12 ms·
What does GCHQ know about our devices that we don't?
- dclusin 12y agoIt's surprising that they didn't destroy the entire computer to cover up what they were hiding. This seems like a relatively small subset of components to investigate.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- patrickyeon 12y agoThere is a possibility that GCHQ knows these chips are storing data without users knowing it. It's equally possible that GCHQ isn't sure that they aren't storing data (double negative, I know). Or that GCHQ wants to be sure nobody at the Guardian was savvy enough to sneak data on to these chips. I'm not suggesting one or the other is more likely, I really wouldn't know. I find it more interesting that they felt the need to do this, when really the only assurance they have that the documents are destroyed is the word of the Guardian's employees. Other than someone speaking up, there's no way for anybody to actually know if there are other copies floating around.
- icodestuff 12y agoI think the second possibility is much more likely. If it was the first, they wouldn't have tipped their hand, given that the guardian staff would have been among those users.
- Alphasite_ 12y agoObviously, the easy answer is that theres somehow something that lets you record data in those components. On the other hand, you have to consider that perhaps those are components that they've known other groups (them selves included) to use to store data, so they want to ensure that they're destroyed. Perhaps they dont want any inadvertent leaks of the data to a third party?
- revelation 12y agoNo, the easy answer is that the same idiots run GCHQ that are employed in other government branches and they sent the trained equivalent of metalworkers to destroy these things, and they accordingly proceeded to hack into every computery looking piece. I think this part gets lost in the cloak and dagger stories that dominate the media. No, the NSA and GCHQ have not revolutionized computing, they run the same shitty Java enterprise stuff designed by thieving contractors we all do. Just take a look at their hideous powerpoint presentations.
- Phlarp 12y ago>Perhaps they dont want any inadvertent leaks of the data to a third party? Little late for this.
- deleted 12y ago[deleted]
- mutagen 12y agoYes, this really clarifies how this may be misplaced paranoia. While I won't ever completely discount extreme paranoia when it comes to government spy agencies, I think this is a distraction from more relevant issues. "On Saturday 20 July 2013, in the basement of the Guardian's office in Kings Cross, London, watched by two GCHQ technicians, Guardian editors destroyed hard drives and memory cards on which encrypted files leaked by Edward Snowden had been stored." GCHQ was merely observing to see that the Guardian staff were cooperating. Instructing journalists to remove their 'special storage chips' while leaving others intact would be a breach of operational security. This event was more of a PR move because GCHQ, the NSA, and others had no idea what was going on and had to be seen "doing something", even if it was pointless, absurd, and violated the free speech rights of the newspaper and journalists.
- ZenPro 12y agoYou were so close with this line > GCHQ was merely observing to see that the Guardian staff were cooperating. Instructing journalists to remove their 'special storage chips' while leaving others intact would be a breach of operational security There is nothing more to it. It is the law. I cannot stress this point enough. Destroying the electronic devices was not optional. It was not a PR move at all. In testimony the Guardian even admitted it was not a PR move. It was necessary. [Source [Video] http://www.theguardian.com/uk-news/2014/jan/31/footage-released-guardian-editors-snowden-hard-drives-gchq http://www.theguardian.com/uk-news/2014/jan/31/footage-relea...] EDIT TO ADD: I really don't care if you think I am a shill shrug - that says more about you and your tolerance of new facts than it says anything about me. The source I posted is from The Guardian, about the Guardian with video testimony from the Guardian. It couldn't be further from GCHQ to be honest.
- tobiasu 12y agoMy shill alarm is off the scale while reading your posts. Surely you have a link to that law...
- shin_lao 12y agoProbably a procedure against potential bugs placed by a foreign intelligence.
- highlander 12y agoConsidering the circumstances, I wouldn't be surprised if they destroyed those extra chips just to troll the internet...
- jimrandomh 12y agoOne possibility, as mentioned, is that these ICs are not what they're claimed to be. Someone should take them out of equivalent devices, decap them, and publish some photos. Another possibility is that they weren't just looking to destroy data, but also to sneak a peak at the data being destroyed. Scraping off a power IC might let them attach a power source, to turn on parts that were supposed to be off. Scraping off other ICs might get them access to I2C buses.
