Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right.
With closed firmware and wireless capabilities, you can never know what they're doing at a given time.
Stuxnet reached systems which were seriously air gapped. Consider a what a laptop with a witty wireless card firmware can do.
I'm not getting into TEMPEST attacks and their newer versions, passive surveillance, etc.
I've listened tales about Cisco devices which were configured to isolate and prevent internet traffic but, they mistakenly forgot to drop some magic packets. Uh.
---
Random facts about this stuff:
- Your Intel system runs a special version of Minix on its Management Engine. A version of Minix customized for Intel by its original developer.
- There are photos of Cisco devices which were delightfully enchanced by NSA before shipping to its customer via special firmware and/or hardware. NSA still retains this capability.
The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industrial PICs etc).
The fact that they could choose and align 4 zero days indicates that the NSA probably has a large list of zeros days.
- They got exact hardware details and topology of the centrifuges somehow.
- They've stolen Realtek's driver signing keys.
- The virus looks like a simple worm which can infect other USB devices and doesn't unpack beyond a certain point if it can't find the SCADA equipment and the correct device ID & topology (It's like a homing cruise missile which looks like an RC plane from distance until it finds its target).
It's possibly the most sophisticated hacking campaign when social and technical aspects combined.
It’s the most sophisticated one _we know of_
I have been to Realtek's offices in Hsinchu many times. While the other efforts may have taken major resources I don't think getting their private keys would have been hard at all. Especially back then. IMHO the building and some people could be easily compromised and I suspect they didn't really care much about security.
Some ideas about the reason they had this particular hardware and software combination:
- The SCADA hardware they got was not compatible with newer software which runs on more modern OSes.
- The SCADA software didn't have any newer version which runs on newer OSes (Windows 7 and further versions are more restrictive in terms of direct HW access).
- Since there are sanctions it was the only hardware and software combo they were able to legally obtain.
Industrial control is like automotive industry. Everything is improved in minuscule steps and by encapsulating everything in more modern carriers. A good example is MODBUS. They still carry the same data, the old way. Only thing is it's either encapsulated in USB or TCP/IP. Why? Because it works and allows perfect backward compatibility.
Since neither the hardware and the software has to run latest version of Doom (metaphorically), if the application is reliable, it's left as is. Even if it runs on DOS 6.22.
Fun fact: There's an auto repair shop in Poland which runs its main application on a C64 [0].
[0]: https://www.popularmechanics.com/technology/gadgets/a23139/c...
[0]: https://www.goodreads.com/book/show/18465875-countdown-to-ze...
"USB drives in the parking lot" could be the tech industry's Korean fan death.
They are used to great effect in pentesting. I think it's natural to see a drive and think "Oh no, I need to get this back to a coworker."
Not on all systems. It's neutralized and disabled on my Librem 15: https://puri.sm/learn/intel-me/.
https://www.ebay.com/itm/191879410081
I hear a lot about Intel's ME, but not much about AMD's PSP. I assume it's just as bad. At least we know how to hobble the ME.
No, we just think we know how to hobble the ME.
A common counterargument comes up when discussing devices like smart speakers. Defenders say that the devices are too low-power and that we would be able to notice power usage changes and sniff network data being sent if spying were happening. IMO, this is true to an extent, but also any onboard preconfigured recognition of certain products could easily send info back to, say, Amazon servers and you wouldn't be able to distinguish it from a "false positive" question to "Alexa". Knowing the extent to which these capabilities are plausible and/or would have been caught by now if they existed is, to me, murky.
This also applies to on-board chips and wireless data. Would we not notice from power usage and sniffing?
Wait until they put 5g chips in every single product to make them "smart". Few people talk about that but I believe it's the main use case for 5g. Everything will be connected and you'll have no way to opt out
> 4G can support about 4,000 devices per square kilometre, whereas 5G will support around one million
I assume for the radio to stay on, it's either subsidized by the parent company (Amazon pays for Alexa's 5G) or I'm paying for a subscription (Xbox subscription pays for 5G on some future mobile XBox)
Maybe you could get the cost down to $1 / month. If you invest $400 in the market it should pay out about that much, so you could make it a one-time payment of $400 for a 5G chip.
Consumer network connections, of any kind I'm aware of, don't go down to $1 per month. Maybe with a big volume order and a low bandwidth cap the cell companies would do it, or maybe 5G itself is just cheaper, but where does that monthly cost come from?
That is patently false.
Ah, the "just move to the wilderness and grow your own food if you don't like the government infringing your constitutional rights" argument. I want to be able to meaningfully engage in normal society by buying consumer goods and connecting them to communications platforms and I want my 4th amendment rights protected. I really don't think that is too much to ask.
(I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function — but without big antennas, how’s it going to report?)
https://www.schneier.com/blog/archives/2014/03/ragemaster_ns...
Or this?
https://www.schneier.com/blog/archives/2014/03/cottonmouth-i...
If you have actually attracted the attention of the NSA, pulling your NIC is playground stuff.
If the NSA has enough of an interest to be intercepting your packages, they're not going to shy away at adding in a transmitter or two of their own preference.
I guess if I was the NSA I'd bring my own Stingray, but then you have to amortize in the cost of the van.