6 ms·
To be fair, the microphone _is_ listed on the specsheet of the LicheeRV Nano https://wiki.sipeed.com/hardware/en/lichee/RV_Nano/1_intro.html https://wiki.sipee
by tayiorrobinson 10mo ago
To be fair, the microphone _is_ listed on the specsheet of the LicheeRV Nano
https://wiki.sipeed.com/hardware/en/lichee/RV_Nano/1_intro.html https://wiki.sipeed.com/hardware/en/lichee/RV_Nano/1_intro.h...
I assume they didn't intend to put a mic on the KVM product, but they wanted to make a KVM product, already had this SBC product, which reusing their existing stock of helped keep cost low.
Should they have been more up front about it it? Sure, and it's not great that they had a bunch of security issues in the FW anyway, so not exactly great, but "hidden microphone in a Chinese KVM" lets the mind wander
- ndsipa_pomu 10mo agoIt doesn't strike me as that useful to have a hidden microphone in a KVM product as most of the time, they're going to be stuck in server rooms with just lots of fan noise to record. Far more of an issue would be any kind of keylogger built into the software, which is why it's best to go for devices that support open source software.
- i_am_proteus 10mo agoIt is possible to keylog via audio. https://ieeexplore.ieee.org/abstract/document/10190721 https://ieeexplore.ieee.org/abstract/document/10190721
- BenjiWiebe 10mo agoBut the point of a device like this is that you (and your keyboard) are NOT physically present.
- hinkley 10mo agoThey mean the K in KVM could trivially have a keylogger. For the computers attached to that KVM. Audio is for logging for computers not attached to the device in question. Which could be up to and including a whole server room save a couple machines.
- ndsipa_pomu 10mo agoWhat would you be able to get from the noise of loads of servers in a room where no-one is using a keyboard?
- Featherknight 10mo agoThe conversations of server goblins ofc. Gotten listen in on the little gnomes inside the racks.
- hinkley 10mo agoI think I’m thinking of old school kvms you attach a laptop to instead of VNCing into.
- ErroneousBosh 10mo agoA long time ago (maybe in the mid-90s) I knew an elderly radio amateur who could not just "copy" CW by ear, but also RTTY. He could also pretty much tell what a teleprinter was printing just by listening to the noises it made, like he'd be facing away from it on the other side of the room reading out entire words from what was coming through. Apparently in the 50s when he did his National Service he'd been in the Signals but "not in the regiment that's on his papers", make of that what you will. I have noticed that with PSK modes and particularly PSK31 you can hear "CQ CQ CQ" as a distinctive pattern much in the same way as it is with CW. IBM spent a fortune developing ATM keypads that - when correctly mounted - had keys that made the exact same noise no matter how you pressed them or how worn they were. So I don't doubt that someone suitably clever could extract audio from a room and work out what was being typed.
- f1shy 10mo agoDo you have a pointer to learn more about the ATM keyboards? I would love to learn more about it
- ErroneousBosh 10mo agoMaybe. They were necessarily very cagey about it back then, but I might have some documentation kicking about in storage. I tended to keep copies of every service manual I could get my hands on back then.
- CamperBob2 10mo agoOne really-cool way to solve that problem is to embed a 7-segment LED under each keycap. You walk up to the keypad and the 0-9 digits appear in random order. No one can shoulder-surf, look for wear or IR emission from the buttons, or train on the click sounds. Dell had those on every lab door in the building back in the early 90s. You felt like 007 every time you punched in your access code. I've never seen them anywhere since.
- NoMoreNicksLeft 10mo agoAnd now days I can't put in my card's pin without 10 overhead cameras aimed at the register area. All the cameras of which are network-connected, video stored persistently, and high res/fidelity enough to here the little beeps as I press the keys, and to know that I've hit the enter because the screen indicates it immediately. But then Dell cared about its own security, and the grocery store doesn't give a single shit about whether my life is ruined by identity theft.
- seszett 10mo agoIt would take an especially perverse mind to keylog using audio on a KVM, though. The KVM basically has access to everything, any secondary spying using a microphone or a camera would provide very little added value.
- saltcured 10mo agoMaybe it's for the super secret stuff that the datacenter emergency ops worker knows not to type through the KVM? ;-)
- Y_Y 10mo agojust fan noise? https://arxiv.org/abs/1606.05915 https://arxiv.org/abs/1606.05915 Any signal that you can modulate can be an exfiltration channel, and fan noise is no different.
- ndsipa_pomu 10mo agoI wonder if that's feasible in a room filled with many servers and fans going?
