4 ms·
Instead of assuming you could lock down your internet pipe. Use a RPi as a security appliance with strong whitelisted firewall policy. At least have some insigh
by hackerrenews 7y ago
Instead of assuming you could lock down your internet pipe. Use a RPi as a security appliance with strong whitelisted firewall policy. At least have some insight into what traffic is going to and from your LAN.
Could also put in an entirely passive NIDS on a physical layer in-line with your network’s service entrance. Very difficult for anyone to defeat, when done right.
Apologies for term misuse.
- balt_s 7y agoOr perhaps "the only winning move is not to play". I hear it is difficult to surveil through books.
- monksy 7y agoNot unless they require your id to buy the book or check it out. The book store El Ateneo Grand Splendid requested my passport to buy the book "Argentinian Cooking". WTF
- diego 7y agoWere you paying with a credit card? In Argentina the norm is to ask for id when paying with credit card, and if you're a foreigner the default would be to ask for your passport.
- pmoriarty 7y agoNot only that, but some years back there was an expose about some government profiling software marking people as more likely to be terrorists if they didn't have a social media profile.
- A4ET8a8uTh0 7y agoEven if you don't enough people do. My wife still uses FB. Amazon just came up with echo in frames. The privacy quickly becomes a luxury available only to select few.
- jecke8888888 7y agoyou still have to buy those books, presumably using a cc or at least by showing your face
- gscott 7y ago> I hear it is difficult to surveil through books. Unless if you swipe your library card.
- oil25 7y ago> Instead of assuming you could lock down your internet pipe. Use a RPi as a security appliance with strong whitelisted firewall policy. At least have some insight into what traffic is going to and from your LAN. Not only would a Raspberry Pi be severely under-powered for routing even a small home network, in no way does monitoring that "goes to and from your LAN" defend against an adversary Snowden warns about. > Could also put in an entirely passive NIDS on a physical layer in-line with your network’s service entrance. Very difficult for anyone to defeat, when done right. Again, I'm not sure what threat model you think this defends against, but certainly not a three letter agency intent on either tailored exploitation nor passive monitoring of your inbound and outbound network traffic by the same actor.
- hackerrenews 7y agoYou used “either”, then “nor”, sorry I lost the point you were making. Wasn’t sure on your point about the adversary already owning the pipe. Tailored exploitation is a good point though. Admittedly RPi isn’t any current advice except for outdated hobbyist advice. If I cared to defend against nation state I’d avoid gen purpose CPU’s altogether and focus on in house manufactured minimal circuits, possibly fpga’s and printers or some other trusted peripherals. I’d build my own keyboards too. The poster was concerned about video being hacked. This would be hard to hide, at least for being owned in real-time, if one were keeping track of the packets coming and going. If you’re whitelisting all your outbound and disallowing inbound, and if your decoupled passive nids is set up right you at least have the physical network layer covered. If you’re targeted for tailored exploitation then you’d be considering a scif anyway if you really have something that important to hide. In a pinch, a faraday cage would probably be a good idea if you can set it up right. Don’t trust any devices that come in or out.
- oil25 7y ago> The poster was concerned about video being hacked. This would be hard to hide, at least for being owned in real-time, if one were keeping track of the packets coming and going. How would keeping track of packets detect a compromised web cam absolutely? An SSL-encrypted connection to Amazon servers, for example, could easily be used to exfiltrate pictures, audio and even low-bandwidth recordings while still blending in with typical, expected Web traffic.