Re: "For What It's Worth" (or How do I know my Gentoo source code hasn't been messed with?)
Mark Knecht <[email protected]>
| Newsgroups | gmane.linux.gentoo.amd64 |
|---|---|
| Message-ID | <CAK2H+edh1c4EhN8XNAT65P-3bwyibozKoVETRK7a0B9xWh6mWw@mail.gmail.com> |
On Thu, Aug 7, 2014 at 9:06 AM, Lie Ryan <[email protected]> wrote: <SNIP> > > Also, did you apply the same level of scrutiny to your hardware? > That's the basis of the now well known NSA hack on Cisco routers. Intercept the box, modify the hardware, send the box onto some foreign land and the router lets them in. No hacking required. > For the truly paranoid, I recommend unplugging. > In the aforementioned book that's pretty much exactly what Snowden required of the reporter & documentary film maker he started out disclosing the info to. They had to buy new laptops and never attach them to the net. He apparently used PGP encryption to chat & transfer files over normal nets but (as I understand it) the encrypted files are never opened on anything other than your off-the-net machine. Of course, according to Snowden the NSA can enable the microphone on my cell phone and listen to me talking in the house. He required batteries be removed or cell phones be placed in a freezer. I recently saw a similar story about new TVs having built in cameras (for game interfaces I suppose) which could be enabled over the net to watch what's going on in my living room. If the TV has power applied, even if I'm not using it, what do I know really about what it's doing? All of that argues for Max's suggestion about sniffing the network full time, assuming I can relay on the sniffer not being hacked... ;-)