Apple helped make 'top secret' iPod for US government
bbc.co.uk
bbc.co.uk
https://tidbits.com/2020/08/17/the-case-of-the-top-secret-ip...
David is good story teller. Really enjoyed it.
"So my friend who used to work at the DOE was getting rid of some stuff and he had this iPod, and it looks like a regular iPod but I took a look inside and does anybody know what the hell this is...?"
It's surprising how frequently restricted computing devices end up in public hands.
Through a relative who worked for a guy who knew a guy and so on, I ended up with the world's most awesome GRiD Compass back in the 80's. It was supposedly formerly used by someone in the Reagan administration, and had big stickers on the bottom listing all the countries where it was never to be used.
I threw it away when I got my first IBM XT. Stupid of me.
Of course, most legitimate indie communities stay away from this, preferring clean-room RE efforts.
"Devkits" (at least in the context used here) are hardware for developing console videogames. Console manufacturers work quite hard to control who gets to develop for their platform and how. The devkits are often quite expensive and you won't (usually) get your hands on one unless you work for a company that has signed a very detailed contract with the console manufacturer.
Obviously, the severity of the problem depends on what gets auctioned. PS4 kits? Probably not much, pretty much everything about the console and its capabilities has been leaked a long time ago. But if some PS5 devkits were to go missing right now it would be a huge deal as the console isn't even out yet.
You know the rest of the story. Apple is entirely familiar with the Osborne Effect.
He was not fired for it, as it was an honest mistake, and he stayed with the company for several more years.
Does anyone have the link to the story about the guy who found a Made in China power strip w/ a hidden bug inside?
https://www.cbsnews.com/news/hacked-from-china-is-your-kettl...
The power strip calls you as soon as it detects a sound.
https://www.npr.org/2019/12/23/790832681/6-year-old-finds-me...
/edit: if you don’t want your country to be an international pariah
It makes me wonder what he knew back then, but as I cant visit him, if he is ever let out, or I dont get another attempt on my life, maybe one day we'll meet & he'll spill the beans more openly.
Of course, I can get nodules of raw uranium sticking out the soil eroded by the sea along the Jurassic Coast in Dorset, UK. It doesnt take a rocket scientist to make a dirty nuke or even a decent nuke. There is enough information online from reputable sources like the BBC, Youtube showing 50year WW2 US & UK Govt archive footage and interviews in scientific journals who worked on the Manhattan Project and other nuclear projects to piece together the "meta data" in order to make one, including spotting the spurious info which will make you fail if one should attempt to make one.
>is unlikely to escape the notice of the world's intelligence and energy agencies Thats how Iran and Stuxnet came together.
Some history https://www.miningreview.com/uranium/avoiding-covid-fatigue-... https://en.wikipedia.org/wiki/Uranium_mining_in_Namibia#Back...
Teflon as mentioned in the Youtube vid at the beginning also demonstrates another way to enrich uranium. Are those the only two? I think not.
> Uranium-235, while occuring in natural uranium to the extent of only 0.71percent, is so fissionable with slow neutrons that a self-sustaining fission chain reaction can be made in a reactor constructed from natural uranium and a suitable moderator, such as heavy water or graphite, alone.
https://fas.org/issues/nonproliferation-counterproliferation...
Also, anyone who can build a Farnsworth Fusor could generate neutrons suitable for enrichment. You are overestimating the difficulty of obtaining and producing dangerous quantities of radioactive materials. This is a convenient falsehood as it breeds a level of comfort in the population, but it is certainly not true.
In any case, you have everything you need for a dirty bomb.
I don't think this is what you meant, though. Why can't [an independent actor] recover Pu-239 from the core of a uranium reactor? I'll admit I don't know a lot about chemical reprocessing, but the proposition here is using a series of highly corrosive and/or explosive chemicals ([fuming] nitric acid, tributyl phosphate, hydrazine) to extract Pu-239 from very radioactive irradiated fuel rods with unknown actinide concentrations. Chemical reagents for this process (e.g. for PUREX, tributyl phosphate) are controlled and monitored by non-proliferation agencies. Chemical re-processing will not separate the Pu-240 from the Pu-239. Pu-239 is unsuitable for a gun-type weapon, as it is so fissile that it will blow itself apart in a partial detonation ("fizzle") before the slug and target are brought together--this means you need an implosion-type ("Fat man") weapon to effectively use Pu-239 as a fuel. A high concentration of Pu-240 exacerbates this problem. A fizzle in a populated area is still very bad, but not bad in a way that couldn't feasibly be produced by conventional explosives and/or chemical weapons much more easily. In order to produce enough Pu-239 to form a weapons core within years instead of decades or centuries (provided extraction is feasible), the independent actor probably is looking at a >1 MW reactor with the cooling towers and infrastructure that surrounds a project of that scale.
