So @bunniestudios & Limor @adafruit, is this bullshit?https://twitter.com/dragosr/status/1001114342958317568 …
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
...or compromise something like AMD Secure Processor, Intel SGX and ARM TrustZone.
I'm pretty sure the VideoCore stuff is higher privileged than TrustZone. Though TrustZone would be more portable to other chips.
and yet paradoxically, this attacker seems to have dispensed with stealth altogether here. I have so many IOCs it’s not funny, so I get the impression this is more about stopping extraction of the samples I do have.
If you have so many IOCs, why not show them to us? You might get some people excited and less likely to call BS on you. Take a video of what you see that isn't normal. Even the most advanced NSA implant can't plug the analog hole.
Heh, creating malicious VideoCore firmware would be a fun project xDhttps://github.com/christinaa/rpi-open-firmware …
But the fun thing about the Raspi is that videocore blob isn’t invisible. It lives on the SD card and must be readable for the device to boot.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.