7 ms·
I’m a bit disappointed the mechanism to exfiltrate data is based on sharing the USB between an internet-connected and air gapped devices. It would have been coo
by binary_slinger 2y ago
I’m a bit disappointed the mechanism to exfiltrate data is based on sharing the USB between an internet-connected and air gapped devices. It would have been cool if it used some other side channel like acoustic signals.
- ChocolateGod 2y agoJust wait till neuralink gets hacked and people themselves become the side channel.
- A4ET8a8uTh0 2y agoI am not sure why you are being downvoted. Just like fridges, cars, ovens gained internet access, enhanced humans will be extremely likely to be, eventually -- and possibly with interesting consequences -- hacked.
- dingnuts 2y agoif Neuralink became pervasive like smartphones I'd join the Amish
- MOARDONGZPLZ 2y agoLike the January 6 question, I’m assuming that anyone who had a neuralink would likely be ineligible for any sort of clearance to access information like this.
- A4ET8a8uTh0 2y agoI am not as certain. Sure, Musk and his product are no longer 'cool' given his move to US political right faction, but tech is tech. Some tried banning cell phones and whatnot and the old guard there had to adjust their expectations. In short, I am not sure you are right about it. If anything, and I personally see it as a worst case scenario, use of that contraption will be effectively mandatory the way having cell phone is now ( edit: if you work for any bigger corp that and and want to log from your home ).
- MOARDONGZPLZ 2y agoAs far as I am aware, no electronic devices from outside, and no devices that transmit anything, are allowed in these high security areas. That’s inclusive of cell phones, for example. That is: the point I am making is more nuanced than whether something is popular (like cell phones or other tech).
- A4ET8a8uTh0 2y agoOh, I am sure there are restrictions for the rank and file, but the higher ups with such access can ( and apparently do ) get exceptions[1] and while this is one of the more visible examples, I sincerely doubt he is the only one. [1]https://www.wired.com/2017/01/trump-android-phone-security-threat/ https://www.wired.com/2017/01/trump-android-phone-security-t...
- renewiltord 2y agoYou can already hack people by just telling them things. Many of them will do dumb shit if you just use the right words.
- A4ET8a8uTh0 2y agoI like the analogy. Lets explore it a little. << You can already hack people by just telling them things. True, but language fluctuates, zeitgeist changes and while underlying techniques remain largely the same, what nationstate would not dream of being able to simply have people obey when it tells them to do behave in a particular way. Yes, you can regimen people through propaganda, but what if it you could do it more easily this way?
- renewiltord 2y agoCertainly people would like an API for others without needing to reverse engineer them. Agreed that there is a threshold of simplicity past which it becomes easier to organize than having to give speeches and run propaganda.
- willy_k 2y ago> True, but language fluctuates, zeitgeist changes and while underlying techniques remain largely the same This applies to software as well > Yes, you can regimen people through propaganda, but what if it you could do it more easily this way? Widespread use of BCIs would help with this for sure, but don’t be under the impression that individual and population level manipulation techniques haven’t progressed well past simple propaganda.
- A4ET8a8uTh0 2y ago<< don’t be under the impression that individual and population level manipulation techniques haven’t progressed well past simple propaganda. I absolutely buy it based merely on the glimpse of the document from various whistleblowers over the years. At this point, I can only imagine how well oiled a machine it must be.
- 2y ago
- rad_gruchalski 2y ago> I am not sure why you are being downvoted. Trigger-happy emotional non-intelligence.
- ruthmarx 2y agoThat's not really true, in that context security will largely be a solved problem. Using chips with a secure architecture, safe languages and safe protocols is going to result in secure implants. Not to say there might not be some new vulnerability, but I disagree with this idea people love to repeat that security is impossible.
