Post by JasonI have to wonder, what happens if all trust in the integrity of our
computing platforms is suspect?
Um, we lost that a long time ago.
Have you read the case of the security researcher, who
keeps getting infected over and over again ? He can't
figure out how it is getting in, but there are some
pretty wild theories as to how machines are communicating
with one another. When you read that thread,
you'll lose all hope.
They can mess these machines up bad enough, that they
can't be disinfected. Computers have lots of firmware
devices (NAND flash), so there are plenty of places for
stuff to get in. That security researcher could add
a new computer to his network, and it would be
infected in minutes. And he's not even sure if
someone did this on purpose (targeted attack),
or he is just collateral damage.
And that's really the only protection we have,
is the actors doing these things, don't want
to "waste their ammunition" on everybody. The
serious attacks are more targeted. Script kiddies
don't usually have the "good stuff" that
governments have. The government malware
likely calls home, so the control server
can tell it to politely exit, or tell
it to take over.
I'm not particularly surprised by the "NSA and
hard drive story". It could just as easily
be done with motherboard BIOS, without too much
trouble. And the Computrace product (whitehat)
doesn't really seem that much different than
a blackhat effort. It's pretty hard to tell the
good guys from the bad guys, when the all use
the same techniques. For example, that AV software
you use, is in many ways a "root kit". But it's
a root kit invented by a White Hat.
Oh. I see that I'm being port scanned, so I have to go...
Paul