626 karma · joined July 13, 2010
If the NSA ( or anyone ) are going to modify the firmware and hide malicious or preparatory exploit code in that area, the end user will have little recourse post-exploit. Though, beforehand, if the HDD vendor published, for example: the md5/sha1 of the firmware the OS vendor could then write a "control panel" or application that the number has been entered/seeded by that vendor. If the hash on boot does not match the hash in storage, alert the user the drive has been hampered with. Alert the vendor, they send you a new drive, and you throw away the old drive.
I'm not entirely sure how to do this if they happen to not modify the firmware but instead just store in the areas wasted space. I can think that you would use sized to make values you could then hash. As long as the vendor knows the values of of what they did, those can always become keys to compare to make sure they have not been modified. ( I hope at the very least. I don't want a stalemate or a loss when it comes to this type of security, it has to be a win for the consumer. )
Is there any reason this approach wouldn't work? What other alternatives are there if they are writing to the firmware area of the HDD?
What if this were the firmware of the hardware itself. There are firmware(s) within your USB bus, wifi chipset, cpu chipset, keyboard chipset, display, power management, some cables, everywhere. Those can be leveraged individually or via a RAID style merging of all these firmware areas to give you, hundreds of MB of super difficult to locate storage space.
If no one is looking, you can get away with anything you want. And in this case, even if someone is looking, it will take a very good set of eyes a few times over, as it seems one voice is never loud enough to get the word out. Be prepared to go to jail for talking about any of their methods, even in a theoretical sense.
If you know this well, and it is working for you, and you used it to dev clients, then that says a lot, as if you are dev'ing a client, you need a defined corpus and easy way to roll in and out of certain things you have done.
I wish I had this when I was trying to make a webmail based IMAP reader in php.
They are in ~ in a dir that is a .dir so hidden from 90% ( guessing ) of most casual DB users. If someone were to delete their home files, by putting them in the trash, they may think they deleted their DropBox data too, but they would be wrong.
It was that scenario I was concerted about, or at least, wanted to know more about so I could be sure to delete those files and know it is safe to do so, and won't harm the files stored in my DropBox on other machines, or in a recovery procedure.
I see the "problem" as a simple one. If there is chance that a systems DRM can be broken by merely one person, all efforts by that provider, and now most other providers, at least those that share methodologies, is pointless.
If a song, book, or movie are locked down, only legitimate subscribers can use that media under the terms the owner or distributor of that media define. But if only one person of the potentially millions is able to break that encryption, one person has now made all the work and man hours of into said encryption completely worthless.
If it takes a few weeks to break encryption that took months of multiple man hours to create, was that time wisely spent? Once it's broken, the data is now open to everyone. That being the case, I feel were in a "why bother" scenario.
The main reason I see illegally pirated material not proliferating even more is the technical barrier to acquiring the files. And often times, applications and protocols like bit-torrent, tor, VPN's, SSL links, etc. have too high a technical barrier for the common user to start pirating their media.
Once that burden is removed, it's game over and everything will be free at a click of the mouse, until something new comes along or a better business model that works with the fast changing technology world we are in.
When you are waging a war of one against millions and the one can actually win without putting themselves in harms way, you have a war that many will think is a sure fire win for the millions. A million against one is a pretty good ratio. But in this case, the one has a very good chance of annihilating the millions.
Eventually we will learn there is no point. In the meantime, people do this type of reverse engineering for a number of reasons I imagine. Curiosity, the challenge, making a political statement, and most importantly, to learn.
From this, perhaps something new is learned. And from that a new library is made which then gets adapted to detect intrusions on our personal computers and embedded devices. Who knows what may come of this research.
In the end, my position on piracy doesn't matter. What I do know is it will happen, encryption will be reverse engineered or broken, and those who can't learn the technology to use the new research will continue to find the barrier to piracy too high. Others won't, and will get their media freely, sans any lockdown from what you want to do with what you purchased.
