Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #185677 > unrolled thread
| Started by | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| First post | 2017-08-22 04:50 +0200 |
| Last post | 2017-08-23 00:40 +0200 |
| Articles | 20 on this page of 26 — 9 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: USB wireless keyboard in stretch Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 04:50 +0200
Re: USB wireless keyboard in stretch Jape Person <japers@comcast.net> - 2017-08-22 06:10 +0200
Re: USB wireless keyboard in stretch Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 15:40 +0200
Re: USB wireless keyboard in stretch Jape Person <japers@comcast.net> - 2017-08-22 17:30 +0200
Re: USB wireless keyboard in stretch Zoltán Herman <zoltanhbz@gmail.com> - 2017-08-22 18:20 +0200
Re: USB wireless keyboard in stretch Zoltán Herman <zoltanhbz@gmail.com> - 2017-08-22 21:10 +0200
Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 19:20 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 19:40 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 19:50 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Nicolas George <george@nsup.org> - 2017-08-22 20:10 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Nicolas George <george@nsup.org> - 2017-08-22 20:00 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Nicolas George <george@nsup.org> - 2017-08-22 20:00 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Jape Person <japers@comcast.net> - 2017-08-22 20:10 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 20:50 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Jape Person <japers@comcast.net> - 2017-08-22 22:20 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 23:20 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Jape Person <japers@comcast.net> - 2017-08-23 00:10 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Jape Person <japers@comcast.net> - 2017-08-23 00:10 +0200
Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) Fungi4All <fungilife@protonmail.com> - 2017-08-22 23:40 +0200
Re: USB wireless keyboard in stretch Darac Marjal <mailinglist@darac.org.uk> - 2017-08-22 11:20 +0200
Re: USB wireless keyboard in stretch Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-22 15:50 +0200
Re: USB wireless keyboard in stretch Dominic Knight <dominicknight@gmx.com> - 2017-08-22 12:30 +0200
Re: USB wireless keyboard in stretch <tomas@tuxteam.de> - 2017-08-22 12:30 +0200
Re: USB wireless keyboard in stretch Zoltán Herman <zoltanhbz@gmail.com> - 2017-08-22 14:40 +0200
Re: USB wireless keyboard in stretch Ben Caradoc-Davies <ben@transient.nz> - 2017-08-23 00:40 +0200
Re: USB wireless keyboard in stretch Ben Caradoc-Davies <ben@transient.nz> - 2017-08-23 00:40 +0200
Page 1 of 2 [1] 2 Next page →
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 04:50 +0200 |
| Subject | Re: USB wireless keyboard in stretch |
| Message-ID | <uh7qp-4sV-7@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
On 21/08/17 17:09, Alle Meije Wink wrote: > Does anyone understand the cause of this problem *The USB wireless keyboard IS itself a problem*. You are unnecessarily contaminating the environment consuming Voltaic cells where none is needed (obviously wired keyboards feed through the cable) and broadcasting what you write over the air, including your passwords. >& how to fix it? Thanks! Very simple: Use a wired keyboard.
[toc] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-22 06:10 +0200 |
| Message-ID | <uh8FP-5u6-5@gated-at.bofh.it> |
| In reply to | #185677 |
On 08/21/2017 10:46 PM, Mario Castelán Castro wrote: > On 21/08/17 17:09, Alle Meije Wink wrote: >> Does anyone understand the cause of this problem > *The USB wireless keyboard IS itself a problem*. You are > unnecessarily contaminating the environment consuming Voltaic cells > where none is needed (obviously wired keyboards feed through the > cable) and broadcasting what you write over the air, including your > passwords. > >> & how to fix it? Thanks! > > Very simple: Use a wired keyboard. > <long, sad, sigh> I just got my new Cherry wireless keyboards delivered. And then I read about Mousejack. The keyboard communications are encrypted, and both mouse and keyboard are rechargeable. But I at least have to check with Cherry support to learn whether or not my new toys are vulnerable. I suspect that they are. Dangit. Though the keyboard had nice action, and the mouse was at least okay, they did suffer from intermittent loss of communication with the systems we were using them on. Back to the cheap wired Dell clackity keyboard and the rather nice wired Microsoft comfort mouse. <another long, sad, sigh>
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 15:40 +0200 |
| Message-ID | <uhhzt-31r-29@gated-at.bofh.it> |
| In reply to | #185679 |
[Multipart message — attachments visible in raw view] — view raw
On 21/08/17 23:02, Jape Person wrote: > The keyboard communications are encrypted, and both mouse and keyboard > are rechargeable. But I at least have to check with Cherry support to > learn whether or not my new toys are vulnerable. I suspect that they are. The problem is that even if the manufacturer assures you that the wireless link is secured cryptographically, all you have is their word for it. The implementation is very probably unauduitable (and even if would not audit it yourself, somebody among the community of users probably would do so and report if he found any vulnerability), as almost all firmware is. That is why opaque cryptographic systems can not be trusted. This is covered in any practical cryptography book.
