4 ms·
Since the monitor is external, I wonder if they've considered monitors as attack surface: https://github.com/RedBalloonShenanigans/MonitorDarkly https://github.
by startling 10y ago
Since the monitor is external, I wonder if they've considered monitors as attack surface: https://github.com/RedBalloonShenanigans/MonitorDarkly https://github.com/RedBalloonShenanigans/MonitorDarkly
- talltower 10y agoCorrection. The temperature monitor is INSIDE the secure shell.
- dogma1138 10y agoHe's talking about display monitors AKA the screens which can be exploited via the i2c bus over the graphical interface (e.g. HDMI). The GP is 100% correct, if you can't trust your keyboard, mouse, and the monitor the "secure computer" concept in this case is problematic, while it does reduce the attack surface somewhat it just focuses the attention of the adversary onto a different vector. If we take their "cleaning man/evil maid" scenario then while implanting the computer might not be possible, implanting the keyboard, mouse or screen would be very possible, and in fact somewhat easier than implanting a regular computer with decent security measures such as an encrypted drive. Add a USB storage device with a micro-controller to the keyboard and you own the computer once it's connected, a monitor today comes with a CPU powerful enough to run custom code which can be used to exfiltrate data as well. Additionally both the keyboard and the monitor could potentially be used to exploit software flaws on the software running on the ORWL unit also. The concept is interesting however this is mostly "security theater" any adversary which would be sophisticated enough to require taking these measures would likely be able to circumvent them, and for the rest these measures don't really do anything; if you use this for day to day operations or on-net activity you'll get pwned via the network; if you keep secrets on this thing worthy of sending some one into your home to implant your PC then they'll implant something else which is connected to it. Oddly enough the only "high tier" adversary that this might thwart would be law enforcement since their computer forensic SOP would pretty much melt down when encountering something which is tamper resistant. But hey, you gotta start somewhere.
- thisrod 10y agoI'm a bit surprised that, in 2016, there is no standard way for a computer to authenticate its keyboard and monitor. Has anyone even thought about how that could be done?
- munin 10y agoyes but since an application is DRM the hacker groupthink decided that this was a double unplus good thought and so no one should think it lest evil happen.
- wtallis 10y agoHDCP is arguably the standard for authenticating the monitor, but it's not quite intended for this purpose. I'm not aware of a standard for authenticating input devices, but disabling USB HID and relying solely on tamper-evident PS/2 input devices goes a long way.
- dogma1138 10y agoEven if you can, yous implant a keylogger onto the keyboard, and some malware/implant into the screen you get a full readout of every keystroke and every pixel displayed. If you are going to prevent physical attacks from adversaries that can circumvent basic protection (e.g. FDE) you have to make sure that every device is as secure because the system is as secure as its weakest link. If your adversaries are just the random person that might steal your PC then any full disk encryption even a cryptographically insecure one would be sufficient because the people who end up dealing with these devices won't have the knowhow or the resources to attack even bad encryption.
- jacquesm 10y agoGP probably means display monitor, not temperature monitor.
- startling 10y agoI do mean display monitor, not temperature monitor.
- talltower 10y agoThanks for the correction. I was not sure at the time.
- AgentME 10y agoThis is an example of someone reprogramming the monitor, not using a monitor to attack the computer that it's connected to the video-out of. I'm not clear if there's an attack against the ORWL itself you have in mind here.
- startling 10y agoOnce you reprogram the monitor, you can store or exfiltrate all of the data the user sees, and do clever things like erase and redraw the mouse pointer, or draw new prompts, to induce the user to click on the things they wouldn't have otherwise.
- AgentME 10y agoAn attacker swapping the monitor with one that records or displays other content isn't very different from the possibility that an attacker replaces your keyboard with one that keylogs or inserts crafted sequences of keypresses. I don't think ORWL tries to do anything about these possibilities, and it's difficult to imagine good fixes that don't massively change the scope of the project. And even if you do make the keyboard and monitor tamper-proofed and securely paired with the ORWL, it can't prevent an attacker from hiding a video camera in the room or using skimmer-like devices between the user and the devices.
- nickpsecurity 10y agoOr the one I coinvented and described before the leaks: https://www.schneier.com/blog/archives/2014/03/ragemaster_nsa.html https://www.schneier.com/blog/archives/2014/03/ragemaster_ns... There's no direct solution to the subverted monitor problem that I'm aware of. You basically get them from random places under different names or from people unlikely to be spies then use I/O protection both ways. Same with most hardware you can't produce yourself. There's potential to market something here where the monitor is immune to code injection, does I/O filtering, can't store anything, and does these with visually-inspectable chips & board. Add TEMPEST shielding while you're at it since that's an existing market that will drop lots of cash on improving security. See EMCON's products for examples. EDIT: Forgot to mention that spectrum analysis is often used to try to catch radio emissions. There's techniques to tell if monitor sends out stranger than usual signals. That's just kind of limited and doesn't help if it's black bag job where person can show up twice (eg maintenance person).