Snooping TV.

Mar 10, 2017 282 Replies

Some remotes do have a mic in them. I have one for the tv/sat and the Wii ones have mics. And they all have RF connections, a spy would be ecstatic (and very bored).

So why do you keep making stuff up about how its impossible to do stuff so I have to show that it is?

And that is the only reason why you think spys can't do the things I said.

You keep saying the stuff is impossible, I have to correct you. Then you try and BS about it being impossible for a different reason.

Lets see on mine.. The disk drive individual usb ports the keyboard back light the ethernet chip the wifi chip the screen back light half of the CPU and probably other stuff

I have been to bed and the software has updated without waking me up.

That is what is being discussed!

But you don't - that's the point.

All you've said is such and such is practicable, but is banned by the unions. ;-)

You seem to be suggesting a system where a unique public key pair is used to allow the device to verify the authenticity of code updates without replying on signed binaries and the more commonly used systems for establishing trust in these circumstances.

The difficulty with those types of systems is that they fall about in a heap the moment the private key is compromised. As nicely demonstrated by the CSS system applied to DVDs.

The old adage about every engineer can conceive of a crypto system that they could not themselves break, it perhaps worth keeping in mind.

Also, reading more deeply on the subject, this does indeed appear to be the use case that the CIA/NSA devised for this particular hack.

i.e. they wanted their own back door introduced into the system.

You need to put your TV in the bathroom and put the shower on or have water flowing, easy when you know how to foil these spies ;-)

Friends have samsung and have never activate the speech thing I wonder if that measn it's NOT or can't listen.

Maybe they have male and female modes.

Male listen only female talk only :-)

All of which to help with battery life.

Domestic TVs normally run off the mains only. And most don't leave them powered up when not using them - unlike a computer.

Laptops (like most PCs) have a number of discrete power states:

formatting link

However the control is *far* more fine grained than that. The power management controller will typically control a multitude of individual rails - combinations of which will need to be switched for any given power state (laptops are much more complex than desktops in this respect since they also have to allow multiple power sources as well as deal with charging). Quite often there is a logic chain that will detect and prove one bit of circuitry before powering the next. That allows for more comprehensive fault reporting.

True, but you can get off the shelf power management controllers that do much of the grunt work for you. It may cost you a bit more at board layout time, but not a large change to the BoM once into production.

Yup. Mine certainly does timed recordings without turning the screen or audio on.

Custom software would need to be written at least for each individual platform, and possibly even tuned for individual sets.

The 2014 hack that was described in the leak, was for a particular range or possibly even model of set from 2013.

I am not sure what you are referring to as signed binaries

my understanding of signed binaries is to make sure that what you have received is what was sent, so that you don't try and load accidentally faulty code

the "encryption" used to make sure that the download is authentic, lies above that

I understand that this is the weak link

but I also *know* that it is the technique used to control downloads of software in some safety critical applications - applications where the acceptance of hacked code could kill someone (if that were the intention of the hacker)

I have no idea how the holder of that key makes sure it remains secure, I was only working on the public end.

tis difficult to come up with any scheme that cannot be broken by a rogue employee revealing the secret formula

tim

timing

Echo cancellation, as in mics and speakers in the same box, only needs event sync. Simple enough to match the wave forms between incoming stream and that coming back from the mic(s) to maximise cancelation. There is no need to make an absolute measurement that a ToA range finding system would require.

Yes and you asked for what reason?

Why are you still going on about what's powered up on a TV?

You have said array mics work, I have posted links to where you can buy laser mics others have said how you can hack TVs what exactly are you claiming I have said that's impossible now?

You're the only one to mention bans by unions.

Been done....

formatting link

:-)

Are you really that incapable of following a discussion?

Why are you on about anything?

Sigh. Thanks for confirming you can't even remember what you posted. Here's a reminder:-

From: dennis@home Subject: Re: Snooping TV. Date: Sat, 11 Mar 2017 12:50 Newsgroups: uk.d-i-y

Do you think the unions would allow half the crew to be sacked?

No, that would just be a checksum, or possibly a cryptographic hash like a MD5 checksum.

This is normally done with digital certification and a secured communications channel. The initial part of the secure session establishment will typically use public key cryptography (even if a higher performance symmetric algorithm is used once a secure key exchange can be done). The key pairs will be created on the fly. The digital signature is issued by a certification authority to guarantee that a public key paid is actually owned by who it claims to be owned by.

So using this approach you get a good combination of protections without needing any hard coded keys that could be compromised, and you also get to verify you are actually talking to the right endpoint, and eliminate the potential for impersonation or "man in the middle" attacks.

(Its the way web based https or other SSL channels connections are established example).

Plenty more on it here:

formatting link
and
formatting link

That's why modern systems will often use one time key pairs to initiate the channel. Once the connection is done with, the old keys are of no further value.

The whole point of decent encryption is that there should be no secret stuff. The whole algorithm should be open and freely available. Any form of "security by obscurity" always fails.

They use an adaptive finite impulse response filter where all the filter coefficients can be varied. Once adaptation has completed the filter has an impulse response which is the complement of the impulse response of the speaker + room + microphone. If something changes, like a person moving around, there will be a slight echo that gradually disappears as re-adaptation takes place. The filter needs enough taps to delay the audio by a time corresponding to the reverberation time of the room in order to get "complete" cancellation. John

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required