It is really only a viable threat for a terrorist organization if that organization has the clandestine support of a nation state.
EDIT: Or otherwise enough financial support, technical expertise, and freedom of activity to engage in serious construction projects and industrial chemistry. The point is that it's not something you can put together in a basement lab.
This sounds like an really great story if you feel like sharing; I'm hooked to hear more about this guy, why he's in jail and the attempt on your life...
Apologies if it was really traumatic and I'm being insensative...
No, his full degree titles do not take up 300 words.
If you want to converse online without sounding completely crazy, focus on reducing the ridiculous hyperbole and stick to short, comprehensive and digestible statements that flow together and form a cohesive argument/statement.
Still, I have a point. The comment I was replying to contains lots of disconnected insinuations dropped casually. Including apparently that he has had people try to kill him.
You cannot casually mention these things in a rambling monologue without sounding crazy. And discussions with crazy people on the internet are hardly ever fruitful.
So working on improving how you communicate to ensure people don’t completely dismiss what you say is a valuable exercise.
Typical Geiger tubes (and high voltage generator) would be too big to fit in an iPod.
But why would they need such tight integration with the iPod itself? The data isn’t big (each reading would only be an 8 or 16bit int) and could easily be stored on some small flash by something like an PIC12/MSP430.
So you’d only need some simple trigger, which might be a hidden menu item which flips a GPIO to take a reading. Or even just tap the audio output and trigger on a specific frequency being played.
Audio recordings might make sense. I don’t think the iPod video had a built in mic, so one would need to be added. That doesn’t ring totally true to me either though...
The whole thing seems quite weird. I can’t really see any good reason for such tight integration with the iPod.
You would want the tight integration if you wanted to steganographically store the recorded information for covert exfiltration. The agencies driving this have a high level of paranoia and may have deemed this necessary for a variety of reasons.
Steganographic storage would make sense, but the article mentions storing on a separate partition.
So the tight integration still seems odd to me. Another comment suggested that they wanted to gain general “iPod” modification skills for other projects. That seems like an interesting idea.
As an aside... I kind of like the idea of playing specific songs, or a sequence of songs to trigger a secondary processor (which is sampling frequencies played). This could potentially take over the USB port if necessary.
That generation of iPods used hard drives, it was possible to replace those with smaller flash drives. This would give you a lot of space to add sensors/secondary compute. And could be done without coordinating with Apple.
It does seem weird that they took the chance of this leaking too... and I would have thought they would have taken any other route possible.
But audio recording would be most straightforward function, as it is built in. Switch (or simply re-flash) the player that belongs to journalist or politician when they leave it, then recover the data periodically. That would mean they knew who their target was.
By the way, which model did Steve Jobs use? It might be possible that these “secret agents” were not secret agents at all. I suspect that any official business starts and ends with you signing papers that prevent you from, say, talking to newspapers about it because you feel like it, and existence of one-time high-profile project like that is something any sane agency would really like to keep secret. “No paper trail” is actually the most non-ordinary part of all of this, secrecy agreements are a common thing. Oral order to work with two random guys (because they have ominous business cards?), and tell them every corporate secret they need to know? Seems suspicious.
There are lots of sources but this is one: https://electricalstrategies.com/about/in-the-news/spies-in-...
I don't think that such a thing ever existed.
I don't think they had to actually "prevent" it — just as jeans, baby diapers, disposable paper towels and stockings, USSR was just very bad at consumer items. It didn't even had real mass adoption of toilet paper.
Example: https://en.m.wikipedia.org/wiki/The_Thing_(listening_device)
Absolutely spot on David Shayer…
This project was real w/o a doubt.
There was whole surreal drama & interesting story about how this project was kicked off & then kept secret.
