Hacker News new | ask | show | jobs
by 127361 897 days ago
Yes, I assume the hardware is not compromised, which is much easier to detect.
1 comments

Is it though? How would you personally detect compromised hardware?
Minimizing all software phoning home as much as possible, and then watching for suspicious network activity.

Also dumping the flash* contents out with JTAG. And even better than that, physically disabling the network interfaces completely and not ever connecting the device to the Internet at all.

* = also the eMMC controller internal firmware, this is where a sophisticated implant will likely reside

It's also very unlikely that the hardware would be compromised, the government doesn't want to waste a potentially high value exploit on ordinary people. If they do, they risk having their exploit captured and exposed, and thus wasting it.

heck, how would you detect compromised models?