Russian researchers expose breakthrough U.S. spying program
reuters.com
reuters.com
Didn't someone else also manage to run Linux on a HDD?!
edit: it was the same guy, it's just hidden on the last page of the series and it's just linux, no userspace
Who says one can not use bugs in e.g. SMART or other (S)ATA protocol implementations in order to spread malware by disk?
And... isn't data transfer of HDDs usually handled by DMA? Is there a way for a malicious HDD to compromise a system? Everyone locked down their FireWire port, but is eSATA vulnerable?
On the other hand you have PCI/PCIe/FW/Thunderbolt/SCSI, those buses allow every device to take over as a temporary bus master, and some of them (Im not familiar/sure about scsi, probably not) allow arbitrary memory access.
So you cant use SATA in a way FW can be exploited. There might be some obscure state machine bugs in some hardware host implementations, but why bother when you have low hanging fruit of access to raw binary data. Travis Goodspeed demonstrated (using usb storage, same mechanism) how analysis of read access call order and frequency patterns can be used to estimate OS and use scenario (boot, normal execution, forensic imaging of the drive). Thus infected device can pretend to be fine when analysed standalone.
I was more thinking of Linux or Windows hardware driver level compromises, as a filesystem exploit requires that the drive in question is actively mounted and a protocol driver exploit pwns your system as soon as you attach the drive.
Combine a OSX, a Linux and a Windows exploit in the ATA protocol drivers and you have a cyberweapon capable of infecting even a forensic analysis system. And in contrast to USB, I don't believe that ATA and other low-level hardware protocol implementations in kernels get very much attention from developers.
Forensic imagers are pretty much standard equipment in any police lab, but I doubt that a normal investigator will disassemble a disk and do raw forensics on the disk platters... heh, if I were a guy with something to hide, I'd hack the firmware to either wipe the disk upon imaging or compromising the investigator's machine.
http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.h... https://www.youtube.com/watch?v=D8Im0_KUEf8
It's _really_ nice...
I came up with yet another, truly weird plan. Take a 2-platter disk with 500GB (so 250GB per platter), scratch off the label. Modify the firmware so that:
a) both platters are encrypted with a hardcoded, generated-at-lowlevel-reformat secret key to delay forensic efforts
b) the ATA identify and other ID values point to a 250GB drive (half the original capacity!)
c) the bootloader is two-staged, boot0 running on the HDD CPU and boot1 running on the host before the OS bootloader. If e.g. a specific key is pressed during boot, boot1 asks for a password and gives this password to boot0 (e.g. via custom ATA command). boot0 now uses this password to apply a second decryption to platter1 - so there is no TrueCrypt or anything on the "hidden" OS which impacts performance (you can reveal if you're using TrueCrypt via a sidechannel attack. Determine the HDD model and compare write speed with a reference value. If you're inside spec - no crypto. If you're slower - crypto).
If no key is pressed, then boot0 boots the bootloader from the unlocked platter2 - the "clear" OS will have no way of seeing the data on platter2 and even if the reported HDD size is compared with the specifications of the (manipulated!) HDD model name as reported to the OS, a malware has no way of knowing that this HDD in fact has a hidden area.
2/ you can do this _yourself_ today on off the shelf drive using HPA/DCO
3/ Dont really understand your plan, you want to prepare drive like that to hide your own data from others? average foresic investigator will immediately tell your 'clear' OS is an unused decoy (no signs of regular daily use).
Similarly for other code loaded from hard drive (system files, drivers, etc).
Profile here: http://www.wired.com/2012/07/ff_kaspersky/all/
"Kaspersky’s rise is particularly notable—and to some, downright troubling—given his KGB-sponsored training, his tenure as a Soviet intelligence officer, his alliance with Vladimir Putin’s regime, and his deep and ongoing relationship with Russia’s Federal Security Service, or FSB."
The question is: is Kaspersky going to abuse all that trust and good will they are gathering?
the sad side effect of the moral elite proving hollow is that those you may consider enemies might become allies. Despite everything there is little proof of malice at kaspersky while the same cant be said for many companies in the west.
