The threat on your desk: Building an evil USB-C dock
research.aurainfosec.io
research.aurainfosec.io
https://en.wikipedia.org/wiki/Intel_Management_Engine https://en.wikipedia.org/wiki/AMD_Platform_Security_Processo...
Edit: Yes, it's called TrustZone.
https://en.wikipedia.org/wiki/ARM_architecture_family#Securi...
Intel Management Engine is very different. It's basically another CPU within your real CPU, running its own software with no visibility to the main OS, and it has (AFAIK) full access to other components. If it's compromised, or has a factory backdoor, you're 0wned.
The closest thing to Intel IME that the iPhone has, is the baseband, which can run its own code. But if I'm reading marcan correctly (https://news.ycombinator.com/item?id=30393283), modern iPhones/Android phones all use IOMMUs to isolate that (with the exception of a few so-called "free/libre" phones). The IOMMUs can be easily inspected from the OS to make sure they're correct, so it's just not a concern, unlike IME.
Not to mention the technical challenge of quickly understanding and editing Apple’s designs from the limited information that is shared with the foundry.
this is for me when I want to enable virtualization on a user's laptop remotely, without sending a human to their desk or to their house to enter the bios password and to enable virtualization or do whatever else I need done in there.
this is how I ship a laptop from the manufacturer directly to an end user, at their home, and they unbox it, turn it on, log in, and the computer becomes a corporate-managed device. I don't have to fly someone out so they can set up the computer, or ship the computer to the office for configuration before it gets shipped again to the end user.
this is not a nefarious thing, nor is it a target for hackers, because there are far easier ways to trick someone into doing something which lets the hacker onto their system.
I think hackers will decide on this, not you. And at least acknowledge that IME/PSP seriously expands the attack surface of the hardware at a very low level, enabling new classes of exploits against which the OS has no defense.
if you don't want to spend $0.10 on the feature in the chip, spend 100 billion times more than that to start a CPU fabrication company and license x86_64 so you can make your own CPU.
we can't have everything a la carte. it doesn't make sense.
And it's not that they'd have to re-tool their fabs to make it either; they're already set up to make non-ME systems for certain government buyers. Please let civilians buy those systems.
the thing isn't even capable of the devastating things you all fear. it's a minimal CPU (a slow 486 on Intel chips) with a miniscule web server which is off unless configured to be on and it can't read your disk or read RAM. all it can do is talk to hardware. it's how you configure the bios without rebooting at the console.
You literally got destroyed and that’s your comeback?
you are smart enough to have firewalls in place, right? or are you so knowledgeable about security that you turn those off?
I see you linking to attempts and maybe some real vulns but even if they were exploited in the wild without local USB access, which I don't see in those links, firewalls would have prevented them.
physical access appears to be a requirement for those now-patched vulnerabilities, so while I was mistaken about a bit of this, my overall point stands. wow I guess you sure proved your side!
if you don't like this kind of thing in your CPUs, please feel free to start a CPU company and make your own stuff.
So is the internet. And a few other things. I do not feel your arguments particularly strong.
E.g. wouldn't this purpose a target for specially prepared external managmenet dongles (similar like those hinted in the article but of course made professionally and with the noblest of noble system admin motives) that could be plugged in where and when corporate management is necessary to set up, then remove, send to the next computer if necessary? And not built into EVERY computer, from granny to the schoolboy so YOU could do something? This concept soulds like the key under the doormat kind of security. And you rely corporate systems on this.
>this is not a nefarious thing
Hell is paved with good intentions. The intent is irrelevant. Every substance that we banned so far in agriculture were developed, and used with the intent of improving the crops. Yet, they turned out to be a net negative. We don't know the end game of the ME/PSP yet, but I'm not keen to participate, I'd gladly buy a CPU without it, and let other people find out.
...and if they don't I should propose it, sounds like a fun project. Leave a random cable or USB stick that just shows a warning that it could have been malicious. Or something that just opens up https://nyan.cat and sets the volume to max :D.
We need crowdsourced behavioral fingerprints and open-source test suites for peripherals which may be subject to supply chain or shipment interdiction. Measure power consumption and response latency baselines, when idle and with reference workloads. Fingerprint units of the same model procured via multiple supply chains: brick & mortar, online, different couriers, new/used.
