Hacker News .hnnew | past | comments | ask | show | jobs | submitlogin

Every device can do things behind the users back. Intel Management Engine runs even when the computer is turned off, contains a full blown operating system and has access to tcp/ip stack.

If privacy is a concern, no device should be trusted. By device I mean anything that contains a chip.

What's worse, people might suspect their phone or PC might be leaking data to third parties, but they will be less suspecting about their TV, their fridge or their car. But since anything is becoming smart these days, one can assume that anything that runs out of electricity is a potential privacy problem.



The NSA specifically orders motherboards without these management components. No one else can typically get them, they’re not available to people like you and me.

I think some things are overblown and unjustified paranoia.

Other things? Justified paranoia.


> No one else can typically get them, they’re not available to people like you and me.

Isn't that just setting the HAP (High Assurance Platform) bit in the ME blob to disable it after bring-up? For Intel platforms it is possible for the end-user to modify the firmware themselves in many cases. https://hackaday.com/tag/hap-bit/


My approach as an practicing paranoic: Use retro Computers.


How much retro are we talking? If retro enough we can't use them for any modern use case.

Maybe something like a RISC-V core written to a FPGA by yourself is pretty safe.


You can have both.

* https://github.com/MiSTer-devel/Main_MiSTer/wiki

Combine retro with FPGA as you like(within the constraints of that development board).

Or waste Watts by using software emulation.


It all depends on the one question: What IS your use case?

Mine is as an tutor on an evening college, casual writer and some dabbling into some embedded projects. For THIS use case my (very retro) Atari 520 ST with 4 MB Ram is totally working. Is it nuts? Yup, but i can be sure that no state trojan is monitoring my totally boring behaviour.


Take this behavior too far and you might just sign up for more monitoring.

"Why does citizen #2743652 have internet/electricity service with no registered devices or online profiles?" *Does deep background check*


Nah, no problem: Just use some cheap tablet for a bit casual time in the "commercinet" (e.g. YouTube)... ;-)


This is the avenue I've started taking, myself.


The IME is just a "smarter than needed" addition, so it's probably not too hard to take it out

But every PC has a SMC which deals with things like power-on, WOL, etc


You can remove “modules” of the management engine but it’s responsible for booting the x86 cores so you cannot entirely turn it off.


I think you were most likely right, coz you just reminded me one incident that I talked with my colleagues regarding solar power one day and just one day after that I received a cold call trying to sell me some solar solutions. There were 3 ppl in the conversation, I was the only one without solar at home and I was the only one received the call too. How likely that would be a coincident?

Such things are so scary but what can we do? For most of the ppl, they cannot prove something like that happened. For me, I might be able to prove it but I cannot easily do it without significant efforts.


>>How likely that would be a coincident?

People say this all the time but literally no one has been able to prove any kind of secretive listening-based advertising.

The best explanation is that either you or someone else in your household has searched for something related and now it's appearing in your ads, or actually more likely, advertisers are incredible at linking cookies to actual users, and it's enough if your friend searched for solar panels and then his interests were associated with you. Like, advertisers can figure out all your friends have solar panels but you don't - so they show you ads for them. It's far easier to do than listening and to your conversations covertly.


If you have "OK Google" or whatever it is turned on, it is indeed listening to you.

I've seen it with my parents. They will talk about it, not to their phones, but around their phones, and they'll start seeing ads for something they talked about.

I've always had that featured turned off (I have to press the button), and I don't notice it.

My wife also sees it with her iPhone with siri turned on. I talked to her about, for example, Jordan Peterson, and her phone starts blowing up with Jordan Peterson on Instagram.

I dont think it's pure coincidence.


>>I talked to her about, for example, Jordan Peterson, and her phone starts blowing up with Jordan Peterson on Instagram.

And why did you talk to her about Jordan Peterson? Is it perhaps because you read an article about Jordan Peterson earlier? If so, I assume you both share the same IP at home - so she starts seeing things you viewed or browsed. Facebook owns Instagram too, so if you look at something on Instagram it's not that wild that your partner's Instagram starts showing her things that interest you - it's just association.

>>If you have "OK Google" or whatever it is turned on, it is indeed listening to you.

Sure, and that's what I meant in the first paragraph - no one has been able to prove that this feature is sending your voice to Google/apple/Amazon servers unless you trigger the key word. Recording and sending voice would create some trace and no one has been able to prove this exist. That's not me saying it doesn't exist, just that for what is supposedly wide spread phenomenon, we have no proof it's actually happening other than anecdotal stories which can be easily explained by other means.