If the FSB is funding research that brings unwanted transparency to the NSA, allowing us to better understand and criticize the US corporations and agencies compliment with them, then I welcome it. I doubt it is the case but if your fantasy turns out to be correct they would also deserve some poli sci props.
Have proof of actual malice being committed? Intelligence gathering in of itself isn't malicious. That's literally the very reason for the NSA's existence. It's like saying the FBI is malicious because they "investigate". That's what they do, that's their job. I'd be more pissed if they weren't doing this sort of thing. I'd wonder where the hell my tax dollars are going.
The only thing that bothers me is when they spy on their own citizens, us. I have no problem with them spying or hacking Russia, China or Iran. Their job is to protect their country and their allies from foreign aggression and international criminal organizations. When you wake up in the morning, China, Russia, Iran, Etc... are all still going to try and hack U.S businesses, governmental services and try to gain access to classified information. Pretending like these acts don't happen doesn't make them go away.
I'm not an American, so it would be wrong of me to assert what you or your government should or should not do in this regard. However in general I think GCHQ and the NSA have a case for some of the kinds of monitoring they are doing, I just think it's lacking in legal basis and appropriate oversight. They have shown repeatedly that we can't trust them.
If you have lots of private information about someone that means you have power over that person. For starters it makes blackmail a whole lot easier. In combination with data about other people it helps you determine who you have to remove from a group to make that group collapse.
Now if somebody has this sort of power about some foreigners, that's not really a big problem for you country. But if somebody has that power about the entire population of your own country, that's a bit worse. That somebody could disable any form of democracy by silencing citizen protests before they even start while covertly controlling key politicians.
If communism has thought us anything it's that you don't want anybody to have intimate knowledge over large parts of your population, it doesn't tend to end well. Oversight is a nice idea but there was already supposed to be all kinds of oversight which apparently failed. I don't really trust oversight in things this important.
>The question is: is Kaspersky going to abuse all that trust and good will they are gathering?
There are a dozen or so American companies that most would have hoped would stand up to domestic intelligence companies, rather than take the safe route of cooperating.Was the power abused or was it co-opted? Will a Russian company fare any better against their own government?
How does talking about the messenger change the message?
We need to judge the messenger's integrity in order to judge the message's accuracy. Putin might say there are no Russian soldiers in Ukraine.
We can't rely on plausibility. Good propaganda is plausible, and the Russian intelligence services are very good at propaganda.
* Microsoft - US
* Avast - Czech Republic
* AVG - Czech Republic
* ESET - Slovakia
* Symantec - US
* Avira - Germany
* Kaspersky - Russia
* Malwarebytes - US
* McAfee - US
* COMODO - US
* Bitdefender - Romania
* Panda - Spain
To be fair, Kaspersky does a pretty good job of reporting on even Russian originated banking trojans and the like.Oh, I almost forgot https://en.wikipedia.org/wiki/Clam_AntiVirus#Effectiveness
But it's not famous enough...
I think that's about as relevant to this article.
https://securelist.com/files/2015/02/Equation_group_question...
I know it's not Germany.. just wanted to provide another example, so we know Germany isn't special.
It is a feature sold, not something undercover that the poor drivers are unaware of.
Other auto makers do the same, afaik.
>Seems that everybody hacking everybody is just an implicitly accepted practice these days.
My view is that:
1. this area is so new, no one knows what the limits should be (disagreements even within governments and agencies),
2. but that there are red lines,
3. that it is likely that the US and other actors have crossed a few of them,
4. and that the world is in the process of reacting and establishing norms of behavior.
With no proof showed to the public.And Obama put another set of sanctions on north korea as a result of this.
This episode is no different from the WMDs in Irak during Bush era. At least Bush tried to make a case. Here no case,no smoking gun,just the Obama administration saying NK did it, but what is frightening is the total absence of reaction from the american people.NK is bad, but what the Obama administration did is bad too. Even though, again, NK government is horrible, what happened here is just frightening. Because tomorrow it can be country B or D that did nothing yet gets sanctions from US because the US administration said it did something?
