Writing a firmware-only keylogger
8051enthusiast.github.io
8051enthusiast.github.io
The funny thing is that this is effectively a keylogger that does not run any code on the CPU while it is running.
I already knew it, but this just reinforced how terribly vulnerable pretty much every computer system is. Makes me think ransomware/hacks are going to get a lot worse, and I can’t see how the situation can be improved, at least for quite some time.As a first step, I'd like to see some tough laws that hold companies liable for data leaks. Once it becomes a major liability to be the source of a data leak, most companies won't bother collecting PII, and will make it a point to ensure it's not stored on their systems. Nonetheless, systems will always have vulnerabilities and be exploited. This is at least worrisome from many, if not terrifying, and that should not be automatically interpreted as "security-paranoia FUD".
And no, I'm not worried that because of this article anyone can keylog my stuff. It's the realization from OPs summary that there are many attack vectors, and vulnerabilities hiding in and between layers and components. iPads are no different in that respect.
Seriously, how do we get passed the current state of zero-days and major vulnerabilities cropping up on the reg?
Some ideas from other commenters here aren't entirely convincing to me: require open source, require software standards (both of which would need to apply to hardware/silicon as well). I'm honestly looking for some thoughts on how to build a more secure digital future (Links to articles or studies are welcome).
But really, I think some perspective is needed on what is "safe". Is riding in a car "safe"? Is eating food from the supermarket "safe"? Can you ABSOLUTELY GUARANTEE that it's IMPOSSIBLE to screw it up? How did my parents survive for 60 years under these UNSAFE conditions?
I think electronic devices can be pretty damn safe, even without totally locked-down firmware and secure-boot. They can be flashed with low-level firmware at the hardware level (SPI or JTAG or similar), then boot trusted install media, wipe the mass storage and install fresh.
Then, keep it minimal, keep it under control. Don't install and use 20k components/libraries which you are not familiar with and of which hundreds want to update every other day. At least, be familiar with all the processes and daemons running. Either you should know why they're there, or they should not be there. You don't need a firewall if no process is listening for connections (and if you need a firewall to block it, why are you running it ?!) Just run less junk.
Of course not. But, the meat of the discussion is that everyone agrees it IS safe to use iPads. So, is there a practical middle ground?
Software is the perhaps that area where "good" or "crappy" is most undetermined. A given piece of software can be bullet-proof today and a catastrophic hole can appear tomorrow. And even if the producer releases an update, there's no guarantee it will be picked-up.
Overall situation is that what's needed is standards of software use for those companies which actually do damage. Without standards, your use of "crappy" is meaningless.
Sometimes you do everything you can and things still go wrong. That's okay.
What happens in practice is totally different though. Gross negligence is endemic in the technology industry. Most companies out there simply don't give a shit. Their negligence is deliberate, calculated and pre-meditated. They know exactly how much damage they're causing and they don't care because caring costs money.
> Without standards, your use of "crappy" is meaningless.
It's not meaningless at all. For example, nearly every laptop manufacturer I've ever seen has delivered to me software that is unambiguously bad. This opinion is not controversial at all. You just need to fire up some manufacturer app to see just how incredibly bad they are.
I've posted about that here many times and people explained to me that the software is garbage because hardware companies literally don't care about it. They see it as just additional costs to be eliminated and as a result we get products which are total crap. My laptop came with a driver that intercepts my keystrokes and sends signals to the keyboard so that it can light up the LEDs under the keys I pressed. What caused an insane design like this to even come into existence is beyond me, no doubt it came down to saving a few cents in manufacturing. I replaced this functionality with free software and I'm not sure if I even want to know whether there are any vulnerabilities in that driver.
That sounds pretty cool and hackable actually.
Only because you didn't notice the catastrophic hole today, and that's true of everything. When a building collapses the construction company/architects can't really get out of that by going "well it was perfectly fine yesterday, it's hardly our fault!", I don't see why we'd accept that attitude from software engineers.
Because of that, software simply can't be treated the same as other engineering disciplines, at least not yet.
Is it? Unless we can accurately simulate reality at the atom level and bruteforce building designs against every possible scenario to make sure it doesn't fail catastrophically, it's still all down to prior knowledge/experience, reasonable assumptions, approximations and measurements, just like in software. If anything, software is easier, as with enough efforts (formal methods, etc) you can get to prove the correctness of your software, but you can't really do so with a building.
A large chunk of software vulnerabilities is either due to outright incompetence, legitimate mistakes or cost-cutting. The example of an insecure, black-box backdoorable EC like in this article would have a "building" equivalent of using rebar or concrete of unknown specs and origin and then wondering why the construction collapsed.
