So @bunniestudios & Limor @adafruit, is this bullshit?https://twitter.com/dragosr/status/1001114342958317568 …
If it ain't broke, I'll fix it!
I'm porting Linux to Apple Silicon Macs at @AsahiLinux.
http://patreon.com/marcan | http://github.com/sponsors/marcan
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
Add this Tweet to your website by copying the code below. Learn more
Add this video to your website by copying the code below. Learn more
By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.
| Country | Code | For customers of |
|---|---|---|
| United States | 40404 | (any) |
| Canada | 21212 | (any) |
| United Kingdom | 86444 | Vodafone, Orange, 3, O2 |
| Brazil | 40404 | Nextel, TIM |
| Haiti | 40404 | Digicel, Voila |
| Ireland | 51210 | Vodafone, O2 |
| India | 53000 | Bharti Airtel, Videocon, Reliance |
| Indonesia | 89887 | AXIS, 3, Telkomsel, Indosat, XL Axiata |
| Italy | 4880804 | Wind |
| 3424486444 | Vodafone | |
| » See SMS short codes for other countries | ||
This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.
Hover over the profile pic and click the Following button to unfollow any account.
When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.
The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.
Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.
Get instant insight into what people are talking about now.
Follow more accounts to get instant updates about topics you care about.
See the latest conversations about any topic instantly.
Catch up instantly on the best stories happening as they unfold.
Naomi Wu 机械妖姬 Retweeted dragosr
So @bunniestudios & Limor @adafruit, is this bullshit?https://twitter.com/dragosr/status/1001114342958317568 …
Naomi Wu 机械妖姬 added,
Given where his parents are coming from, @dragosr's concerns are legitimate:
https://en.wikipedia.org/wiki/The_Thing_(listening_device) …
but can be disproven.
Again, compromise is certain (extra consoles on ttyAMA0, new systemd slices that sandbox users and leave some system components unconfigurable, nfs mounts on machines with no net hardware, funny kernel modules you can’t touch, and oh so much more fun), just need to explain how.
“Trivial” heh. See earlier posts about flash controllers. This is how advanced malware spreads. IT guy takes his favourite memory stick with his OS install and puts it a compromised machine to reinstall. Instead now it becomes the way every new computer in the company gets owned.
So... use something else? Dump the filesystem over the network? XMODEM it out the serial port? There are endless ways to gather evidence safely; it's nigh impossible to "cover everything" for the malware. No implant, no matter how sophisticated, magically counters everything.
If there are as many indicators of compromise as you claim (and it's not just you misinterpreting totally normal stuff), then the malware is shoddy and clearly not designed for stealth. So show us some of them.
FWIW: if I were a three-letter agency designing a Raspberry Pi implant, it would live in the VideoCore firmware blob that rules the system from the shadows and be completely invisible to Linux. And I wouldn't be leaving behind "systemd slices that sandbox users".
and yet paradoxically, this attacker seems to have dispensed with stealth altogether here. I have so many IOCs it’s not funny, so I get the impression this is more about stopping extraction of the samples I do have.
If you have so many IOCs, why not show them to us? You might get some people excited and less likely to call BS on you. Take a video of what you see that isn't normal. Even the most advanced NSA implant can't plug the analog hole.
What analog hole? Are you suggesting I get out my film camera?
Are you suggesting your digital camera is compromised too? It's analog until it hits the sensor.
No but what do you use to post? Or communicate? All the fun data I get, always encounters issues. So I’m just going to talk through my analysis with folks... feel free not to listen if you think I’m deranged.
Use the same device you're using to tweet text. Just take a photo and post it.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.