Hacker News new | ask | show | jobs
by alexeichemenda 2175 days ago
You’re focused on the wrong part of the chain here. As the camera system is only as weak as it’s weakest link, if Apple indeed made a circuit connected to the LED (and I fully trust you on that), then the weakest link is elsewhere: company provided laptops are often altered prior to be given to an employee. I know of colonies who install software to track messages etc. What’s to say the same companies don’t alter the circuit board to modify the LED behavior?

There is a risk/reward/effort to look at, putting a small piece of tape is low risk / low effort / high reward (if your company actually angers laptops).

2 comments

If they take the efford to alter the circuit they might as well place a camera somewhere else, listen to all your network traffic, install a (hardware) keylogger and what not.

I think you are taking this too far.

People who fear to be tracked buy a laptop in a random store and don't use a provided one.

What about company laptops,where you're much more likely to be targeted based on your job, not your personality.

Snowden already showed us the depths that governments will go to, to compromise their victims with hardware swaps and worse. And it's already been 7 years. They're even better at it now.

> What’s to say the same companies don’t alter the circuit board

The realities of modifying hardware. Is it possible? Sure. Is a company going to do it routinely at scale? Highly unlikely, because unlike software modifications, this would be pretty expensive. Are you aware of any companies that routinely do _hardware_ modifications on employee Macbooks?

Not aware of any that do that for laptops but I know 2 personally that do that for phones. They have a collection of devices (phones) trash to go, so it’s not as unscalable as I initially thought because they re-use the devices.

So I’m assuming if some do it for phones, must be some doing it in laptops.

Again. It’s all about probabilities. 1/ What’s the likelihood of the company doing that? Close to none. 2/ what would be the severity of the issue if they were doing that for me? Very high. 3/ what’s the effort level to prevent that? Very little.

This ratio ultimately tells us what to do.