[toc] | [prev] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-22 17:30 +0200 |
| Message-ID | <uhjhT-4dB-11@gated-at.bofh.it> |
| In reply to | #185707 |
On 08/22/2017 09:33 AM, Mario Castelán Castro wrote: > On 21/08/17 23:02, Jape Person wrote: >> The keyboard communications are encrypted, and both mouse and keyboard >> are rechargeable. But I at least have to check with Cherry support to >> learn whether or not my new toys are vulnerable. I suspect that they are. > > The problem is that even if the manufacturer assures you that the > wireless link is secured cryptographically, all you have is their word > for it. The implementation is very probably unauduitable (and even if > would not audit it yourself, somebody among the community of users > probably would do so and report if he found any vulnerability), as > almost all firmware is. > Hence, why I suspect that they are vulnerable. I bought these things because my wife trips over her cables 3 or 4 times a day, and wireless ones are just easier to deal with from a workstation logistics standpoint. Dummy that I am, I had only considered the issues like password interception, and had never considered the possibility that an unencrypted mouse connection would be a path for introducing keystrokes to the system, though it's a really obvious attack path. Surely proper design of the transceiver could keep the mouse input from sending keystrokes, but then I suppose some of the "special features" of the mouse wouldn't work -- and we couldn't have that, could we? I'll look into getting the test suite from Bastille to see if I can figure out how to do some testing on these things to see if they look vulnerable. Do you really think that this is unauditable? Bastille claims to have produced Open Source tools for doing just that. Maybe I'll just use the wireless keyboards and mice to control TVs. > That is why opaque cryptographic systems can not be trusted. This is > covered in any practical cryptography book. > Practical cryptography -- isn't that an oxymoron, for most users at least? People at my lower level of competence are at least aware that cryptography can be used in a variety of ways. I implemented encrypted e-mail on my own systems years ago, only to find that I couldn't persuade even one other among my acquaintances to use it. Not even if I set it up for them. Some of these folks were medical professionals who were exchanging the health data of patients among themselves and with patients -- by e-mail! In a day when people post their most personal experiences and thoughts on Facebook or Twitter for everyone to read, most people don't seem able to comprehend that some of us would prefer not to broadcast our underwear preferences to the universe. Thank you very much for your thoughts. They jerked me a little further back into such reality as I can tolerate. ;-) JP
[toc] | [prev] | [next] | [standalone]
| From | Zoltán Herman <zoltanhbz@gmail.com> |
|---|---|
| Date | 2017-08-22 18:20 +0200 |
| Message-ID | <uhk4i-4NV-9@gated-at.bofh.it> |
| In reply to | #185722 |
[Multipart message — attachments visible in raw view] — view raw
Hi Alle, I found this on https://wiki.archlinux.org/index.php/xfce( but analog can be here as well.. look at ) or look into the xfce4-session-verbose-log file, there is something wrong with in( error on mouse/keyboard) Greetings Zoltán 2017-08-22 17:22 GMT+02:00 Jape Person <japers@comcast.net>: > On 08/22/2017 09:33 AM, Mario Castelán Castro wrote: > >> On 21/08/17 23:02, Jape Person wrote: >> >>> The keyboard communications are encrypted, and both mouse and keyboard >>> are rechargeable. But I at least have to check with Cherry support to >>> learn whether or not my new toys are vulnerable. I suspect that they are. >>> >> >> The problem is that even if the manufacturer assures you that the >> wireless link is secured cryptographically, all you have is their word >> for it. The implementation is very probably unauduitable (and even if >> would not audit it yourself, somebody among the community of users >> probably would do so and report if he found any vulnerability), as >> almost all firmware is. >> >> > > Hence, why I suspect that they are vulnerable. I bought these things > because my wife trips over her cables 3 or 4 times a day, and wireless ones > are just easier to deal with from a workstation logistics standpoint. > > Dummy that I am, I had only considered the issues like password > interception, and had never considered the possibility that an unencrypted > mouse connection would be a path for introducing keystrokes to the system, > though it's a really obvious attack path. Surely proper design of the > transceiver could keep the mouse input from sending keystrokes, but then I > suppose some of the "special features" of the mouse wouldn't work -- and we > couldn't have that, could we? > > I'll look into getting the test suite from Bastille to see if I can figure > out how to do some testing on these things to see if they look vulnerable. > Do you really think that this is unauditable? Bastille claims to have > produced Open Source tools for doing just that. > > Maybe I'll just use the wireless keyboards and mice to control TVs. > > That is why opaque cryptographic systems can not be trusted. This is >> covered in any practical cryptography book. >> >> > Practical cryptography -- isn't that an oxymoron, for most users at least? > People at my lower level of competence are at least aware that cryptography > can be used in a variety of ways. I implemented encrypted e-mail on my own > systems years ago, only to find that I couldn't persuade even one other > among my acquaintances to use it. Not even if I set it up for them. Some of > these folks were medical professionals who were exchanging the health data > of patients among themselves and with patients -- by e-mail! > > In a day when people post their most personal experiences and thoughts on > Facebook or Twitter for everyone to read, most people don't seem able to > comprehend that some of us would prefer not to broadcast our underwear > preferences to the universe. > > Thank you very much for your thoughts. They jerked me a little further > back into such reality as I can tolerate. > > ;-) > > JP > >