- bigiain 2y agoSecurity will never be a "largely solved problem", when there are humans involved (and probably even when humans are not involved). There is no technical solution to people uploading high res photos with location metadata to social network de jour. Or the CEO who wants access to all his email on his shiny new gadget. Or the three letter agency who think ubiquitous surveillance is a great way to do their job. Or the politician who can be easily convinced the backdoors that can only be used by "the good guys" exist. Or the team who does all their internal chat including production secrets in a 3rd party chat app, only to have them popped and their prod credentials leaked on some TOR site. Or the sweatshop IT outsourcing firm that browbeats underpaid devs into meeting pointless Jira ticket closure targets. Or the "move fast and break things" startup culture that's desperately cutting corners to be first-to-market. None of the people involved in bringing "enhanced human" tech to market will be immune to any of those pressures. (I mean, FFS, in the short term we're really talking about a product that _Elon_ is applying his massive billionaire brain to, right? I wonder what the media friendly equivalent term to "Rapid Unscheduled Disassembly" for when Nerualink starts blowing up people's brains is going to be?)
- ruthmarx 2y ago> Security will never be a "largely solved problem", when there are humans involved (and probably even when humans are not involved). It absolutely will. I didn't say completely solved, I said largely solved. > There is no technical solution to people uploading high res photos with location metadata to social network de jour. Bad example honestly, since most social media sites strip out exif data by default these days. Not sure there are any that don't. > Or the CEO who wants access to all his email on his shiny new gadget. Or the three letter agency who think ubiquitous surveillance is a great way to do their job. Or the politician who can be easily convinced the backdoors that can only be used by "the good guys" exist. Or the team who does all their internal chat including production secrets in a 3rd party chat app, only to have them popped and their prod credentials leaked on some TOR site. Or the sweatshop IT outsourcing firm that browbeats underpaid devs into meeting pointless Jira ticket closure targets. Or the "move fast and break things" startup culture that's desperately cutting corners to be first-to-market. Yes yes, humans can be selfish and take risks and be bribed and negligent and blah blah blah. The context of the comment was in neuralink implants getting hacked the way an out of date smart tv might. As when it comes to the actual tech, security will be a solved problem, because most of the problems we see today are due to everything being built on top of insecure foundations on top of insecure foundations.
- m463 2y agothe-computer-wears-sneakers-net
- dexwiz 2y agoThis is the plot of most of Ghost in the Shell. That series looks more and more prescient as time goes on. Another big plot point is that most of the internet is just AIs talking to each other. 10 years ago that sounded ridiculous, now not so much.
- Terr_ 2y agoAlso how super-sensitive may be kept on physical books and papers, albeit in a form scannable by optic implants.
- bigiain 2y ago"Ralfi was sitting at his usual table. Owing me a lot of money. I had hundreds of megabytes stashed in my head on an idiot savant basis, information I had no conscious access to. Ralfi had left it there. He hadn't, however, came back for it." -- Johnny Mnemonic, William Gibson, 1981
- 4ggr0 2y agoIf you're a gamer, you should try Cyberpunk2077 :D Currently playing it, at over 200 hours, and it really feels like a scarily accurate, techno-dystopian version of our world.
- getwiththeprog 2y agoIt is my view that television and other propaganda can hack persons.
- olalonde 2y agoYou might like the movie Videodrome[0]. [0] https://en.wikipedia.org/wiki/Videodrome https://en.wikipedia.org/wiki/Videodrome
- LargoLasskhyfv 2y agohttps://en.wikipedia.org/wiki/Snow_Crash https://en.wikipedia.org/wiki/Snow_Crash , or much of https://en.wikipedia.org/wiki/Philip_K._Dick https://en.wikipedia.org/wiki/Philip_K._Dick , especially https://en.wikipedia.org/wiki/The_Man_in_the_High_Castle https://en.wikipedia.org/wiki/The_Man_in_the_High_Castle or https://en.wikipedia.org/wiki/The_Man_in_the_High_Castle_(TV_series) https://en.wikipedia.org/wiki/The_Man_in_the_High_Castle_(TV... Or https://en.wikipedia.org/wiki/The_Giver https://en.wikipedia.org/wiki/The_Giver / https://en.wikipedia.org/wiki/The_Giver_(film) https://en.wikipedia.org/wiki/The_Giver_(film) Or https://en.wikipedia.org/wiki/The_Congress_(2013_film) https://en.wikipedia.org/wiki/The_Congress_(2013_film) Or Nineteeneightyfour and so much more...(yawn)... Or
- nullc 2y agoyou don't need that, just make the airgapped system give odd error messages that people will google across the gap.