To be able to routinely steal something from the PC it will need to be tailored to specific configuration.
Am I wrong?
[1] http://25zbkz3k00wn2tp5092n6di7b5k.wpengine.netdna-cdn.com/f...
The firmware malware is mainly to create hidden, unremovable, persistant space on the drive, and likely hijack the boot process. At that point it passes off to other malware.
NVDIA driver is the same for all cards.
Tablets and smartphones are very homogeneous and the most widely used, Apple's totally closed source, including the hardware.
Most people use Intel processors.
Any of those vectors are very easy to target if you have the hardware and software source code.
The problem is, firmware is pretty small. You can't fit much function there.
Or it was; I imagine modern hard drives might have many megabytes of firmware which allows for pretty sophisticated hacks.
Ditto for accessing the file system.
[1] http://www.jwz.org/blog/2015/02/ip-over-avian-carriers-nsa-e...
This is known as bit rot, data rot, data decay or data degradation.
See https://en.wikipedia.org/wiki/Data_degradation#Decay_of_stor...
As the article says, they could ask for the code for making an audit. Of course they can do whatever they want with it.
They can abuse this power in so many ways, from giving this source code to competitors but "closer to home", individual members of those agencies selling it for profit, or analyzing vulnerabilities and not reporting them to you.
What the article doesn't reveal is the attack vector, how did the firmware in these drives come to be infected?
If criminals can target a bank to steal $300M from clients, the NSA can target a HD company to steal the source code.
It's really not that difficult.
Remember, the best attack isn't a direct assault. It's a sneak assault.
The story is that during WWII, Ian Fleming was part of a group of spies in training, who were asked to get into a secure nuclear research facility. Everyone else got caught. Sneaking in under the wire, etc.
Ian called a professor friend to vouch for him. Then, call the facility, and asked for a tour, as a visiting "researcher". After the tour was over, he called his boss, and told them his briefcase was hidden next to a critical part of the facility.
Bugging HD firmware is a brilliant ploy. Who looks there?
http://www.kaspersky.com/about/news/virus/2015/Equation-Grou...
Classic spying methods to deliver malware
The attackers used universal methods to infect targets: not only through the web, but also in the physical world. For that they used an interdiction technique – intercepting physical goods and replacing them with Trojanized versions. One such example involved targeting participants at a scientific conference in Houston: upon returning home, some of the participants received a copy of the conference materials on a CD-ROM which was then used to install the group’s DoubleFantasy implant into the target’s machine. The exact method by which these CDs were interdicted is unknown.
http://www.theguardian.com/books/2014/may/12/glenn-greenwald...
Alternatively could they use software exploits in an OS to execute arbitrary code and rewrite the firmware?
What the article doesn't reveal is the attack vector, how did the firmware in these drives come to be infected?
Worst case scenario; They all are infected as they come out of the factory. Best case, they are rerouted and patched during postal delivery by a targeted ops team.Edit: are downvotes because you don't think it's "medium", or implausible, or what?
Anyway, I'm not interested in getting into a debate, but it sounds like an impressive bit of work.
That said, right now there is not a single hardware manufacturer in the world who is not open to government pressure.
Perhaps the only answer to all this is to make our institutions irrevocably open - that there are open publicised hardware standards and means of verifying the circuits are the design expected.
A TPM can then read the boot sector and ensure it hasn't been modified, so the firmware can't take advantage of the unencrypted code there.
Of course there's other things the firmware can target, but at least not being able to directly read/write data is a huge bonus. And it'll greatly reduce the surface area for exploits, since just the encrypted block device code can be messed with, not all the internals of various filesystems.
Question: If there's a good chance a machine w/ one of the said HD's has the NSA spying app, how do you remove it??
I have a Seagate HDD and I run Linux (Ubuntu), so I'm wondering if I'd be immune to the spyware.
If they don't have an exploit for your OS yet, they'll write one.
