Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?)

Mark Knecht <[email protected]>
Newsgroups gmane.linux.gentoo.amd64
Message-ID <CAK2H+edh1c4EhN8XNAT65P-3bwyibozKoVETRK7a0B9xWh6mWw@mail.gmail.com>
On Thu, Aug 7, 2014 at 9:06 AM, Lie Ryan <[email protected]> wrote:
<SNIP>
>
> Also, did you apply the same level of scrutiny to your hardware?
>

That's the basis of the now well known NSA hack on Cisco routers.
Intercept the box, modify the hardware, send the box onto some foreign
land and the router lets them in. No hacking required.

> For the truly paranoid, I recommend unplugging.
>

 In the aforementioned book that's pretty much exactly what Snowden
required of the reporter & documentary film maker he started out
disclosing the info to. They had to buy new laptops and never attach
them to the net. He apparently used PGP encryption to chat & transfer
files over normal nets but (as I understand it) the encrypted files
are never opened on anything other than your off-the-net machine.

Of course, according to Snowden the NSA can enable the microphone on
my cell phone and listen to me talking in the house. He required
batteries be removed or cell phones be placed in a freezer.

I recently saw a similar story about new TVs having built in cameras
(for game interfaces I suppose) which could be enabled over the net to
watch what's going on in my living room. If the TV has power applied,
even if I'm not using it, what do I know really about what it's doing?

All of that argues for Max's suggestion about sniffing the network
full time, assuming I can relay on the sniffer not being hacked... ;-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.