The Case of the Top Secret iPod
https://twitter.com/tfadell/status/1295727727606104064Why oh WHY are companies like this? If we want to put our own OS on a cool bit of hardware, what is the problem with that? Absolutely shocking mentality that needs to die (but looks like frankly it is getting worse).
I don’t mind that freedom being limited to desktops and specialist hardware like Raspberry Pi and Arduino, and taken away from everything else like a phone or an MP3 player or a printer.
What’s the saying? The ‘S’ in IoT stands for ‘security’?
Moreover, I do mind such freedom being taken away.
So how does this work in weekly on-on-one meetings with his boss?
> My boss was told I was working on a special project and not to ask questions.
For the Mac Intel switch, the situation was even more curious, as the earlier work was carried out by a larger group of engineers, with little special secrecy, but the final stretch was done by a smaller subset of those engineers in strict secrecy, while the others were led to conclude that the effort had petered out.
The difference in this case was, of course, that the client of the special project was apparently external…
Engineer hours cost the company time they would otherwise invest in their current products in development.
Why do it for free? It's not like the US Gov can't afford it.
My favorite part, the last line, "We wanted to release a Windows version as part of Windows 98, but sadly, Microsoft has effective building security."
Presumably sending spies to gather data on nuclear weapons production sites? Wouldn't those sites have crazy operational security and would confiscate things like iPods before entering anyways?
Or is the idea to detect facilities that are building dirty-bombs in dense urban areas (a-la some scene set in middle-eastern country X from the show 'Homeland')
Most likely it was for use against Iran or some allies who we didn't want to overtly say we don't trust.
Here's a couple overviews:
https://www.energy.gov/nnsa/nnsa-and-nuclear-smuggling-detec...
https://www.epa.gov/radtown/radiation-and-shipping-port-secu...
On second thought I wonder if it was a geiger counter that can secretly phone home and report data when connected to the Internet when the user adds music. Get into the Apple supply chain and make sure they end up in Apple stores near your "targets".
That's exactly why it would need to be undetectable.
So that it's extremely difficult to detect that it's not a regular ipod, even if disassembled.
Chinese do it in a completely different way, using prefabricated components.
Secret services can not use prefabricated Chinese components because those need to be audited and that cost millions too.
So using already made American companies components' is the obvious solution. It just cost hundreds of thousands of dollars.
FTFY
https://www2.lbl.gov/abc/wallchart/chapters/03/4.html
Using modern sensors seems like the logical extension of that.
(to clarify, I believe this story and am skeptical of the Bloomberg one, I just find the 15-year secrecy and limited scope notable)
The idea that senior execs know everything that happens at their respective company is borderline nonsense.
Not a valid one. The story was false.
Not even Steve Jobs? Shouldn't this have been his decision?
Edit: It actually says he got the clearance because Pixar was doing some government work at the time.
It does make me wonder what the others are doing.
Don't forget Apple was one of the many companies part of the PRISM program.
The idea that Apple doesn't protect user privacy is absolute nonsense.
Not if it's an old mac ;-) I was an early iPod touch adopter (bought with X-mas money IIRC). Plugged it into my iBook G4 and was informed the version of iTunes was both too old and the latest this laptop was going to get.
Plugged it into a Windows 2000/XP machine (which I think was already old for the time) and it managed to get the latest version of iTunes.
Now of course, I'm aware of the context of the PPC to Intel shift and that there was a non-zero cost to maintaining both streams of iTunes build but it really put me off Apple at the time.
This has nothing to do with a geiger counter or measuring radioactivity.
Watch the doco Zero Days. It's an ok round up of Stuxnet.
Obviously the final product might not have used this iPod. It was a huge operation on many levels with failed projects. This iPod also obviously might not have been for recording, since that's a level one misdirect, oh it's secret spy recording device, person who's watched to much James Bond.
But how did they do the 'usb' zero day since you know it isn't a iPod?
It takes 2 days for me to run badblocks on my 16TB drive!
There isn't any factual basis where that incident contribuites to that fallacious narrative. If I were a plumber and doing work on a CIA building they might do a background check so deep that it finds and analyzes any colon polyps to ensure I won't be planting any bugs in the plumbing but it doesn't mean "I am pretty much the CIA."
All apple did was provide a little bit of JTAG/Build/Source Code support. The rest was up to a third party.