How the NSA’s Firmware Hacking Works and Why It’s So Unsettling
wired.com
wired.com
I honestly don't think it's as difficult as they make it out to be. About ten years ago we were hacking Treo 650 firmware to read and write to flash without actually knowing how to do it at a low level. We just found the appropriate "read sector" and "write sector" commands and wrote a heuristic to search for them in whatever version was running. Later Android hacking attempts did exactly the same thing with HTC's HBOOT.
HDD, CD-ROM, DVD-ROM, BluRay -- firmware for all of those types of drives have been decompiled before. With the right JTAG hardware and/or creativity it just isn't that difficult for someone who knows that they are doing.
Now, if you can execute code on the HDD's CPU through whatever exploit you can find, you can search through RAM for whatever methods you need to write yourself to persistent storage. That persistent exploit can then use heuristics to hook the appropriate methods to intercept reads and writes as needed.
If anyone here has done reasonably well at https://microcorruption.com/ and has experience with IDA, I'd say they were qualified to do something like this (experience with ARM and JTAG a bonus!).
Note that there have been proofs-of-concept of this for some time [3], as linked elsewhere in this thread. While it is still impressive that they could link it into their exploit framework, I honestly believe that you could "weaponize" something like the previously linked exploit without a massive effort.
Also note that this is not a "complete takeover" of an HDD, but rather an exploit that allows it to interpose between the platter data and the computer.
[1] grack.com/romtool
[2] unrevoked.com
How is it not a complete takeover? I realize news articles are not the best technical sources as they get terms & concepts wrong, but I am reading that the firmware is completely reflashed, which means the HDD CPU has been utterly "pwned", for lack of a better term.
I also find the timing interesting here. Suddenly Kaspersky has what could be nation state cyberwar tools, while coincidentally in a propaganda war with the West?
Russian hackers’ ‘Trojan Horse’ malware inside U.S. critical infrastructure since 2011
http://www.washingtontimes.com/news/2014/nov/6/russian-hacke...
Sneaky Russian hackers slurped $15 MILLION from banks
http://www.theregister.co.uk/2014/12/22/russian_cyber_heist_...
Russian Hackers Attack NATO, Lithuania Girds for Unconventional War
http://www.tol.org/client/article/24515-russian-hackers-atta...
That is not a solution for this. You have to assume that a state-level attacker will be able to either coerce the vendor or its employees into signing malicious firmware or just compromise their network and steal the signing key.
The right way to secure firmware updates is with a hardware write-enable switch/jumper that has to be physically set to make any changes to the firmware.
eg: http://www.hynix.com/datasheet/pdf/flash/HY27UF084G2M%20Seri...
Apple would likely just ask you to bring it into the Apple store.
http://support.apple.com/en-us/HT201966
http://support.apple.com/kb/DL1378
Here's one from Lenovo:
http://support.lenovo.com/us/en/downloads/migr-62282
With suitable search terms you'll find similar updates from other OEMs.
For HDD firmware, I think it's something that should not be updatable at all through regular software; instead it's something manufacturers should be getting right before shipping product. I've owned disks from over two decades ago, and not once have I needed to update any firmware on them.
Somehow I feel that this "update culture" has just lead to more problems due to propagating an attitude of "it can always be updated later", where shipping devices with imperfect firmware becomes almost acceptable and it can sometimes become a case of fixing one bug and introducing others.
Don't forget feature bloat & the increased attack surface they inevitably create.
http://support.apple.com/kb/DL1283
"Locate the programmer's button on the side of the iMac, to the right of the reset button. Press and hold in the programmer's button. You may need to use a pen or a straightened paper clip."
Which they stopped making around 2003. Further the button was accessible from the outside.
Presumably stock external flash parts are okay, but it's still conceivable that evil circuitry could cause a write, or at least an addressing "mistake".
Yeah, I'm a suspicious cuss.
Some targets may fall under surveillance and not acquire new hardware for long periods of time. Years.
http://www.samsung.com/global/business/semiconductor/minisit...
Now tedu being a BSD guy ;) probably is finding out some other way but I'm going to guess the vast majority of SSD customers have a Windows or Mac computer and just go with the utility provided by the hardware vendor, Samsung or some other company.
