Mail an pamusb-devel-request@lists.sourceforge.net Mailinglist

One-Time Pad should jump arround in Memory faster than CIA (not NSA!!!) can read it out by Hardware Backdoors (Shanon/Nyquist)

Hello PamUSB

i guess that the CIA (not the NSA!!!) has some sort of Hardware Backdoors in most of the devices available.

Simplest way would be that the WLAN card (they probably would use this way, because it has an antenna that maximizes the range and not like Jacob Applebaum in said in «to protect and infect» at the 30c3 eg in the network plug) Firmware, and that thing has possibly DMA Access so they could read out the one time pad easily. So probably it would be wise if the pad would jump arround in the Memory faster than can be read out by this Channel, eg. 300Mbit/s 801.11n, Shannon/Nyquist [2].

The other thing is that we guess the Equation Group stuff is widely in use and if I would be the CIA (not NSA) I would also place an RF module in the Harddisk, to be as near as possible at the data they want to steal or delete. Or probably the Equation Group Firmware makes some side channel noise that could be fetched with tempest [3,4], where it could be red from the disk directly.

/home/$user/.pamus/*

Any idea about this sort of problems?

[1] https://www.youtube.com/watch?v=vtQ7LNeC8Cs
[2] https://en.wikipedia.org/wiki/Nyquist%E2%80%93Shannon_sampling_theorem
[3] https://en.wikipedia.org/wiki/Tempest_%28codename%29
[4] https://www.youtube.com/watch?v=oLQbp6hj7-c

With Kind regards
Marc Landolt jr.
dipl Informatiker HF
Rombachtäli 13
5022 Rombach
+41 79 291 07 87
mail@marclandolt.ch
www.marclandolt.ch
https://twitter.com/FailDef

Related Articles:
http://marclandolt.ch/ml_buzzernet/2015/07/25/anfrage-an-tierarzt-fur-rfid-authentication/
http://marclandolt.ch/ml_buzzernet/2015/07/17/xen-4-4-auf-debian-jessie/

[Update]
Could that be found out if i would protocol all the system calls, so i would see if something like AX.25 with low bandwith would enable eg. the Wireless interface without telling me?

Leave a comment

Ihre E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert