zlacker

[return to "Toward a Reasonably Secure Laptop"]
1. HugoDa+bg[view] [source] 2017-07-11 14:05:02
>>doener+(OP)
"Finally, we are going to require that Qubes-certified hardware does not have any built-in USB-connected microphones (e.g. as part of a USB-connected built-in camera) that cannot be easily physically disabled by the user, e.g. via a convenient mechanical switch. However, it should be noted that the majority of laptops on the market that we have seen satisfy this condition out of the box, because their built-in microphones are typically connected to the internal audio device, which itself is a PCIe type of device. This is important, because such PCIe audio devices are – by default – assigned to Qubes’ (trusted) dom0 and exposed through our carefully designed protocol only to select AppVMs when the user explicitly chooses to do so."

This made me download Qubes. Amazing project that seems to care.

◧◩
2. pmoria+pv[view] [source] 2017-07-11 15:53:47
>>HugoDa+bg
I personally would not trust any laptop with an internal microphone at all.

If a laptop does have an internal microphone, I just assume it is on and recording.

◧◩◪
3. alasda+4y[view] [source] 2017-07-11 16:13:04
>>pmoria+pv
What about one with a hardware switch for the mic?
◧◩◪◨
4. pmoria+Gy[view] [source] 2017-07-11 16:17:38
>>alasda+4y
Do any such laptops actually exist?

Anyway, I'm not going to take the laptop apart and analyze the internal microphone hardware to make sure that the switch actually disables the mic. So even in that case, I'd assume the mic was still on even if the switch was in the off position.

On the other hand, I'd prefer to buy a laptop with a hardware switch for the internal microphone, if one existed, as it's better to have such a switch in case it actually does work as advertised.

◧◩◪◨⬒
5. CaptSp+cD[view] [source] 2017-07-11 16:45:09
>>pmoria+Gy
> https://puri.sm/posts/camera-microphone-hardware-kill-switch...

The purism laptops do, but afaik, they are the only ones.

[go to top]