>We are also always open for ideas but our focus is on firmware, BIOS, BUS or driver level attacks.
Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
If you aren't running fully free software, you're affected. And if you are a rare case running fully free software, you're an easy target for interdictions, since there's so few of you.
But, well, you can stop at your CPU's manufacturer website, where you will find ME/PSP, well documented as a backdoor. It will save you the trouble of verifying the hardware and firmware.
You might be thinking of me_cleaner[1], which removes most but not all of the ME blobs. This is unrelated to Libreboot though, it works on newer systems and is not needed when using Libreboot because the latter gets rid of the (very early versions of) the ME completely.
https://stikonas.eu/wordpress/2019/09/15/blobless-boot-with-...
SoCs will also have "pre-boot" code that runs before that:
> However, even one of their most ardent open-source advocates pushed back quite hard when I suggested they should share their pre-boot code. By pre-boot code, I’m not talking about the little ROM blob that gets run after reset to set up your peripherals so you can pull your bootloader from SD card or SSD. That part was a no-brainer to share. I’m talking about the code that gets run before the architecturally guaranteed “reset vector”. A number of software developers (and alarmingly, some security experts) believe that the life of a CPU begins at the reset vector. In fact, there’s often a significant body of code that gets executed on a CPU to set things up to meet the architectural guarantees of a hard reset – bringing all the registers to their reset state, tuning clock generators, gating peripherals, and so forth. Critically, chip makers heavily rely upon this pre-boot code to also patch all kinds of embarrassing silicon bugs, and to enforce binning rules.
It's a ROM. Read only.
https://www.fsf.org/news/freebios.html
"The BIOS was impossible to replace because it was stored in ROM: the only way to to put in a different BIOS was by replacing part of the hardware. In effect, the BIOS was itself hardware--and therefore didn't really count as software. It was like the program that (we can suppose) exists in the computer that (we can suppose) runs your watch or your microwave oven: since you can't install software on it, it may as well be circuits, not a computer at all."
Edit: >ROMs can still be backdoored, which is the point of this discussion.
You said it wasn't free, and when proven wrong, you moved the goalpost. Since I'm a wrongthinker who can only post once every hour or two on this site, I'm done discussing this with you. If you want to try to convince people that a 32K ROM is the same as IntelME, then you're not worth my time anyway.
Since we're editing: Free has many definitions. The FSF's on that one page doesn't take into account backdoored software; they would absolutely agree that backdoored ROMs aren't free. It removes user ownership over their computation. It's not "moving the goalposts" to point this out, especially when the entire point of the discussion is around backdoored software.
Remember when the NSA tools were dumped with their secret Windows exploits? WannaCry? North Korea picked that up and launched ransomware attacks. That's the sort of thing that's going to happen again with the newly published Intel backdoors. Just wait and see. Tim Cook is 100% vindicated this week about not adding intentional iPhone backdoors.
The Wifi Alliance has made some heinously bad choices that if you attributed to incompetence simply make no sense, they treat anyone who questions them with disdain and shoots down attempts to fix the mess they make. WPA3 was hilariously broken a month after getting rolled out.
> That's the sort of thing that's going to happen again with the newly published Intel backdoors.
This is not even remotely true. You have to read more than just the headlines.
> Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
Extraordinary claims require extraordinary evidence. Please provide some.
there is proof that NSA has been mass hacking WiFi since at least 2005. that batch of Snowden leaks came out one week after the Shadowbroker's first leak.
NSA programs SECONDDATE and BADDECISION were used to mass hack into WiFi routers in Iraq in 2005-2007. note the slides say NSA breached the WiFi routers of EVERY INTERNET CAFE IN IRAQ. that is the Collect-It-All scale we expect from NSA.
also note, NSA did this FROM THE SKY! SECONDDATE is a sensor installed in Cessna and low flying planes. NSA flew over every WiFi hotspot of every Internet cafe in Iraq and deployed the BADDECISION exploit to install implants on the WiFi routers to then mass surveil everyone.
no futher leaks about BADDECISION have come out. we dont know if it is a protocol attack or crypto exploit. we dont know if WiFi is still vulnerable to BADDECISION.
how much do you want to bet that NSA only used SECONDDATE and BADDECISION in Iraq and NOT back here at home in America?
how much would you bet that NSA is NOT bulk hacking WiFi routers of ENTIRE US CITIES FROM THE AIR?
consider how much cheaper and easier that would be now in 2020 compared to 2005?
> how much would you bet that NSA is NOT bulk hacking WiFi routers of ENTIRE US CITIES FROM THE AIR?
I would bet very good money that they are not doing this. If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?
https://m.startribune.com/mystery-surveillance-plane-that-ci...
https://minnesota.cbslocal.com/2015/06/02/secret-aerial-fbi-...
since at least 2014, the FBI has a secret air force of over 100 planes that fly constant circles over the biggest US cities.
what do you think FBI is doing? joy riding?
https://www.eff.org/deeplinks/2016/03/new-foia-documents-con...
those FBI planes are equipped with DRTBOX's--cell site simulators and wifi interception sensors.
in the TAO ANT Catalogue leaked by Snowden, it shows NSA SECONDDATE is manufactured by Harris.
Harris also makes DRTBOX, and Stingray.
wanna bet FBI is using DRTBOX in exactly the same way NSA used it in Iraq? wanna bet NSA is actually helping FBI run this little domestic program?
why would NSA and FBI surveill all US cities from the sky? because you dont need a warrant or even a subpoena. "reading the air" is free--it's public space with no expectation of privacy. and radio signals you emit through your phone or wifi router are also public space.
but what is FBI and NSA's endgame to run a real-time monitoring program over US cities?
back in 2004-2008 in Iraq, the Pentagon deployed something called GORGON STARE. it stiched together the video feeds from all drones and jets and satellites into a composite video watching entire cities.
https://longreads.com/2019/06/21/nothing-kept-me-up-at-night...
Gorgon Stare has come home to roost.
> Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
Still _zero_ evidence of any of this. Why not post some?
You also ignore questions like..
> If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?
> Just this week a 20GB dump of private Intel source was dumped with backdoors included. > That's the sort of thing that's going to happen again with the newly published Intel backdoors. >> This is not even remotely true. You have to read more than just the headlines.
> If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?