Hacker News new | ask | show | jobs
by the_ancient 3700 days ago
On most (if not all) Laptop Webcams the Light is not controlled by hardware, but by the Operating System

it is Trivial to create software to no turn on the light.

The Light is not considered by manufacturers to be a Security feature, or something to warn a user of someone other than the user is using the webcam, it is simply there to inform the user when their cam is active using normal "friendly" software, it is a convenience feature, not a security feature

Many commercial management and security software packages sold to schools, corporations, and individuals have the ability to turn on the webcam with out illuminating the light, this often billed as a "theft prevention" feature.

Several schools have gotten in trouble for using this feature to spy on students using school owned laptops

In short, they do not have to "defeat all of the laptops" they just have to right a program for windows, and get 99% of them, the capability is already in the OS, the harder part is installing it with out the user knowing, and hiding the process from the user... Disabling the LED is trivial

1 comments

This statement isn't even really true of the old iSight cameras; they were attackable, but only by overwriting the firmware on the camera itself.

Is disabling the LED on a modern Macbook trivial? I'm genuinely asking. If so, can you provide a link demonstrating how? The ability to override the LED on the old iSight cameras was interesting enough that the paper demonstrating it got published at USENIX.

I was not aware that apple was the only manufactures of computers.... or Webcams.

I personally have never and will never own a Apple product, so I can not say what is true or not True in the Apple Space, I speak to the 90% of other computers running Windows Operating Systems

Do we perhaps have different definitions of "most if not all"?
By Laptops I mean PC not MAC...

MAC's are better left to the history books

Ok, can you point me to a paper describing an LED bypass attack on a Dell produced within the last 2 years?