- leoedin 12y agoThere's a huge leap between having access to pins and actually accessing data. Even talking to unknown i2c devices requires some experimentation. Even if there was a clear channel through which you could access data over i2c (I'm not aware of any consumer bulk storage device which makes data available over i2c), doing that covertly in a short period of time while giving pretences that you're destroying the device would be practically impossible. GCHQ employees aren't magicians. I suppose it's possible that the guardian hid all the secret data in i2c eeprom chips which happened to be on their motherboard. "Possible" in the very remotest sense. You'd need to be pretty knowledgeable in digital electronics to even approach that successfully. I suspect it's more likely that GCHQ have a list of ICs which can store data, and to be safe they are required to destroy them all.
- hendzen 12y agoI doubt the components are backdoored by default in stock hardware. More likely, GHCQ was worried that other nations (China, Russia, etc.) were targeting Guardian journalists in an effort to gain access to the Snowden cache. As such, GHCQ probably was simply taking extra precautions in the event that hostile intelligence agencies had installed implants into the Guardian's hardware. Or perhaps, GHCQ/NSA had installed the implants themselves to monitor the journalists, and then wanted to destroy the evidence. See the leaked ANT catalog for an idea of the types of hardware implants that SIGINT agencies have developed.
- ZenPro 12y agoIt was previously my job (for 3 years) to investigate security breaches and destroy devices. You are almost uncannily correct. >I doubt the components are backdoored by default in stock hardware. More likely, GHCQ was worried that other nations (China, Russia, etc.) were targeting Guardian journalists in an effort to gain access to the Snowden cache. As such, GHCQ probably was simply taking extra precautions in the event that hostile intelligence agencies had installed implants into the Guardian's hardware. This is it in a nutshell, and, legislation states they had to physically destroy the devices. It was not optional. It was the law. There is absolutely nothing more to it. > [Edit to Add] Believe me, I have destroyed the brand new iDevices of senior Government personnel because they plugged it into a classified network to charge it for less than a minute. The law is the law. I actually had a wall of digital devices we had drilled, degaussed etc etc. The Guardian were treated the same way we treated everybody. I had my phone confiscated cause I stupidly did the same thing at the start of my career. shrug There really is no story here which makes the cloak and dagger theories even more funny. It is almost cargo cult-ish. Some guys at Cheltenham will be rolling in the aisles reading these comments. > [Legislation Guidance for those asking] You can Google and read the statutes and policies yourself. >> Once the classified material had been confirmed, security operators were then legislatively bound to destroy or other render unusable the material in question. The legislation which required all reasonable and necessary measures are contained within the Official Secrets Act 1989, the National Security Strategy, the Data Protection Act and the Regulation of Investigatory Powers Act 2000 with detailed policy guidance promulgated to intelligence operators via HMG Information Assurance Notes (1/2 (SPF)) and, more importantly, HMG Information Assurance Note 5 and the Joint Services Publication 440 which governs counter-compromise measures. Ultimate responsibility for HMG security policy lies with the Prime Minister and the Cabinet Office. Departments and Agencies, via their Permanent Secretaries and Chief Executives, must manage their security risks within the parameters set out in the framework, as endorsed by the Official Committee on Security (SO). All HMG employees (including contractors) have a collective responsibility to ensure that government assets (information, personnel and physical) are protected in a proportionate manner from terrorist attack, and other illegal or malicious activity. The loss or compromise of such Critically Important Assets would have a severe, widespread impact on a national scale and Departments must work with the National Technical Authorities and the Cabinet Office to ensure they are afforded appropriate levels of protection. [EDIT TO FURTHER ADD] I have posted the links to 7 policy and legal frameworks. If you cannot find these documents or you are still asking then frankly, you are too fucking stupid to trying to analyse the law or most other things. People on HN are not your legal secretary. You not being able to find something is not proof of it's absence.