As an example of a rather serious firmware update that likely went unnoticed by most drive owners, some Samsung F4 EcoGreen hard drives (the ones Samsung actually made before the Seagate buyout) had a serious bug[1] that caused data corruption if a specific S.M.A.R.T. command was issued to the drive during normal operation:
"The above suggests that the disk sometimes discards a
pending 64 sector write command when a IDENTIFY DEVICE
command is received. This data loss occurs silently.
There is no error message in kernel log, SMART Error log,
NCQ Command Error log page, or SATA Phy Event Counters
log page."
Manufacturers can't notify people directly about these things unless buyers contact info is submitted along with info about which specific drive model they own. I don't know if this patch was pushed out via Windows Update but I'd bet it wasn't. I only heard about it because Smartmontools warned me.Samsung fixed it in a firmware update but neglected to bump the version number of the firmware, so it's impossible to tell which drives have been fixed. As a result, it's quite easy to assume your drive is fine, so Smartmontools will print this in any system with any HD204UI or HD155UI detected:
==> WARNING: Using smartmontools or hdparm with this
drive may result in data loss due to a firmware bug.
****** THIS DRIVE MAY OR MAY NOT BE AFFECTED! ******
Buggy and fixed firmware report same version number!
See the following web pages for details:
http://knowledge.seagate.com/articles/en_US/FAQ/223571en
http://www.smartmontools.org/wiki/SamsungF4EGBadBlocks
[1] http://www.smartmontools.org/wiki/SamsungF4EGBadBlocksEven ignoring that, let's move on to... enterprise storage. I don't foresee someone with a 1200 disk storage array being enthused at the prospect of popping out drives one at a time to be able to update firmware (something that is currently an online operation).
Look back at floppy disks: while many people were caught by the write-protect tab/switch while they were still learning, it was an easy concept for people to understand once taught. I knew many non-technical people that quickly adopted habits that utilized write-protection.
The physical interlock is something that can be taught a lot easier than how to use crypto without screwing up. If you require proactive checking or fancy technique, it will be forgotten and skipped. On the other hand, if you fail the update with a message "did you forget to flip the write-protect switch? [picture of switch]", a lot of people will figure it out.
There are similarities to Schneier's (et al) recommendation to make good (long, random) passwords, but write them down and keep them someplace safe. (i.e. leverage the physical security knowledge that people already have)
It's actually specified in the SD spec [1], which says on p. 38 that the mechanical protect switch is "Host responsibility only" and that the "The position of the write protect switch is unknown to the internal circuitry of the card."
1. https://www.sdcard.org/downloads/pls/simplified_specs/part1_... [pdf file]
Hardware write protection is harder to find than you think..
The ultimate solution would be to make HDD firmware open-source, just like Coreboot for BIOSes, so the truly paranoid could download, verify, compile, and flash their drives themselves. Unfortunately, I don't see this happening due to all the trade secrets (including some existing backdoors into passworded drives that you can find on data recovery forums, but obviously manufacturers don't want you to know about...) that are likely involved.
To access a BIOS passworded drive all you had to do was swap it for another for which you knew the password, boot into the BIOS and change the HDD password. It will ask you for your old password, you enter it and you go to the new password input screen. Now you take out the HDD and put the locked one in its place. You press enter twice, setting the password as blank, and voilá, you have your locked drive unlocked. Just boot the computer and no more HDD password. Have fun.
They must know that it's wrong? Or do they buy the government arguments about the balance between privacy and security; maybe are they just young, talented and excited to be doing something "legally" that most people would be put in jail for?
What to do when governments become untrustworthy actors to such an extent?
Lots of these revalations are being published by a non-US security company. The US security companies have either missed these security issues, deliberately ignored them, or have been forced to keep them secret. In my opinion, the fact that there are still some non-US IT security companies is a good thing.
Also for having the upper hand in negotiations and forcing the lesser states and their politicians to do as you please...
Which is much more important than some BS need for "diplomatic stability" without any other major player like USSR around, except maybe with China.
If you're the 10,000-pound gorilla you don't get instabilized by the small 10 pound zoo animals...