Cars can go well over the speed limit. Some to speeds that make no sense to even exist. But they are legal, and most people follow the speed limit laws. The cost and barriers of breaking those laws are too high so people follow the rules. With DRM, the cost is negligible, so the rules will be broken.
But mainly, I think the answer to your question is that curiosity drives a lot of this. Aside from curiosity it could be a lack of trust. Researchers want to know what is going on with their media and hardware.
How do you know an encrypted file is not up to nefarious deeds? The common user never will. But a researcher like this would discover that the file was up to more than just DRM, and that could potentially help those millions of people become more aware of security, and learn to be more skeptical of what they buy.
'Regenerated 2 years ago', does that mean they in fact did not revoke, regenerate, and re-issue?
You are right, at the core, it is simple, but it is time consuming to me. And it falls over under load unless you have a bit of time or money to throw at it, or both.
I like the idea or working in a text editor of my liking, knowing that quote marked in code aren't auto converted to smart quotes, knowing that the raw markdown is raw, and I can move it anywhere.
I am sure you can do all this in Wordpress, I am just looking to remove all that overheard, as starting a blog again is feeling more daunting than ever given my current medical issues. If I can just get it off the ground I will be happy.
But I feel I have to do something, so I want to do something that gets me to my end goal as quick as possible, but allows things to possibly grow without me thinking about what a Varnish, CDN, Cloudfront, etc all are.
But then, when you click "post" it rips through the database using a library of markdown -> HTML or whatever the case may be. Thhere can't be must overheard to a single include to pull in the html, but you could render the enter page. I just can't see php falling down too much with a few includes and functions being called to generate a header, the included rendered HTML, and a footer with some design elements.
It's not much fun building your own database out of flat files. I cut my teeth on a Mac only system that more or less only talked to Filemaker, which was only as fast as the actual screen could redraw and search out the data. It could be painfully slow.
In a way I am glad, as I learned how to do things and think differently when most were just running a "select * from foo where bar = 'x'" which was a 15 minute luxury I didn't have. There were no joins, no tables, you actually ran applescripts on the database and it returned the data somehow back to a web server on the Mac.
So we used the database on the backend, where admins could be more patient, or do more intricate things, but almost always generated out some HTML, so in the end, the site was semi-dynamic. I think I was doing "caching" of data as a result almost 15 years ago.
The rule was, no more than 2 database calls per page, ever. And you couldn't do things like update foo set name = 'me' where id = 1, because there was no exposed notion of a record id, it was internal, so you had to select name from foo where name = 'whatever' which would return the name, but also a RedID value, which you then got to run another query to update foo set name = 'me' where if = <special RecID token>
Made me think a bit different.
I use a clipboard manager which is nice, and past copies are saved for a defined few hours or additional entries.
The screenshot is only moved, not deleted. It's in the DropBox preferences — and along with this feature you enable photo syncing and all your phone taken pics get put in your DropBox folder in "Camera Uploads", or the "Screen Shots" directory. You also get a good deal of bonus space for enabling these features.
You won't have time to grab the screenshot and edit it or draw on it. It happens fast. I use Skitch, which is a screen shot collaboration and editing tool. Once done, you can drag and drop the image to DropBox and get a share URL. Or drag and drop out of any app onto "Droppings", a small "app" I wrote.
I wrote a small script that fishes out your DropBox ID, which is used as your ID in a URL ( this is done once on install ). On receipt of a resource, the script creates a directory and time stamps it. This script is wrapped up in an app that accepts drag and drop. Drop a batch of jpg and gif etc., images, and it will copy them to the DropBox public folder, and put unique URL's to imgur on your clipboard. Full support for maintaining Mac Resource forks and all that as long as you compress on the Mac.
Drag and drop a zipped or compressed set of files, and it will do it's best to look and see if they are all web displayable, extract them, and give you a set of public links. If it contains other zips, binaries, etc, the original format is maintained.
