Vendors must start adding physical on/off switches to devices that can spy on us
larrysanger.org
larrysanger.org
Metrocop: “She'll get years for that. Off switches are illegal!”
—Max Headroom, season 1, episode 6, “The Blanks” https://www.maxheadroom.com/index.php?title=Episode_ABC.1.6:...
As mentioned elsewhere ive been taping cameras and stabbing microphones for years now.
— Blank Reg
Set up the hardware, link up with existing mesh if you're in a dense enough area.
Push federated services like Matrix and ActivityPub based services like Mastadon, so when it's time to go mesh, people don't laugh when you say "It doesn't reach Facebook/Insta".
https://github.com/Byzantium/Byzantium
https://project-byzantium.org/
https://hackaday.com/2015/04/28/meshing-pis-with-project-byz...
" Major changes include: Kernel 4.16.3 Core is based on Slackware current 7 desktop options to choose from! http://www.mirrorservice.org/sites/dl.porteus.org/"
i believe its OLSR you may like.https://wiki.dd-wrt.com/wiki/index.php/Mesh_Networking_with_...
Solidarity
The problem, I guess, was that probably none of the U.S. people greenlighting the TV series had actually watched the original British TV movie; they probably only thought about getting such a popular character. They probably did not know that things like 1984, Judge Dredd and V for Vendetta are all very distinctly British things. The Max Headroom TV movie, as well as the TV series, are both essentially very dark cyberpunk; acerbically critical of prevailing trends in technology and also scarily prescient for 1987. It was also very critical of television itself as a phenomenon, which was probably what ultimately killed it, and by that time the huge fad for the character had passed.
Fake edit: I think this is it:
https://www.theverge.com/2015/4/2/8285139/max-headroom-oral-...
Interesting story in many ways, particularly the wrestling for ownership of the show, and how they recreated it as a carbon copy for the American market. I remember hearing years ago that he wasn’t actually CG, which made a lot of sense — but as a kid I definitely thought he was.
The subversiveness of the show is great; but it’s particularly amazing how accurately they saterized the future.
Ahead of its time apparently...
I fear that the sense of security people feel from putting tape over their webcam might be hiding much more realistic threats.
I mean, yeah, being hacked (and thereby compromising your screen/HDD's contents) is an issue in the first place and keyloggers are only a few lines of code, but I don't think there is anything wrong with controlling the parts that you can control.
You can't make a physical "no keyloggers for this piece of text, please" switch, but at least they can't hear you talk to a close friend or watch you walk by as you get into the shower (though the latter is a bigger risk for women than for the more common HN visitor, I guess). You're not the first comment I see wondering why we even want this, and it's really weird to see. Why would we not want this?! I don't think that, just because we have webcam stickers, we suddenly stop caring about malware altogether. I think even (metaphorically) my mom understands that if you tape your webcam, a virus can still steal the bank login that is happening on her computer. Even if she doesn't really get the concept of a process, malware, and a web browser in the first place, taping a cam does not make everything on a computer virus-proof.
It doesn't even need to be about you. It could be about your parent, child, or sibling. What judge wants to risk exposing a relative to prosecution, even if the relative would be acquitted?
If you wonder about inexplicable judgments, consider the possibilities.
Am I the only one who realizes that I may not be the one who may benefit the most from having a way to physically turn off the camera/mic device?
All you people who insist on carrying eavesdropping devices near me are a threat to my privacy.
All of you people who persist in posting to FB and tagging pics I might be in are a threat to my privacy.
Yes. It is a problem.
> You probably noticed your device is acting strangely lately. That's because you downloaded a nasty software I created while you were browsing the Ƿornographic website...
> The software automatically: > 1) Started your Ƈamera and begun recoding you, uploading the footage to my server...[...]
> If you do not do what I ask you now, I will upload this ugly video file with you ... and the stuff you were watching to several video upload sites and I will send the links to all your friends, family members and associates.[...]
> I think 2,000 USD is a fair price for my silence. I know you can handle to send me this money - and it is enough for me to get lost. So how do you send the cash?? Bitcoin.
I wasn't worried about it being real, but being able to dismiss it out of hand is useful.
Those situations are physically dangerous when they happen.
Helping the victim out of that relationship is what needs to happen - no amount of technical cleverness is going to make it better. Improving our laws certainly would (i.e. taking that sort of device compromise as a serious crime would be extremely useful in this context).
The default being "easy to spy and control someone else's devices" makes abuse easy and escape (both mental and physical) hard.
That helping and escaping and staying away is not something that happens without communication and privacy.
Think of the OPM hack[0] and the potential for a foreign entity to compromise someone (that they know has a security clearance) with blackmail. This has a much larger and potentially far longer ROI than a simple compromise of a password; which probably has to be changed every 'x' days, anyways.
You have to think of things like this in terms of long-term yield and not immediate results; unless we're talking crackers, then they're almost always after immediate results.