- GigabyteCoin 12y agoPerhaps they were looking for common attack vectors/device modification surfaces, rather than looking for specific information there. For example, perhaps the GCHQ have reason to believe that Chinese spys were bugging keyboards and mice sent to journalists and their companies. So they removed the chips that they knew could possibly be bugged and took them home for further inspection? If they could prove that the Guardians computers were already compromised by Chinese spys, and that the guardian was holding top secret sensitive information on them... GCHQ could skewer the Guardian publicly for releasing state secrets to China. /speculation
- fidotron 12y agoThe purpose of the exercise was only partly to destroy any potential storage, but also to intimidate the Guardian. Having an air of fake mystery to irrational actions just adds to the effect. If the whole thing was too easy the capacity for that intimidation would have been greatly reduced, and leaving it hanging allows paranoid people to latch on to stuff while giving GCHQ the air of having preserved some secrets, when their instructions were probably get rid of certain components, for sure, but randomly do some other stuff for confusion to cover exactly what it was we did have to get rid of.
- ZenPro 12y agoNope. There is absolutely no intimidation whatsoever and reports by the Guardian journalists confirm that the GCHQ engineers were simply resigned to an extremely common and boring task. They joked about the futility of it as I understand. There was no intimidation.
- mnordhoff 12y agoThat doesn't follow. You don't have to use jackbooted thugs to intimidate someone. Ordering government agents to be sent to a newspaper to destroy information sounds pretty intimidating to me, even if the agents in question are friendly and doing something routine to them. Is it not intimidation if a gang sends a couple scrawny members to your restaurant to enjoy a pleasant meal the day before your protection payment is due?
- mikeash 12y agoAre you serious? From a link that you yourself provided in another comment (http://www.theguardian.com/uk-news/2014/jan/31/footage-released-guardian-editors-snowden-hard-drives-gchq http://www.theguardian.com/uk-news/2014/jan/31/footage-relea...): > Days later Oliver Robbins, the prime minister's deputy national security adviser, renewed the threat of legal action. "If you won't return it [the Snowden material] we will have to talk to 'other people' this evening." Asked if Downing Street really intended to close down the Guardian if it did not comply, Robbins confirmed: "I'm saying this." In what universe does "we will shut down your company if you don't obey" not qualify as intimidation?
- vajorie 12y agoWho was that guy with that bigass beard was? You know, the one everyone in tech takes lightly and treats as the butt of the joke? He keeps owning your asses as you keep ignoring him. The one who advocates open hardware. You know.
- pyre 12y agoIt's all a matter of trust in the end. Even with Open Hardware, the production line, or the transport of the hardware to your doorstep could be compromised. The same way that even Open Source software can be compromised if no one is paying attention or you are being specifically targeted.
- femto 12y agoHow much trust is required also depends on how far one takes "Open". The homecmos project [1] is taking it down to the level of atoms. https://code.google.com/p/homecmos/ https://code.google.com/p/homecmos/
- Zigurd 12y agoThat's all true. But if intelligence agencies are constrained to physically breaking in to your premises to bug you, that gets hard to scale up to pervasive mass surveillance.
- chroem 12y agoRichard Stallman? https://en.wikipedia.org/wiki/Richard_Stallman https://en.wikipedia.org/wiki/Richard_Stallman He's about free software as well. People that haven't started subscribing to his ideas post-leaks are part of the problem.
- krapp 12y agoAnother part of the problem is the assumption that using free software necessarily protects you from government intrusion. I think at this point you pretty much have to live out in the woods with nothing more complicated than a gun in your possession to avoid that.
- jradd 12y agoMy theory is that they were not destroying any kind of persistent data on these components like IC's; rather, destroying what/where/whom they might be able to identify or correspond with via serial numbers, dates, manufacturer, locations of where that component came from, etc. At least for the components of which have no memory, volatile or not.
- dfox 12y agoBoth keyboard and trackpad controllers are microcontrollers with embedded flash, third chip (LT3957) says it is "programmable" in it's datasheet (although in this case it means that it's characteristics can be changed by values of external components, not that it contains any kind of non volatile memory).
- josephcooney 12y agoGCHQ are probably pretty far ahead of the game as far as disinformation goes. Consider what the UK government did to cover up operation overlord. http://en.wikipedia.org/wiki/Operation_Bodyguard http://en.wikipedia.org/wiki/Operation_Bodyguard I seem to recall a story where they put fake plans in the pocket of an army coat, which they put on a recently deceased person dressed in full military uniform (of military service age), and then strategically dumped it where they knew the germans would find it. Or maybe that was just a spy movie I watched.
- anveo 12y agoI believe the story you recall was from Neal Stephenson's Cryptonomicon novel.