- runjake 10mo agoYes, just modulate the fan noise on the transmitter, and apply a filter on the receiver.
- faidit 10mo agoDoesn't being able to modulate the fan presume you already control the target device?
- alextingle 10mo agoIt's possible to get malware onto even air-gapped machines. This is a way to then communicate across the air-gap.
- overfeed 10mo ago> Any signal that you can modulate can be an exfiltration channel, and fan noise is no different. This KVM has HDMI input and can directly emulate USB mass storage; fan-modulation is the lowest-bandwidth (side-)channel available to the attackers.
- nine_k 10mo agoYou can exfiltrate data from a machine which is not connected to the KVM. A high-security machine may be even air-gapped most of the time, but be physically nearby.
- PunchyHamster 10mo agoThe KVM just uses a devboard that's also sold separately and just happens to have a microphone, given how cheap the mics are having one extra SKU would probably just cost them more than savings. Also I wouldn't really consider it "server room" product. Pretty much any new server has KVM, this is more "a hobbyist needing KVM for their home server"
- deleted 10mo ago[deleted]
- ndsipa_pomu 10mo agoI can't recall seeing any server that includes KVM-over-IP, but instead they have some shitty remote access controller (e.g. Dell iDRAC) that is buggy as hell and requires a subscription to even get working.
- fsmv 10mo agoSupermicro boards have it via the IPMI Ethernet port. Doesn't require any sign up.
- ndsipa_pomu 10mo agoThat sounds good - I thought they required a license key to get working. (However, IMPI is a security nightmare with backdoors, default passwords and weak encryption)
- n5NOJwkc7kRC 10mo agoIntel AMT? Whatever AMD calls theirs?
- hinkley 10mo agoUltrawideband never caught on because it turns out that the speed of light and sound in air is frequency dependent, so you have to know the distance to the target pretty accurately and then skew the signal to send or receive. (Imagine a phased array antenna but also with a frequency domain to work out as well). But that doesn’t mean you can’t make it function in a loud server room. The whole point of it is working in and around noise.
- parineum 10mo agoThe Chinese part makes one think the Chinese could access the microphone. Nevermind that, if they could access the device, they'd also be able to read your kvm i/o.
- motbus3 10mo agoYou might be right but I think we cannot assume malice when it could be laziness. It might be that the exact same board has multiple target audiences and they just rebrand it for different purposes with different pricing. That said, the microphone is so weirdly positioned that it gets suspicious indeed.
- inetknght 10mo ago> I think we cannot assume malice when it could be laziness Why can't it be both?
- calmworm 10mo agoPerception of laziness with an option for later maliciousness and somewhat plausible deniability.
- Ekaros 10mo ago>That said, the microphone is so weirdly positioned that it gets suspicious indeed. How is it weirdly positioned? To me it seems there is rather few options for such small board.
- b00ty4breakfast 10mo ago> I think we cannot assume malice when it could be laziness If you are too lazy to go back and check if you left the gas on, you bear responsibility if the place explodes. At the very least, it's negligent to leave something like that in and not be very upfront about it.
- TheRealPomax 10mo agoAnd rather than "the Chinese", how about "anyone robo-dialling some SSH connections"?
- Rygian 10mo ago"hidden microphone in a Chinese KVM" is the correct way to describe what is going on. "Reusing existing stock" is not a valid excuse. They are currently selling this device without advertising that it contains a working microphone.
- mintplant 10mo agoA working microphone and recording software and hacking tools like aircrack-ng on an otherwise stripped-down OS image...
- heavyset_go 10mo agoVendor BSPs are horrible, it would not surprise me if tools like that were included with it. I used one that included everything in C:\Users\<actual dev's name>\Desktop in it.
- firesteelrain 10mo agoWas it made in China?
- ghostpepper 10mo agoAren't virtually all SBCs made in China?
- firesteelrain 10mo agoI was referring to Board Support Packages
- heavyset_go 10mo agoDepends on what part of the hardware or software stack you're talking about. In general, yes there Chinese software and hardware components. This BSP looks like it was an international effort.
- 10mo ago
- LorenPechtel 10mo agoGiven it's history I suspect there is nothing malicious going on here, just a Chinesium approach to building something. Security isn't documented so it's made of tissue paper.
- deleted 10mo ago[deleted]
- MomsAVoxell 10mo agoI'm completely fine with there being a microphone in the thing. It's literally a remote eyes/hands interface, so it being an eyes/ears/hands interface is perfectly acceptable.