Thankfully the liabilities associated with civil engineering means we mostly don't use unknown materials of shady origin and there are multiple layers of review to catch any oversights. The same can be applied to software, and while you're never going to get 100% in either domain, if software was as reliable as buildings (as in you can count the number of major collapses/bugs on one hand in the past few years) it would be a major improvement.
While a while loop in a computer program will eat away at any sort of redundancy you may introduce, and the complexity of computability itself simply leaves behind even mathematics. There is no universal way to prove a non-trivial property of an arbitrary program.
Not really, we've just gotten very good at constructing buildings thanks to millennia of experience. We're terrible at writing software.
This is absolutely true, but it's also proportionally easier to defend software. It's insanely easy to test whether your software is vulnerable to SQL injection, it's not particularly easy to test whether your building can be destroyed with explosives.
Combine that with the fact that just about every piece of consumer software on the planet has a laundry list of bugs that don't require malicious intent to reproduce, and I find it very hard to accept that reasoning for software developers absconding responsibility.
I'm only suggesting that holding programmers liable for security vulnerabilities isn't really precedented across any other engineering discipline. That's not to say there isn't tons of shitty software being shipped with reckless disregard for quality, and some reckoning there might be useful.
Computers are one of the only things we expect flawless defense against malice.
The downside is companies will lock down their hardware even more out of fear of getting sued. It's utterly amazing this person managed to get custom firmware executing on the WiFi chip... stuff like Intel's or AMD's microcode is digitally signed (and iirc, also encrypted) instead of using a plain old XOR checksum, and I'd argue the world is off a lot less safe as a result.
With that said, it always irks me when someone suggests regulation as a solution to misconduct by large corporations and someone chimes in "But they'll just misbehave in some other way."
If the entity that is misbehaving has changed the way that they're misbehaving in response to your regulation that means that your regulations worked and that you merely need to continue regulating the offender.
Just keep making their "clever" workarounds illegal every single time until the desired outcome is achieved. They should have literally no choice other than to make a good product.
Sadly that one won't ever happen, the copyright mafia will do everything they can to prevent that. Just look at how Netflix is locking down people on rooted devices.
We really need to abolish copyright as well. It's the 21st century, copying is trivial.
> Just look at how Netflix is locking down people on rooted devices.
I had no idea. Please elaborate.
Hell, it wouldn’t surprise me if a few less than ethical NSA hackers are doing exactly that in their spare time.
I can. But no one is going to listen to either of us, so what does it matter.
Here is how I would start to improve the situation.
Disconnect untrusted computers from the internet.
In other words the only computer that is allowed to access the internet directly is a computer that has all the properties desired for adequate security. Those properties could be things like the hardware being repairable, having an open BIOS and the bootloader and OS being open source and able to be compiled from source by the user easily. Call this computer a "gateway" if you like, or call it a "firewall", or call it whatever you want to call it. The esential point is that it is the one computer you believe you can best understand and control.
I would be willing to bet any amount of money that just disconnecting all Windows computers from the internet, i.e., no direct connection, would result in a dramatic drop in security problems.
Keyloggers are not very useful on a mass scale if they cannot transfer the keystrokes over the internet.
There was a time when not all computers had unfettered direct access to the internet. They worked just fine. Maybe even better than ones today that are incessantly trying to connect to some server.
Disconnect billions of devices? How would you even enforce this?
> I would be willing to bet any amount of money that just disconnecting all Windows computers from the internet, i.e., no direct connection, would result in a dramatic drop in security problems.
Not really sure I understand your point here. Why stop at just Windows? If we remove all computers from the internet we would be so much more secure.
I'm also not sure why you single out Windows when even the blog post demonstrates this key logger in Linux (which is open source).
> There was a time when not all computers had unfettered direct access to the internet. They worked just fine. Maybe even better than ones today that are incessantly trying to connect to some server.
I hope this is a troll rather than someone honestly believing such a statement. You're claiming disconnected computers are perhaps better... while writing on one connected to the internet.
And jailing the entire population of a contry would reduce car accidents!
I think you’re missing part of their point (which isn’t super clear). You can still surf on such a computer, by going through an http proxy on the same LAN (the “gateway” they’re talking about, or bastion host)
They could very much be writing that comment on such a machine.
Amazing how people can (mis)interpret (unclear) comments as if they were crystal clear. They make assumptions. They read things in that are not there. It is truly entertaining, I never mentioned Linux. I never mentioned "desktop". Nor did I suggest Windows users would not be able to access the internet. Nor did I suggest the computer with IP forwarding enabled (call it what you like) needs to do everything a "firewall" does.