All these actions are logged. I engage with Skitch, a screenshot type app, which I've also integrated logging for and created "cron" ( Launch Items in my case ) actions to clean up the mess Skitch leaves behind. I don't use Skitch as an image storage app, so it keeping multiple copies of everything only ads confusion.
It's pretty handy. If I want to send anything to anyone, I just find it, drop it on an app in my dock, it's 99% bash, the rest is an app that is made to take a shell script and give you same basic UI controls to make a pseudo app.
I started to have tons of link rot on DropBox. Screenshots to CSS questions that I would see posted by others but the screenshots were long since deleted.
My ~/DropBox/Public/drops/date-stamp/the-files.{html, htm, CSS, jpg, gif, png, tif, eps…etc. } directory has been filling up from this droplet for two years now. I think I have about 500MB of stuff that will forever resolve.
I do remove huge files via a "find" command that looks for specific things that I would not want in DropBox beyond a certain date or that I know were meant for specific people and the file will never be needed again. Sort of how I do IMAP image attachment maintenance in gmail but have to use a desktop app to remove attachments.
At any rate, I have had to do a lot with zip codes in the past, long before anything like an API was a common term let alone something every company was happy to let you hook into and use their services. Heck, this was back when it costs a few grand to take CC's on a website and had to deal with that awful Authorienet API. That used to be thought of as crazy talk. Now we have amazing stuff like this: http://www.geonames.org
I found a town called Bakersfield that has more than one zip fro the town, it does JSON back with more data than I thought would be part of free plan.
For some reason I could not get "san_francisco","san-francisco", "sanfrancisco", or "sf" to work.
One of the API's relates to zip codes.
I have had to do zip code to location lookups to find ( I think it's called the Great Circle Calculation ) "within x miles of $zip_code".
I found plenty of companies wiling to sell me the data, sell me updated data quarterly, or API that after testing did not have data change in over a month, though from what I know about zip codes, and for our application, missing a zip code was not the end of the world, I just picked another close one. When drawing a radius around a point, if the point is missing but with so many zip codes, there was aways one close by.
1) How can they sell this? They don't apparently own it. 2) Why not use ones of the many zip, lat, long, databases that I seem to remember being pretty easy to find?
There's some logic behind the zip codes and how they are dished out. Unlike IP that has BGP to find the best route from IP to IP, USPS has none of this, so i imagine this was like trying to solve that "Traveling salesman" quandary with constantly changing and unknown locations. They had to make a sort of zip code prefix that at least gets them to the county level.
Lot's of good data here http://en.wikipedia.org/wiki/ZIP_code
This is like how telco's issues numbers, it was all well thought out ahead of time. You could get kinda dirty and run a loop from zip_code_1 to zip_code_1+1 with each one polling the USPS for a zip code lookup. You would have a pretty accurate database. At one "scrape" of data taking 5 seconds, in a month you would have your data. After that you would only have to test the gaps between numbers to see if new ones were added or just follow some usps page to keep up on new and deprecated zip codes.
There are too many sites that use geolocation with zip to not have this be a solved problem on the very cheap. Probably just another API, where in the future apps will just be lego like API's you copy and paste JS snippets to and from. :)
As long as the warrant requests the same data or less than all the data, then performing those actions trigger an email to the user stating "A third party has requested access to your account.".
I would guess it would be best for these companies to add a few buttons to their internal tools to export user data. Then it's a part of their business process.
Many "third parties" can ask for and get your data legally. And letting them know is also legal. So there is a user value to this user feature.
Now, the next request goes from legal to top guy to tech guy to some guy who clicks a button in a browser.
You can still get the entire page, it comes in over the wire. If they do this, I would assume we can just capture the raw data, and new apps that decode that raw data and give the same tools as the browser developer tools offer.
If not, hopefully there are browsers who refuse to implement, and hopefully it takes less time than it took Adobe to learn their lesson.
A 10 IP round robin setup, if I'm correct, could show stats for 10 different locations. Or does it work differently?