https://github.com/nivekuil/rip This is what you’re looking for
https://github.com/nivekuil/rip This is what you’re looking for
The lower layers all already at least moderately well encrypted, what they’re doing here is trying to pull the unencrypted device ID necessary to establish a connection. It’s not really what you’re sending (though traffic frequency analysis may be included) and more about just figuring out where a particular phone is so they can physically track the user.
I hate that it needs to be said but love that they said it so plainly
There might be a few layers to this one. Drones are becoming a central part of strategic production and the US doesn’t really have many competitive companies manufacturing small ones at volume.
They need to force the domestic market to build up local expertise and manufacturing capacity in the event that small drones are the direction warfare ends up going more broadly.
The us defense apparatus is still on the fence about this given that their volume of use in Ukraine could be more of an aberration due to the respective industrial bases and static nature of the war. That said the numbers are insane enough that they warrant some action just in case.
Yeah, I’d agree with that.
The point I was making was for people who thought this was cellphone cameras and that it would somehow work even if the camera wasn’t actively running.
As far as war driving with an sdr you’d probably occasionally find something interesting, but the vast majority would be cameras just pointed back out at the street. I think you’d mostly see stuff where if you wanted to spy it would make more sense to hide your own camera because it’s already public.
All that said, I would lose my shit if Hollywood did something believable for once and used this for a heist movie.
$250 per camera that you have to be within meters of best case. That doesn’t include the packaging cost to make this look innocuous so probably significantly more money if you wanted this to be stealthy and reliable. Add in the money for the distribution and “installation” of such devices.
This doesn’t scale at all.
It’s just a tempest attack. Firmware won’t fix anything but the attack is an extremely expensive nation state level operation that doesn’t scale.
I work on this stuff, short answer, no, it’s not possible. This is just yet another overly complicated tempest attack. Especially with phones the camera link is so short it’s just not radiating enough. They claim 30cm so you basically need the receiver in the same backpack as the phones. As phones get higher resolution and faster cameras this will become even less of an issue. Also, most importantly the camera has to be powered and running for this to work so just don’t take pictures of classified stuff while carrying around a weirdly warm battery bank an unusually attractive eastern European girl gave you as an engagement gift and you’re good.
The actual target here is some sort of The Thing https://en.m.wikipedia.org/wiki/The_Thing_(listening_device) style attack where someone with a huge budget can get a wildly expensive device really close to a system through a significant human intelligence effort.
The line of reasoning is valid though. These satellites will have some ability to track and intercept low power intentional emissions like WiFi and cellular packets. While these are encrypted there are still things you can do with the metadata.
The unspoken part is that unless Gabe has a very strong plan involving some sort of employee co-op, when he retires or dies the company will likely get sold by the estate to private capital which is 100x worse than being a public company.
Part of the issue is the whole thing smells weird.
Like they won’t talk about their monetization strategy at all but they acknowledge that there will be one. They’re trying to randomly apply crypto to something that’s literally already the one proven blockchain tech, and they started at the height of the crypto token scam industry and it looks a lot like they’re trying to suck up the last dregs of that cycle.
If you are hammering crypto into things that don’t obviously need crypto you really need to justify it thoroughly. A relatively old company just hand waving all of it should raise all of the red flags.
They were shilling on HN too. People were getting frustrated because they were being incredibly evasive about their monetization strategy but, being HN, business model critiques were not well received…
Why the popularity in Yemen? Weird laws or something?
Yeah the security angle gets parroted a lot, I’d call it more of a bad practice thing than a “omg you’ll definitely get haxxord”.
Otoh USB C as a spec is sort of necessarily a nightmare. It’s not hard to end up with shitty devices that’ll gleefully provide 20V when the system expects 5V and even if it’s just USB A, it’s not that hard to end up with 120/240v going straight into your phone.
At least with devices you own and control you know if they’re melting things and haven’t spent their lives being kicked/spilled on/cleaned with corrosive solvents or just generally old as hell and unmaintained.
Personally I bring my own because it’s faster and more reliable, and I have trust issues.
Just my opinion but I don’t really like the common belief of separating nation and non nation state actors. We’re getting to the point where nation states are making up a large portion of the really damaging attacks, and it’s frequently ones own government or a government they’re in conflict with which means there are very kinetic consequences for failure even if you’re a nobody. It’s not just someone stealing some money anymore.
… Why does the sunflower oil factory have a plasma cutter?
Installed it in k3s and then pulled up the Android app but all it does is say every single file is a duplicate and overload my notifications tray while not uploading anything
Judging from how many voters are in the US, it’s basically a totalitarian dictatorship or die.
That like of reasoning is kinda broken. We need people to take responsibility before things go too far. Google engineers can get jobs anywhere, they don’t need to be doing this shit if they don’t want to.
As a SWE you have responsibility for what you do. “Golden handcuffs” isn’t a cover to help wage wars against users. If it becomes an undesirable posting, they’ll either have to pay more or worse engineers will end up working on it.
Recommendation: report the pop-up as a bug with the provided link. Just act confused and claim to not be using an ad blocker. Muddy the waters and make life hell for their devs.
Fuck HDMI. The committee makes doing custom hardware near impossible unless you’re a mega corp