Also, there's an independent OS running inside your Intel CPU (vPro).
Linux kernel privilege escalation bugs come out all the time. There is a long documented history of Linux rootkits. And I'm assuming you are accessing HN through a browser: Firefox/Chrome browser exploits with sandbox escapes get reported each year. Also you probably boot using UEFI, and there was presentation last year about UEFI bootkits which can hook into Kernels.
In addition, Ubuntu is one of the most popular Linux distros (if not the most) and doesn't use rolling releases, so it's probably an easier target compared to most distros.
You can't achieve security strictly through technology choices, such as which operating system you choose. Although there is some value in choosing less-popular technology.
*(Version of Ubuntu developed for long-term use).
I imagine using an encrypted filesystem would be immune though.
>The supported file systems are: FAT, NTFS, EXT3 and UFS.
sits specifically targeting most Windows versions, Linux and OSX.
Is this really a breakthrough? Hasn't this type of attack been around for a long time? Yeah, Reuters. It is interesting that likely a state actor is using this type of attack in a coordinated way. Interesting, but is this really surprising?
In other news, Apple and Google now make a device you can connect right to you skin 24/7.
Politicians pretty much treat us like we're all mentally challenged, which, compared to Ivy league educated officials, I guess most of us are. But it really makes you wonder why such smart people just don't give a fuck.
Government is not a meritocracy. Humans game any system. And it usually makes sense to go for the most leverage/bang for your buck. If one is doing something that is unethical, legal or not, might as well go in for the whole enchilada.
To specifically address your implied question, although I do not think I am all that smart, I am just trying to keep what little I have, improve the small area I live in, cherish the important people around me, and have time to learn new stuff. Railing against the current governing system threatens all of that, and in some cases, results in premature death. I seem to have settled for the Blue Pill.
What is the verse from the third stanza of Queen's 'We Will Rock You?' Something like 'Old man trying to make you some peace some day...'
It's interesting insight from a technical perspective, but apart from that, is it really surprising or upsetting?
Some things about the NSA like Prism are genuinely upsetting, but I don't think this particular story is.
As long as the central bankers and whoever else is in power doesn't turn up the heat too high too fast this isn't that relevant to most of us.
We're all pretty aware they can get our data so this isn't surprising. Just search NSA on LinkedIn and you can see their army of programmers on there who care about real threats and not people who read hacker news.
Probably just a nicely worded letter:
To whom it may concern,
Under the authority of Executive Order 12333 and
pursuant to Title 18 USC Section 2709, you are hereby
compelled to provide the NSA with the source code of the
firmware of your company's line of hard-drive products.Anybody have anymore info on this? I've always been under the impression that it's at least theoretically possible to copy the firmware off of something and decompile it at least.
But why start from scratch if you can just modify the existing firmware? And that seems to be perfectly possible: http://spritesmods.com/?art=hddhack
I'd say the most difficult and resource consuming part is to make versions which work on as many brands, models and revisions as possible, and make them all robust enough so they won't be detected because of random malfunctions.
But I don't know anything about hard disk firmwares: Perhaps they are not too diverse and once you know how to modify one drive, the others will follow easily?
I have personally added new functionality to binary libraries on wintel, and in embedded firmware for instance communications devices. Just jump somewhere else and jump back where you came from, there is often nothing preventing you from doing that.
Imagine having to wait 3 months before you can launch your start up because you have to get the corresponding permits and have your code reviewed.
God damn it. Again with the "kill the messenger" attitude. It's not the disclosure of the acts that harmed the relationships. It's the spying and hacking acts themselves. It's like your friend telling you your girlfriend is cheating on you, and getting mad at the friend instead of the girlfriend, for "harming your relationship".
You don't want your relationships harmed? Uhh..here's a solution for you, US government: don't fucking do it to your allies in the first place if you don't want your relationships "harmed". It's not rocket science.
It's more like _your girlfriend_ getting mad at your friend for telling you she was cheating.
Or "We would have gotten away with it if not for that meddling kid."