- iamthebest 12y agoDid that also happen in Cryptonomicon? I believe the parent was thinking of Operation Mincemeat: http://history.writingwithtony.com/2008/05/27/tries-spies-and-lies-washed-up-into-operation-mincemeat/ http://history.writingwithtony.com/2008/05/27/tries-spies-an... https://en.wikipedia.org/wiki/Operation_Mincemeat https://en.wikipedia.org/wiki/Operation_Mincemeat
- CocaKoala 12y agoSomething similar happened in Cryptonomicon, certainly; in the section of the story where Detachment 2702 is 'widening the bell curve', there's the segment where they take the cook who died of a heart attack in the cold freezer (blond hair, mushroom, tattoo on his arm with a heart and the name "Griselda"), put him in the wet suit with the watch, and dump him in the ocean; they also pack a coffin full of meat from same freezer, nail it shut, and plaster it with biohazard stickers to ensure that it won't be opened. I've read the book a few times.
- adamfeldman 12y agoI believe you're thinking of https://en.wikipedia.org/wiki/Operation_Mincemeat https://en.wikipedia.org/wiki/Operation_Mincemeat
- ZenPro 12y agoJust to be clear on this matter. The Guardian were given every option to return the classified material.[1] In two tense meetings last June and July the cabinet secretary, Jeremy Heywood, explicitly warned the Guardian's editor, Alan Rusbridger, to return the Snowden documents. >> At one point Heywood said: "We can do this nicely or we can go to law" That is not intimidatory. It is exactly how I would expect a democratic institution to act. They didn't send in jackbooted armed personnel to shut down the editorial department. Two computer engineers arrived and oversaw classified material being destroyed. That's it. It's about as intimidating as a police officer telling a suspect he can get in the car nicely or he can be handcuffed. The Guardian were asked point blank in a Parliamentary Hearing - "Do you think the entire episode was a PR stunt?" and they said "No." EDIT TO ADD: I love it :-) Voted down for publishing the story written by the Guardian about the entire incident. [1]http://www.theguardian.com/uk-news/2014/jan/31/footage-released-guardian-editors-snowden-hard-drives-gchq http://www.theguardian.com/uk-news/2014/jan/31/footage-relea...
- declan 12y agoZenPro's comment is a very British way to look at government power, untethered to the limits that the U.S. Bill of Rights still imposes even in its weakened state. > Two computer engineers arrived and oversaw classified material being destroyed. That's it. Yes, but what if the Guardian had said: "Sorry, mates, we're we're not giving it to you. Cheers!" That's when the few dozen agents waiting in the vans outside armed with semiautomatic rifles come in and seize the hardware with a slightly less polite approach. Put another way, everyone who has read NSA/Snowden stories over the last 12 months -- at least the ones with leaked docs embedded -- possessed classified material. That's perhaps 10 million people in the UK alone. Should all of their hard drives be "destroyed" -- "that's it?" Just because it happens to be law doesn't mean it's right, or just, or defensible.
- ZenPro 12y ago[1] I never stipulated the law was defensible. Laws are weird like that though, we don't get to pick and choose which ones we feel like following that day because of how defensible we think they are. [2]You have a very US way to look at Government. UK intelligence services have no powers of arrest and carry no weapons. We certainly would not send military forces into a civilian news office so we would, in line with UK and EU legislation, ask the police to intervene once a legal mandate had been proven. The Guardian knew GCHQ had an airtight case, it is why they complied. No men in black with assault rifles were forthcoming. What would have happened is, the place would have been closed, a thorough audit of IT and Magnetic Media would have been conducted. Everything with anything classified on it would have been destroyed. The building reopened. The Government was doing the the Guardian a favour by saying "Look, we only want these specific info dumps. Carry on business as normal, just give us these or we go to the law and take everything." Exactly the same way a policemen might let you off with a caution if you are caught speeding and apologise. If you fight him, he impounds the car on the spot and uses the full extent of his legally provided powers. Do you honestly think two guys from GCHQ wanted to be standing in the Guardian on camera watching HDD's being grinded for hours?? The issue with cloud computing is separate and distinct from recovering a known quantity of classified information. I really am struggling to comprehend why people are failing to grasp this point. Just because X quantity of classified material exists does not mean you can ignore N quantity that can be removed from circulation. Also, you have no evidence to support that the material destroyed at the Guardian HQ had been already released in full, had been copied or transmitted to another location. You have to take each incident on it's own merits. It is what you know to be the facts at the time, not what you hope to be the facts so you can avoid being diligent.