Nothing like this ever happens to me with Alexa or Siri always listening, but I have all my web browsers locked down and I don’t use any Facebook apps/sites

I think you need to look into how pervasive and creepy ad network tracking is: https://www.nytimes.com/interactive/2019/12/20/opinion/locat...


Not sure why it's downvoted, it's been proved many times


Professionals and hobbyists who analyze smart phone app behavior with APK decompilers, reverse engineering suites, personal cell towers, SDN radios, SIM dongles, mobile device emulators, etc: "Facebook apps are not listening to your conversations in the background, if they were we'd have seen it here, here, here, and here."

People with anecdata about which ads they see, who think of cell phones as inscrutable magic: "No, they definitely are. I can't (won't) think of any other way they'd infer my interests in these topics. You can't see it happening because they are too smart."


Yeah, I hate Facebook as much as anyone, but they’d have way too much to lose by deploying some sort of zero day-based hidden listening tools

I guess the financial incentive might be there for some shady ad network to do it, but that’s just so much risk to take on for such a tiny gain per infected phone..


I was talking about youtube. They do listen to show more relevant videos. I live in a very quiet household and if we say something out loud low and behold it will be in our recommended later.


Again, anecdotes are not data. YouTube is extremely good at guessing things you might be interested in, you could try being completely mute in your household and then after a week you will have to arrive at only one of two conclusions

1) YouTube can read minds and they know what you just thought about

2) with statistical data from literally billions of people it's not so weird to guess what you might be thinking about and show you a video about it.

Again, if they(your phone? Watch? Toaster?) were listening someone would have found some evidence by now, a trace of voice recordings being sent or even something that looks like it might be voice recordings. Yet we have zero. It's not happening, the much easier and much more probable explanation is that we're already tracked through every online service we ever touch, but also we are linked to people we live with or people we interact with, and for a company that possesses exabytes of data it can analyse it's easier to trawl that than try to sneak out voice recordings out of your phone.


Link?


I, a layman, have had similar experiences. It seems tinfoil-tier to think my phone's mic is always on and running some NLP. If I wasn't loosely technical I would dismiss it as such.


But why is it tinfoil-tier?

It's basically common knowledge that if you turn on "hear me say OK Google" that it needs to always be listening to hear "OK Google". That's a green light to start parsing everything said all the time, which will be turned around for advertising. Because that's how Google makes money.

Expecting Google to use data to advertise isn't tinfoil?


The tinfoil part is the parsing.

Actual nlp parsing all audio, or even a tiny subset of devices, is far beyond Google's capabilities. It's not a trivial task to process.

Your phone locally has some extremely basic recognition for "ok google", after which selective actual nlp parsing takes place.


But detecting “oh, this is voice” is easy. Recording the time where that happens is also easy. Knowing when people are chatting around the phone, and roughly what the fundamental frequency of their voice is, could make $0.001 per person. At Google's scale, that's worth it.

So long as they don't get caught, anyway, because that's all sorts of illegal. Especially at Google's scale. (I don't think Google does this… probably.)


What's you're saying is possible and what we're talking about are two entirely different things though.


The fundamental frequency of the voice doesn't tell you what words they were saying.


It's probably that psychological effect where if you buy a red car, all you can see is red cars. How many times have you received a completely random, unrelated cold call?


I think that's the the Baader–Meinhof phenomenon.

From Wikipedia: Frequency illusion, also known as the Baader–Meinhof phenomenon or frequency bias, is a cognitive bias in which, after noticing something for the first time, there is a tendency to notice it more often, leading someone to believe that it has a high frequency of occurrence – a form of selection bias.

https://en.wikipedia.org/wiki/Frequency_illusion


Shouldn't that be necessary if you want to boot your PC from the network?


Realistically, how many real people actually use PXE? It must be tiny. Seems strange to include what is essentially a business function in a product for normal people.


I consider netbooting like drawers in the kitchen, where I grab tools according to task. Be it preparing meals, or actually eating.

In a reversal of what you call business function, I'd consider it as my business to do what I want in my space when I want, how and where.

That shrinkwrapped pre-installed OS/Appstore is just another business sector, which the masses have been conditioned into accepting.

Convenient. But sometimes not, rather the opposite.


Any IT department that images devices, for starters. The number of people who actually use it is quite small, but the number of devices those people image with PXE is massive.


Right, but "IT department" falls under business use. I was talking about people who aren't technically inclined.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: