If you open your computer's case, it is already vulnerable to hacking, because no consumer x86 computer is secure under that threat model. Yes, this is another bullshit hyped attack with minimal practical consequence because under their threat model you are already pwned.https://twitter.com/WIRED/status/1259669698494509056 …
-
Show this thread
-
This Tweet is unavailable.
-
Replying to @deanpierce @marcan42
No, it's not even a little bit like that. If "knows my phone number" == "can physically isolate my device in a way that allows hardware tampering" in your threat model, you've got a really screwed up model.
0 replies 0 retweets 6 likes -
This Tweet is unavailable.
-
There are plenty of x86 class devices that you'd probably want to avoid being affected by such attacks. Of course they're not the devices in your home but that doesn't remove them from the equation entirely. You'd hope that physical controls protect them but...
1 reply 0 retweets 1 like -
Oh, there are many x86 class devices that you'd *want* to avoid being affected by such attacks. But none of them *are*, except maybe the Xbox One. That one gets pretty close.
1 reply 1 retweet 5 likes -
Replying to @marcan42 @timb_machine and
By the way, the Chromebook spec, the original one, explicitly *excluded* physical attacks from their threat model. Which is why those chromebooks shipped with a "bypass all firmware security" jumper under a screw/sticker.
2 replies 1 retweet 7 likes
Current Chromebooks with the new security chip still have a physical access backdoor (remove the battery), because Google knows it doesn't matter how many security chips you throw at x86, case open == pwnable, and recovery / owner control is important. https://chromium.googlesource.com/chromiumos/platform/ec/+/master/docs/case_closed_debugging_cr50.md#can-remove-the-battery …
-
-
This Tweet is unavailable.
-
No, this isn't about the dev mode. You don't need to take the case off for that. This is about complete firmware takeover. So you can e.g. remove that big warning sign.
1 reply 0 retweets 3 likes - Show replies
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.