- reggplant 12y agoDestroying those components would render the machine useless without external inputs and outputs, maybe their intention was simply just to disable the machine, executed in a rather odd manner.
- deleted 12y ago[deleted]
- joshfraser 12y agoIt sounds like there are 3 plausible reasons. (1) they had compromised those components and were trying to clean up after themselves (2) they were afraid someone else had compromised them (3) intentional misdirection. If the GHCQ knew that these components were easily compromised, they would have bugged them themselves given their interest in the material on those machines.
- vasquez 12y ago4) They were on a power trip and looking to destroy things for the sake of it, just to make some point. 5) Extending their "field time" for personal reasons, e.g. because it pays really well. 6) The people in question were just completely clueless about hardware.
- dfox 12y agoIt seems to me that they simply destroyed everything that contains the word "programmable" in it's description, including switching regulator that is "programmed" by choice of external resistor.
- sheldor2398 12y agoWell it could be misdirection but id argue that they have better ways to spread misinformation than doing it on exactly this OP. Also they most certainly dont want people to speculate if they use such methods or not, especially on possible stock hardware on a large scale, therefore I dont see much logic in that scenario. What we do know thanks to the Snowden files is, that they indeed install stealthy espionage equipment in seemingly uninteresting components (by intercepting mail orders for example). Not just to monitor keystrokes, etc but also to manipulate the PRNG (looking at you power converter). The fact that some of those destroyed components are actually related to espionage relevant parts (such as keyboard, touchscreen, etc), rings some alarm bells at least. Maybe they were indeed afraid that the systems were compromised but if so, why only destroy specific components and not just the whole thing? Its top secret material after all and the protocols for safely destroying it are ridiculously strict. How could they be sure that there are no further compromised components which might survive? The way I see it, I would tend to your first scenario.
- mbell 12y ago> We have reached out to Apple to understand the storage characteristics of this component and the role it plays in overall device operation. I spit out my beverage when I read that. They reached out to Apple to understand the 'storage characteristics' and 'role' of a DC regulator...
- Elrac 12y agoThat was my reaction too. Unlike other chips which at least sit on some data buses and theoretically have electrical access to the information being processed by the PC, _this_ device is attached to little other than a DC power lead. To target this particular device as a data tap borders on science fiction. It's theoretically possible to glean bits of data from surges in power consumption, but not very practical.
- motters 12y agoThe most likely explanation I think is that these extra chips are targeted for implantation as part of Tailored Access Operations, or the GCHQ equivalent. https://en.wikipedia.org/wiki/Tailored_Access_Operations https://en.wikipedia.org/wiki/Tailored_Access_Operations
- pjc50 12y agoWe've been here before, 20 years ago, in the "Spycatcher" trial. The UK sued to suppress information from the book which had been printed in Australia from making it into the UK newspapers. http://news.bbc.co.uk/onthisday/hi/dates/stories/october/13/newsid_2532000/2532583.stm http://news.bbc.co.uk/onthisday/hi/dates/stories/october/13/... United Kingdom vs. Observer (sister paper to the Guardian) is worth reading at this point: http://hudoc.echr.coe.int/sites/eng/pages/search.aspx?i=001-57705 http://hudoc.echr.coe.int/sites/eng/pages/search.aspx?i=001-... " These two newspapers had for some time been conducting a campaign for an independent investigation into the workings of the Security Service. The details given included the following allegations of improper, criminal and unconstitutional conduct on the part of MI5 officers: (a) MI5 "bugged" all diplomatic conferences at Lancaster House in London throughout the 1950’s and 1960’s, as well as the Zimbabwe independence negotiations in 1979; (b) MI5 "bugged" diplomats from France, Germany, Greece and Indonesia, as well as Mr Kruschev’s hotel suite during his visit to Britain in the 1950’s, and was guilty of routine burglary and "bugging" (including the entering of Soviet consulates abroad); (c) MI5 plotted unsuccessfully to assassinate President Nasser of Egypt at the time of the Suez crisis; (d) MI5 plotted against Harold Wilson during his premiership from 1974 to 1976; (e) MI5 (contrary to its guidelines) diverted its resources to investigate left-wing political groups in Britain." (a) and (b) are basically the same as some of Snowden's allegations: diplomatic meetings are bugged. (c) is a routine violation of international law, although to be fair we were trying to invade Suez at the time; (d) is MI5 trying to overthrow our democratic government, straightforward totalitarianism; (e) is still going on, and Scotland Yard are involved as well (e.g. the deeply embedded undercover officers in the Green movement). The judgement eventually held that MI5 attempting to block the publication of Spycatcher was a human rights violation. I would expect a similar result in an ECHR trial about attempts to block Snowden's leaks, if such a trial happened.