Indeed, I am writing this comment on such a commputer that runs a proxy for all the other computers. That's only because I like to experiment with different proxy configs.
Every org is different of course but in the general I agree that this should be a more common pattern.
The secure Linux distros are all of the locked down kind, like Chrome OS and Android.
The reason why we aren't seeing widespread desktop Linux malware campaigns is because almost nobody uses desktop Linux. The year of the Linux desktop, whenever it will be, will be followed by the year of the Linux desktop malware.
I love open source and free software, but it's not inherently more secure.
https://invisiblethingslab.com/resources/2014/A%20crack%20on...
It's true that windows has way more mitigation technologies, and X11 is more laissez-faire. But if you don't run untrusted or crappy software, linux can be pretty damn good. You just don't really know how crappy all the components of windows really are, or which mitigations are really useful or really working correctly, and in software with that much complexity there's always some stuff that isn't really working and nobody notices. In linux, if you really care, you can trim down to a very minimal curated setup, and that's really the only way to know what's really going on in your computer.
Given how many security problems come from the internet, I imagine that there would be a dramatic drop in security problems if any platform with as much popularity as usage as was cut off from contacting other machines over the internet, even if the platform had above average security.
Where I live it's not too hard to wardrive around the block playing funny noises into random peoples' bluetooth speakers and headphones inside their homes.
Don't use Bluetooth keyboards, period.
It can be improved if we support companies selling computers with FLOSS firmware and disabling Intel ME.
Also, we use them at work in our products, and usually just get the firmware and driver binaries thrown over the wall by the board vendor, withouy any description or changelog. I'm tempted to throw a few different bins through Ghidra and see if I can tell what changed.
You can use this safely if you know what you're doing but only with a lot of filtering. Or by not transmitting as such but outputting into a receiver directly with some attenuation.
Somehow the world didn't end though?
Maybe we should just assume the RF spectrum can and will be interfered with regarding of regulation and design accordingly, rather than trying to put the cat in the bag? After all, that's the approach we take for security despite "hacking" being illegal in most countries, and yet we still use HTTPS and authentication.
If that is the case, my list of reasons to like open-source firmwares and dislike intel IME has just increased a bit more.
Can anyone explain what the author meant by that? I thought 8051 is just an ISA, is there something special there for cross IC communication compared to other ISAs? And what the the connection to USB?
It in fact runs code on two "CPU"s, the EC and the WiFi card; both of which could reasonably be considered computers of their own.
Preventing hackers from hacking sucks balls when you're that hacker hacking your own hardware. For me this is a feature and what differenciates a general purpose computer from a locked down games console.
They've been on the retreat from the WiFi space for years, both WiSoC, and STA space.
They even sell their latest router chips with third party WiFi 6 chips these days.
Great read. That "technology" included in Realtek is absolutely bonkers -- who asked for that functionality at a consumer level? No one.
I believe the post is from Juho Snell:
What tech are we talking about? WoL is definitely appreciated in all devices, although the "RealWoW" thing is very much diminishing returns. Otherwise, everything is just normal programmable chips and DMA-type data movement, both of which are generally desirable.
in fact, i think i'd prefer a computer that leaves all the layer 4+ up to the operating system as at least it has a chance of being audited.
that said, this raises an interesting point. the only way to really be sure is to sniff your own packets... but if everything moves to being encrypted that's going to get a lot harder...
In addition if he could achieve code execution on the card it wouldn't matter whether the card has this functionality as he could implement it himself if needed.
that is exactly the kind of crap that gets exploited.
So I don't mean to be rude, but I'm guessing this is a chatbot? Skimmed for proper-nouns, then generic shrills about how the author and article are great and how technology's too complicated?
He said, before being rude & condescending. Here, would a chat bot pick apart your miserable comment like this?
Oh no I mixed up social media handles I must be a chat bot
> Skimmed for proper-nouns
Oh no I mixed up social media handles I must be a chat bot
> then generic shrills
Huh? I'm complaining about the very real technology present in the Realtek chips that enables any moron with access to a web browser to send firmware-level commands anywhere in the world.
Did you even read the article?
> about how the author and article are great
Are you a chatbot? I didn't even sing about the article being great, I asked if anyone had a real consumer application for the tech presented as an attack vector in the article.
Go outside. Talk to a human being. I'm betting it's been a couple years for you if you're this bad at not only misjudging intention but going straight to "this must not be a human being, only a bot would respond with something I do not wholly understand".
Again, what a miserable comment.
Thanks for clarifying! =)
Work on your approach.