- zahlman 2y agoI felt like the article spent way too many words to explain the idea of "the agency shared data across the air gap using USB drives, and a vulnerability was used to surreptitiously copy the malware onto the USB and then onto the target machine", and AFAICT none on explaining what that vulnerability is or why it exists (or existed). Then the rest is standard malware-reversing stuff that doesn't say anything interesting except to other malware reverse engineers. The inner workings of the tools aren't interesting from a security perspective; the compromise of the air gap is. (As for acoustic etc. side-channel attacks: these would require a level of physical access at which point the air gap is moot. E.g. if you can get a physical listening device into the room to listen to fan noise etc. and deduce something about the computation currently being performed, and then eventually turn that into espionage... you could far more easily just directly use the listening device for espionage in the form of listening to the humans operating the computers.)
- ghostly_s 2y agoThere was no novel vulnerability. The pwned machine just replaced a recently-accessed folder on the stick with an exe to trick the user into executing it on the target machine.
- authorfly 2y agoYeah it is very bloated. I am suspicious that the article was bloated with AI rather than a human, though. I wonder if they either made the first section as a summary or extended sections necessarily. For example, early on it says: " collect interesting information, process the information, exfiltrate files, and distribute files, configurations and commands to other systems." and later on: " they were used, among other things, to collect and process interesting information, to distribute files, configurations, and commands to other systems, and to exfiltrate files." It also mentions several times that the attack on a South Asian countries embassy was the first time this software was seen. Repeating info like this was kind of a sign of part-applied AI edits with RAG a while ago, might still be true today.
- aenis 2y agoYup, no respect for the people who published the article. It was one paragraph of content impossibly diluted. TLDR: some idiots allowed USB sicks to be plugged into the supposedly air-gapped system. Hilarity ensued.
- RicoElectrico 2y agoSuch side channel attacks are academic. In fact someone on HN pointed out there's a researcher that invents new ones by the dozen and media run with it whenever he presents another one.
- bawolff 2y agoI mean, someone who researches security of airgap computers continually coming up with new ways to break them, seems like the expected outcome. Its their job after all.
- 6510 2y agoI would start by asking what they need computers for. You don't really need one to read text from a screen. Of that most would be old documents that for the most part should be public. What remains besides reading is most likely 95% stuff they shouldn't be doing. The most secure part is the stuff we wish they were doing.
- baseballdork 2y agoI’m having a real hard time understanding what this comment is saying. Are you asking what high side computers are used for besides reading classified information?
- 6510 2y agoMaybe, I could also be asking why you would use a computer if all you want is to read documents. If you have an operator send a telegram for you that person is capable of doing a lot more with your text than you want. On the other end is another telegram operator to further increase the risk. You might want to send a letter in stead. It's slower but more secure. If you want to read text from a monitor a computer is super convenient but like the operator it can do other things you don't want. You don't need a computer to put text on a screen. Alternatives might be slow and expensive but in this case you don't have to send things to the other side of the world. That would be the thing you specifically don't want.
- whartung 2y agoOne of my favorite hacks of yore was somehow some folks managed to compromise the iPod to that point that they could run some of their code, and make a beep. They compressed the ROM, and "beeped" it out, wrapping the iPod in an acoustic box, recording it, and then decoding it to decode the ROM.
- Scoundreller 2y agoI think it was more of a “click” Back in the ?ps/2? days, I had a joke equalizer plugin for Winamp that used the 3 LEDs on your keyboard. Another output device!