- arethuza 12y agoNitpick - it was MI6 (AKA The Secret Intelligence Service) that plotted to kill Nasser - MI5 is the Security Service. http://en.wikipedia.org/wiki/Spycatcher http://en.wikipedia.org/wiki/Spycatcher Poor Harold Wilson - he really was a case of 'Just because you're paranoid doesn't mean they aren't after you' NB Given the famously poor relationship between MI5 and MI6 I did wonder if the former had decided to take up "spying" by itself... :-)
- datenwolf 12y agoIf I may speculate about why those ICs were destroyed, then I'd wager on, that the decision about which ICs to destroy was not made by an engineer, but by some overseeing manager who went through a number of PowerPoint slides (like they were leaked over the past year) and identified those as a threat, because those ICs have been mentioned for being an active part in data exfiltration. Let me explain: What those ICs have in common is, that each of them bases their function on fast switching of voltages: The keyboard controller IC rapidly (at several hundred kHz) switches voltage through the key matrix row-lines (addressing the row) so that on the column lines the voltage is read out and thereby telling if a key is pressed, hence making the connection. The touchpad controller IC does the same, but not for reading out electrical connection made by keys, but the change of capacitance caused by a dielectric (=finger). The voltage inverter IC is switching a voltage to drive an induction coil for a voltage converter. Now the (often unwanted) side effect of switching voltages is, that they create electromagnetic waves, that radiate away. Unless you're building a radio transmitter you don't want that, as this is then EMI (electromagnetic interference). EMI is a big concern in the design of keyboard, touchpad and voltage conversion controller. But for spooks the EMI caused by regular device operation can be a great covert channel to exfiltrate information. To the unwary it just looks like the regular, random EMI but a spy agency may know how to cleverly use it. Now making use of keyboard row-column switching caused EMI to eavesdrop on user input is by no way something new. This kind of tempest attack is as old as it gets. You can nicely see on an oscilloscope when the controller begins reading out the keypad (there's some pause before) and every row switching produces a pulse; if there's a key pressed the pulse looks different; also the shape of the pulse depends on the amount of wire closing the circuit, so this gives you the key position on the row and column, thereby telling you which key is pressed. When voting computers were about to introduced in the Netherlands European hackers demonstrated, that the entry system of the machines used could be eavesdropped on by their EMI. Unless you got yourself a super EMI optimized keyboard on your computer, you're likely giving away your inputs by EMI. The touchpanel controller is similar. Now the inverter controller is interesting, because those normally drive a display's backlight, which is more or less independent from the data displayed on the display. But then the display brightness can be controlled by software! So by having a spy program run on the computer that modulates the display brightness with some data you want to exfiltrate you can make use of that channel. However the bitrate will not be very high; if I had to make an educated guess, I'd say about 100 Baud to 1 kBaud. Anyway I think those techniques may have been presented or documented somewhere and a person without the technical understanding at GCHQ command thought those particular controllers would maybe hold some secrets or are something special, while in fact the really interesting stuff happened somewhere else. It's not even clear that the laptop computer had display modulating spyware installed. But that's what I was looking for on suspect computers first, because the keyboard and touch controllers are boring and their principal vulnerability to eavesdropping by EMI emission is well known.
- ZenPro 12y agoWhen I was serving I always used to wonder why the Ministry of Defence never used to defend itself with a public spokesman about public allegations. Now I know why - people are morons and no explanation will suffice. It is really not worth the time or resources to argue with people who have no primary experience of the subject they think they are qualified to argue about. Carry on HNers; you are doing a fine job.