[toc] | [prev] | [next] | [standalone]
| From | Zoltán Herman <zoltanhbz@gmail.com> |
|---|---|
| Date | 2017-08-22 21:10 +0200 |
| Message-ID | <uhmIO-6Dr-33@gated-at.bofh.it> |
| In reply to | #185726 |
[Multipart message — attachments visible in raw view] — view raw
or apt-get install xfce4-goodies 2017-08-22 18:11 GMT+02:00 Zoltán Herman <zoltanhbz@gmail.com>: > Hi Alle, > > I found this on https://wiki.archlinux.org/index.php/xfce( but analog can > be here as well.. look at ) > or > > look into the xfce4-session-verbose-log file, there is something wrong > with in( error on mouse/keyboard) > > > Greetings > > Zoltán > > > > 2017-08-22 17:22 GMT+02:00 Jape Person <japers@comcast.net>: > >> On 08/22/2017 09:33 AM, Mario Castelán Castro wrote: >> >>> On 21/08/17 23:02, Jape Person wrote: >>> >>>> The keyboard communications are encrypted, and both mouse and keyboard >>>> are rechargeable. But I at least have to check with Cherry support to >>>> learn whether or not my new toys are vulnerable. I suspect that they >>>> are. >>>> >>> >>> The problem is that even if the manufacturer assures you that the >>> wireless link is secured cryptographically, all you have is their word >>> for it. The implementation is very probably unauduitable (and even if >>> would not audit it yourself, somebody among the community of users >>> probably would do so and report if he found any vulnerability), as >>> almost all firmware is. >>> >>> >> >> Hence, why I suspect that they are vulnerable. I bought these things >> because my wife trips over her cables 3 or 4 times a day, and wireless ones >> are just easier to deal with from a workstation logistics standpoint. >> >> Dummy that I am, I had only considered the issues like password >> interception, and had never considered the possibility that an unencrypted >> mouse connection would be a path for introducing keystrokes to the system, >> though it's a really obvious attack path. Surely proper design of the >> transceiver could keep the mouse input from sending keystrokes, but then I >> suppose some of the "special features" of the mouse wouldn't work -- and we >> couldn't have that, could we? >> >> I'll look into getting the test suite from Bastille to see if I can >> figure out how to do some testing on these things to see if they look >> vulnerable. Do you really think that this is unauditable? Bastille claims >> to have produced Open Source tools for doing just that. >> >> Maybe I'll just use the wireless keyboards and mice to control TVs. >> >> That is why opaque cryptographic systems can not be trusted. This is >>> covered in any practical cryptography book. >>> >>> >> Practical cryptography -- isn't that an oxymoron, for most users at >> least? People at my lower level of competence are at least aware that >> cryptography can be used in a variety of ways. I implemented encrypted >> e-mail on my own systems years ago, only to find that I couldn't persuade >> even one other among my acquaintances to use it. Not even if I set it up >> for them. Some of these folks were medical professionals who were >> exchanging the health data of patients among themselves and with patients >> -- by e-mail! >> >> In a day when people post their most personal experiences and thoughts on >> Facebook or Twitter for everyone to read, most people don't seem able to >> comprehend that some of us would prefer not to broadcast our underwear >> preferences to the universe. >> >> Thank you very much for your thoughts. They jerked me a little further >> back into such reality as I can tolerate. >> >> ;-) >> >> JP >> >> >
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 19:20 +0200 |
| Subject | Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhl0m-5py-15@gated-at.bofh.it> |
| In reply to | #185722 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 10:22, Jape Person wrote: > Hence, why I suspect that they are vulnerable. I bought these things > because my wife trips over her cables 3 or 4 times a day, and wireless > ones are just easier to deal with from a workstation logistics standpoint. Wireless things do not solve the problem of having to cope with wires. They just replace this with the bigger problem of unauduitable firmware directly exposed to the attacker (via radio or sometimes infrared communication). My suggestion is to instead address cabling directly. If your wife trips because cables are in the floor, then use some wire to coil the excess length so that it does not hang. If your cables have to go through a walkway, then pass them through the bottom of the ceiling, so that the floor will be clear and thus avoid the “tripping hazard”. Use a cable extension if required. You may need to go to a hardware store to buy a cable tray or a wall-mountable cable clamp. > I'll look into getting the test suite from Bastille to see if I can > figure out how to do some testing on these things to see if they look > vulnerable. Do you really think that this is unauditable? Bastille > claims to have produced Open Source tools for doing just that. If the device firmware is secret, then it is unauduitable. Of course, this applies to wired keyboards too. The problem is that wireless keyboards are exposed to possible attackers, while wired keyboards are not. I have not heard about Bastille. Apparently they sell a vulnerability scanner for wireless devices. I can easily be wrong here because I just took a quick glance at “https://www.bastille.net/product/introduction/”. By doing vulnerability scanner, one can only test the device for a limited set of *known* vulnerabilities (the test suite must