7 ms·
Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes thr
by btashton 7y ago
Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card.
This is from the same group that tries to explain how they don't use proprietary firmware blogs by using the Redpine chips just because the blog is already flashed on it rather than loaded into RAM on boot.
I wish they would just say it how it is rather than overselling.
- Dunedan 7y ago> Why do I trust my WiFi cards disable pin, but not the "soft button" on my laptop that triggers it via the OS? I get that there is more software when it goes through the OS, but I trust that a whole lot more than the firmware on the WiFi card. When using a physical kill switch you have to trust the hardware. You don't have to trust the firmware or operating system, as a physical kill switch usually disables the power lines to the device. That's something a remote attacker can't circumvent.
- btashton 7y agoThey are just controlling the W_DISABLE signal which the firmware uses to control the actual radio hardware. It is _not_ a hardware switch in the since that the power is shut-off.
- cmrx64 7y agoAt least in the case of Purism’s Librem 5 (unreleased), it’s not a disable pin, it’s removing power entirely from the wifi peripheral. Which is a step up for sure.
- btashton 7y agoIf it is the same as the laptop they are using the W_DISABLE pin not power.
- cmrx64 7y agoYeah, according to the devkit schematics the switch controls W_DISABLE- their blog post talks about the virtues of "removing power"...
- Scoundreller 7y agoThat may not work for low power electronics: they can gather enough power to operate from I/O lines that have pull-up resistors on them. When this goes really wrong, the chip can burn out. Some satellite provider in the past tried to exploit differences between genuine cards and fake cards based on Atmel 8515 simulator boards. The fix was to lift the VCC pin of the 8515.
- everdrive 7y agoIn Android, you actually can't trust when the OS says the WiFi is "off." Yes, the network is not connected, but google is still tracking SSIDs.
- lucb1e 7y agoYou can turn that off, though. Not that I trust it to work, but at least legally you can deny that. Do you happen to know about GPS? Because my phone sometimes picks up GPS faster than should be physically possible (knowing a thing or two about how GPS works), and sometimes it takes a normal amount of time. I have GPS turned off almost all the time, don't have a Google account logged in, everything I can deny to Google apps I have denied, nothing weird seems to be running in process lists... any idea where to even start looking?
- kiallmacinnes 7y agoMost phones use Assisted GPS. It's a combination of cell tower triangulation and GPS. You'll get a potentially inaccurate "GPS" location based on the cell towers and signals you can see, and this will eventually turn into a real GPS lock. As I understand it, this cell tower location actually helps achieve a real GPS location faster that would be normal - but I'm unsure how that would work .. I'd be guessing at best ;)
- int_19h 7y agoAs I understand it, roughly knowing your position lets it get a lock on enough satellites faster, because, given position and time, it knows where they're supposed to be. http://gpsinformation.net/main/gpslock.htm http://gpsinformation.net/main/gpslock.htm Also, I believe that part of the reason why Google wants that SSID info is because they can later use it for location purposes as well, making that initial position determination more accurate than with just the cell towers alone. In general, the more environmental data they can correlate with accurate GPS coordinates, the better they can predict location when GPS is unavailable.
- drivebycomment 7y ago
- nixpulvis 7y agoIt's about "who" you distrust. If you distrust the hardware vendor, hope is lost. If you distrust someone with physical access to the device it's about how hard it is, and firmware/hardware is harder to hack (generally) than software. The likelihood of finding a remote exploit into the firmware is a lot lower than finding a remote exploit into a software disable.