That's not always true for either countries[1] or animals[2].
[1] https://en.wikipedia.org/wiki/Category:Former_British_coloni...
It's not like some small nation came and took Wales from the UK -- which would be actual de-stabilizing.
Megarians doused some pigs with combustible pitch, crude oil or resin, set them alight, and drove them towards the enemy's massed war elephants. The elephants bolted in terror from the flaming, squealing pigs, often killing great numbers of their own soldiers by trampling them to death.
From of foreign policy standpoint it's often less about the entire country vs small groups of well-connected people with foreign interests. In the end most of what the US government does is easier to understand when you reolise and account for just how corrupt it is.
EX: US immigration policy seems vary reasonable when you reolise exploting both legal and illigal immigrants makes some people lot's of money.
That's what "diplomatic stability" means.
Its especially interesting that the mere assumption that the US security companies are covering for the intel agencies is going to make it look more like they are. If Kaspersky is on 90% of the computers targeted by the NSA/CIA, they're going to be much more likely to get the data necessary for this kind of analysis, which reinforces the thought that the US companies might be covering it up.
Government and industry have betrayed the Internet, and us.
By subverting the Internet at every level to make it a vast,
multi-layered and robust surveillance platform, the NSA has
undermined a fundamental social contract. The companies that
build and manage our Internet infrastructure, the companies
that create and sell us our hardware and software, or the
companies that host our data: we can no longer trust them
to be ethical Internet stewards.
This is not the Internet the world needs, or the Internet
its creators envisioned. We need to take it back.
And by we, I mean the engineering community.
https://www.schneier.com/blog/archives/2013/09/take_back_the...That's a fair and likely true statement. However, imho, leaning on appeals to authority for one's moral compass tends to corrupt more reliably than individualism.
Iow, follow the patriotism of your heart, not what others tell you it means.
Maybe you do yourself believe that this type of work is justified. That's a defensible position: I'll disagree with you, but you made your own decision. Just don't do it for external accolades and validation.
When were governments ever trustworthy actors in this respect?
I say we give them their just deserts - hang 'em high and let them be a message to any other collaborators that this sort of shit is not tolerated in a civilized society.
The most brilliant minds are often bored by the fact they can't find anything that challenge their skills. You give any problem to talent, talent won't care about the nature of it. Talent will be put to work.
And to be honest, maybe the work they do can be legitimate or might serve good in the end. It's just that you will never know about it, for the simple fact that it's classified.
For example, catching tax evasion or financial crimes is very hard. If you really want to catch those criminals (who have the worst effect on society), you might want to step up the spying game and scan everybody. Catching or discouraging terrorists is difficult too.
The issue is not that you scan everybody, the issue is that those spying tools can be used against inncocents or for the sake or private interests. So of course people will scream bloody murder, but if the NSA has a very well made policy to avoid misuse, and if you don't hear about any big scandal, maybe there's no big harm done.
All in all, civilization works in a hierarchy, and politics will lead people to do things. Moral standards are guidelines, they're not rules. Civilization works towards its perpetuation. I doubt those spying tools are used for private interests. I know freedom is important, but you can't escape the fact that information technologies can give new powers to criminals.
The question is, do you want civilization to be the norm, or would you prefer to have people taking advantage of civilization with the use of technology ? I know the US has a history of liberty, but when it comes to domestic telecommunications, I doubt any government will let people use gadget because it feels "free". You're not free when you use any device, any of those device requires telecom infrastructures, and thus it requires civilization.
In the light of dirty finance, I think I can be be okay with those spying program, because I really want those bad guys to be caught. On the other hand, citizens are both protected and housed by government, so I don't think kids can really complain about their parents peeking in their room.
Of course my cynicism doesn't excuse my arguments, but I like to understand the real reasons behind those programs, and children rarely realizes the real reasons the behavior of their parents.
Freedom in modern western countries requires a lot of regulation and very hard police work. Freedom has a very high cost.
The people who are meant to be serving our best interest are clearly often serving themselves.
>> I doubt those spying tools are used for private interests
It's proven from the Snowden papers and elsewhere that America uses it's spying power for industrial espionage.
