targets. And I'd expect the targets to have equally sophisticated countermeasures.
A policy of "inject hot glue into exposed USB ports" gets you further.
This slogan should indeed never happen.
One can also do tricks like authenticated peripherals or profiling signatures of them. I had some designs on former. CompSci had results on latter. Not sure if there's any products in this area and if they'd be trustworthy.
What's difficult is to build an organisation with a purchasing and new hardware approval process that's quick and efficient enough that people choose to follow it.
I've worked at places where the official policy said "no unapproved USB sticks" but getting approval was so difficult most of the engineering workforce installed Linux using unofficial USB sticks. As firing the most of the workforce for knowingly breaking policy would have been cutting off their nose to spite their face, the policy went unenforced.
In 2016, is the NSA operating inside the USA at all?
Are they doing it without warrants?
Even the President likely doesn't know every program comprehensively, not for lack of access but because it's so large that it would be hard to get all of it in such detail.
As the top intelligence officer, I would assume it's his job to know where all the tentacles are?
Technically that role is held by James Clapper as the Director for National Intelligence (DNI).
It's also more complicated than just appointing someone as the head of "Intelligence" because most of the directors of the Intelligence Agencies guard a lot from each other so they don't get resources nabbed.
Prior to the formation of the DNI role, the "Top Spy" was the Director for Central Intelligence (DCI) AkA Director of the CIA - who had outsized pull and purview.
Today there is a push and pull between the DNI and DCI, at the presidential level.
Long story short, it's complicated and very very large.
https://news.ycombinator.com/item?id=11358724
This story was linked from that one.
There's already stuff in CompSci and industry that can stop all of these attacks which they could straight up buy. Some of it is very low-overhead to enforce critical properties. That they haven't implemented any of that plus keep making common mistakes reinforces my decision that they're not capable of high-assurance security. So, their mechanisms will raise a baseline but not be adequate for intended opponents.
- Treat firmware like a file, save hashes of them in a public-key signed baseline db. Basically hash everything that can be dumped and throw alerts if anything in the targeted policy changes. (Tripwire for firmware)
- Thinking about it again, v2: end-to-end encryption is needed from driver/app through to device silicon. Key management might require "pairing" would be an initial secret provided separately (like the security model of an Entropy Key, but perhaps not a burned-in secret). Given that most actual drivers are proprietary anyhow, consider today's drivers as http:// when https:// everywhere is needed to defend against bus-sniffing.