know what to look for). I would not trust any wireless device just because a vulnerability scanning found nothing on it. Without seeing the firmware source code, one can not tell if it has vulnerabilities previously unknown. > Maybe I'll just use the wireless keyboards and mice to control TVs. Ugh? I did not know that TVs that have any use for keyboard and mice input existed. I guess it's just yet another class of devices with “walled-garden type” proprietary software providing an incountable number of fancy but completely useless bells and whistles. What is next? A toaster that makes a Twitter post when the toasts are ready? >> That is why opaque cryptographic systems can not be trusted. This is >> covered in any practical cryptography book. > > Practical cryptography -- isn't that an oxymoron, for most users at > least? [...] I was referring to *books* that address the issues related to *deploying* cryptographic systems as opposed to theoretical issues or cryptanalysis (for example, the mathematics of elliptic curve cryptography, hash constructions “probably secure” based on the random oracle model, and other details that are not relevant to the end users). The question of whether cryptography can be practical is a very different matter. I believe that cryptography is already practical. For example, encrypting e-mail with Enigmail and Thunderbird is very easy. Many distributions have graphical installers (lay users are allergic to ncurses-type interfaces) with which an encrypted volume can be set up easily. Many web sites use TLS transparently to the user, et cetera. > In a day when people post their most personal experiences and thoughts > on Facebook or Twitter for everyone to read [...] But about the huge amorphous mass of typical Facebook users, those are a lost case. The fact that they couldn't be made to properly secure their information –even if their despicable lives depended on it– is not a fault of the cryptography systems. It is a fault of their indolence and incompetence. Related: <https://web.archive.org/web/20140329180453/http://eatliver.com/i.php?n=4043>. Personally I do not care about “privacy” in the normal sense, because I do not care about the opinion of people about myself (However, I do care about *arguments* that I am doing something wrong). However, I care abut encryption because I do not want to leave through the Internet personal information that maybe can be used *against* me. Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 19:40 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhljI-5x9-15@gated-at.bofh.it> |
| In reply to | #185729 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 12:33, Nicolas George wrote: > Le quintidi 5 fructidor, an CCXXV, Mario Castelán Castro a écrit : >> Wireless things do not solve the problem of having to cope with wires. >> They just replace this with the bigger problem of unauduitable firmware >> directly exposed to the attacker (via radio or sometimes infrared >> communication). > > Well, that is not the SAME problem, so the original problem is solved. Just as the problem of having to pay a loan is “solved” by requesting a new loan to pay the old loan. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 19:50 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhlto-5B5-19@gated-at.bofh.it> |
| In reply to | #185730 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 12:38, Nicolas George wrote: > Wrong, "pay a loan" and "pay a loan" are the same problem. "Pay a loan" > and "escape the police after robbing a bank" are two different problems, > for example. Wrong. Your ambiguous choice of words has hidden the difference. First it is “pay THE loan X” first, and then it is “pay THE loan Y”, where X≠Y. Therefore, they are different problems. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2017-08-22 20:10 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhlMJ-5Zp-3@gated-at.bofh.it> |
| In reply to | #185731 |
Le quintidi 5 fructidor, an CCXXV, Mario Castelán Castro a écrit : > Wrong. Your ambiguous choice of words has hidden the difference. That was YOUR own choice of words, showing how this discussion is pointless. Regards, -- Nicolas George
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2017-08-22 20:00 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhlto-5B5-21@gated-at.bofh.it> |
| In reply to | #185730 |
Le quintidi 5 fructidor, an CCXXV, Mario Castelán Castro a écrit : > Just as the problem of having to pay a loan is “solved” by requesting a > new loan to pay the old loan. Wrong, "pay a loan" and "pay a loan" are the same problem. "Pay a loan" and "escape the police after robbing a bank" are two different problems, for example. The real question is, of course, which problem is the most severe for the person who decides. Regards, -- Nicolas George
[toc] | [prev] | [next] | [standalone]
| From | Nicolas George <george@nsup.org> |
|---|---|
| Date | 2017-08-22 20:00 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhljI-5x9-17@gated-at.bofh.it> |
| In reply to | #185729 |
Le quintidi 5 fructidor, an CCXXV, Mario Castelán Castro a écrit : > Wireless things do not solve the problem of having to cope with wires. > They just replace this with the bigger problem of unauduitable firmware > directly exposed to the attacker (via radio or sometimes infrared > communication). Well, that is not the SAME problem, so the original problem is solved. ObPratchett: # ‘You closed the road? You closed the road!’ he yelled, above the wind. # # ‘And Kings Way, sir. Just in case,’ Carrot shouted down. # # ‘You closed two major roads? Two whole damn roads? In the rush hour?’ # # ‘Yes, sir,’ said Carrot. ‘It was the only way.’ # # Vimes hung on, speechless. Would he have dared do that? But that was # Carrot all over. There was a problem, and now it's gone. Admittedly, the # whole city is probably solid with wagons by now, but that's a new # problem.