A program with limitless powers such as this will lead to limitless abuses. I'm all for governments being able to individually monitor bad people but it seems to me the old mechanisms are still the most effective and that particularly mass surveillance, but also deep and difficult to detect hacks like this make me think that everything we believe about democracy is probably false and that we actually live in a kleptocracy.
I still think that we know very little about the people using these systems for the wrong reasons. I think government should be reporting them where abuse occurs; it would make me feel a lot safer about their use. If there are never any abuses reported you can be sure that they are many.
I don't have a problem with that. It's totally expected from government to do industrial espionnage. It has nothing to do with privacy and liberties. I think any patriot would be happy to know his country is trying to spy on another country. It's expected, spying is a common denominator. In french I'd say "c'est de bonne guerre".
http://www.aljazeera.com/news/2015/02/spy-cables-world-espio...
And talented people will have to care about politics more and more as time goes on. It's vital that we get better more moral people into politics and everyone has a duty to act in accordance with their own morality. Maybe we can fix some of the problems around the world that cause most of the harm if more people stop being quiet about the bad things that governments are doing in their name.
I'd love to work on problems like this, especially in a team of highly skilled coworkers. It'd be a lot of fun (and a lot of frustration, reverse engineering generally is). The part I wouldn't like is having to keep it secret from family and such.
Maybe talented people have a different perspective than you? Maybe they recoginize the worldwide cyberwar and don't want to have their pants down when Russia and China do whatever they want? Or they realize that good intelligence has value, if not moral value, assuming good intel could stop or minimize future armed conflicts? This is like calling Turing a baby-killer because he worked for the UK intelligence. Turns out good intel is a lifesaver.
But it's not wrong. It's honourable work when done on behalf of one's nation.
They don't want to worry about your "reg cleaner" and ask.com toolbar suddenly taking 100% of the CPU and screwing up the firmware write.
Heck, BIOS updates are done the same way, pretty much. The Windows installer shoves the new firmware binary into a space the BIOS can access, reboots the computer, updates during POST/BIOS, and then only when its successful, reboots again into Windows. Its not run when Windows is running. You'd have to be a little crazy to do that.
http://www.seagate.com/www-content/product-content/savvio-fa...
8.7 AUTHENTICATED FIRMWARE DOWNLOAD In addition to providing a locking mechanism to prevent unwanted firmware download attempts, the drive also only accepts download files which have been cryptographically signed by the appropriate Seagate Design Center. Three conditions must be met before the drive will allow the download operation: 1. The download must be an SED file. A standard (base) drive (non-SED) file will be rejected. 2. The download file must be signed and authenticated. 3. As with a non-SED drive, the download file must pass the acceptance criteria for the drive. For example it must be applicable to the correct drive model, and have compatible revision and customer status.
If said company would change the private key, obviously the same legal framework can be used to get this new key, in turn. So it's fruitless.
Of course, if it's an "inofficial" leak, a revocation and renewal of keys makes sense.
No telling what other exploits those sons-a-bitches have come up with and deployed in the meantime.
They're describing SWAP [0]. Cool they Kasperksy now has binaries to reverse-engineer.
What's impressive is the number of OSes and filesystems that are supported. Keep in mind the documentation publicized is from 2008, so they likely support ZFS, ext4 & btrfs as well now.
[0] https://www.schneier.com/blog/archives/2014/02/swap_nsa_expl...
In particular, I'm wondering whether host machines' HDDs can be flashed from VMs. And further, which hypervisors and emulators are least vulnerable in that way.
If the VM is using an emulated disk based on an image file on the host, probably no chance at all as only "read block" and "write block" types of commands will be interpreted by the virtual disk. Even other mundane commands like "spin down to save power" won't make it to the hardware due to the effect that would have on the host or other VMs on it.
If the VM is configured to passthrough directly to the hardware, then it has full control over the HDD.
Maybe four.
HyperV, KVM, ESX, what you mentioned, etc...
But really, 3 vendors - Oracle, Microsoft, and VMWare covers the majority.
Way fewer virtualization technologies (mainstream) than hard drive firmwares.
"They do this specific thing, or they do that specific thing" -- at the level of implementation / deployment etc.