[0] - https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
That... really depends on the society you live in and your own insecurities.
Fear and prohibition surrounding the naked body is a cultural/religious thing.
The most prudish US-regions are probably somewhere in the middle of central Europe and Islamic countries like Saudi Arabia.
I won't generalize to the whole of the US because I know there's a wide spectrum.
However US-wide media serve the lowest common denominator, spreading the unfounded phobia and taboo of nude people.
Personally I couldn't give a damn whether someone has pictures of me nude. People probably do since I was bathing in the ocean naked on some occasions. I don't really want any pictures of myself on the internet (with my name), but nude or not doesn't make much of a difference to me.
I'm more afraid of ending up in some facial recognition database and private companies starting to track my every move.
The problem with blackmail is it almost never happens - i.e. the profitable digital blackmail is cryptolocker. But the real negative to your life is the unaccountable compiling and production of data products which can be used to try and describe your life to others - credit ratings being mapped to internet activity or insurance rates, or digital dossiers being sold to companies to screen new hires in combination with some blackbox "risk" AI system - or surveillance cameras running people in-real time through a profiler which then re-deploys police units on the go.
The risk is...not dramatic? I think is what I want to say. It's mundane - so mundane that its been creeping up on us for decades and is very gradually attacking people all because individually it all sounds reasonable.
Mostly: formerly Holy Roman and Habsburg Empires.
This is from the same group that tries to explain how they don't use proprietary firmware blogs by using the Redpine chips just because the blog is already flashed on it rather than loaded into RAM on boot.
I wish they would just say it how it is rather than overselling.
When using a physical kill switch you have to trust the hardware. You don't have to trust the firmware or operating system, as a physical kill switch usually disables the power lines to the device. That's something a remote attacker can't circumvent.
When this goes really wrong, the chip can burn out.
Some satellite provider in the past tried to exploit differences between genuine cards and fake cards based on Atmel 8515 simulator boards. The fix was to lift the VCC pin of the 8515.
Yes, the network is not connected, but google is still tracking SSIDs.
Do you happen to know about GPS? Because my phone sometimes picks up GPS faster than should be physically possible (knowing a thing or two about how GPS works), and sometimes it takes a normal amount of time. I have GPS turned off almost all the time, don't have a Google account logged in, everything I can deny to Google apps I have denied, nothing weird seems to be running in process lists... any idea where to even start looking?
As I understand it, this cell tower location actually helps achieve a real GPS location faster that would be normal - but I'm unsure how that would work .. I'd be guessing at best ;)
http://gpsinformation.net/main/gpslock.htm
Also, I believe that part of the reason why Google wants that SSID info is because they can later use it for location purposes as well, making that initial position determination more accurate than with just the cell towers alone. In general, the more environmental data they can correlate with accurate GPS coordinates, the better they can predict location when GPS is unavailable.
This is fun to observe when you buy a new phone and don't connect network yet, it takes a good while to find any satellites and finally find a fix. Then after cycling GPS, it finds it almost instantly.
It typically claimed (not using it much lately) to have GPS reception after maybe 20 or 30 seconds since power up.
I believe it cached the position of the GPS satellites, or something similar... could that be it?
To be clear, I don't like the behaviour.. but it's not misleading, it just doesn't cater to everyones desires.
So the issue would no longer be one of ignorance (no button) but of premeditation (button with hidden bypass).
Such that we have an open-ish platform built on a sound foundation of security.
We, as a populace, need to grow our own food and build our own quality things again.
If this means everyone is equipped to be an electrical engineer and low-level scripter, awesome for business and tech education in general.
Also, microphones.
I just learned than IR-transparent plastics are more common than I thought: they reduce heat load and make the plastic last longer.
So if closed, the Mic could not EVER function as it would have been physically disconnected.
Is that true? Assuming they’d market it that way, originally?
After all, they had to turn on the computer first.
No, the goal of the switches is to fend off 3rd party hackers.
For one (silly but common) example, you can turn off your iphone, but it will turn back on if it's plugged into a charger.
[1] https://www.ecfr.gov/cgi-bin/text-idx?c=ecfr&SID=06b088e611c...
UL may be a 'joke', but it does keep a lot of sketchy electronics out of the market (at least in the US). In my personal experience dealing with them, bad hardware design is more to blame for a bad experience with UL than the UL process itself (which, is brutally long, but just might be for a reason..)
You know that every loudspeaker can be used as a microphone, do you?
You know that even stuff without radio can be converted to send files wireless (e.g. CPU as radio, already published a while ago by someone)?
Cryptographically I believe it is possible to encrypt a message such that either the user's key or the vendor's key can decrypt, but I'm not 100% sure.
But yeah you could give the user access to the devices private keys and certificate store.
Haven’t seen anything for the home market yet, and I’m not sure how you’d get a consumer IOT device to accept your cert.