[toc] | [prev] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-22 20:10 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhlMJ-5Zp-11@gated-at.bofh.it> |
| In reply to | #185729 |
On 08/22/2017 01:17 PM, Mario Castelán Castro wrote: > On 22/08/17 10:22, Jape Person wrote: >> Hence, why I suspect that they are vulnerable. I bought these >> things because my wife trips over her cables 3 or 4 times a day, >> and wireless ones are just easier to deal with from a workstation >> logistics standpoint. > > Wireless things do not solve the problem of having to cope with > wires. They just replace this with the bigger problem of unauduitable > firmware directly exposed to the attacker (via radio or sometimes > infrared communication). > > My suggestion is to instead address cabling directly. If your wife > trips because cables are in the floor, then use some wire to coil the > excess length so that it does not hang. If your cables have to go > through a walkway, then pass them through the bottom of the ceiling, > so that the floor will be clear and thus avoid the “tripping hazard”. > Use a cable extension if required. You may need to go to a hardware > store to buy a cable tray or a wall-mountable cable clamp. > There's no fix for my wife and the presence of cables. In this case, the cables for keyboard and mouse run from the Intel NUC computer nestled in a table beside her recliner to the keyboard on her lap and the mouse on her arm rest. She has yanked the cables free of the computer, pulled the computer out of its shelf, dropped the keyboard and then tripped over it when she tried to retrieve it, and actually toppled the table while "arguing" with the keyboard and mouse cables. Wireless devices were a ploy to reduce the likelihood of her causing damage to the various devices because of her interaction with things that were tied together physically. Her clumsiness doesn't reduce her charm a bit. But you do have to be careful not to stand next to her in the kitchen. She gestures a lot with her hands -- even when holding knives. Ever seen a Fellini movie? Kindest, sweetest person I've ever known. Over 60 years together, and she hasn't killed me yet. If she does, everyone can rest assured that it was an accident. >> I'll look into getting the test suite from Bastille to see if I >> can figure out how to do some testing on these things to see if >> they look vulnerable. Do you really think that this is unauditable? >> Bastille claims to have produced Open Source tools for doing just >> that. > > If the device firmware is secret, then it is unauduitable. Of > course, this applies to wired keyboards too. The problem is that > wireless keyboards are exposed to possible attackers, while wired > keyboards are not. > > I have not heard about Bastille. Apparently they sell a > vulnerability scanner for wireless devices. I can easily be wrong > here because I just took a quick glance at > “https://www.bastille.net/product/introduction/”. > > By doing vulnerability scanner, one can only test the device for a > limited set of *known* vulnerabilities (the test suite must know what > to look for). I would not trust any wireless device just because a > vulnerability scanning found nothing on it. Without seeing the > firmware source code, one can not tell if it has vulnerabilities > previously unknown. > Point taken. Saves me the time of fiddling with it. I just won't use the wireless stuff on my computers. I live in a large condominium which houses everything from script kiddies to DoD security folks. >> Maybe I'll just use the wireless keyboards and mice to control >> TVs. > > Ugh? I did not know that TVs that have any use for keyboard and mice > input existed. I guess it's just yet another class of devices with > “walled-garden type” proprietary software providing an incountable > number of fancy but completely useless bells and whistles. > > What is next? A toaster that makes a Twitter post when the toasts are > ready? > Actually, the LG OLED TVs we have use an OS and application software for which source is readily available. Firmware for the bluetooth and / or usb wireless connectors may be another thing. But I haven't checked because I don't care if someone sends keystrokes to the TV. Yeah, good place for the wireless keyboards and mice. The Web browser on the TV actually works pretty well, though I hardly ever use it. The keyboards make entering search terms or passwords for connection to things like Hulu and Netflix a ton easier than doing such things with a "smart" remote. >>> That is why opaque cryptographic systems can not be trusted. This >>> is covered in any practical cryptography book. >> >> Practical cryptography -- isn't that an oxymoron, for most users >> at least? [...] > I was referring