zlacker

[return to "Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230"]
1. sbarre+T1[view] [source] 2024-11-27 20:27:36
>>xairy+(OP)
I thought the whole point of these camera LEDs was to have them wired to/through the power to the camera, so they are always on when the camera is getting power, no matter what.

Having the LED control exposed through the firmware completely defeats this.

◧◩
2. 542458+96[view] [source] 2024-11-27 20:54:08
>>sbarre+T1
They are hardwired on Macbooks. From Daring Fireball, quoting an email from an Apple engineer.

> All cameras after [2008] were different: The hardware team tied the LED to a hardware signal from the sensor: If the (I believe) vertical sync was active, the LED would light up. There is NO firmware control to disable/enable the LED. The actual firmware is indeed flashable, but the part is not a generic part and there are mechanisms in place to verify the image being flashed. […]

> So, no, I don’t believe that malware could be installed to enable the camera without lighting the LED. My concern would be a situation where a frame is captured so the LED is lit only for a very brief period of time.

https://daringfireball.net/2019/02/on_covering_webcams

◧◩◪
3. nine_k+YR[view] [source] 2024-11-28 05:05:19
>>542458+96
That's backwards.

The LED should be connected to camera's power, or maybe camera's "enable" signal. It should not be operable via any firmware in any way.

The led also has to be connected through a one-shot trigger (a transistor + a capacitor) so that it would light up, say, for at least 500 ms no matter how short the input pulse is. This would prevent making single shots hard to notice.

Doing that, of course, would incur a few cents more in BOM, and quite a bit more in being paranoid, well, I mean, customer-centric.

◧◩◪◨
4. jdblai+BY[view] [source] 2024-11-28 06:52:44
>>nine_k+YR
or, you can have a physical switch, like the Framework. that also hits your BOM but its not complex!
◧◩◪◨⬒
5. onesht+q21[view] [source] 2024-11-28 07:29:53
>>jdblai+BY
You can buy/print and stick a physical «webcam cover»[1] manually on your notebook or phone.

My current notebook, manufactured in 2023, has very thin bar on top of screen with camera, so I need a thin, U-like attachment for the switch, which is hard to find.

[1]: https://www.printables.com/model/2479-webcam-cover-slider

◧◩◪◨⬒⬓
6. ddalex+R31[view] [source] 2024-11-28 07:46:33
>>onesht+q21
Am I the only one that is not worried at all about the camera and super concerned about microphones ? The camera may see me staring into the screen, woo hoo. The microphones will hear everything I discuss, incl. confidential information.

There is no physical microphone cover there, is it ?

◧◩◪◨⬒⬓⬔
7. dghugh+LE1[view] [source] 2024-11-28 14:50:57
>>ddalex+R31
And the true or not Google or other apps listening then you see ads based on that conversation. I think it's true since far too many times obscure things I've spoken about appear in ads soon after the conversation. So yes I'd say a mic blocking feature you can confirm is working, blocking, is needed.
◧◩◪◨⬒⬓⬔⧯
8. ch4s3+vG1[view] [source] 2024-11-28 15:08:24
>>dghugh+LE1
> I think it's true since far too many times obscure things I've spoken about appear in ads soon after the conversation

People have been making claims like this since at least the early 90s, about TV then, and no one ever credibly claims to have worked on something like this. I've worked with purchased ad data and I've never seen this data or anything that implies that it exists. It seems far more likely that its a trick of memory. You ignore most ads you see, but you remember ones that relate to odd topics that interest you.

◧◩◪◨⬒⬓⬔⧯▣
9. wsintr+7K1[view] [source] 2024-11-28 15:36:48
>>ch4s3+vG1
I agree with this sentiment, people talk about x product then realise they are seeing ads for x product. Most likely the ads were there first and the people only start talking about it cause the ads have been working.
◧◩◪◨⬒⬓⬔⧯▣▦
10. ch4s3+6S1[view] [source] 2024-11-28 16:25:15
>>wsintr+7K1
That’s pretty much it. You see an obscure ad without realizing it and have a related conversation later. Then when you see the ad again and make note of it, it feels strange.
[go to top]