(Personally have been using a MITM proxy on my network for over a decade. Besides the filtering, it also has a useful side-effect of upgrading all connections to TLS 1.2, and when 1.3 becomes more common or mandated, I only need to upgrade the OpenSSL the proxy uses to start using it for all TLS coming from the network. Even older devices that don't support it will still use it when communicating outside the network.)
You should be able to firewall your smart toaster so it can only communicate with a service under your control. In particular a service the manufacturer has no control over.
Example for automobiles: OBD-II diagnostic ports.
Edit: Thanks for all your comments. It seems that there a few vendors that do offer webcan covers by default now. Definitely will have to check those out.
The OpenBSD people have recently made microphone off the default at the kernel level. You need to have root access to turn it on again and you need to take an explicit action to have it come on at boot. That is actually sort of secure as people don't run as root in *nix environments when they are doing things that can get them cracked (i.e. run web browsers). Turning the microphone on should really be an admin level thing...
Perhaps what we want isn't a switch but a button. You can activate it but it is off by default. There really needs to be a obvious light as well...
Maybe this could be a nice kickstarter, a smart USB hub that can be integrated into the smart home/IoT world. I'd buy it.
Since it is separate software, not the webcam software, that is switching the webcam off, we would not have to trust the webcam software maker to fullfill the promise.
Maybe not in one year, but in five.. ten?
If they get proper penetration it would be a tempting target for various governments for differing reasons.
The future is bleak.
The recent HN post about Mozilla's IOT offering was encouraging: https://news.ycombinator.com/item?id=19695595
I think a physical off switch would be good. At the moment I just unplug my Alexa if I'm particularly concerned it might hear something sensitive.
I know many HN readers are far more privacy-conscious than I am, but that's just how I think about it. I personally consider cybercriminals and people who dislike me far greater privacy and security risks to me than tech giants or even the US government.
Super freaking simple to implement.
And if it were a page that you could just toggle the ability of the stream flow by clicking on it... to create the FW rule instantaneously and stop that flow.
You pull up a dashboard and see all your threads. If you see a thread from [phone]-->[Facebook] and you can just disable that stream. (Where [Facebook] is a list item of all the known FB addresses etc)
If I don't trust their software switches, why would I trust their hardware switches?
Other macs may be like this too.
One of their hacks, IIRC, was that they turned off the standby light so it would appear the TV was shut off.
I’d rather physically removable sensors rather than off switches, though.
Cameras on laptops are far from my greatest concern. Microphone on cellphone is a much bigger concern, as well as perpetual passive metadata plus sensitive data on third party servers required for normal functioning of most services.
The webcam and microphone is only half of the story.
We need control back on our devices. I friend went so far as to add a physical on/off on he's macbook. I went out of my way to get a mobile i can root easily. There is a market for this.
It's just as easy to make a faux off switch that actually just triggers it to disable itself in software. The switch needs to actually cut ALL power going to the camera hardware.
I remember some webcams having LEDs that were controlled in software so hackers were able to turn the LED off in code while still recording with the camera the entire time.
For now, I will still have my physical webcam cover on because hackers can't stop it from working without physical access to my machine.
That said, there isn't much interesting to watch if you really wanted a live feed of my webcam (other than frustrated looks on my face while I'm debugging the work issue du jour).
More importantly, there is a social norm that you don't look through people's windows with binoculars. Of course police, spies, or creeps might do it, but that's incredibly rare. Unfortunately, the social norm (and business model) of the modern web is that companies build ever-more-powerful binoculars to constantly stare. That's the real problem we need to fix.
Fully turning off either means have to wait for the devices to boot up whenever you want to actually use them. That time adds up. A mic kill switch would allow the device to be immediately used at the flick of that switch.
To gain trust, I think we need tactile physical interventions: a built-in webcam cover and a slider over the microphone. If it doesn't exist already, I'd imagine there's a market for a nicely designed phone case that includes both.
Like so many other privacy articles I read, this one has its heart in the right place, but it treats reality and implementation as an afterthought.
I'd hazard a guess that once the public seemed relatively unconcerned about Echo snooping on them, the hardware cut-off would have been removed for cost reductions (alongside the twist-to-adjust volume control).
A sheath is an off-switch for a blade.
In theory. Plenty of reported instances of audio being recorded in situations where the wake word wasn't used, was misheard, etc. So the wake word concept doesn't seem reliable. :(
Or spend $3 on an inline-USB switch, so you can be sure that the switch actually does what it says on the tin.
Pirates used to install locks on their satellite receivers to prevent countermeasures, or at least defer problematic updates.
It's actually a screw, and it's not totally trivial to access though.
webcams with closable eyelids (and eyelashes, eyelash mites)
then in hacker movies the eyelid can spring open
Physical switches are physical and auditable and if the switch is audited to work, it works.