to *books* that address the issues related to > *deploying* cryptographic systems as opposed to theoretical issues > or cryptanalysis (for example, the mathematics of elliptic curve > cryptography, hash constructions “probably secure” based on the > random oracle model, and other details that are not relevant to the > end users). The question of whether cryptography can be practical is > a very different matter. > > I believe that cryptography is already practical. For example, > encrypting e-mail with Enigmail and Thunderbird is very easy. Many > distributions have graphical installers (lay users are allergic to > ncurses-type interfaces) with which an encrypted volume can be set > up easily. Many web sites use TLS transparently to the user, et > cetera. > >> In a day when people post their most personal experiences and >> thoughts on Facebook or Twitter for everyone to read [...] > > But about the huge amorphous mass of typical Facebook users, those > are a lost case. The fact that they couldn't be made to properly > secure their information –even if their despicable lives depended on > it– is not a fault of the cryptography systems. It is a fault of > their indolence and incompetence. Related: > <https://web.archive.org/web/20140329180453/http://eatliver.com/i.php?n=4043>. > > Personally I do not care about “privacy” in the normal sense, > because I do not care about the opinion of people about myself > (However, I do care about *arguments* that I am doing something > wrong). However, I care abut encryption because I do not want to > leave through the Internet personal information that maybe can be > used *against* me. > > Regards. > Precisely. Governments and other entities have proved many times over how untrustworthy they are when they get their hands on personal data. Political and monetary motivations often tempt them to weave fascinating narratives based upon the slimmest of coincidental associations. Once the narratives are created, they are tempted to act upon them -- especially if they need a scapegoat on short notice. Them: "Don't worry, if you drown when we dunk you, we'll know you weren't a witch! You'll be exonerated!" Me: glub, glub, glub
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 20:50 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhmpr-6fC-11@gated-at.bofh.it> |
| In reply to | #185735 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 13:01, Jape Person wrote: > There's no fix for my wife and the presence of cables. In this case, the > cables for keyboard and mouse run from the Intel NUC computer nestled in > a table beside her recliner to the keyboard on her lap and the mouse on > her arm rest. She has yanked the cables free of the computer, pulled the > computer out of its shelf, dropped the keyboard and then tripped over it > when she tried to retrieve it, and actually toppled the table while > "arguing" with the keyboard and mouse cables. Wireless devices were a > ploy to reduce the likelihood of her causing damage to the various > devices because of her interaction with things that were tied together > physically. I see. You may be also interested in “magnetic quick release USB cables”. They are held together at one part by a magnet. A strong pull (accidental or otherwise) will disconnect it, and thus it is supposed to be less dangerous for the user and the equipment. I have never seen any such in my life, but I know they exist. > Her clumsiness doesn't reduce her charm a bit. But you do have to be > careful not to stand next to her in the kitchen. She gestures a lot with > her hands -- even when holding knives. Ever seen a Fellini movie? Well, at least as she does not injuries herself or you it's alright. :) ----- There is nothing else to add from my part to this conversation, so good luck! -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-22 22:20 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhnOy-7kH-35@gated-at.bofh.it> |
| In reply to | #185737 |
On 08/22/2017 02:40 PM, Mario Castelán Castro wrote: > On 22/08/17 13:01, Jape Person wrote: >> There's no fix for my wife and the presence of cables. In this case, the >> cables for keyboard and mouse run from the Intel NUC computer nestled in >> a table beside her recliner to the keyboard on her lap and the mouse on >> her arm rest. She has yanked the cables free of the computer, pulled the >> computer out of its shelf, dropped the keyboard and then tripped over it >> when she tried to retrieve it, and actually toppled the table while >> "arguing" with the keyboard and mouse cables. Wireless devices were a >> ploy to reduce the likelihood of her causing damage to the various >> devices because of her interaction with things that were tied together >> physically. > > I see. You may be also