The "unsettling" thing should be that they spy on citizens, period. Not how they do it, if it's 200,000 or 40.000.000 targets, how long they retain the data, if they're "allowed" to see them, etc...
Modern workstations and servers implicitly trust hard disks
to act as well-behaved block devices. This paper analyzes
the catastrophic loss of security that occurs when hard disks
are not trustworthy. First, we show that it is possible to
compromise the firmware of a commercial off-the-shelf hard
drive, by resorting only to public information and reverse
engineering. Using such a compromised firmware, we present a
stealth rootkit that replaces arbitrary blocks from the disk
while they are written, providing a data replacement backdoor.
Zaddach et al. (2014) Implementation and Implications of a Stealth Hard-Drive BackdoorThey don't need to be the best of the hackers.
The fascist(collusion between private companies and State) laws that were created after 11-9 let them have access to the source code of hardware and software.
With source code, doing this is not that hard. I believe most of them do not need to be stars.
I don't know about the specific NSA, but normally secret agencies have lots of ways of finding who is good at hacking-cracking(the stars). For example who is behind the release of the crack to a software protection.
As simple as "recording the web" for unique documents upload, and analyzing which dark web page was the first to upload the document. Follow all the proxies and who is really behind is not that hard if you have resources.
Once you know who is the target you want to hire you study her with social connections in facebook-twitter-whatsapp- gmail-smartphone, very easy for the NSA.
You study her weaknesses, she probably needs money, you give her(first one's is free, so you give her lots of money for her first easy job so she believes she could be rich easily). She is lonely, you give her a partner. Needs sex? And so on.
The rest is easy, once they take the bait maintaining them hooked requires them much less energy(money, resources or coercion). They can destroy you life with the pinky finger.
Life is good if you do exactly what they ask you. If your vice is thinking for yourself or ethical scruples(and most hackers have those vices) your life could be hell.
If you help them, you are a patriot, if you don't, you are a traitor. You are with me or against me is their favorite motto.
Stars know personally other stars, and they know who is good at it at a glance. So you make one of her jobs to hire other hackers crackers.
That might be the case for a hacked firmware on a ethernet card, but on a hard-drive? How would windows even interpret a outbound request that comes from the hardware in the first place?
The only way I can imagine this works is if when doing a fresh install with a hacked hard-drive, the operating system would request the drivers from the hard-drive itself, which would give it the infected DLL which could obviously do whatever it needed- But it doesn't work that way, drivers are almost always downloaded, no?
If the NSA ( or anyone ) are going to modify the firmware and hide malicious or preparatory exploit code in that area, the end user will have little recourse post-exploit. Though, beforehand, if the HDD vendor published, for example: the md5/sha1 of the firmware the OS vendor could then write a "control panel" or application that the number has been entered/seeded by that vendor. If the hash on boot does not match the hash in storage, alert the user the drive has been hampered with. Alert the vendor, they send you a new drive, and you throw away the old drive.
I'm not entirely sure how to do this if they happen to not modify the firmware but instead just store in the areas wasted space. I can think that you would use sized to make values you could then hash. As long as the vendor knows the values of of what they did, those can always become keys to compare to make sure they have not been modified. ( I hope at the very least. I don't want a stalemate or a loss when it comes to this type of security, it has to be a win for the consumer. )
Is there any reason this approach wouldn't work? What other alternatives are there if they are writing to the firmware area of the HDD?
What if this were the firmware of the hardware itself. There are firmware(s) within your USB bus, wifi chipset, cpu chipset, keyboard chipset, display, power management, some cables, everywhere. Those can be leveraged individually or via a RAID style merging of all these firmware areas to give you, hundreds of MB of super difficult to locate storage space.
If no one is looking, you can get away with anything you want. And in this case, even if someone is looking, it will take a very good set of eyes a few times over, as it seems one voice is never loud enough to get the word out. Be prepared to go to jail for talking about any of their methods, even in a theoretical sense.
Because the only way to actually verify the hash of the firmware is to connect to the drive's controller outside of the firmware's control with something like JTAG or a direct dump of the flash. Otherwise, the PC would send a command to ask the HD firmware what it's own hash is. The compromised HD firmware can then simply respond with a published vendor hash.