More generally, there is ongoing work for integrity verification of devices, including PCIe device authentication [1][2], USB device authentication [3] and SPDM for remote attestation between DICE-RoT and system firmware, before allowing a device to communicate with the system.
[1] PCIe component auth, https://pcisig.com/pcie®-component-authentication
[2] Intel PCI Express Device Security, https://www.intel.com/content/dam/www/public/us/en/documents...
[3] https://www.zdnet.com/article/usb-type-c-gets-authentication...
USB data blocker with transparent case for physical inspection: https://portablepowersupplies.co.uk/product/pure-usb-data-bl....
Do we need transparent docks?
I don't think transparent docks would work because a serious enough actor can make it look and work like the real thing.
I recently bought a little used Yoga Thinkpad, I’m not really a Windows guy. On plugging just the cable into a USB port with nothing on the other end Windows made its little “device plugged in” ba-da-doop sound that Windows makes.
I didn’t see anything interesting in my quick scan of device manager but that single ba-da-doop stopped me from using my favorite cable cold turkey. I should investigate it further.
Such a cable would be very useful but your comment makes me think twice...
Are there good reasons to believe they're safe, that the brands are trustworthy?
Are there good reasons to believe that the brand name that's printed on the case means it's actually made by that company?
How could anyone determine if it contains a keylogger, or an HDMI screen grabber, or a network sniffer, or a reverse shell, or a rootkit installer?
Even with trusted brands, a malicious actor can attack the vendor. For example, one could order devices, tamper with them, and then send them back via returns. The vendor likely tests it a bit, and then repackages it and sells it as refurbished, or maybe even as a new one.
The fun thing is that the same is true with software. Looking at a source code is hard enough, even for experienced programmers, and then how do you verify a piece of software that you don't even have the source code to? And if you have the code, how do you verify that the software is made out of that code?
People basically just operate on trust, you can't verify much of the stuff. Just try to stick to entities with reputation, and hope for the best.
if you don't want to spend your entire life living in a faraday cage, there must be some level of trust.
I don't even think that most people need to think about this. It's enough that a few security minded people do, and that they end up pushing for good regulation. Similarly to food safety, we then end up in a system where you can go to most places and expect to not get food poisoning.
For Anker in particular, sadly there may be a reason _not_ to trust them. See the recent Anker-owned Eufy cloud camera scandel
The US government rerouted CISCO routers to a factory that tampered with them before sending them to their final destinations. There's no reason to believe this stopped or isn't still being done in similar ways. It doesn't have to be a USB-C dock, it could be anything.
These attacks are not easy or cheap, and by their very nature need to be deployed in small % of total installs (as every use increases the likelihood of discovery).
Criminal organizations interested in ransoming details might be interested in casting a wide net, but intelligence services less so.
No. Sentimental values aren't an objective measure.
>Are there good reasons to believe that the brand name that's printed on the case means it's actually made by that company?
No. Most companies don't manufacture their products, in fact.
>How could anyone determine if it contains a keylogger, or an HDMI screen grabber, or a network sniffer, or a reverse shell, or a rootkit installer?
By having a sacrificial computer that tests every single piece of hardware and software before they are allowed access into your inner sanctum.
Even still, it could be intercepting & mitm'ing your devices. There are some potential advanced games here. But without also having a network device to exfiltrate out on, it seems pointless. As soon as you have USB networking the risk skyrockets though.
There are good reasons to believe Anker is not trustworthy [0].
[0]: https://arstechnica.com/gadgets/2022/11/eufys-no-clouds-came...
It's a solid niche IMO. I don't like buying devices that will effectively stop working if the manufacturer goes out of business or shuts down the services they're dependent upon. OTOH, there's generally a lot more effort required by the end user to get it working, so I completely understand why most manufacturers go with a service-mediated design.
I like to think people that know their trade (electronics, etc) can figure this out; the absence of proof of there being things like keyloggers in these docks is enough for me. Same with the distrust of ZTE devices, has there been any conclusive evidence that there actually IS espionage or remote controls in there, or is it fearmongering to protect the US / western market?
https://support.apple.com/en-bw/guide/mac-help/mchlf779ae93/...
It is probably possible to automate the keystrokes to quickly kill this screen though.
I tossed mine in the trash. Odds that is was legit? 99.99%?
But just seemed like a major oversight to just toss out usb devices en masse
...or you could use something invented a century ago, called an X-ray machine.