interested in “magnetic quick release USB > cables”. They are held together at one part by a magnet. A strong pull > (accidental or otherwise) will disconnect it, and thus it is supposed to > be less dangerous for the user and the equipment. I have never seen any > such in my life, but I know they exist. > >> Her clumsiness doesn't reduce her charm a bit. But you do have to be >> careful not to stand next to her in the kitchen. She gestures a lot with >> her hands -- even when holding knives. Ever seen a Fellini movie? > > Well, at least as she does not injuries herself or you it's alright. :) > > ----- > There is nothing else to add from my part to this conversation, so good > luck! > You have been *very* helpful. You educated / reminded me on why even testing for exploits isn't necessarily useful when the firmware is not Open Source, and you told me about the existence of magnetic quick release USB cables. Time to shop! And thank you very much again. Best regards, JP
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-22 23:20 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhoKC-7YR-11@gated-at.bofh.it> |
| In reply to | #185744 |
[Multipart message — attachments visible in raw view] — view raw
On 22/08/17 15:11, Jape Person wrote: > You have been *very* helpful. You educated / reminded me on why even > testing for exploits isn't necessarily useful when the firmware is not > Open Source, and you told me about the existence of magnetic quick > release USB cables. Time to shop! > > And thank you very much again. I am glad that you found my commentary useful. By the way, I prefer the free software philosophy and term instead of open source, although of course, almost all open source software is free software and vice-versa. Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-23 00:10 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhpx0-74-13@gated-at.bofh.it> |
| In reply to | #185748 |
On 08/22/2017 05:12 PM, Mario Castelán Castro wrote: > On 22/08/17 15:11, Jape Person wrote: >> You have been *very* helpful. You educated / reminded me on why even >> testing for exploits isn't necessarily useful when the firmware is not >> Open Source, and you told me about the existence of magnetic quick >> release USB cables. Time to shop! >> >> And thank you very much again. > > I am glad that you found my commentary useful. > > By the way, I prefer the free software philosophy and term instead of > open source, although of course, almost all open source software is free > software and vice-versa. > > Regards. > Understood. I was just thinking of it from the standpoint of what we can see, not from the standpoint of the philosophy as to why we can see it or what we can do with it. But you're right. the philosophy is always important. I'd love to run into a few folks here who care about such things. Conversations in this region have a tendency to get really boring, really quickly. The only things most people around here are willing to discuss are physical trivialities and things I'm reasonably certain don't exist. ;-) Friends don't let friends eat friends. JP
[toc] | [prev] | [next] | [standalone]
| From | Jape Person <japers@comcast.net> |
|---|---|
| Date | 2017-08-23 00:10 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhpx0-74-29@gated-at.bofh.it> |
| In reply to | #185751 |
On 08/22/2017 06:01 PM, Jape Person wrote: > On 08/22/2017 05:12 PM, Mario Castelán Castro wrote: >> On 22/08/17 15:11, Jape Person wrote: >>> You have been *very* helpful. You educated / reminded me on why even >>> testing for exploits isn't necessarily useful when the firmware is not >>> Open Source, and you told me about the existence of magnetic quick >>> release USB cables. Time to shop! >>> >>> And thank you very much again. >> >> I am glad that you found my commentary useful. >> >> By the way, I prefer the free software philosophy and term instead of >> open source, although of course, almost all open source software is free >> software and vice-versa. >> >> Regards. >> > > Understood. I was just thinking of it from the standpoint of what we can > see, not from the standpoint of the philosophy as to why we can see it > or what we can do with it. But you're right. the philosophy is always > important. > > I'd love to run into a few folks here who care about such things. > Conversations in this region have a tendency to get really boring, > really quickly. The only things most people around here are willing to > discuss are physical trivialities and things I'm reasonably certain > don't exist. > > ;-) > > Friends don't let friends eat friends. > > JP > > Heh. Ambiguity is my middle name. By "here" and "this region" above, I'm referring to physical location. There are lots of interesting folks in this "here".
