Bypassing the WiFi Hardware Switch on the Lenovo X201 (2023)
btxx.org
btxx.org
If your work is sensitive in any way, this is what you can expect from Lenovo:
> In February 2021, Bloomberg Businessweek reported that U.S. investigators found in 2008 that military units in Iraq were using Lenovo laptops in which the hardware had been altered. According to a testimony from the case in 2010, "A large amount of Lenovo laptops were sold to the U.S. military that had a chip encrypted on the motherboard that would record all the data that was being inputted into that laptop and send it back to China." [0]
How is this company still allowed to do business in the USA? There are ThinkPads in the most important of places. Not just in government, but in research...
There are apparently no adults in the room, so make your own decisions.
[0] https://en.wikipedia.org/wiki/Lenovo#Security_and_privacy_in...
However, I know that trusting the CCP is not a great idea. Everyone, including the USA and the CCP, invest so much money in Advanced Persistent Threat actors. So on the side, buying the ThinkPad line would be the equivalent of the NSA's Tailored Access Operations, wouldn't it?
Why wouldn't they take advantage of this? Why take the chance if you work on anything that is gov or commercially sensitive?
[0] https://en.wikipedia.org/wiki/Normalcy_bias
note: if anyone could correct my terminology or logic here, I would appreciate it.
I proposed the case where I believe the current Wikipedia entry to be true.
Wouldn't the person who believes the contrary case be the best person to update the wiki?
On top of that, being in the security industry, the very vocal parts were very adamant that something like this could never happen, while also starting to fubd better supply chain verification. The less vocal parts noticed that the refutations boiled down to "why wouldn't people break their NDAs to show us hardware that probably got the NSA involved" and "the NSA wouldn't lie to us".
If you really need secure hardware, a librem laptop (iirc the right name) with openboot is the best.
However if you aren’t dealing with state secrets, any average computer is likely good enough. Just steer clear of unheard brands that sometimes have shady installers (there was a recent incident but it was an unheard brand name).
Let's say I am a sensitive US gov worker or contractor, or I work on state of the art tech/research in the USA. (all juicy targets for the CCP)
I would be correct in thinking that Intel Management Engine is likely NSA pwned, and likely not CCP pwned, correct?
That is of course assuming that the CCP didn't reverse engineer or crack it or hack NSA and also have access.
I think you will be better served by articles/blogs by the likes of librem and amnesty (I'm thinking of the group that found pegasus, I think it was some other human rights org from Canda?)/eff. Those guys will have better suggestions to harden your device. Also - ask your IT guy, or the IT guy of the US govt dept where you're working for their best practices.
Hacking risks can either be specific (eg Bezos being personally targeted) or a catch-all (eg stuxnet) where they target your entire department. If you're just one of hundreds of contractors you're likely in the second category which is relatively easier to protect yourself from.
what does this mean?
https://forums.lenovo.com/t5/Security-Malware/BIOS-automatic...
UEFI BIOS can also initiate OS actions thru shitty MS mechanisms. You will love WPBT (Windows Platform Binary Table)
https://www.howtogeek.com/226308/the-windows-platform-binary...
"Beginning with Windows 8, a PC manufacturer can embed a program -- a Windows .exe file, essentially -- in the PC's UEFI firmware. This is stored in the "Windows Platform Binary Table" (WPBT) section of the UEFI firmware. Whenever Windows boots, it looks at the UEFI firmware for this program, copies it from the firmware to the operating system drive, and runs it. "
" Lenovo shipped a variety of PCs with something called the "Lenovo Service Engine" (LSE) enabled. "
“Obfuscated” is another word, that is used to describe a thing that, while requiring no password, intentionally made complicated to achieve similar effect.
Hollywood style “the system is encrypted” is not real. That’s total technobabble, I’d say like “soft boiling a dinner plate”, nobody knows what it even amounts to.
see https://www.xyte.ch/mods/x210-x2100/ for an overview, although sadly the availability is diminishing (and the hardware is far from bleeding edge four years later) -- the above linked vendor is awol.
i've got myself 2.5 x2100s, hoping that will tide me over until something new becomes available.
I never got the appeal of those laptops either. It's not a Thinkpad, its an Chinese motherboard that is overpriced to get it working with a nice keyboard, and yet you'll still have to bend your neck to use it unless you're using the dock.
I guess that’s how things like cameras status led is compromised?
The author taped the switch readout pin (mPCIe pin 20) at the card side, and the card was so designed that it assumes the switch is set to not-kill when the switch is not present at all.
We do not know how deep the mechanism goes within the card. It is only shown that the card do work if the pin is open.
I think with billion dollar budget year after year, you pretty much go for firmware level attacks thees days. 0click 0day as-a-service is private economy and.. cheap and very different from what they want: long term backdoor access to everything, without the possiblility to spot it in user space or OS.
Most webcam use firmware control over the led: https://www.youtube.com/watch?v=ggRU9gGVRzE
Also/IIRC, the old webcam issue was some cameras had ~1s delay between first image to LED on, and zero for last frame to LED off, so initialization or configuration change commands could be mashed to allow LED to light in user unhelpful ways: e.g. only lit for imperceptible length of time or intermittently lit as shown. Apple and few other vendors modified this behavior as well as added a minimum LED on duration while after this went on media. It's still "controlled by software", sure, not like tapped off of CMOS imager power supply, but not like implemented in /lib/modules/webcam_comforting_led.so.1, either.
I made the video on the webcams, these are quite modern ones. Nearly all of them have special UVC commands that allow reading and writing the internal CPUs memory (a lot are 8051 based). You can find the register that controls the led GPIO and control it freely. Only on one of them I did not find a way to modify the led behavior without modifying the firmware to add an extra command.
(No wifi killswitch on Framework laptops at this time.)
Because it is practically not possible with current hardware. Theoretically it is possible to design PCIe hot-plugging but no WiFi card/driver supports it.
Maybe it is possible to do over Thunderbolt but I wouldn't hold my breath.
Of course there are USB WiFi chips but they are much worse in every aspect than PCIe ones.
If you're concerned about this type of thing discard the internal wifi card and use an usb-attached wifi dongle you can unplug to achieve a "wifi physically disconnected" state with certainty.
The other advantage is whatever firmware's running on the wifi dongle isn't going to be potentially accessing host memory over usb, which a pci bus master could theoretically do.
(What may actually be happening is that they switch is telling the embedded controller to toggle the WiFi card pin, in which case modifying the EC firmware might let you achieve the desired outcome, but that's still not an ACPI hack)