Bitcoin Forum
June 18, 2024, 09:08:00 AM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bad news for BTC-devs!?  (Read 1312 times)
Trance (OP)
Hero Member
*****
Offline Offline

Activity: 551
Merit: 500


View Profile
November 19, 2013, 08:25:33 AM
 #1


http://arstechnica.com/security/2013/10/meet-badbios-the-mysterious-mac-and-pc-malware-that-jumps-airgaps/

Some people are so poor ALL they have is money
Barek
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 19, 2013, 08:54:59 AM
 #2

Rumor has it properly disinfecting the usb port helps prevent spread!

Jokes aside, there is a difference to what is theoretically could be possible, and what really is.
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
November 19, 2013, 08:59:51 AM
 #3

I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

Barek
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 19, 2013, 09:04:09 AM
 #4

I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

You mean for offline transactions (e.g. Armory)? While it would be a nice feature, it feels more like security by obscurity. Nothing prevents an adversary to manipulate the sent QR codes, if the online computer is compromised.
freedomno1
Legendary
*
Offline Offline

Activity: 1806
Merit: 1090


Learning the troll avoidance button :)


View Profile
November 19, 2013, 09:05:58 AM
 #5

Wow BIOS
NO ONE Edit
Brilliant Smiley
But seems almost April fools like on Halloween XD
Then again if it is real this is interesting no known defense but computer silence

Believing in Bitcoins and it's ability to change the world
DeathAndTaxes
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
November 19, 2013, 09:06:14 AM
 #6

I have always thought using webcam and qr codes an ultra-paranoid way of airgapping. 

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

You mean for offline transactions (e.g. Armory)? While it would be a nice feature, it feels more like security by obscurity. Nothing prevents an adversary to manipulate the sent QR codes, if the online computer is compromised.

The offline computer wouldn't trust the online computer.   The online computer is simply used for blockchain data and to broadcast the offline signed transaction.  
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1078


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 19, 2013, 09:07:21 AM
 #7

The offline computer wouldn't trust the online computer.   The online computer is simply used for blockchain data and to broadcast the offline signed transaction. 

Exactly - I use QR codes for the CIYAM Safe and it does feel a lot safer to be completely "air-gapped".

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Elwar
Legendary
*
Offline Offline

Activity: 3598
Merit: 2386


Viva Ut Vivas


View Profile WWW
November 19, 2013, 09:16:27 AM
 #8

USBs carrying viruses has been known.

Burn CDs from offline wallets to move private keys for spending.

First seastead company actually selling sea homes: Ocean Builders https://ocean.builders  Of course we accept bitcoin.
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1078


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 19, 2013, 09:23:33 AM
 #9

QR codes have a pretty limited capacity but I have been experimenting with animated QR codes (like a flipbook of codes) for passing larger amounts of data.

I use an old e-book that has a built in "slideshow" function for all the photos in a directory - currently am only using it with my offline computer (to move new addresses to the online computer) but am thinking of buying another one for the online computer (as they are dirt cheap devices).

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Barek
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 19, 2013, 09:23:58 AM
 #10

Well, the argument is that somehow the USB or sound card can be manipulated for code injection.

If that argument is allowed, then why should it not be possible through the camera. An adversary generates a "magic" QR code (same as the magic audio or USB hijack), which causes the camera to create some sort of malicious code that causes the offline computer to be infected.

All of them are a far stretch, which is the point I was trying to make.
CIYAM
Legendary
*
Offline Offline

Activity: 1890
Merit: 1078


Ian Knowles - CIYAM Lead Developer


View Profile WWW
November 19, 2013, 09:31:32 AM
 #11

If that argument is allowed, then why should it not be possible through the camera. An adversary generates a "magic" QR code (same as the magic audio or USB hijack), which causes the camera to create some sort of malicious code that causes the offline computer to be infected.

All of them are a far stretch, which is the point I was trying to make.

There is no "code" transmitted via QR - just an unsigned raw tx (which you can check before signing).

So it is not a question of malicious code - there is *no code* at all.

With CIYAM anyone can create 100% generated C++ web applications in literally minutes.

GPG Public Key | 1ciyam3htJit1feGa26p2wQ4aw6KFTejU
Barek
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 19, 2013, 09:34:29 AM
 #12

Quick Response code. The data you transmit is encoded in a picture.
PenAndPaper
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


View Profile
November 19, 2013, 09:36:13 AM
 #13

The guy in this article describes an alien computer virus. Cyberpunk x-files.
Actually describes a virus that managed to do a lot more than what mit scientists are struggling with in research.
Seriously?  Roll Eyes
AnonyMint
Hero Member
*****
Offline Offline

Activity: 518
Merit: 521


View Profile
November 19, 2013, 09:37:37 AM
 #14

Printout and then OCR scan to cross airgap?

unheresy.com - Prodigiously Elucidating the Profoundly ObtuseTHIS FORUM ACCOUNT IS NO LONGER ACTIVE
Tesla71
Sr. Member
****
Offline Offline

Activity: 302
Merit: 252



View Profile
November 19, 2013, 09:38:59 AM
 #15

https://en.wikipedia.org/wiki/Virus_%281999_film%29
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!