Now I can't wait for rogue monero miners to use ME to propagate :)
Now I can't wait for rogue monero miners to use ME to propagate :)
- If it were to periodically "check in" with an external server to see if it needs to do any kind of spying -- admins would notice the network traffic.
- If it needed to be contacted externally to "initiate" any kind of spying at all, that would mean anyone behind a NAT would be safe, and furthermore, the the moment anybody notices such a thing, it would make the headlines and get blocked on networks, so this capability would need to be kept secret and turned off except for ultra-high-value targets... which most people do not view themselves as.
The NSA routinely intercepted Google internal traffic. Did Google, who are presumably running the most advanced network on the planet and staffed by people who don't suck, notice the intrusion? They did not; they got informed via PowerPoint.
While the sophistication of the attackers decreases as you move from NSA to random hackers, so does the sophistication of the network as you move from Google to mid-sized businesses.
How are these even similar? Did the NSA ever send traffic of their own on the Google network infrastructure? Citation needed if so, because I recall they merely listened in on existing traffic using external network equipment.
Not at all.
When you have something that good, you use it for specific targeting. You get a guy with a work laptop at home, you infect him, then you use the machine to get one closer to your objective. Slowly. With time between the events. Without being a beacon in the network.
Or you just use it to spy on a guy you suspect.
Or to get access to secrets of somebody you wanna black mail.
Did you even read what I wrote? Specifically the last sentence?
Admins would use network dedicated hardware with network chipsets driven by closed source firmware. In a crazy but technically doable scenario, that closed source firmware could contain instructions to "send packets containing magic word X to address a.b.c.d" and not reporting or counting that traffic, even to applications opening the device in promiscuous mode, with all routers in between to obey the same instructions. Not a single byte would be reported, counted or sniffed unless someone sticks a digital analyzer on the network cable.
No, I fully expect there are enough admins out there running dedicated hardware whose design & source code they have access to. That is sufficient.
Similarly inbound control signals could be delivered by modifying inbound traffic that the ME observed and decided.
Depending on your throughput needs the signal could be delivered subtly by for example modifying the timing between packets in a way that would be very hard to identify as a signal.
I’m hoping the ME firmware Now gets dumped and studied closely. I’m betting there are some surprises in there
Until there is evidence, this is technically just a government conspiracy theory.