[toc] | [prev] | [next] | [standalone]
| From | Fungi4All <fungilife@protonmail.com> |
|---|---|
| Date | 2017-08-22 23:40 +0200 |
| Subject | Re: Wireless devices and cryptography in practice (Was: USB wireless keyboard in stretch) |
| Message-ID | <uhp3Y-86X-19@gated-at.bofh.it> |
| In reply to | #185729 |
[Multipart message — attachments visible in raw view] — view raw
> From: marioxcc.MT@yandex.com > To: debian-user@lists.debian.org > > On 22/08/17 10:22, Jape Person wrote: >> Hence, why I suspect that they are vulnerable. I bought these things >> because my wife trips over her cables 3 or 4 times a day, and wireless >> ones are just easier to deal with from a workstation logistics standpoint. > > Wireless things do not solve the problem of having to cope with wires. > They just replace this with the bigger problem of unauduitable firmware > directly exposed to the attacker (via radio or sometimes infrared > communication). > > My suggestion is to instead address cabling directly. If your wife trips > because cables are in the floor, then use some wire to coil the excess > length so that it does not hang. If your cables have to go through a > walkway, then pass them through the bottom of the ceiling, so that the > floor will be clear and thus avoid the “tripping hazard”. Use a cable > extension if required. You may need to go to a hardware store to buy a > cable tray or a wall-mountable cable clamp. > >> I"ll look into getting the test suite from Bastille to see if I can >> figure out how to do some testing on these things to see if they look >> vulnerable. Do you really think that this is unauditable? Bastille >> claims to have produced Open Source tools for doing just that. > > If the device firmware is secret, then it is unauduitable. Of course, > this applies to wired keyboards too. The problem is that wireless > keyboards are exposed to possible attackers, while wired keyboards are not. > > I have not heard about Bastille. Apparently they sell a vulnerability > scanner for wireless devices. I can easily be wrong here because I just > took a quick glance at “https://www.bastille.net/product/introduction/”. > > By doing vulnerability scanner, one can only test the device for a > limited set of *known* vulnerabilities (the test suite must know what to > look for). I would not trust any wireless device just because a > vulnerability scanning found nothing on it. Without seeing the firmware > source code, one can not tell if it has vulnerabilities previously unknown. > >> Maybe I"ll just use the wireless keyboards and mice to control TVs. > > Ugh? I did not know that TVs that have any use for keyboard and mice > input existed. I guess it"s just yet another class of devices with > “walled-garden type” proprietary software providing an incountable > number of fancy but completely useless bells and whistles. > > What is next? A toaster that makes a Twitter post when the toasts are ready? > >>> That is why opaque cryptographic systems can not be trusted. This is >>> covered in any practical cryptography book. >> >> Practical cryptography -- isn"t that an oxymoron, for most users at >> least? [...] > I was referring to *books* that address the issues related to > *deploying* cryptographic systems as opposed to theoretical issues or > cryptanalysis (for example, the mathematics of elliptic curve > cryptography, hash constructions “probably secure” based on the random > oracle model, and other details that are not relevant to the end users). > The question of whether cryptography can be practical is a very > different matter. > > I believe that cryptography is already practical. For example, > encrypting e-mail with Enigmail and Thunderbird is very easy. Many > distributions have graphical installers (lay users are allergic to > ncurses-type interfaces) with which an encrypted volume can be set up > easily. Many web sites use TLS transparently to the user, et cetera. > >> In a day when people post their most personal experiences and thoughts >> on Facebook or Twitter for everyone to read [...] > > But about the huge amorphous mass of typical Facebook users, those are a > lost case. The fact that they couldn"t be made to properly secure their > information –even if their despicable lives depended on it– is not a > fault of the cryptography systems. It is a fault of their indolence and > incompetence. Related: > <https://web.archive.org/web/20140329180453/http://eatliver.com/i.php?n=4043>. > > Personally I do not care about “privacy” in the normal sense, because I > do not care about the opinion of people about myself (However, I do care > about *arguments* that I am doing something wrong). However, I care abut > encryption because I do not want to leave through the Internet personal > information that maybe can be used *against* me. > > Regards. > > -- > Do not eat animals, respect them as you respect people. > https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan Very nice article reming people of the obvious. There is one specific area where mediums mix-match, air and copper that is, and this is a not so recent gadget of using mains/electrical outlets for networking by placing a pair or more dongles on any plugs on the same circuit. Well, electrical circuits are not very isolated from the generator and back through your house. It is just that those little boxes are powered by the current and use the current's medium to transmit a signal. Either with a copy of the same little box or by a sensor around the wire someone can get the ethernet signal and join the conversation. The signla strength drops the further you go, but it is still there, despite of the electrical noise. People tend to think it is just like connecting a wire from your pc to a router or a hub/bridge whatever. In this case it is very likely that your toaster can tweet the results on the network. It is the blender you should worry about :)
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-08-22 11:20 +0200 |
| Message-ID | <uhdvP-jp-11@gated-at.bofh.it> |
| In reply to | #185677 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Aug 21, 2017 at 09:46:30PM -0500, Mario Castelán Castro wrote: >On 21/08/17 17:09, Alle Meije Wink wrote: >> Does anyone understand the cause of this problem >*The USB wireless keyboard IS itself a problem*. You are unnecessarily >contaminating the environment consuming Voltaic cells where none is >needed (obviously wired keyboards feed through the cable) and >broadcasting what you write over the air, including your passwords. > >>& how to fix it? Thanks! > >Very simple: Use a wired keyboard. > Don't forget your TEMPEST-approved faraday cage (I mean, what's the wire between the keyboard and the computer if not a nice aerial?) Oh, and don't forget to regularly check around the back of your computer to confirm no-one's put a keylogger in between the computer and the keyboard. Honestly, unnecessary paranoia adds NOTHING to this conversation. -- For more information, please reread.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web